Wordfence Intelligence Weekly WordPress Vulnerability Report (January 12, 2026 to January 18, 2026)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 170 vulnerabilities disclosed in 123 WordPress Plugins and 37 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 68 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 32,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 62
Unpatched 108

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 2
Medium Severity 108
High Severity 46
Critical Severity 14

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 50
Missing Authorization 37
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 17
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 10
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 9
Unrestricted Upload of File with Dangerous Type 9
Deserialization of Untrusted Data 7
Cross-Site Request Forgery (CSRF) 6
Exposure of Sensitive Information to an Unauthorized Actor 5
Improper Privilege Management 3
Server-Side Request Forgery (SSRF) 3
Authentication Bypass Using an Alternate Path or Channel 2
Authorization Bypass Through User-Controlled Key 2
Incorrect Authorization 2
Client-Side Enforcement of Server-Side Security 1
Improper Control of Generation of Code (‘Code Injection’) 1
Improper Input Validation 1
Improper Restriction of XML External Entity Reference 1
Incorrect Privilege Assignment 1
Insufficient Verification of Data Authenticity 1
Missing Authentication for Critical Function 1
Relative Path Traversal 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
36
11
9
8
6
5
5
5
4
4
4
3
3
3

Os
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Accordion Slider PRO accordion_slider_pro
Advanced Ads – Ad Manager & AdSense advanced-ads
AffiliateX – Amazon Affiliate Plugin affiliatex
AJS Footnotes ajs-footnotes
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic all-in-one-seo-pack
All-in-One Video Gallery all-in-one-video-gallery
Antideo Email Validator antideo-email-validator
Aplazo Payment Gateway aplazo-payment-gateway
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments
Awesome Support – WordPress HelpDesk & Support Plugin awesome-support
bidorbuy Store Integrator bidorbuystoreintegrator
Booking Calendar booking
Breeze Cache breeze
Church Admin church-admin
CleverReach® WP cleverreach-wp
CM E-Mail Blacklist – Simple email filtering for safer registration cm-email-blacklist
Community Events community-events
Cost Calculator Builder cost-calculator-builder
CP Image Store with Slideshow cp-image-store
Crush.pics Image Optimizer – Image Compression and Optimization crush-pics
CubeWP Framework cubewp-framework
DASHBOARD BUILDER – WordPress plugin for Charts and Graphs dashboard-builder
Demo Importer Plus demo-importer-plus
DK PDF – WordPress PDF Generator dk-pdf
Dooodl dooodl
Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7
DZS Video Gallery dzs-videogallery
Electric Studio Download Counter electric-studio-download-counter
Eli’s WordCents adSense Widget with Analytics wordcents
Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite
Event Espresso – Event Registration & Ticketing Sales event-espresso-decaf
Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner
EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management
Filr – Secure document library filr-protection
Float Payment Gateway float-gateway
g-FFL Checkout g-ffl-checkout
GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation geeky-bot
GetContentFromURL getcontentfromurl
GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools getgenie
Gotham Block Extra Light gotham-block-extra-light
HDForms | Contact Form Builder hdforms
Hide My WP – Amazing Security Plugin for WordPress! hide_my_wp
Infility Global infility-global
Integrate Dynamics 365 CRM integrate-dynamics-365-crm
Integration Opvius AI for WooCommerce woosa-ai-for-woocommerce
Internal Link Builder internal-link-builder
JNews – Frontend Submit jnews-frontend-submit
JNews – Pay Writer jnews-pay-writer
JNews – Video jnews-video
Jupiter X Core jupiterx-core
Kunze Law kunze-law
LEAV Last Email Address Validator last-email-address-validator
LinkedIn SC linkedin-sc
List Site Contributors list-site-contributors
LottieFiles – Lottie block for Gutenberg lottiefiles
Makesweat makesweat
Membership Plugin – Restrict Content restrict-content
Modular DS: Monitor, update, and backup multiple websites modular-connector
Name Directory name-directory
Netcash WooCommerce Payment Gateway netcash-pay-now-payment-gateway-for-woocommerce
News and Blog Designer Bundle news-and-blog-designer-bundle
Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto codistoconnect
onepay Payment Gateway For WooCommerce onepay-payment-gateway-for-woocommerce
PAYGENT for WooCommerce woocommerce-for-paygent-payment-main
PayHere Payment Gateway payhere-payment-gateway
Payment Button for PayPal wp-paypal
PDF Resume Parser pdf-resume-parser
Peach Payments Gateway wc-peach-payments-gateway
Perfit WooCommerce perfit-woocommerce
Phrase TMS Integration for WordPress memsource-connector
Quick Contact Form quick-contact-form
Quote Master quote-master
Real Post Slider Lite real-post-slider-lite
Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit woo-rede
Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login custom-registration-form-builder-with-submission-manager
Related Posts by Taxonomy related-posts-by-taxonomy
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress computer-repair-shop
Reservation Plugin dt-reservation-plugin
Responsive Accordion Slider responsive-accordion-slider
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates responsive-addons-for-elementor
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging wp-rss-aggregator
SearchWiz searchwiz
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches wp-simple-firewall
Shipping Rate By Cities shipping-rate-by-cities
Shipping Rates by City for WooCommerce flat-shipping-rate-by-city-for-woocommerce
Short Link short-link
Shown Connector shown-connector
SocialChamp with WordPress auto-post-to-social-media-wp-to-social-champ
Sosh Share Buttons sosh-share-buttons
SpiceForms Form Builder spiceforms-form-builder
Spin Wheel – Interactive spinning wheel that offers coupons spin-wheel
Stopwords for comments stopwords-for-comments
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder supreme-modules-for-divi
Synergy Project Manager synergy-project-manager
Syntax Highlighter Compress syntax-highlighter-compress
Team Section Block – Showcase Team Members with Layout Options team-section
Testimonials Creator testimonials-creator
Thim Blocks thim-blocks
Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system
Tutor LMS Pro tutor-pro
UiChemy — Figma Converter for Elementor, Gutenberg and Bricks uichemy
User Registration Using Contact Form 7 user-registration-using-contact-form-7
User Submitted Posts – Enable Users to Submit Posts from the Front End user-submitted-posts
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments wallet-system-for-woocommerce
WDV One Page Docs – Documentation Plugin for WordPress wdv-one-page-docs
WMF Mobile Redirector wmf-mobile-redirector
Woocommerce Book Price woo-book-price
WooCommerce Frontend Manager – Ultimate wc-frontend-manager-ultimate
Workreap Core workreap_core
WP Allowed Hosts wp-allow-hosts
WP Duplicate Page wp-duplicate-page
WP Hotel Booking wp-hotel-booking
WP Lead Capturing Pages wp-lead-capture
WP Mail wp-mail
WP Simple Redirect wp-simple-redirect
WP Test Email wp-test-email
WP-CRM System – Manage Clients and Projects wp-crm-system
WP-Members Membership Plugin wp-members
WPBlogSyn wpblogsync
WPLMS Plugin wplms_plugin
xPromoter top_bar_promoter
YouTube Feed Pro youtube-feed-pro

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Anon – Multipurpose Elementor WooCommerce Themes anon2x
Anona – Pest Control WordPress Theme anona
Auto Repair auto-repair
AutoParts – Car Parts Store WordPress Theme autoparts
bajaar bajaar
Barberry – Modern WooCommerce Theme barberry
Biagiotti biagiotti
Blogistic blogistic
Blogzee blogzee
Brookside brookside
Consult Aid: Business Consulting And Finance PSD consultaid
Dreamer Blog dreamer-blog
Drone Media | Aerial Photography & Videography Theme drone
electron electron
Energia – Renewable Energy WordPress Theme energia
Hostme v2 – Responsive WordPress Theme hostmev2
Kalium 3 | Creative WordPress & WooCommerce Theme kalium
KenthaRadio – Addon for Kentha Music WordPress Theme To Add Radio Station and Schedule Functionality qt-kentharadio
Kids Heaven – Children Education WordPress Theme kids-world
Melania | Blog about Handmade & Crafts WordPress Theme + Shop melania
Mella – Minimalist Ajax eCommerce PSD Template mella
Miion | Multi-Purpose WordPress Theme miion
Myour – Personal Portfolio Resume WordPress Theme myour
North – One Page Parallax WordPress Theme north-wp
OneLife – Medical WordPress Theme onelife
Powerlift – Fitness and Gym WordPress Theme powerlift
Promo promo
Reprizo – Jewelry & Watch Store Shopify Theme reprizo
Restaurt restaurt
Right Way | Election Campaign and Political Candidate WordPress Theme rightway
Search & Go – Directory WordPress Theme search-and-go
Skillate skillate
Solace solace
The Aisle – Elegant Wedding WordPress Theme theaisle
TheNa – Photography & Portfolio WordPress Theme thena
Wedding Photographer WordPress Theme – Vivagh vivagh
xSmart – App Landing Page WordPress Theme in Tech Presentation, Promo Marketing & Advertising Agency xsmart

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-50002
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-68015
Patch Status
Unpatched
Published
Jan 15, 2026
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-68001
Patch Status
Patched
Published
Jan 15, 2026
Affected Software
g-FFL Checkout
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-14301
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2026-23800
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2026-23550
Patch Status
Patched
Published
Jan 14, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-14502
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-10484
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-15403
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-69101
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
Workreap Core
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-68901
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-68912
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
HDForms | Contact Form Builder
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-68907
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-69097
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12957
Patch Status
Patched
Published
Jan 15, 2026
Affected Software
All-in-One Video Gallery
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-68909
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Blogistic
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-68910
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Blogzee
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-68986
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (8.8)
CVE-ID
CVE-2026-22327
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Restaurt
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22331
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69004
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
bajaar
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-68908
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67938
Patch Status
Patched
Published
Jan 15, 2026
Affected Software
Biagiotti
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67617
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22324
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67616
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67615
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69100
Patch Status
Unpatched
Published
Jan 15, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67940
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22325
Patch Status
Unpatched
Published
Jan 12, 2026
Affected Software
Promo
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22326
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2026-22330
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69005
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67941
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68903
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68902
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68017
Patch Status
Unpatched
Published
Jan 16, 2026
Affected Software
Antideo Email Validator
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68034
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
CleverReach® WP
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-14478
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Demo Importer Plus
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68905
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
JNews – Pay Writer
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-50004
Patch Status
Patched
Published
Jan 12, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-67619
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68913
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-69099
Patch Status
Unpatched
Published
Jan 15, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-69002
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-14770
Patch Status
Patched
Published
Jan 13, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-22332
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Tutor LMS Pro
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-68899
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-15378
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
AJS Footnotes
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-14613
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
GetContentFromURL
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-68864
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
Infility Global
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-15283
Patch Status
Patched
Published
Jan 13, 2026
Affected Software
Name Directory
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-68898
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
Synergy Project Manager
CVSS Rating
High (7.1)
CVE-ID
CVE-2025-14615
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-49049
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-68007
Patch Status
Unpatched
Published
Jan 15, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-15020
Patch Status
Patched
Published
Jan 13, 2026
Affected Software
Gotham Block Extra Light
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-13725
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Thim Blocks
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-49050
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2026-22334
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
Woocommerce Book Price
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2026-22335
Patch Status
Unpatched
Published
Jan 15, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8615
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
CubeWP Framework
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12178
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
SpiceForms Form Builder
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-69362
Patch Status
Patched
Published
Jan 12, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49066
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67620
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2026-22328
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Auto Repair
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68883
Patch Status
Unpatched
Published
Jan 16, 2026
Affected Software
bidorbuy Store Integrator
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67618
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Brookside
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68871
Patch Status
Unpatched
Published
Jan 16, 2026
Affected Software
Dooodl
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49249
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68872
Patch Status
Unpatched
Published
Jan 16, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69098
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68904
Patch Status
Unpatched
Published
Jan 12, 2026
Affected Software
JNews – Frontend Submit
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68906
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
JNews – Video
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69003
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2026-0594
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
List Site Contributors
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68008
Patch Status
Unpatched
Published
Jan 16, 2026
Affected Software
WP Mail
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68849
Patch Status
Unpatched
Published
Jan 16, 2026
Affected Software
Quote Master
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68884
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
WP Simple Redirect
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2026-22329
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Skillate
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-68859
Patch Status
Unpatched
Published
Jan 16, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-69102
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
WP Test Email
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67614
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49046
Patch Status
Unpatched
Published
Jan 12, 2026
Affected Software
xPromoter
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-50006
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Medium (5.9)
CVE-ID
CVE-2025-12002
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
YouTube Feed Pro
Researcher
CVSS Rating
Medium (5.8)
CVE-ID
CVE-2025-12718
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-14001
Patch Status
Patched
Published
Jan 12, 2026
Affected Software
WP Duplicate Page
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-15512
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69364
Patch Status
Patched
Published
Jan 13, 2026
Affected Software
Breeze Cache
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14029
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Community Events
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14757
Patch Status
Patched
Published
Jan 15, 2026
Affected Software
Cost Calculator Builder
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12129
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
CubeWP Framework
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-15513
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12895
Patch Status
Patched
Published
Jan 15, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-0717
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68016
Patch Status
Patched
Published
Jan 16, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14078
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
PAYGENT for WooCommerce
Researchers
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14463
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14464
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
PDF Resume Parser
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67942
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Peach Payments Gateway
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14173
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Perfit WooCommerce
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69095
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Reservation Plugin
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68003
Patch Status
Unpatched
Published
Jan 15, 2026
Affected Software
Shown Connector
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-0808
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12825
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68896
Patch Status
Unpatched
Published
Jan 15, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14075
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
WP Hotel Booking
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-12984
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2026-0678
Patch Status
Unpatched
Published
Jan 13, 2026
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0741
Patch Status
Unpatched
Published
Jan 13, 2026
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14632
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-15021
Patch Status
Patched
Published
Jan 13, 2026
Affected Software
Gotham Block Extra Light
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0725
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Integrate Dynamics 365 CRM
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14725
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Internal Link Builder
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-15486
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Kunze Law
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0812
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
LinkedIn SC
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-13627
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Makesweat
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0680
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Real Post Slider Lite
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0813
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Short Link
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14379
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Testimonials Creator
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0739
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
WMF Mobile Redirector
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2026-0734
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
WP Allowed Hosts
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14982
Patch Status
Patched
Published
Jan 15, 2026
Affected Software
Booking Calendar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-0684
Patch Status
Patched
Published
Jan 12, 2026
Affected Software
CP Image Store with Slideshow
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-10915
Patch Status
Unpatched
Published
Jan 14, 2026
Affected Software
Dreamer Blog
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-5805
Patch Status
Unpatched
Published
Jan 12, 2026
Affected Software
electron
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14853
Patch Status
Unpatched
Published
Jan 15, 2026
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12168
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14846
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
SocialChamp with WordPress
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68911
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Solace
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-15377
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Sosh Share Buttons
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-15376
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
Stopwords for comments
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67939
Patch Status
Patched
Published
Jan 16, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14389
Patch Status
Unpatched
Published
Jan 13, 2026
Affected Software
WPBlogSyn
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54002
Patch Status
Unpatched
Published
Jan 12, 2026
CVSS Rating
Low (2.2)
CVE-ID
CVE-2026-0682
Patch Status
Patched
Published
Jan 16, 2026
Affected Software
Church Admin
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (January 12, 2026 to January 18, 2026) appeared first on Wordfence.

Leave a Comment