Wordfence Intelligence Weekly WordPress Vulnerability Report (July 28, 2025 to August 3, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through September 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

💉 Participate in the SQLsplorer Challenge! Now through September 22, 2025, all SQL Injection vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier AND earn a 20% bonus on all SQL Injection vulnerability submissions.


Last week, there were 107 vulnerabilities disclosed in 91 WordPress Plugins and 8 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 43 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 28,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 86
Unpatched 21

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 74
High Severity 26
Critical Severity 7

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 42
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 12
Missing Authorization 12
Cross-Site Request Forgery (CSRF) 9
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 4
Deserialization of Untrusted Data 3
Exposure of Sensitive Information to an Unauthorized Actor 3
Unrestricted Upload of File with Dangerous Type 3
Authorization Bypass Through User-Controlled Key 2
Improper Privilege Management 2
Incorrect Privilege Assignment 2
Absolute Path Traversal 1
Authentication Bypass Using an Alternate Path or Channel 1
Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) 1
Improper Authorization 1
Improper Control of Generation of Code (‘Code Injection’) 1
Incorrect Authorization 1
Server-Side Request Forgery (SSRF) 1
URL Redirection to Untrusted Site (‘Open Redirect’) 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
9
8
8
8
5
4
4
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Bao
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
360 Photo Spheres 360-sphere-images
Advanced Google Universal Analytics advanced-google-universal-analytics
AI Engine ai-engine
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier aio-time-clock-lite
Appointment Booking Plugin for WordPress | Efficient Booking, Calendar & Client Scheduling – Bookify bookify
BeeTeam368 Extensions beeteam368-extensions
BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript searchpro
BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security bitfire
BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed blockspare
Bonanza – WooCommerce Free Gifts Lite bonanza-woocommerce-free-gifts-lite
Brave Conversion Engine (PRO) bravepopup-pro
Brizy – Page Builder brizy
BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field
Button Block – Get fully customizable & multi-functional buttons button-block
Chartify – WordPress Chart Plugin chart-builder
Classified Listing – Classified ads & Business Directory Plugin classified-listing
Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets
Content Egg content-egg
Custom API for WP custom-api-for-wp
Custom Word Cloud custom-word-cloud
Customer Reviews for WooCommerce customer-reviews-woocommerce
DELUCKS SEO delucks-seo
Easiest Funnel Builder For WordPress & WooCommerce, Specialized For Digital Creators – WPFunnels wpfunnels
Easy Elementor Addons easy-elementor-addons
Ebook Store ebook-store
Elementor Website Builder – More Than Just a Page Builder elementor
Event Booking Manager for WooCommerce – WpEvently mage-eventpress
Fan Page fan-page
File Manager for Google Drive – Integrate Google Drive with WordPress integrate-google-drive
GiveWP – Donation Plugin and Fundraising Platform give
Google Map Targeting gmap-targeting
Graphina – Elementor Charts and Graphs graphina-elementor-charts-and-graphs
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks advanced-gutenberg
HT Mega – Absolute Addons For Elementor ht-mega-for-elementor
Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings hydra-booking
IDonate – Blood Donation, Request And Donor Management System idonate
Image Gallery bee-quick-gallery
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-constant-contact
JetEngine jet-engine
JetTabs jet-tabs
Magic Edge – Lite magic-edge-lite-image-background-remover
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) magical-addons-for-elementor
Magical Posts Display – Elementor Advanced Posts widgets magical-posts-display
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education learning-management-system
Medical Addon for Elementor medical-addon-for-elementor
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor metform
Mmm Unity Loader mmm-unity-loader
Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. mycred
Newsletters newsletters-lite
NinjaScanner – Virus & Malware scan ninjascanner
Ocean Social Sharing ocean-social-sharing
oik oik
Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
Photo Engine (Media Organizer & Lightroom) wplr-sync
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI contest-gallery
PressForward pressforward
Product Configurator for WooCommerce product-configurator-for-woocommerce
Product XML Feed Manager for WooCommerce – Google Shopping, Social Sites, Skroutz & More product-xml-feeds-for-woocommerce
Qi Addons For Elementor qi-addons-for-elementor
Realtyna Organic IDX plugin + WPL Real Estate real-estate-listing-realtyna-wpl
RT-Theme 18 Responsive WordPress Theme rt18-extensions
SEO Metrics seo-metrics-helper
Service Finder Bookings sf-booking
Service Finder SMS System aone-sms
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization shortpixel-adaptive-images
Simple File List simple-file-list
Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) sina-extension-for-elementor
Sky Addons – Elementor Addons with Widgets & Templates sky-elementor-addons
Smart Slider 3 smart-slider-3
StoreKeeper for WooCommerce storekeeper-for-woocommerce
Stratum – Elementor Widgets stratum
StreamWeasels Kick Integration streamweasels-kick-integration
StreamWeasels Twitch Integration streamweasels-twitch-integration
StreamWeasels YouTube Integration streamweasels-youtube-integration
Super Store Finder superstorefinder-wp
Supermalink supermalink
SureDash suredash
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce the-plus-addons-for-elementor-page-builder
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) header-footer-elementor
Woffice Core woffice-core
woozone-contextual woozone-contextual
WordPress Booking Plugin – TheBooking thebooking
WordPress Image Gallery Plugin – WordPress Photo Gallery cubeportfolio
WP CTA easy-sticky-sidebar
WP LOL Rotation league-of-legends-rotation
WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration
WP REST Cache wp-rest-cache
YITH WooCommerce Popup yith-woocommerce-popup
YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin youram-youtube-embed

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Appzend appzend
Blogger Buzz blogger-buzz
Bricks bricks
Cook&Meal – Food Blog & Recipe WordPress Theme cookandmeal
Druco – Elementor WooCommerce WordPress Theme druco
Exertio – Freelance Marketplace WordPress Theme exertio
MediCenter – Health Medical Clinic WordPress Theme medicenter
News Magazine X news-magazine-x

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-7710
Patch Status
Patched
Published
Aug 1, 2025
Affected Software
Brave Conversion Engine (PRO)
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-48332
Patch Status
Patched
Published
Jul 28, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-32288
Patch Status
Unpatched
Published
Jul 28, 2025
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-5947
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
Service Finder Bookings
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-5954
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
Service Finder SMS System
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-48148
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
StoreKeeper for WooCommerce
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2025-48158
Patch Status
Patched
Published
Jul 31, 2025
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-7847
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
AI Engine
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-54049
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
Custom API for WP
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-48165
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
DELUCKS SEO
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-6754
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
SEO Metrics
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-48164
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
SureDash
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-25174
Patch Status
Unpatched
Published
Jul 30, 2025
Affected Software
BeeTeam368 Extensions
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-48149
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-54686
Patch Status
Patched
Published
Jul 31, 2025
CVSS Rating
High (8.1)
CVE-ID
Unknown
Patch Status
Unpatched
Published
Jul 28, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-54014
Patch Status
Patched
Published
Jul 28, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-24766
Patch Status
Unpatched
Published
Jul 28, 2025
Affected Software
News Magazine X
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-54034
Patch Status
Patched
Published
Jul 29, 2025
Affected Software
Newsletters
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-54052
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52716
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
WP REST Cache
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-30633
Patch Status
Unpatched
Published
Jul 31, 2025
Affected Software
woozone-contextual
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-6495
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
Bricks
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52732
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
Google Map Targeting
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52720
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
Super Store Finder
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-8213
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (6.8)
CVE-ID
CVE-2025-7694
Patch Status
Patched
Published
Aug 1, 2025
Affected Software
Woffice Core
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-47536
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
Content Egg
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-52823
Patch Status
Unpatched
Published
Jul 31, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4588
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
360 Photo Spheres
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-5587
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
Appzend
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54680
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
Blogger Buzz
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8317
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
Custom Word Cloud
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-5720
Patch Status
Patched
Published
Jul 30, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54704
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
Easy Elementor Addons
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-3075
Patch Status
Patched
Published
Jul 28, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4566
Patch Status
Patched
Published
Jul 28, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6681
Patch Status
Unpatched
Published
Jul 28, 2025
Affected Software
Fan Page
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54688
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
JetEngine
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54687
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
JetTabs
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8391
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
Magic Edge – Lite
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54706
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-54699
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8212
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
Medical Addon for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8399
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
Mmm Unity Loader
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-7500
Patch Status
Patched
Published
Aug 1, 2025
Affected Software
Ocean Social Sharing
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-28987
Patch Status
Unpatched
Published
Jul 31, 2025
Affected Software
PressForward
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8146
Patch Status
Patched
Published
Aug 1, 2025
Affected Software
Qi Addons For Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-7809
Patch Status
Patched
Published
Jul 28, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-7811
Patch Status
Patched
Published
Jul 28, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49433
Patch Status
Unpatched
Published
Jul 28, 2025
Affected Software
Supermalink
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49437
Patch Status
Unpatched
Published
Jul 29, 2025
Affected Software
WP LOL Rotation
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6692
Patch Status
Unpatched
Published
Jul 28, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-54681
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-54055
Patch Status
Patched
Published
Aug 2, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-8400
Patch Status
Unpatched
Published
Aug 1, 2025
Affected Software
Image Gallery
Researcher
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2025-54683
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-7810
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
StreamWeasels Kick Integration
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-6722
Patch Status
Patched
Published
Aug 1, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-4370
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
Brizy – Page Builder
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-54691
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-54021
Patch Status
Patched
Published
Jul 28, 2025
Affected Software
Simple File List
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-52801
Patch Status
Unpatched
Published
Jul 30, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-8152
Patch Status
Patched
Published
Aug 1, 2025
Affected Software
WP CTA
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-6348
Patch Status
Patched
Published
Jul 29, 2025
Affected Software
Smart Slider 3
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-28962
Patch Status
Unpatched
Published
Jul 28, 2025
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-6730
Patch Status
Unpatched
Published
Jul 28, 2025
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54694
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54673
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54698
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54682
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54702
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
Ebook Store
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-8401
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54695
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54703
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54671
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
oik
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54672
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54674
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54685
Patch Status
Patched
Published
Jul 31, 2025
Affected Software
SureDash
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54705
Patch Status
Patched
Published
Jul 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54675
Patch Status
Patched
Published
Jul 30, 2025
Affected Software
YITH WooCommerce Popup
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 28, 2025 to August 3, 2025) appeared first on Wordfence.

Leave a Comment