Wordfence Intelligence Weekly WordPress Vulnerability Report (January 5, 2026 to January 11, 2026)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 264 vulnerabilities disclosed in 214 WordPress Plugins and 31 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 78 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 32,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

      • WAF-RULE-885 – Data redacted while we work with the vendor on a patch.
      • WAF-RULE-886 – Data redacted while we work with the vendor on a patch.

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 134
Unpatched 130

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 210
High Severity 48
Critical Severity 5

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 97
Missing Authorization 70
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 25
Cross-Site Request Forgery (CSRF) 15
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 12
Authorization Bypass Through User-Controlled Key 8
Exposure of Sensitive Information to an Unauthorized Actor 8
Incorrect Authorization 5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 4
Server-Side Request Forgery (SSRF) 4
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 3
Unrestricted Upload of File with Dangerous Type 3
Improper Authorization 2
Improper Control of Generation of Code (‘Code Injection’) 2
External Control of File Name or Path 1
Files or Directories Accessible to External Parties 1
Improper Privilege Management 1
Missing Support for Integrity Check 1
Use of Insufficiently Random Values 1
Use of Less Trusted Source 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
24
21
13
12
11
9
9
9
9
8
7
7
6
6
6
6
6
5
5
5
4
4
4
4
4
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
1180px Shortcodes 1180px-shortcodes
AA Block country aa-block-country
aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder ablocks
Absolute Addons For Elementor absolute-addons
Accordions – Responsive Accordion & FAQ Plugin for WordPress accordions-wp
ACF to REST API acf-to-rest-api
AD Sliding FAQ ad-sliding-faq
AffiliateX – Amazon Affiliate Plugin affiliatex
AH Shortcodes ah-shortcodes
AI BotKit – AI Chatbot & Live Chat for WordPress (No-Code) ai-botkit-for-lead-generation
AMP for WP – Accelerated Mobile Pages accelerated-mobile-pages
Appointment Booking Calendar – WP Timetics Booking Plugin timetics
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments
AS Password Field In Default Registration Form as-password-field-in-default-registration-form
Autogen Headers Menu autogen-headers-menu
Automotive Listings automotive
Awesome Hotel Booking awesome-hotel-booking
BD Courier Order Ratio Checker bd-courier-order-ratio-checker
Better Business Reviews – Trustpilot WordPress Plugin better-business-reviews
BetterDocs – Knowledge Base Documentation & FAQ Solution for Elementor & Block Editor betterdocs
Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder bit-form
Block Slider – Responsive Image Slider, Video Slider & Post Slider block-slider
Blockons – Gutenberg blocks for WordPress and WooCommerce websites blockons
Blog2Social: Social Media Auto Post & Scheduler blog2social
Booking Calendar booking
Booking for Appointments and Events Calendar – Amelia ameliabooking
Breadcrumbs for Elementor – Crumber crumber-elementor
Brevo for WooCommerce woocommerce-sendinblue-newsletter-subscription
BuddyPress Xprofile Custom Field Types bp-xprofile-custom-field-types
Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO) bulk-image-alt-text-with-yoast
Bulk Page Generator – LPagery lpagery
BulletProof Security bulletproof-security
Campaign Monitor for WordPress forms-for-campaign-monitor
CBX Bookmark & Favorite cbxwpbookmark
Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer clearfy
Client Testimonial Slider wp-client-testimonial
Contact Form vCard Generator contact-form-vcard-generator
Contact Us Simple Form contact-us-simple-form
ConvertForce Popup Builder convertforce-popup-builder
Cookies and Content Security Policy cookies-and-content-security-policy
Cool YT Player cool-yt-player
Countdown Timer – Widget Countdown widget-countdown
CountDown With Image or Video Background countdown-with-background
Creator LMS – The LMS for Creators, Coaches, and Trainers creatorlms
Curved Text curved-text
Customer Reviews for WooCommerce customer-reviews-woocommerce
Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder
Debt.com Business in a Box debtcom-business-in-a-box
Demo Importer Plus demo-importer-plus
Depicter — Popup & Slider Builder depicter
Docket Cache – Object Cache Accelerator docket-cache
Download Manager download-manager
Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7
Easy Form Builder by WhiteStudio — Drag & Drop Form Builder easy-form-builder
Easy GitHub Gist Shortcodes easy-github-gist-shortcodes
Easy Media Download easy-media-download
EDD Download Info edd-download-info
eHive Search ehive-search
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder email-customizer-for-woocommerce
EmailKit – Email Customizer for WooCommerce & WP emailkit
Entry Views entry-views
Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) wp-event-solution
Famous – Responsive Image And Video Grid Gallery WordPress Plugin famous_grid_image_and_video_gallery
FastDup – Fastest WordPress Migration & Duplicator fastdup
Featured Image from URL (FIFU) featured-image-from-url
Felan Framework felan-framework
FireStorm Professional Real Estate Plugin fs-real-estate-plugin
Flashcard Plugin for WordPress flashcard
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
Fluent Support – Helpdesk & Customer Support Ticket System fluent-support
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager folders
Form Vibes – Database Manager for Forms form-vibes
Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator
ForumWP – Forum & Discussion Board forumwp
Frontend Admin by DynamiApps acf-frontend-form-element
FS Registration Password registration-password
GA4WP – Analytics Dashboard for the Website ga-for-wp
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress gamipress
GiveWP – Donation Plugin and Fundraising Platform give
Guest posting / Frontend Posting / Front Editor – WP Front User Submit front-editor
Gutenverse Form – Contact Form Builder, Booking, Reservation, Subscribe for Block Editor gutenverse-form
Handmade Framework handmade-framework
HBLPAY Payment Gateway for WooCommerce hblpay-payment-gateway-for-woocommerce
Header and Footer Scripts header-and-footer-scripts
HelpDesk Contact Form helpdesk-contact-form
HTML5 Video Player with Playlist & Multiple Skins lbg-vp2-html5-rightside
HTML5 Video Player WordPress Plugin lbg-vp2-html5-bottom
Icegram Engage – Popups, Optins, CTAs & lot more… icegram
ilGhera Support System for WooCommerce wc-support-system
Image Slider Slideshow image-slider-slideshow
Image&Video FullScreen Background lbg_fullscreen_fullwidth_slider
IMGspider – 图片采集抓取插件 imgspider
IndieWeb indieweb
iPaymu Payment Gateway for WooCommerce ipaymu-for-woocommerce
Japanized for WooCommerce woocommerce-for-japan
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress jeg-elementor-kit
JetEngine jet-engine
Key Figures key-figures
Latest Registered Users latest-registered-users
Latest Tabs kento-latest-tabs
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress
Lesson Plan Book lesson-plan-book
Link Whisper Free link-whisper
Listeo-Core – Directory Plugin by Purethemes listeo-core
ListingHub listinghub
Magic Responsive Slider and Carousel magic_slider
Magic Responsive Slider and Carousel WordPress magic_carousel
Mamurjor Employee Info mamurjor-employee-info
MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system
MediaPress mediapress
Menu Card menu-card
MG AdvancedOptions mg-advancedoptions
miniOrange OTP Verification and SMS Notification for WooCommerce miniorange-sms-order-notification-otp-verification
Money Space money-space
Moosend Landing Pages moosend-landing-pages
Mstoic Shortcodes mstoic-shortcodes
MTCaptcha WordPress Plugin mtcaptcha
Multi-column Tag Map multi-column-tag-map
My Album Gallery my-album-gallery
Nearby Now Reviews nearby-now-reviews
Newsletter Email Subscribe newsletter-email-subscribe
NextGEN Download Gallery nextgen-download-gallery
Niche Hero | Beautifully-designed blocks in seconds niche-hero
Ninja Tables – Easy Data Table Builder ninja-tables
nK Themes Helper nk-themes-helper
NS Ie Compatibility Fixer ns-ie-compatibility-fixer
Optional Email optional-email
Page Expire Popup/Redirection for WordPress page-expire-popup
Page Keys page-keys
PhotoFade photofade
Piraeus Bank WooCommerce Payment Gateway woo-payment-gateway-for-piraeus-bank
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers popup-builder-block
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor post-and-page-builder
Post Like Dislike post-like-dislike
Premmerce WooCommerce Customers Manager woo-customers-manager
Proxy & VPN Blocker proxy-vpn-blocker
PullQuote pullquote
QR Code for WooCommerce order emails, PDF invoices, packing slips qr-code-tag-for-wc-from-goaskle-com
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next
Quote Comments quote-comments
Rankology SEO and Analytics Tool rankology-seo-and-analytics-tool
Re Gallery – Responsive Image & Photo Gallery regallery
Real Estate Pro – WordPress Plugin real-estate-pro
Recras recras
reHub Framework rehub-framework
Responsive Pricing Table dk-pricr-responsive-pricing-table
Reviewify — Review Discounts & Photo/Video Reviews for WooCommerce review-for-discount
RSS Feed Widget rss-feed-widget
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories post-expirator
Shabat Keeper shabat-keeper
ShareThis Dashboard for Google Analytics googleanalytics
ShopMagic – email automation shopmagic-for-woocommerce
Shortcodes and extra features for Phlox theme auxin-elements
Simcast simcast
Simple User Meta Editor simple-user-meta-editor
SlimStat Analytics wp-slimstat
Smart App Banners smart-app-banners
Snillrik Restaurant snillrik-restaurant-menu
Speed Kit baqend
Spiffy Calendar spiffy-calendar
Starred Review starred-review
Sticky Action Buttons sticky-action-buttons
STM Gallery 1.9 stm-gallery
Stumble! for WordPress stumble-for-wordpress
Stylish Order Form Builder stylish-order-form-builder
Super Interactive Maps super-interactive-maps
SVG Map Plugin svg-map-by-saedi
Table Field Add-on for ACF and SCF advanced-custom-fields-table-field
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI simple-tags
Taskbuilder – WordPress Project Management & Task Management taskbuilder
teachPress teachpress
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! templately
Testimonial Master testimonial-master
The Events Calendar the-events-calendar
The Events Calendar Countdown Addon countdown-for-the-events-calendar
The Tooltip the-tooltip
TheGem Theme Elements thegem-elements-elementor
TheGem Theme Elements (for WPBakery) thegem-elements
Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system
Top Position Google Finance top-position-google-finance
Travel Bucket List – Wish To Go wish-to-go
Tutor LMS – eLearning and online course solution tutor
twinklesmtp – Email Service Provider For WordPress twinklesmtp
Unify unify
Uper – Back to Top Button for Elementor uper-elementor
URL Image Importer url-image-importer
User Activity Log user-activity-log
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin user-registration
Viitor Button Shortcodes viitor-shortcodes
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot wedocs
Woffice Core woffice-core
WooCommerce Orders & Customers Exporter woocommerce-orders-ei
WooCommerce Square woocommerce-square
Woodpecker for WordPress woodpecker
Workreap workreap
WP Attractive Donations System – Easy Stripe & Paypal donations WP_AttractiveDonationsSystem
WP Enable WebP wp-enable-webp
WP Google Street View (with 360° virtual tour) & Google maps + Local SEO wp-google-street-view
WP Js List Pages Shortcodes wp-js-list-pages-shortcodes
WP Lead Capturing Pages wp-lead-capture
WP Page Permalink Extension change-wp-page-permalinks
WP Photo Album Plus wp-photo-album-plus
WP Popup Magic wppopupmagic
WP Recipe Manager wp-recipe-manager
WP Status Notifier wp-change-status-notifier
WP Table Builder – Drag & Drop Table Builder wp-table-builder
WP Virtual Assistant VirtualAssistant
WP Widget Changer wp-widget-changer
WP-Members Membership Plugin wp-members
X Addons for Elementor x-addons-elementor
Xagio SEO – AI Powered SEO xagio-seo
xShare xshare
Yoco Payments yoco-payment-gateway

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AeroLand – App Landing Software Website WordPress Theme aeroland
Amuli | Property & Real Estate Marketplace WordPress Theme amuli
Anarkali – Fashion Shop WooCommerce Elementor Theme anarkali
Athens – Law Agency WordPress Theme athens
atlas atlas
Brook – Agency Business Creative WordPress Theme brook
Corpkit – Business Consulting WordPress Theme corpkit
Curly – A Stylish WordPress Theme for Hairdressers and Hair Salons curly
DeepDigital – Web Design Agency WordPress Theme deepdigital
Depot – eCommerce WordPress Theme depot
Grand Restaurant WordPress grandrestaurant
Hendon – Single Property WordPress Theme hendon
Jobify – Job Board WordPress Theme jobify
Lobo – WordPress Portfolio for Freelancers & Agencies lobo
Mitech – Technology IT Solutions & Services WordPress Theme mitech
Navian – Multi-Purpose Responsive WordPress Theme navian
Neo Ocular – Optician and Optical Store WordPress Theme neoocular
OchaHouse – Organic Tea Store WooCommerce WordPress Theme ochahouse
Optimize – SEO & Social Media WordPress Theme optimizewp
Oshin oshin
Phlox phlox
photography photography
Racquet – Tennis, Badminton & Squash WordPress Theme racquet
Rozy – Flower Shop WooCommerce WordPress Theme (4+ Indexes + Mobile Layouts Ready) rozy
tm-moody tm-moody
Travel Booking WordPress Theme traveler
Typify – Newspaper & Magazine WordPress Theme typify
VideoPro – Video WordPress Theme videopro
WellSpring | Aqua Filters & Drinking Water Delivery WordPress Theme wellspring
Woffice CRM woffice
zorka zorka

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-14996
Patch Status
Unpatched
Published
Jan 5, 2026
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-14736
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
Frontend Admin by DynamiApps
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-15001
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
FS Registration Password
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-15018
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Optional Email
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-67924
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-15158
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
WP Enable WebP
Researcher
CVSS Rating
High (8.6)
CVE-ID
CVE-2025-13371
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
Money Space
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-14429
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-50003
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-47474
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-49994
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-22509
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
atlas
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-14430
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67936
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-54003
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67937
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-22708
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-22707
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
tm-moody
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-14431
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67920
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-12550
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67935
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-14359
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
Oshin
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-68510
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
photography
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-69369
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-12549
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-22712
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-58913
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-67934
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-67928
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-67925
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-23993
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Felan Framework
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2026-22521
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-13493
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Latest Registered Users
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-49055
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-69356
Patch Status
Patched
Published
Jan 10, 2026
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-11877
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
User Activity Log
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-13457
Patch Status
Patched
Published
Jan 9, 2026
Affected Software
WooCommerce Square
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-13801
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
Yoco Payments
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2025-15364
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Download Manager
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-14436
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
Brevo for WooCommerce
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-14997
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-14937
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
Frontend Admin by DynamiApps
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-67923
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
JetEngine
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-12551
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
ListingHub
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-15057
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
SlimStat Analytics
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-15055
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
SlimStat Analytics
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-22725
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
High (7.1)
CVE-ID
CVE-2025-14835
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
WP Photo Album Plus
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-13652
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
CBX Bookmark & Favorite
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2026-22469
Patch Status
Unpatched
Published
Jan 5, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-14059
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-14867
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Flashcard Plugin for WordPress
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-66533
Patch Status
Patched
Published
Jan 8, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-67921
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-69351
Patch Status
Patched
Published
Jan 7, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-22713
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-22728
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Workreap
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-14172
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
WP Page Permalink Extension
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14114
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
1180px Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14122
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
AD Sliding FAQ
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14109
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
AH Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-0627
Patch Status
Patched
Published
Jan 8, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13704
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Autogen Headers Menu
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13849
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Cool YT Player
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13854
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Curved Text
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14891
Patch Status
Patched
Published
Jan 6, 2026
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13852
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Debt.com Business in a Box
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14147
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Easy GitHub Gist Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-69169
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
Easy Media Download
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14121
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
EDD Download Info
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13729
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Entry Views
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-11453
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Header and Footer Scripts
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-22482
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14893
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
IndieWeb
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14552
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
MediaPress
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-22519
Patch Status
Patched
Published
Jan 7, 2026
Affected Software
MediaPress
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13862
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Menu Card
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14144
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Mstoic Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14796
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
My Album Gallery
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13853
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Nearby Now Reviews
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22726
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
nK Themes Helper
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4776
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Phlox
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13847
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
PhotoFade
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13903
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
PullQuote
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13497
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
Recras
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13418
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-15058
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
Responsive Pricing Table
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13841
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Smart App Banners
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14112
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Snillrik Restaurant
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13848
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
STM Gallery 1.9
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13531
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12067
Patch Status
Patched
Published
Jan 5, 2026
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13908
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
The Tooltip
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-69357
Patch Status
Patched
Published
Jan 10, 2026
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14053
Patch Status
Unpatched
Published
Jan 6, 2026
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14120
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
URL Image Importer
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14113
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Viitor Button Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13967
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Woodpecker for WordPress
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14110
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
WP Js List Pages Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13900
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
WP Popup Magic
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13667
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
WP Recipe Manager
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2026-22518
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
X Addons for Elementor
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-14438
Patch Status
Patched
Published
Jan 5, 2026
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-27002
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67930
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
eHive Search
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67922
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-27005
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-32123
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-47666
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67916
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13893
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Lesson Plan Book
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67927
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Link Whisper Free
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67932
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49043
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-48094
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13892
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
MG AdvancedOptions
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-14130
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Post Like Dislike
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13369
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13504
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13701
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Shabat Keeper
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-14118
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Starred Review
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-14128
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Stumble! for WordPress
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49045
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13519
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
SVG Map Plugin
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67933
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-14127
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Testimonial Master
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13895
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-67918
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Woffice CRM
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-14131
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
WP Widget Changer
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13694
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
AA Block country
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14352
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14360
Patch Status
Unpatched
Published
Jan 8, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14146
Patch Status
Patched
Published
Jan 8, 2026
Affected Software
Booking Calendar
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67931
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
BulletProof Security
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-63019
Patch Status
Unpatched
Published
Jan 5, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69359
Patch Status
Patched
Published
Jan 10, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-22488
Patch Status
Unpatched
Published
Jan 7, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-11370
Patch Status
Patched
Published
Jan 5, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68558
Patch Status
Patched
Published
Jan 5, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-68507
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14886
Patch Status
Patched
Published
Jan 8, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13496
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Moosend Landing Pages
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-0675
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
NextGEN Download Gallery
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14370
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Quote Comments
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-22486
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-14358
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
reHub Framework
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-69093
Patch Status
Patched
Published
Jan 7, 2026
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13215
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67915
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67917
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Travel Booking WordPress Theme
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13529
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Unify
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67919
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Woffice Core
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12648
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
WP-Members Membership Plugin
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2026-0676
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
zorka
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2026-22470
Patch Status
Unpatched
Published
Jan 6, 2026
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-13409
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (4.7)
CVE-ID
CVE-2025-12540
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-69350
Patch Status
Patched
Published
Jan 7, 2026
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14028
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Contact Us Simple Form
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14792
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Key Figures
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14057
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Multi-column Tag Map
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-15000
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
Page Keys
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-14888
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Simple User Meta Editor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22468
Patch Status
Unpatched
Published
Jan 5, 2026
Affected Software
Absolute Addons For Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12030
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
ACF to REST API
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69346
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14468
Patch Status
Patched
Published
Jan 6, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22481
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
BD Courier Order Ratio Checker
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69354
Patch Status
Patched
Published
Jan 9, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22522
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22490
Patch Status
Patched
Published
Jan 7, 2026
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-0674
Patch Status
Unpatched
Published
Jan 8, 2026
Affected Software
Campaign Monitor for WordPress
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13749
Patch Status
Patched
Published
Jan 8, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66143
Patch Status
Unpatched
Published
Jan 10, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69091
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Demo Importer Plus
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22492
Patch Status
Patched
Published
Jan 7, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22472
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13393
Patch Status
Patched
Published
Jan 9, 2026
Affected Software
Featured Image from URL (FIFU)
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67926
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22517
Patch Status
Unpatched
Published
Jan 7, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13657
Patch Status
Patched
Published
Jan 6, 2026
Affected Software
HelpDesk Contact Form
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22489
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
Image Slider Slideshow
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14999
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Latest Tabs
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13990
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Mamurjor Employee Info
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13520
Patch Status
Unpatched
Published
Jan 6, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14904
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Newsletter Email Subscribe
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14845
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
NS Ie Compatibility Fixer
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69345
Patch Status
Patched
Published
Jan 5, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69361
Patch Status
Patched
Published
Jan 11, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69353
Patch Status
Patched
Published
Jan 9, 2026
Affected Software
Proxy & VPN Blocker
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69349
Patch Status
Patched
Published
Jan 7, 2026
Affected Software
RSS Feed Widget
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14077
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Simcast
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22487
Patch Status
Unpatched
Published
Jan 7, 2026
Affected Software
Speed Kit
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-68523
Patch Status
Patched
Published
Jan 5, 2026
Affected Software
Spiffy Calendar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-14465
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
Sticky Action Buttons
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2026-22483
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
teachPress
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69352
Patch Status
Patched
Published
Jan 9, 2026
Affected Software
The Events Calendar
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69348
Patch Status
Patched
Published
Jan 6, 2026
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-69355
Patch Status
Patched
Published
Jan 9, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66140
Patch Status
Unpatched
Published
Jan 10, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13521
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
WP Status Notifier
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13753
Patch Status
Patched
Published
Jan 8, 2026
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13527
Patch Status
Unpatched
Published
Jan 6, 2026
Affected Software
xShare
Researcher
CVSS Rating
Low (2.7)
CVE-ID
CVE-2025-12958
Patch Status
Unpatched
Published
Jan 6, 2026
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (January 5, 2026 to January 11, 2026) appeared first on Wordfence.

Leave a Comment