Wordfence Intelligence Weekly WordPress Vulnerability Report (June 30, 2025 to July 6, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🌞 Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!


Last week, there were 127 vulnerabilities disclosed in 120 WordPress Plugins and 16 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 27,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-858 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 56
Unpatched 71

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 64
High Severity 50
Critical Severity 12

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 35
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 21
Missing Authorization 15
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 13
Unrestricted Upload of File with Dangerous Type 9
Cross-Site Request Forgery (CSRF) 7
Deserialization of Untrusted Data 5
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 4
Server-Side Request Forgery (SSRF) 4
Improper Control of Generation of Code (‘Code Injection’) 3
Incorrect Privilege Assignment 3
Authorization Bypass Through User-Controlled Key 1
Exposure of Sensitive Information to an Unauthorized Actor 1
External Control of File Name or Path 1
Improper Access Control 1
Improper Authentication 1
Improper Authorization 1
Improper Privilege Management 1
URL Redirection to Untrusted Site (‘Open Redirect’) 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
9
9
8
7
6
6
6
5
4
4
4
4
3
3
3
3
3
2
2
2
2
2
2
2

Bao
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
(Simply) Guest Author Name guest-author-name
Ads Pro Plugin – Multi-Purpose WordPress Advertising Manager ap-plugin-scripteo
AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o aibuddy-openai-chatgpt
AI Engine ai-engine
All-in-One Addons for Elementor – WidgetKit widgetkit-for-elementor
Allmart allmart-core
Amazon Products to WooCommerce import-products-to-wc
Auto Thickbox auto-thickbox
Aviation Weather from NOAA aviation-weather-from-noaa
Awesome Gallery awesome-gallery
Awesome Wp Image Gallery awesome-wp-image-gallery
Backwp backwp
Beautiful Cookie Consent Banner beautiful-and-responsive-cookie-consent
BlossomThemes Social Feed blossomthemes-instagram-feed
Bold Page Builder bold-page-builder
Booking Calendar Contact Form booking-calendar-contact-form
Booking calendar, Appointment Booking System booking-calendar
Booking X – Appointment and Reservation Availability Calendar booking-x
bSecure – Your Universal Checkout bsecure
Bulk Featured Image bulk-featured-image
Card flip image slideshow card-flip-image-slideshow
Carousel Slider carousel-slider
Case Theme User case-theme-user
CF7 7 Mailchimp Add-on CF7-mailchimp-addon
Chatra Live Chat + ChatBot + Cart Saver chatra-live-chat
Click & Pledge Connect click-pledge-connect
CMSMasters Content Composer cmsmasters-content-composer
Contact Form 7 Database Addon – CFDB7 contact-form-cfdb7
Contact Form 7 reCAPTCHA contact-form-7-recaptcha
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder bit-form
Contact Form by Everest Forms – Simple Contact Form to Advanced Contact Form, Quiz, Survey, & Custom Contact Form Builder for WordPress everest-forms
Contact Us Page – Contact People contact-us-page-contact-people
Cool fade popup cool-fade-popup
CouponXxL Custom Post Types couponxxl-cpt
CSS3 Vertical Web Pricing Tables css3_vertical_web_pricing_tables
Custom Login And Signup Widget custom-login-and-signup-widget
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer 3d-flipbook-dflip-lite
Divi Builder divi-builder
Divi Torque – Plugin for Divi Theme and Builder addons-for-divi
DocCheck Login doccheck-login
Download Manager and Payment Form WordPress Plugin – WP SmartPay smartpay
Download Plugin download-plugin
Drag and Drop Multiple File Upload (Pro) – WooCommerce drag-and-drop-file-uploads-wc-pro
Easy 3D Viewer woo-3d-viewer
Easy Elements Hider easy-elements-hider
Easy Image Gallery easy-image-gallery
Easy restaurant menu manager easy-pdf-restaurant-menu-upload
Easy Stripe – Tips, Payments, and Donations easy-stripe
Element Pack Elementor Addons and Templates bdthemes-element-pack-lite
Email Address Security by WebEmailProtector webemailprotector
Essential Addons for Elementor – Popular Elementor Templates & Widgets essential-addons-for-elementor-lite
Event List eventlist
EventON (Pro) – WordPress Virtual Event Calendar Plugin eventON
fluXtore Funnel Builder for WordPress – Earn More with Highly Converting Sales Funnels fluxtore
Forminator Forms – Contact Form, Payment Form & Custom Form Builder forminator
Frontend File Manager Plugin nmedia-user-file-uploader
FW Gallery – Photo, video, audio media presentation and management system with players and slideshow fw-gallery
Gallery Widget gallery-widget
GoZen Forms gozen-forms
Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks advanced-gutenberg
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor
Happy Addons for Elementor happy-elementor-addons
iFrame Images Gallery wp-iframe-images-gallery
JKDEVKIT jkdevkit
Lead Form Data Collection to CRM wp-leads-builder-any-crm
Leyka leyka
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes lifterlms
LMSACE Connect – WooCommerce Moodle™ LMS Integration lmsace-connect
Magic Buttons for Elementor magic-buttons-for-elementor
Masteriyo LMS PRO learning-management-system-pro
Melapress File Monitor website-file-changes-monitor
MF Plus WPML mf-plus-wpml
Migration, Backup, Staging – WPvivid Backup & Migration wpvivid-backuprestore
MobiLoud – WordPress Mobile Apps – Convert your WordPress Website to Native Mobile Apps mobiloud-mobile-app-plugin
NGG Smart Image Search ngg-smart-image-search
Opal Estate Pro – Property Management and Submission opal-estate-pro
OwnerRez ownerrez
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
PayMaster for WooCommerce woocommerce-paymaster-gateway-019
Paytiko for WooCommerce paytiko
PeepSo Core: Groups peepso-groups
Photo Gallery, Images, Slider in Rbs Image Gallery robo-gallery
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery nextgen-gallery
Pixelating image slideshow gallery pixelating-image-slideshow-gallery
Portfolio for Elementor & Image Gallery | PowerFolio portfolio-elementor
Posts Slider Shortcode posts-slider-shortcode
Premium Addons for Elementor premium-addons-for-elementor
Printcart Web to Print Product Designer for WooCommerce printcart-integration
PrivateContent – Mail Actions private-content-mail-actions
ProcessingJS for WordPress processingjs-for-wp
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! radio-station
RD Contacto rd-wapp
Service Finder Bookings sf-booking
Smart Docs smart-docs
Soumettre.fr soumettre-fr
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder supreme-modules-for-divi
Testimonials Showcase testimonials-showcase
Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2
Ultra Addons for Contact Form 7 ultimate-addons-for-contact-form-7
Uncode Core uncode-core
URL Shortener Plugin For WordPress exact-links
Video Gallery Block – Display your videos as a gallery in a professional way video-gallery-block
Video List Manager video-list-manager
VikRentCar Car Rental Management System vikrentcar
WC Pickup Store wc-pickup-store
WooCommerce Product Multi-Action Woo-product-multiaction
WooCommerce Shop Page Builder dzs-wootable
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg groundhogg
WP Compress – Instant Performance & Speed Optimization wp-compress-image-optimizer
WP fancybox wp-fancybox
WP Firebase Push Notification wp-push-notification-firebase
WP Front-end login and register wp-front-end-login-and-register
WP Human Resource Management hrm
WP Shortcodes Plugin — Shortcodes Ultimate shortcodes-ultimate
WP Travel Gutenberg Blocks wp-travel-blocks
WP Video Lightbox wp-video-lightbox
WP Visitor Statistics (Real Time Traffic) wp-stats-manager
WPQuiz wpquiz
yContributors ycontributors
YouTube Embed, Playlist and Popup by WpDevArt youtube-video-player

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Alone – Charity Multipurpose Non-profit WordPress Theme alone
Amwerk – Industry & Corporate Business WordPress Theme amwerk
Classiera – Classified Ads WordPress Theme classiera
CouponXxL couponxxl
Divi Divi
Divi Extra extra
Diza – Pharmacy Store Elementor WooCommerce Theme diza
Elessi – WooCommerce AJAX WordPress Theme – RTL support elessi-theme
Home Villas | Real Estate WordPress Theme homevillas-real-estate
Houzez houzez
Kossy – Minimalist eCommerce WordPress Theme kossy
LMS – Education WordPress Theme lms
LogisticsHub – Logistics and Transportation WordPress Theme logistics-hub
Networker – Tech News WordPress Theme with Dark Mode networker
OceanWP oceanwp
Vikinger vikinger

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-52718
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-28983
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Click & Pledge Connect
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-52725
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CouponXxL
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-52726
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CouponXxL Custom Post Types
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-49302
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-49414
Patch Status
Unpatched
Published
Jun 30, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-30933
Patch Status
Unpatched
Published
Jun 30, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-53209
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Masteriyo LMS PRO
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-6934
Patch Status
Unpatched
Published
Jun 30, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-23970
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Service Finder Bookings
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-48300
Patch Status
Patched
Published
Jul 4, 2025
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-5014
Patch Status
Unpatched
Published
Jul 1, 2025
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-2932
Patch Status
Unpatched
Published
Jul 2, 2025
Affected Software
JKDEVKIT
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-5692
Patch Status
Patched
Published
Jul 1, 2025
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52724
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-28980
Patch Status
Unpatched
Published
Jun 30, 2025
Affected Software
Aviation Weather from NOAA
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-5804
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Case Theme User
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-4414
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
CMSMasters Content Composer
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52729
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-53204
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Event List
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-53198
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Houzez
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52807
Patch Status
Unpatched
Published
Jul 1, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52805
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Leyka
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-52723
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-47627
Patch Status
Unpatched
Published
Jul 1, 2025
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-4946
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
Vikinger
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-49417
Patch Status
Unpatched
Published
Jul 1, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-53207
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
WP Travel Gutenberg Blocks
Researcher
CVSS Rating
High (8.0)
CVE-ID
CVE-2025-6238
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
AI Engine
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52830
Patch Status
Unpatched
Published
Jul 3, 2025
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52722
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-49070
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-6782
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
GoZen Forms
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-6783
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
GoZen Forms
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52717
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52833
Patch Status
Unpatched
Published
Jun 30, 2025
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52832
Patch Status
Patched
Published
Jul 1, 2025
Affected Software
NGG Smart Image Search
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-49870
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-52831
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Video List Manager
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2025-47479
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-23968
Patch Status
Unpatched
Published
Jul 3, 2025
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-5817
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Amazon Products to WooCommerce
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-28951
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Bulk Featured Image
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-49029
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Custom Login And Signup Widget
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-6586
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Download Plugin
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-9017
Patch Status
Patched
Published
Jul 2, 2025
Affected Software
PeepSo Core: Groups
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-28963
Patch Status
Unpatched
Published
Jul 4, 2025
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-5322
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-28967
Patch Status
Unpatched
Published
Jul 4, 2025
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-30947
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Cool fade popup
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-28969
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Gallery Widget
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-30969
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
iFrame Images Gallery
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-30979
Patch Status
Unpatched
Published
Jul 4, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-24780
Patch Status
Unpatched
Published
Jul 3, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-6739
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
WPQuiz
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-24764
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
(Simply) Guest Author Name
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49418
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
Allmart
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-48231
Patch Status
Patched
Published
Jun 30, 2025
Affected Software
Booking Calendar Contact Form
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-30983
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Card flip image slideshow
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6673
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Easy restaurant menu manager
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-28976
Patch Status
Unpatched
Published
Jun 30, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-49032
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6687
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Magic Buttons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6686
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Magic Buttons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-28957
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
OwnerRez
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6729
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
PayMaster for WooCommerce
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-30943
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Posts Slider Shortcode
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11937
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Premium Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6039
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
ProcessingJS for WordPress
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-5567
Patch Status
Unpatched
Published
Jul 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6787
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Smart Docs
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6944
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Uncode Core
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-26591
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
WP fancybox
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-53566
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-28956
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Backwp
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49866
Patch Status
Patched
Published
Jul 1, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-6740
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-52727
Patch Status
Patched
Published
Jul 1, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-49245
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Testimonials Showcase
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11405
Patch Status
Unpatched
Published
Jul 1, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-6041
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
yContributors
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-29012
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
CF7 7 Mailchimp Add-on
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-6786
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
DocCheck Login
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-30929
Patch Status
Unpatched
Published
Jul 4, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49431
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
MF Plus WPML
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-47634
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
WC Pickup Store
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-24735
Patch Status
Unpatched
Published
Jul 4, 2025
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-28971
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Easy Elements Hider
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-23972
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Contact Form 7 reCAPTCHA
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-47565
Patch Status
Unpatched
Published
Jul 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-27358
Patch Status
Unpatched
Published
Jul 4, 2025
Affected Software
Frontend File Manager Plugin
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-29007
Patch Status
Unpatched
Published
Jul 4, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-3702
Patch Status
Patched
Published
Jul 3, 2025
Affected Software
Melapress File Monitor
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-52813
Patch Status
Unpatched
Published
Jun 30, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-50032
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
Paytiko for WooCommerce
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-53568
Patch Status
Patched
Published
Jul 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-5933
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
RD Contacto
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-29001
Patch Status
Unpatched
Published
Jul 4, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-5924
Patch Status
Unpatched
Published
Jul 3, 2025
Affected Software
WP Firebase Push Notification
Researcher
CVSS Rating
Low (3.7)
CVE-ID
CVE-2025-4654
Patch Status
Unpatched
Published
Jul 1, 2025
Affected Software
Soumettre.fr

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 30, 2025 to July 6, 2025) appeared first on Wordfence.

Leave a Comment