Wordfence Intelligence Weekly WordPress Vulnerability Report (June 16, 2025 to June 22, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!


Last week, there were 131 vulnerabilities disclosed in 124 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 44 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 27,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-849 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-853 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 38
Unpatched 93

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 121
High Severity 8
Critical Severity 2

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 59
Missing Authorization 29
Cross-Site Request Forgery (CSRF) 25
Unrestricted Upload of File with Dangerous Type 5
Server-Side Request Forgery (SSRF) 4
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 3
Incorrect Authorization 2
Authorization Bypass Through User-Controlled Key 1
Deserialization of Untrusted Data 1
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
12
11
11
10
10
7
7
4
4
3
3
3
3
3
3
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery interactive-3d-flipbook-powered-physics-engine
AI Engine ai-engine
Anant Addons for Elementor anant-addons-for-elementor
ANON::form embedded secure form anonform-embedded-secure-form
App Builder – Create Native Android & iOS Apps On The Flight app-builder
ATP Call Now atp-call-now
Auto Upload Images auto-upload-images
Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu
Beaver Builder Plugin (Starter Version) bb-plugin
Better Random Redirect better-random-redirect
Blog2Social: Social Media Auto Post & Scheduler blog2social
Bluff Post bluff-post
Breeze – WordPress Cache Plugin breeze
Bulk YouTube Post Creator bulk-youtube-post-creator
Buying Buddy IDX CRM – Real Estate MLS Plugin buying-buddy-idx-crm
Change Cart button Colors WooCommerce wc-style
ClipLink cliplink
Code Engine code-engine
CodePen Embed Block codepen-embed-block
Contact Form 7 AWeber Extension integrate-contact-form-7-and-aweber
ContentStudio contentstudio
Cookie-Script.com cookie-script-com
Creative Contact Form sexy-contact-form
CRM ERP Business Solution | freelancers & SME | for WordPress & WooCommerce crm-erp-business-solution
CSV Importer Improved csv-importer-improved
CSV Me csv-me
Download Manager download-manager
Drag and Drop Multiple File Upload for Contact Form 7 drag-and-drop-multiple-file-upload-contact-form-7
eDS Responsive Menu eds-responsive-menu
Elementor Website Builder Pro elementor-pro
Elementor Website Builder – More Than Just a Page Builder elementor
ElementsKit Elementor Addons and Templates elementskit-lite
Enhanced Blocks – Page Builder Blocks for Gutenberg enhanced-blocks
Esselink.nu Settings esselinknu-settings
Euro FxRef Currency Converter euro-fxref-currency-converter
FastBook – Responsive Appointment Booking and Scheduling System fastbook-responsive-appointment-booking-and-scheduling-system
File Manager Pro – Filester filester
Firelight Lightbox easy-fancybox
Football Pool football-pool
FormLift for Infusionsoft Web Forms formlift
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce wp-marketing-automations
Fyrebox Quizzes fyrebox-shortcode
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers rafflepress
GiveWP – Donation Plugin and Fundraising Platform give
Guest posting / Frontend Posting / Front Editor – WP Front User Submit front-editor
Gutenberg Blocks – ACF Blocks Suite acf-blocks
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news
Hand Talk handtalk
HUSKY – Products Filter Professional for WooCommerce woocommerce-products-filter
Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller
Import YouTube videos as WP Posts import-youtube-videos-as-wp-post
Inventory Presser – Car Dealer Listings inventory-presser
IP Based Login ip-based-login
Job Postings job-postings
JobSearch WP Job Board wp-jobsearch
JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin jobwp
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates kata-plus
Knowledge Base – Knowledge Base Maker knowledge-base-maker
Lewe ChordPress – ChordPro Text Formatter chordpress
Live Sports Streamthunder live-sports-streamthunder
Login & Register Customizer – Popup | Slider | Inline | WooCommerce easy-login-woocommerce
Logo Manager For Samandehi samandehi-logo-manager
Mailing Group Listserv wp-mailing-group
Master Slider – Responsive Touch Slider master-slider
Media Hygiene: Remove or Delete Unused Images and More! media-hygiene
Modern Footnotes modern-footnotes
Oganro Travel Portal Search Widget for HotelBeds APITUDE API oganro-travel-portal-search-widget-for-hotelbeds-apitude-api
PDPA Consent for Thailand pdpa-consent
Pixabay Images pixabay-images
Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more woocommerce-google-adwords-conversion-tracking-tag
PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-channel-manager-booking-engine
Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage
Polls CP cp-polls
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor post-and-page-builder
PowerPress Podcasting plugin by Blubrry powerpress
RDFa Breadcrumb rdfa-breadcrumb
Real Estate Manager – Property Listing and Agent Management real-estate-manager
Recipes manager – WPH wph-recipes-manager
Related Products Manager for WooCommerce related-products-manager-woocommerce
School Management System for WordPress school-management
Scroll UP scroll-to-up
Send Notifications from Woocommerce, Form Plugins and More! notifier
Simple Logo Carousel simple-logo-carousel
Simple Sticky Footer simple-sticky-footer
Sitekit sitekit
Smart Notification WordPress Plugin. Web & Mobile Push, FB Messenger, FB Notifications & Newsletter. smio-push-notification
SpecFit-Virtual Try On Woocommerce try-on-for-woocommerce
Spoki – Chat Buttons and WooCommerce Notifications spoki
TableOn – WordPress Posts Table Filterable  posts-table-filterable
Target Video Easy Publish brid-video-easy-publish
Tealium tealium
TinyNav tinynav
TM Replace Howdy tm-replace-howdy
Ultra Addons for Contact Form 7 ultimate-addons-for-contact-form-7
UpStream: a Project Management Plugin for WordPress upstream
User Roles and Capabilities user-roles-and-capabilities
Video List Manager video-list-manager
Virtual Moderator virtual-moderator
Wise Chat wise-chat
WooCommerce Fortnox Integration woocommerce-fortnox-integration
Woocommerce Line Notify woo-line-notify
WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily innovs-woo-manager
WordPress Infinite Scroll – Ajax Load More ajax-load-more
WP Customer Area customer-area
WP Dummy Content Generator wp-dummy-content-generator
WP Inventory Manager wp-inventory-manager
WP Register Profile With Shortcode wp-register-profile-with-shortcode
WP Roadmap – Product Feedback Board wp-roadmap
WP Social AutoConnect wp-fb-autoconnect
WP User Profile Avatar wp-user-profile-avatar
WP User Stylesheet Switcher wp-user-stylesheet-switcher
WP Visitor Statistics (Real Time Traffic) wp-stats-manager
WP Voting Contest Lite wp-voting-contest
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin cf7-zoho
WP-DownloadCounter wp-downloadcounter
WP-Members Membership Plugin wp-members
WP-Recall – Registration, Profile, Commerce & More wp-recall
WPBakery Page Builder for WordPress js_composer
WPComplete wpcomplete
WPThumb wp-thumb
XML Travel Portal Widget oganro-reservation-widget
YITH PayPal Express Checkout for WooCommerce yith-paypal-express-checkout-for-woocommerce
Zapier for WordPress zapier
Zara 4 Image Compression zara-4

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Fitness Park fitness-park
Hello FSE Blog hello-fse-blog
HYDRO – One Page Portfolio WordPress Theme hydro
OceanWP oceanwp
Spark Multipurpose spark-multipurpose

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-5071
Patch Status
Patched
Published
Jun 18, 2025
Affected Software
AI Engine
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-52708
Patch Status
Patched
Published
Jun 19, 2025
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-4413
Patch Status
Unpatched
Published
Jun 17, 2025
Affected Software
Pixabay Images
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-4102
Patch Status
Patched
Published
Jun 19, 2025
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-6086
Patch Status
Unpatched
Published
Jun 17, 2025
Affected Software
CSV Me
Researcher(s): Unknown
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-6220
Patch Status
Patched
Published
Jun 17, 2025
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-3774
Patch Status
Patched
Published
Jun 16, 2025
Affected Software
Wise Chat
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-5673
Patch Status
Patched
Published
Jun 16, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-52821
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Video List Manager
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-52822
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50038
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Anant Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-52733
Patch Status
Patched
Published
Jun 19, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49985
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Auto Upload Images
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50048
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50037
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50043
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Code Engine
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4367
Patch Status
Patched
Published
Jun 18, 2025
Affected Software
Download Manager
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4479
Patch Status
Patched
Published
Jun 18, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6257
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
Euro FxRef Currency Converter
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-52707
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
Firelight Lightbox
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50033
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Fitness Park
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50035
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Fyrebox Quizzes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50041
Patch Status
Unpatched
Published
Jun 19, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50050
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Job Postings
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50049
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
Modern Footnotes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49984
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50045
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-5700
Patch Status
Patched
Published
Jun 16, 2025
Affected Software
Simple Logo Carousel
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50019
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Simple Sticky Footer
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50047
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
Sitekit
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50030
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Spark Multipurpose
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-5237
Patch Status
Patched
Published
Jun 17, 2025
Affected Software
Target Video Easy Publish
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4775
Patch Status
Patched
Published
Jun 16, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50042
Patch Status
Unpatched
Published
Jun 19, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50051
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
WP-Members Membership Plugin
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-4965
Patch Status
Patched
Published
Jun 18, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-50046
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WPComplete
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49983
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WPThumb
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49423
Patch Status
Unpatched
Published
Jun 18, 2025
Affected Software
Bulk YouTube Post Creator
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-25173
Patch Status
Unpatched
Published
Jun 18, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-47654
Patch Status
Unpatched
Published
Jun 18, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-31428
Patch Status
Unpatched
Published
Jun 18, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-52789
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-47574
Patch Status
Unpatched
Published
Jun 18, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-52782
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Scroll UP
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-39478
Patch Status
Unpatched
Published
Jun 18, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-23973
Patch Status
Unpatched
Published
Jun 18, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-30972
Patch Status
Unpatched
Published
Jun 18, 2025
Affected Software
Woocommerce Line Notify
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-52792
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP User Stylesheet Switcher
Researcher
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2025-5490
Patch Status
Patched
Published
Jun 18, 2025
Affected Software
Football Pool
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2025-50015
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Hand Talk
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49989
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49988
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49990
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
ContentStudio
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49993
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Cookie-Script.com
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49987
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-52802
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49986
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Video List Manager
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49996
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49991
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-5524
Patch Status
Patched
Published
Jun 18, 2025
Affected Software
OceanWP
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50024
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
ATP Call Now
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50021
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Better Random Redirect
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50023
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
CodePen Embed Block
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50025
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Polls CP
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50013
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
CSV Importer Improved
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-52710
Patch Status
Patched
Published
Jun 19, 2025
Affected Software
File Manager Pro – Filester
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50012
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50016
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
IP Based Login
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50027
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50014
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50020
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
RDFa Breadcrumb
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50011
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Recipes manager – WPH
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50026
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50018
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Tealium
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50017
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP Voting Contest Lite
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-50022
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP Social AutoConnect
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52784
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Bluff Post
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-23999
Patch Status
Patched
Published
Jun 18, 2025
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52783
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49964
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
ClipLink
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52794
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Creative Contact Form
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49971
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
eDS Responsive Menu
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50034
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52793
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Esselink.nu Settings
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49970
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Hello FSE Blog
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49973
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49978
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
JobSearch WP Job Board
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49975
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50009
Patch Status
Patched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52791
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49967
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Live Sports Streamthunder
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52780
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Logo Manager For Samandehi
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50036
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Mailing Group Listserv
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49979
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49966
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49965
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52825
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50044
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52781
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
TinyNav
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49972
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
TM Replace Howdy
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49974
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49981
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
User Roles and Capabilities
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52772
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Virtual Moderator
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49976
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49998
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49982
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP Customer Area
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49234
Patch Status
Patched
Published
Jun 16, 2025
Affected Software
WP Dummy Content Generator
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52795
Patch Status
Unpatched
Published
Jun 19, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49977
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP Inventory Manager
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49980
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP User Profile Avatar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52790
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
WP-DownloadCounter
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49968
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
XML Travel Portal Widget
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-48111
Patch Status
Patched
Published
Jun 16, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50010
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Zapier for WordPress
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49969
Patch Status
Unpatched
Published
Jun 19, 2025
Affected Software
Zara 4 Image Compression

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 16, 2025 to June 22, 2025) appeared first on Wordfence.

Leave a Comment