Wordfence Intelligence Weekly WordPress Vulnerability Report (September 1, 2025 to September 7, 2025)


📢 Calling all Vulnerability Researchers and Bug Bounty Hunters! 📢

🚀  Operation: Maximum Impact Challenge! Now through November 10, 2025, earn 2X bounty rewards for all in-scope submissions in software with at least 5,000 active installs and fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big!

💉 Participate in the SQLsplorer Challenge! Now through September 22, 2025, all SQL Injection vulnerabilities in software with at least 25 active installs are considered in-scope for all researchers, regardless of researcher tier AND earn a 20% bonus on all SQL Injection vulnerability submissions.


Last week, there were 191 vulnerabilities disclosed in 178 WordPress Plugins and 7 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 52 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 28,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 80
Unpatched 111

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 2
Medium Severity 172
High Severity 16
Critical Severity 1

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 87
Cross-Site Request Forgery (CSRF) 37
Missing Authorization 27
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 8
Deserialization of Untrusted Data 7
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 5
Improper Control of Generation of Code (‘Code Injection’) 4
Exposure of Sensitive Information to an Unauthorized Actor 3
Server-Side Request Forgery (SSRF) 3
Unrestricted Upload of File with Dangerous Type 3
Absolute Path Traversal 2
Authentication Bypass Using an Alternate Path or Channel 1
Authorization Bypass Through User-Controlled Key 1
Improper Input Validation 1
Improper Output Neutralization for Logs 1
Missing Authentication for Critical Function 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
28
19
17
13
11
9

Bao
8
7
6
5
5
5
4
4
3
3
3
3
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Add to Feedly add-to-feedly
Admin Menu Editor admin-menu-editor
Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool
AI Engine ai-engine
Aitasi Coming Soon aitasi-coming-soon
AP HoneyPot WordPress Plugin ap-honeypot
Aparat Video Shortcode aparat-shortcode
ARI Fancy Lightbox – Popup for WordPress ari-fancy-lightbox
Assistant – Every Day Productivity Apps assistant
atec Debug atec-debug
aThemes Addons for Elementor athemes-addons-for-elementor-lite
Authors List authors-list
Auto Last Youtube Video auto-last-youtube-video
BCM Duplicate Menu bcm-duplicate-menu
Biagiotti Core biagiotti-core
Bonus for Woo bonus-for-woo
Booking Ultra Pro Appointments Booking Calendar Plugin booking-ultra-pro
Boxed Content boxed-content
Brilliant Web-to-Lead for Salesforce salesforce-wordpress-to-lead
Brizy – Page Builder brizy
Bulk Featured Image bulk-featured-image
Bulk Watermark bulk-watermark
Carousel Ultimate carousel
Classified Listing – AI-Powered Classified ads & Business Directory Plugin classified-listing
Cloud SAML SSO – Single Sign On Login cloud-sso-single-sign-on
Comment Form WP – Customize Default Comment Form comment-form-wp
Compact Admin compact-admin
connectDaily Events Calendar Plugin connect-daily-web-calendar
Contact Form By Mega Forms – Drag and Drop Form Builder mega-forms
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Blocks, and Elementor Widgets) content-views-query-and-display-post-page
Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner
Course Booking Platform course-booking-platform
Custom Team Manager custom-team-manager
Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce
Dadevarzan WordPress Common dadevarzan-common
Database to Excel database-to-excel
Developer Tools Blocker swiftninjapro-inspect-element-console-blocker
Document Engine – Download Posts as PDF, PDF Embedder, Posts to PDF document-engine
Donation Forms WP by Givecloud donation-forms-by-givecloud
Easy Download Media Counter easy-download-media-counter
Easy Flash Embed easy-flash-embed
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box easy-facebook-likebox
Easy Timer easy-timer
eDS Responsive Menu eds-responsive-menu
Elementor Element Condition ele-conditions
ELEX WooCommerce Google Shopping (Google Product Feed) elex-woocommerce-google-product-feed-plugin-basic
Email Marketing, Email Automation, Newsletter & Cart Abandonment for WordPress and WooCommerce – Mail Mint mail-mint
Enable Latex enable-latex
Exchange Rates exchange-rates
Exit Intent Popup exitintentpopup
F4 Media Taxonomies f4-media-taxonomies
Flatsome flatsome
Floating Window Music Player floating-window-music-player
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
Frisbii Pay reepay-checkout-gateway
FW Anker fw-anker
Gallery PhotoBlocks photoblocks-grid-gallery
Get Cash get-cash
GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership
Great Restaurant Menu WP best-restaurant-menu-by-pricelisto
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor
Hide Real Download Path hide-real-download-path
Html Social share buttons html-social-share-buttons
Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons
If-So Dynamic Content Personalization if-so
immonex Kickstart immonex-kickstart
InPost Gallery inpost-gallery
Instant Locations instant-locations
Invelity MyGLS connect invelity-mygls-connect
IssueM issuem
Job Board Manager job-board-manager
Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce
LA-Studio Element Kit for Elementor lastudio-element-kit
Latest Post Shortcode latest-post-shortcode
License Manager for WooCommerce license-manager-for-woocommerce
LTL Freight Quotes – Day & Ross Edition ltl-freight-quotes-day-ross-edition
LTL Freight Quotes – Daylight Edition ltl-freight-quotes-daylight-edition
LTL Freight Quotes – TQL Edition ltl-freight-quotes-tql-edition
Make Connector integromat-connector
Malcure Malware Scanner — Toolset for Malware Removal wp-malware-removal
Master Paper Collapse Toggle master-paper-collapse-toggle
MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system
Media Author media-author
MediaPress mediapress
Mobile Contact Line mobile-contact-line
MSTW League Manager mstw-league-manager
Multi Step Form multi-step-form
New Simple Gallery new-simple-gallery
Ninja Charts – WordPress Charts and Graphs Plugin ninja-charts
Notification for Telegram notification-for-telegram
Optio Dentistry optio-dentistry
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More themeisle-companion
Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
Parallax Scrolling Enllax.js parallax-scrolling-enllax-js
Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net peachpay-for-woocommerce
Payoneer Checkout payoneer-checkout
PDF for WPForms + Drag and Drop Template Builder pdf-for-wpforms
PopAd popad
Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin mailoptin
Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more post-smtp
Posts Table with Search & Sort posts-data-table
Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor
Property Hive propertyhive
Purge Varnish Cache purge-varnish
Pushe Web Push Notification pushe-webpush
PuzzleMe for WordPress puzzleme
Quick Event Calendar quick-event-calendar
Quick Paypal Payments quick-paypal-payments
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker quiz-master-next
Ray Enterprise Translation lingotek-translation
Recent Posts Widget Extended recent-posts-widget-extended
Responder responder
RumbleTalk Live Group Chat – HTML5 rumbletalk-chat-a-chat-with-themes
Search by Google search-google
Search Cloud One search-cloud-one
SEO Auto Linker wpa-seo-auto-linker
short.io wp-shortcm
Show Eventbrite Events – Event Feed for Eventbrite event-feed-for-eventbrite
Showpass WordPress Extension showpass
SimaCookie simasicher-dsgvo-cookie
Simple Link List Widget simple-link-list-widget
Simple Matomo Tracking Code simple-matomo-tracking-code
Simple Price Calculator simple-price-calculator-basic
Simple Text Slider simple-text-slider
Site Info site-info-dashboard-widget
SKT Addons for Elementor skt-addons-for-elementor
Smart Table Builder smart-table-builder
Smooth Accordion smooth-accordion
Social Sharing Plugin – Kiwi kiwi-social-share
Spirit Framework spirit-framework
SS Font Awesome Icon ss-font-awesome-icon
StagTools stagtools
StreamWeasels Kick Integration streamweasels-kick-integration
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions wp-full-stripe-free
Support Genix – Helpdesk & Customer Support Ticket System support-genix-lite
Surfer – WordPress Plugin surferseo
Table of content content-table
Themify Popup themify-popup
Tickera – WordPress Event Ticketing tickera-event-ticketing-system
Today’s Date Inserter todays-date-inserter
Tooltipy (tooltips for WP) bluet-keywords-tooltip-generator
Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode
TrustMate.io – WooCommerce integration trustmate-io-integration-for-woocommerce
Ultimate AJAX Login ultimate-ajax-login
Ultimate Client Dash ulimate-client-dash
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin user-registration
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP userswp
Vayu Blocks – Website Builder for the Block Editor vayu-blocks
vipdrv vipdrv-vip-test-drive
Widgetize Pages Light widgetize-pages-light
WN Flipbox Pro wn-flipbox-pro
Woocommerce Gifts Product woo-gift-product
Woocommerce Notify Updated Product woocommerce-notify-updated-product
WooCommerce Single Page Checkout woo-single-page-checkout
WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule buffer-my-post
WordPress Error Monitoring by Bugsnag bugsnag
WordPress Events Calendar Plugin – Pie Calendar pie-calendar
WordPress Helpdesk Integration wp-helpdesk-integration
WordPress prettyPhoto prettyphoto
WordPress StoryMap Plugin wp-storymap
WP Bannerize Pro wp-bannerize-pro
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes
WP Email Template wp-email-template
WP Flow Plus wp-imageflow2
WP Github Gist wp-github-gist
WP likes wp-likes
WP Mail wp-mail
WP Notification Bell wp-notification-bell
WP Publication Archive wp-publication-archive
WP-GraphViz wp-graphviz
WPB Elementor Addons wpb-elementor-addons
WPB Image Widget wpb-image-widget
wpForo Forum wpforo
Zoomify embed for WP zoom-image-shortcode
金数据 jinshuju
코드엠샵 소셜톡 mshop-naver-talktalk

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AdForest adforest
ConsultStreet consultstreet
Miraculous – Multi Vendor Online Music Store Elementor WordPress Theme miraculous
REHub – Price Comparison, Multi Vendor Marketplace WordPress Theme rehub-theme
SaasLauncher saaslauncher
Shk Corporate shk-corporate
SoftMe softme

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-8359
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
AdForest
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-58637
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
immonex Kickstart
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-57889
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
InPost Gallery
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2025-58608
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
MediaPress
Researcher
CVSS Rating
High (8.2)
CVE-ID
CVE-2025-7040
Patch Status
Patched
Published
Sep 5, 2025
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-49401
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
High (8.1)
CVE-ID
CVE-2025-9990
Patch Status
Unpatched
Published
Sep 4, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-58628
Patch Status
Patched
Published
Sep 1, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2025-10269
Patch Status
Unpatched
Published
Sep 3, 2025
Affected Software
Spirit Framework
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2025-7366
Patch Status
Patched
Published
Sep 5, 2025
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-9518
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
atec Debug
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-9517
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
atec Debug
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-58819
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Bulk Featured Image
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-9519
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Easy Timer
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-58641
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Exit Intent Popup
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-6085
Patch Status
Unpatched
Published
Sep 3, 2025
Affected Software
Make Connector
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2025-9515
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Multi Step Form
Researcher
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-58815
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Aitasi Coming Soon
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-58839
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
eDS Responsive Menu
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-58644
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-58642
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.6)
CVE-ID
CVE-2025-58643
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-8268
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
AI Engine
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-7045
Patch Status
Patched
Published
Sep 5, 2025
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-58881
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
New Simple Gallery
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-58785
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Ray Enterprise Translation
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9493
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Admin Menu Editor
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58876
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Aparat Video Shortcode
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58784
Patch Status
Unpatched
Published
Sep 5, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8149
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
aThemes Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58812
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Great Restaurant Menu WP
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9057
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Biagiotti Core
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58633
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58851
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Boxed Content
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58887
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Course Booking Platform
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58840
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Custom Team Manager
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58632
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Dadevarzan WordPress Common
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58640
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58842
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Donation Forms WP by Givecloud
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58867
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Easy Download Media Counter
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-48105
Patch Status
Unpatched
Published
Sep 2, 2025
Affected Software
Easy Flash Embed
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58623
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58624
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Exchange Rates
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8684
Patch Status
Patched
Published
Sep 4, 2025
Affected Software
Flatsome
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58836
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
FW Anker
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58610
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Gallery PhotoBlocks
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58823
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Get Cash
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9849
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Html Social share buttons
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58786
Patch Status
Unpatched
Published
Sep 5, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58602
Patch Status
Patched
Published
Sep 3, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58631
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
IssueM
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58790
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Social Sharing Plugin – Kiwi
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8360
Patch Status
Patched
Published
Sep 5, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58609
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Latest Post Shortcode
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58871
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9853
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Optio Dentistry
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58830
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58620
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58618
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58808
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WordPress prettyPhoto
Researcher(s): Unknown
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58612
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Property Hive
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58621
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
PuzzleMe for WordPress
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-6757
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58626
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58834
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
short.io
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58850
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Showpass WordPress Extension
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58868
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
SimaCookie
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58882
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Simple Text Slider
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-8564
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
SKT Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9126
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
Smart Table Builder
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58838
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Smooth Accordion
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58837
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
SS Font Awesome Icon
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58814
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
StagTools
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58874
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WordPress StoryMap Plugin
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-9442
Patch Status
Patched
Published
Sep 5, 2025
Affected Software
StreamWeasels Kick Integration
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58787
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Themify Popup
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-48103
Patch Status
Unpatched
Published
Sep 2, 2025
Affected Software
Today’s Date Inserter
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58614
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Tooltipy (tooltips for WP)
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58880
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58862
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58605
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58625
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
WP Flow Plus
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58875
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP Github Gist
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58822
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP Mail
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58821
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP Notification Bell
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58826
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP Publication Archive
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58870
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP-GraphViz
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58793
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WPB Elementor Addons
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58858
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WPB Image Widget
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58863
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Zoomify embed for WP
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58864
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
金数据
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-58828
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
코드엠샵 소셜톡
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-48104
Patch Status
Unpatched
Published
Sep 2, 2025
Affected Software
Floating Window Music Player
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-58856
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-53307
Patch Status
Unpatched
Published
Sep 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-58848
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP likes
Researcher
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2025-58615
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
WP Bannerize Pro
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-58827
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Job Board Manager
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58835
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Bonus for Woo
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58797
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58600
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58795
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Payoneer Checkout
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58634
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-9616
Patch Status
Unpatched
Published
Sep 3, 2025
Affected Software
PopAd
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58613
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Posts Table with Search & Sort
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-7368
Patch Status
Patched
Published
Sep 5, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58635
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-58603
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Surfer – WordPress Plugin
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-9516
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
atec Debug
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-10046
Patch Status
Patched
Published
Sep 5, 2025
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-58788
Patch Status
Unpatched
Published
Sep 5, 2025
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58820
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Carousel Ultimate
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58825
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58796
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Elementor Element Condition
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58886
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Instant Locations
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58873
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Pushe Web Push Notification
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58832
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Search by Google
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58883
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Search Cloud One
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58791
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
SEO Auto Linker
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58810
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Simple Link List Widget
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58630
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Simple Matomo Tracking Code
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58811
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Ultimate Client Dash
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58884
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
vipdrv
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-58805
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Widgetize Pages Light
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58859
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Add to Feedly
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58855
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
AP HoneyPot WordPress Plugin
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58792
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Authors List
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58843
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Auto Last Youtube Video
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58798
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
BCM Duplicate Menu
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58594
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Brizy – Page Builder
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58845
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Bulk Watermark
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58601
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58865
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Compact Admin
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58813
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
ConsultStreet
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58639
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58799
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58844
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Database to Excel
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58818
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Developer Tools Blocker
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58860
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Enable Latex
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58617
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
F4 Media Taxonomies
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58616
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Frisbii Pay
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58783
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58849
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Hide Real Download Path
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58833
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Invelity MyGLS connect
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-3701
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-54744
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58841
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Media Author
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58622
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
Mobile Contact Line
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58852
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
MSTW League Manager
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58794
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Notification for Telegram
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58599
Patch Status
Patched
Published
Sep 3, 2025
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58831
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58853
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58816
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58807
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Purge Varnish Cache
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58861
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Quick Event Calendar
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-27003
Patch Status
Patched
Published
Sep 4, 2025
Affected Software
Quick Paypal Payments
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58801
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Responder
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58606
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
SaasLauncher
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58824
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Shk Corporate
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58869
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
SimaCookie
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58872
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Simple Price Calculator
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58817
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
SoftMe
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58857
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Table of content
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58611
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58809
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58802
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58854
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Ultimate AJAX Login
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58847
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WN Flipbox Pro
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58878
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Woocommerce Gifts Product
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58804
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58806
Patch Status
Unpatched
Published
Sep 5, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58800
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
WP Email Template
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-58597
Patch Status
Patched
Published
Sep 3, 2025
Affected Software
wpForo Forum
CVSS Rating
Low (2.7)
CVE-ID
CVE-2025-58598
Patch Status
Patched
Published
Sep 3, 2025
CVSS Rating
Low (2.7)
CVE-ID
CVE-2025-58866
Patch Status
Unpatched
Published
Sep 5, 2025
Affected Software
Site Info
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (September 1, 2025 to September 7, 2025) appeared first on Wordfence.

Leave a Comment