Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Special Note: This week’s Wordfence Intelligence Weekly WordPress Vulnerability Report is an extended edition to cover the last few weeks in December over the holidays and the first week in January.
Over the past three weeks, there were 459 vulnerabilities disclosed in 390 WordPress Plugins and 29 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 95 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 32,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Total Unpatched & Patched Vulnerabilities Last Week
| Patch Status | Number of Vulnerabilities |
|---|---|
| Patched | 219 |
| Unpatched | 240 |
Total Vulnerabilities by CVSS Severity Last Week
| Severity Rating | Number of Vulnerabilities |
|---|---|
| Low Severity | 2 |
| Medium Severity | 402 |
| High Severity | 48 |
| Critical Severity | 7 |
Total Vulnerabilities by CWE Type Last Week
| Vulnerability Type by CWE | Number of Vulnerabilities |
|---|---|
| Missing Authorization | 167 |
| Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 133 |
| Cross-Site Request Forgery (CSRF) | 52 |
| Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 25 |
| Exposure of Sensitive Information to an Unauthorized Actor | 24 |
| Authorization Bypass Through User-Controlled Key | 14 |
| Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 10 |
| Server-Side Request Forgery (SSRF) | 9 |
| Improper Control of Generation of Code (‘Code Injection’) | 4 |
| Unrestricted Upload of File with Dangerous Type | 3 |
| URL Redirection to Untrusted Site (‘Open Redirect’) | 3 |
| Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 2 |
| Authentication Bypass Using an Alternate Path or Channel | 1 |
| Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) | 1 |
| Deserialization of Untrusted Data | 1 |
| External Control of File Name or Path | 1 |
| Generation of Error Message Containing Sensitive Information | 1 |
| Improper Authentication | 1 |
| Improper Input Validation | 1 |
| Improper Neutralization of Null Byte or NUL Character | 1 |
| Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
| Improper Privilege Management | 1 |
| Incorrect Authorization | 1 |
| Insertion of Sensitive Information into Log File | 1 |
| Weak Password Recovery Mechanism for Forgotten Password | 1 |
Researchers That Contributed to WordPress Security Last Week
| Researcher Name | Number of Vulnerabilities |
|---|---|
| 49 | |
| 44 | |
| 35 | |
| 33 | |
| 33 | |
| 21 | |
| 21 | |
| 20 | |
| 11 | |
| 10 | |
| 10 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 | |
| 7 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| 6Storage Rentals | 6storage-rentals |
| 907 – Responsive Multi-Purpose WordPress Theme | wbc907-core |
| Academy LMS – WordPress LMS Plugin for Complete eLearning Solution | academy |
| Accept Donations with PayPal & Stripe | easy-paypal-donation |
| Accessibility Press | ilogic-accessibility |
| Accordion Slider Gallery | accordion-slider-gallery |
| Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript | add-custom-codes |
| Add Featured Image Custom Link | custom-url-to-featured-image |
| Addonify – Quick View For WooCommerce | addonify-quick-view |
| Admin and Site Enhancements (ASE) | admin-site-enhancements |
| Advanced Ads – Ad Manager & AdSense | advanced-ads |
| Advanced Classifieds & Directory Pro | advanced-classifieds-and-directory-pro |
| Advanced Custom CSS | advanced-custom-css |
| AdWords Conversion Tracking Code | adwords-conversion-tracking-code |
| AI Content Writing Assistant | ai-content-writing-assistant |
| AI Copilot – ChatGPT Chatbot & AI Engine for Post Automation | ai-copilot |
| AI-Powered Business Directory and Classified Ads Listings – Listdom | listdom |
| All in One Accessibility | all-in-one-accessibility |
| All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements | mystickyelements |
| AM Events | am-events |
| Amazon affiliate lite Plugin | afiliados-de-amazon-lite |
| Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates | animation-addons-for-elementor |
| AnyComment | anycomment |
| Appender – Copycat Content Protection for WordPress | appender |
| Appointify | appointify |
| Appointment Booking and Scheduler Plugin – Truebooker | truebooker-appointment-booking |
| Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | simply-schedule-appointments |
| Appointment Bookings for Zoom GoogleMeet and more – Wappointment | wappointment |
| Astra Widgets | astra-widgets |
| Attachments Handler | attachments-handler |
| Audiomack | audiomack |
| Auto Featured Image (Auto Post Thumbnail) | auto-post-thumbnail |
| Auto Listings – Car Listings & Car Dealership Plugin for WordPress | auto-listings |
| BA Book Everything | ba-book-everything |
| Basticom Framework | basticom-framework |
| Beaver Builder Page Builder – Drag and Drop Website Builder | beaver-builder-lite-version |
| Behance Portfolio Manager | portfolio-manager-powered-by-behance |
| Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss | bp-better-messages |
| Blog Filter Post Filtering | blog-filter |
| Bold Timeline Lite | bold-timeline-lite |
| Booking Calendar | booking |
| Booking calendar, Appointment Booking System | booking-calendar |
| BoomDevs WordPress Coming Soon Plugin | coming-soon-by-boomdevs |
| Bootstrap Modals | bootstrap-modals |
| Branda – White Label & Branding, Free Login Page Customizer | branda-white-labeling |
| Brands for WooCommerce | brands-for-woocommerce |
| Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content | brave-popup-builder |
| BuddyPress Activity Shortcode | bp-activity-shortcode |
| Business Directory Plugin – Easy Listing Directories for WordPress | business-directory-plugin |
| Business Hours for WPBakery – Worker | worker-wpbakery |
| Business hours widget for Elementor – Worker | worker-elementor |
| BWL Knowledge Base Manager | bwl-kb-manager |
| BWL Pro Voting Manager | bwl-pro-voting-manager |
| Calendar | calendar |
| Calendar.online / Kalender.digital – Plugin | kalender-digital |
| Captivate Sync | captivatesync-trade |
| Category Icon | category-icon |
| CC Child Pages | cc-child-pages |
| CedCommerce Integration for Good Market | ced-good-market-integration |
| Chakra test | chakra-test |
| Changelog & Custom List for Elementor | logger-elementor |
| Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist | bit-assist |
| Cincopa video and media plug-in | video-playlist-and-gallery-plugin |
| Claspo – Popups, Spin the Wheel & Email Capture | claspo |
| Co-marquage service-public.fr | co-marquage-service-public |
| Colibri Page Builder | colibri-page-builder |
| Combo Offers WooCommerce | woo-combo-offers |
| Comments – wpDiscuz | wpdiscuz |
| Connect Contact Form 7 and Mailchimp | contact-form-7-mailchimp-extension |
| Contact Form 7 styler for Elementor – Conformer | conformer-elementor |
| Contact Form Widget | new-contact-form-widget |
| Content Fetcher | content-fetcher |
| Content Grid Slider | content-grid-slider |
| Converter for Media – Optimize images | Convert WebP & AVIF | webp-converter-for-media |
| Cooked – Recipe Management | cooked |
| Cookie Banner for GDPR / CCPA – WPLP Cookie Consent | gdpr-cookie-consent |
| CookieHint WP | cookiehint-wp |
| Core Web Vitals & PageSpeed Booster | core-web-vitals-pagespeed-booster |
| Countdowner – Countdown Timer for Elementor | countdowner-elementor |
| Couponer – Discount Coupons for Elementor | couponer-elementor |
| Criptopayer – Crypto Payment Button for Elementor | criptopayer-elementor |
| Crowdsignal Forms | crowdsignal-forms |
| CubeWP Framework | cubewp-framework |
| Curator.io | curatorio |
| Custom Background Changer | custom-background-changer |
| Custom Field Template | custom-field-template |
| Custom Post Status | custom-post-status |
| Custom Style | custom-style |
| Customizable heading for Elementor | headinger-elementor |
| CWW Companion | cww-companion |
| Dashboard Beacon | wp-dashboard-beacon |
| Demo Importer Plus | demo-importer-plus |
| DesignThemes Core | designthemes-core |
| DesignThemes LMS Addon | designthemes-lms-addon |
| DesignThemes Portfolio Addon | designthemes-portfolio-addon |
| Direct Payments WP | direct-payments-wp |
| Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings | directorist |
| Discussion Board – WordPress Forum Plugin | wp-discussion-board |
| DMCA Protection Badge | dmca-badge |
| Docket Cache – Object Cache Accelerator | docket-cache |
| Document Library Lite | document-library-lite |
| Dokan Pro | dokan-pro |
| Download Manager | download-manager |
| Download Media Library | download-media-library |
| Download Plugins and Themes in ZIP from Dashboard | download-plugins-dashboard |
| Draft Notify | draft-notify |
| Easy Appointment Booking & Scheduling System – Webba Booking Calendar | webba-booking-lite |
| Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | easy-digital-downloads |
| Easy Form Builder by WhiteStudio — Drag & Drop Form Builder | easy-form-builder |
| Easy Invoice – PDF Invoice Generator & Quote Builder | easy-invoice |
| Easy Upload Files During Checkout | easy-upload-files-during-checkout |
| EasyIndex | easyindex |
| EasyTest – Simplify A/B Testing | convertpro |
| Editorial Calendar | editorial-calendar |
| Efí Bank | woo-gerencianet-official |
| Eight Day Week Print Workflow | eight-day-week-print-workflow |
| EInvoice App Malaysia | einvoiceapp-malaysia |
| Elementor Website Builder – More Than Just a Page Builder | elementor |
| ELEX WordPress HelpDesk & Customer Ticketing System | elex-helpdesk-customer-support-ticket-system |
| Email Marketing Plugin – WP Email Capture | wp-email-capture |
| Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files | embed-any-document |
| Embeds for YouTube | youtube-embed |
| Essential Addons for Elementor – Popular Elementor Templates & Widgets | essential-addons-for-elementor-lite |
| Event Organiser | event-organiser |
| Events Manager – Calendar, Bookings, Tickets, and more! | events-manager |
| Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin | everest-backup |
| Evergreen Post Tweeter | evergreen-post-tweeter |
| Extra Shortcodes | extra-shortcodes |
| F70 Lead Document Download | f70-lead-document-download |
| Fancy Product Designer | fancy-product-designer |
| FAPI Member | fapi-member |
| Fast User Switching | fast-user-switching |
| Featured Image Generator | featured-image-generator |
| Featured Video for WordPress – VideographyWP | videographywp |
| FiboSearch – Ajax Search for WooCommerce | ajax-search-for-woocommerce |
| File Uploader for WooCommerce | file-uploader-for-woocommerce |
| FileBird – WordPress Media Library Folders & File Manager | filebird |
| Five Star Restaurant Reservations – WordPress Booking Plugin | restaurant-reservations |
| Flex Store Users | flex-store-user |
| FlippingBook | flippingbook |
| Flowbox | flowbox |
| FluentAuth – The Ultimate Authorization & Security Plugin for WordPress | fluent-security |
| FormFacade – Embed Google Forms in your website | formfacade |
| Forumax – Advanced Community Forum Plugin | bbp-core |
| Fox LMS – WordPress LMS Plugin | fox-lms |
| Free Shipping Bar: Amount Left for Free Shipping for WooCommerce | amount-left-free-shipping-woocommerce |
| Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin | frontend-post-submission-manager-lite |
| FV Simpler SEO | fv-all-in-one-seo-pack |
| Gift Hunt | gift-hunt |
| GiveWP – Donation Plugin and Fundraising Platform | give |
| Gmedia Photo Gallery | grand-media |
| Google AdSense for Responsive Design – GARD | google-adsense-for-responsive-design-gard |
| Google Maps for Elementor | gmaper-elementor |
| Google Street View for Elementor – Walker | walker-elementor |
| Graphist – Graphs & Charts for Elementor | graphist-elementor |
| Greenhouse Job Board | greenhouse-job-board |
| GS Portfolio for Envato | gs-envato-portfolio |
| Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | essential-blocks |
| Gutenverse Form – Contact Form Builder, Booking, Reservation, Subscribe for Block Editor | gutenverse-form |
| Happy Addons for Elementor | happy-elementor-addons |
| HAPPY – Helpdesk Support Ticket System | happy-helpdesk-support-ticket-system |
| Health Check & Troubleshooting | health-check |
| Heateor Social Login WordPress | heateor-social-login |
| Hide Plugins | hide-plugins |
| Highlight and Share – Social Text and Image Sharing | highlight-and-share |
| History Timeline for Biography, Company History & Event Timeline | timeline-awesome |
| HomeFix Elementor Portfolio | homefix-ele-portfolio |
| Hotel Booking | nd-booking |
| HR Management Lite | hr-management-lite |
| HTML Forms – Simple WordPress Forms Plugin | html-forms |
| HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player | html5-audio-player |
| Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN | hummingbird-performance |
| HUSKY – Products Filter Professional for WooCommerce | woocommerce-products-filter |
| IF AS Shortcode | if-as-shortcode |
| Image Caption Hover Pro | image-caption-hover-pro |
| Image Photo Gallery Final Tiles Grid | final-tiles-grid-gallery-lite |
| Import into Easy Property Listings | easy-property-listings-xml-csv-import |
| Inboxify Sign Up Form | inboxify-sign-up-form |
| iNext Woo Pincode Checker | inext-woo-pincode-checker |
| Innovs WPBakery Visual Composer WHMCS Elements | void-visual-whmcs-element |
| Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms | cf7-hubspot |
| Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | funnelforms-free |
| Interactive Content – H5P | h5p |
| Invelity SPS connect | invelity-sps-connect |
| JetBlog | jet-blog |
| JetFormBuilder — Dynamic Blocks Form Builder | jetformbuilder |
| JetPopup | jet-popup |
| JetSearch | jet-search |
| JetTabs | jet-tabs |
| Job Postings | job-postings |
| Knowledge Base documentation & wiki plugin – BasePress Docs | basepress |
| LearnPress – WordPress LMS Plugin | learnpress |
| Link Library | link-library |
| Live Composer – Free WordPress Website Builder | live-composer-page-builder |
| Live Shopping & Shoppable Videos For WooCommerce | live-shopping-video-streams |
| Livemesh Addons for Beaver Builder | addons-for-beaver-builder |
| Locatoraid Store Locator | locatoraid |
| Logo Slider , Logo Carousel , Logo showcase , Client Logo | tc-logo-slider |
| Lucky Wheel for WooCommerce – Spin a Sale | woo-lucky-wheel |
| MailerLite – WooCommerce integration | woo-mailerlite |
| MapSVG – Vector maps, Image maps, Google Maps | mapsvg-lite-interactive-vector-maps |
| MAS Videos | masvideos |
| Master Addons For Elementor – White Label, Free Widgets, Hover Effects, Conditions, & Animations | master-addons |
| Maximum Products per User for WooCommerce | maximum-products-per-user-for-woocommerce |
| Meks Quick Plugin Disabler | meks-quick-plugin-disabler |
| Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Dripping | membership-for-woocommerce |
| Membership Plugin – Restrict Content | restrict-content |
| Mergado Pack | mergado-marketing-pack |
| Migration, Backup, Staging – WPvivid Backup & Migration | wpvivid-backuprestore |
| Mobile builder | mobile-builder |
| ModelTheme Addons for WPBakery and Elementor | modeltheme-addons-for-wpbakery |
| Modula Image Gallery – Photo Grid & Video Gallery | modula-best-grid-gallery |
| Multi-Step Checkout for WooCommerce | wp-multi-step-checkout |
| MX Time Zone Clocks | mx-time-zone-clocks |
| My auctions allegro | my-auctions-allegro-free-edition |
| My Calendar – Accessible Event Manager | my-calendar |
| MyBookTable Bookstore by Stormhill Media | mybooktable |
| myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program. | mycred |
| MyD Delivery | myd-delivery |
| Newsletter – Send awesome emails from WordPress | newsletter |
| Newsletters | newsletters-lite |
| Ninja Forms – The Contact Form Builder That Grows With You | ninja-forms |
| Ninja Tables – Easy Data Table Builder | ninja-tables |
| Noindex by Path | noindex-by-path |
| OneSignal – Web Push Notifications | onesignal-free-web-push-notifications |
| OpenHook | thesis-openhook |
| OpenID Connect Generic Client | daggerhart-openid-connect-generic |
| Order Cancellation & Returns for WooCommerce | wc-order-cancellation-return |
| Orders Chat for WooCommerce | orders-chat-for-woocommerce |
| Overstock Affiliate Links | overstock-affiliate-links |
| Page Title Splitter | page-title-splitter |
| PhastPress | phastpress |
| Photo Block – A Modern Image Block With Lightbox and Caption Support | photo-block |
| Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | nextgen-gallery |
| Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more | woocommerce-google-adwords-conversion-tracking-tag |
| PixelYourSite – Your smart PIXEL (TAG) & API Manager | pixelyoursite |
| Plugin Optimizer – Speed Up Your WordPress Like Never Before | plugin-optimizer |
| Poll, Survey & Quiz Maker Plugin by Opinion Stage | social-polls-by-opinionstage |
| Popping Sidebars and Widgets Light | popping-sidebars-and-widgets-light |
| Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales | poptics |
| Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | ays-popup-box |
| Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers | popup-builder-block |
| Portfolio Gallery – Responsive Image Gallery | gallery-portfolio |
| Post Grid | post-grid |
| Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | ultimate-post |
| Post Snippets – Custom WordPress Code Snippets Customizer | post-snippets |
| Postie | postie |
| Premium Addons for Elementor – Powerful Elementor Templates & Widgets | premium-addons-for-elementor |
| Pretty Google Calendar | pretty-google-calendar |
| Prime Slider – Addons for Elementor | bdthemes-prime-slider-lite |
| Print Anywhere & Create PDFs of Order Receipts, Invoices, Labels & More. | print-google-cloud-print-gcp-woocommerce |
| Print Invoice & Delivery Notes for WooCommerce | woocommerce-delivery-notes |
| Product Delivery Date for WooCommerce – Lite | product-delivery-date-for-woocommerce-lite |
| Product Loops for WooCommerce | product-loops |
| Product Table for WooCommerce | woo-product-table |
| Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart | wedevs-project-manager |
| Protect WP Admin | protect-wp-admin |
| QuadLayers TikTok Feed | wp-tiktok-feed |
| Questionar – FAQ Accordions for Elementor | questionar-elementor |
| Quran Gateway | quran-gateway |
| Read More & Accordion | expand-maker |
| Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder | real3d-flipbook-lite |
| Realbig For WordPress | realbig-media |
| Recent Posts From Each Category | recent-posts-from-each-category |
| Redirection for Contact Form 7 | wpcf7-redirect |
| RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | custom-registration-form-builder-with-submission-manager |
| Rencontre – Dating Site | rencontre |
| Request a Quote Form Plugin – Price Quote Request Management Made Easy | request-a-quote |
| RESPONSIVE AND SWIPE SLIDER! | responsive-and-swipe-slider |
| Responsive Block Control – Hide blocks based on display width | responsive-block-control |
| Responsive Posts Carousel WordPress Plugin | responsive-posts-carousel-pro |
| RestroPress – Online Food Ordering System | restropress |
| Reuters Direct | reuters-direct |
| Review Disclaimer | review-disclaimer |
| Robots.txt rewrite | robotstxt-rewrite |
| Sailing | sailing |
| SALESmanago & Leadoo | salesmanago |
| Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories | post-expirator |
| Semrush Content Toolkit | semrush-contentshake |
| SensitiveTagCloud | sensitive-tag-cloud |
| SEO Slider | seo-slider |
| Serial Codes Generator and Validator with WooCommerce Support | serial-codes-generator-and-validator |
| Series | series |
| Sermon Manager | sermon-manager-for-wordpress |
| Share, Print and PDF Products for WooCommerce | share-print-pdf-woocommerce |
| Shortcodes and extra features for Phlox theme | auxin-elements |
| Signature Add-On for Gravity Forms | gravity-signature-forms-add-on |
| Simple Archive Generator | simple-archive-generator |
| Simple Calendar – Google Calendar Plugin | google-calendar-events |
| Simple File List | simple-file-list |
| Simple Folio | simple-folio |
| Simple Keyword to Link | simple-keyword-to-link |
| Simple Like Page Plugin | simple-facebook-plugin |
| Simple Link Directory | simple-link-directory |
| SiteLock Security – WP Hardening, Login Security & Malware Scans | sitelock |
| Sitewide Notice WP | sitewide-notice-wp |
| SlimStat Analytics | wp-slimstat |
| Sliper – Full-screen Slider for Elementor | sliper-elementor |
| Sober | sober |
| Social Profilr | social-profilr-display-social-network-profile |
| Sticky Notes for WP Dashboard | wb-sticky-notes |
| Stratum Widgets for Elementor | stratum |
| Strong Testimonials | strong-testimonials |
| Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress | subscribe-to-unlock-lite |
| Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
| SureForms – Contact Form, Payment Form & Other Custom Form Builder | sureforms |
| Sweet Energy Efficiency | sweet-energy-efficiency |
| Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent | tablesome |
| Tainacan | tainacan |
| Tasty Recipes Lite | tasty-recipes-lite |
| Terms descriptions | terms-descriptions |
| The Moneytizer | the-moneytizer |
| Themebeez Toolkit | themebeez-toolkit |
| Themify Portfolio Post | themify-portfolio-post |
| ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin | thirstyaffiliates |
| Tooltips for WordPress | wordpress-tooltips |
| Trash Duplicate and 301 Redirect | trash-duplicate-and-301-redirect |
| TS Poll – Survey, Versus Poll, Image Poll, Video Poll | poll-wp |
| Twitch Player | ttv-easy-embed-player |
| Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | ultimate-member |
| UnGrabber | ungrabber |
| User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | userfeedback-lite |
| User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration | wp-user-frontend |
| User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin | user-registration |
| User Specific Content | user-specific-content |
| User Submitted Posts – Enable Users to Submit Posts from the Front End | user-submitted-posts |
| UserPro – Community and User Profile WordPress Plugin | userpro |
| UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | userswp |
| UseStrict’s Calendly Embedder | cal-embedder-lite |
| Valenti Engine | valenti-engine |
| Varnish/Nginx Proxy Caching | vcaching |
| Vimeotheque – Vimeo WordPress Plugin & Video Gallery | codeflavors-vimeo-video-post-lite |
| Virusdie – One-click website security | virusdie |
| VK Google Job Posting Manager | vk-google-job-posting-manager |
| VPSUForm – Drag & Drop Contact Form Builder with Email Automation | v-form |
| Watcher – Flexible Video Player for Elementor | watcher-elementor |
| Watu Quiz | watu |
| Wawp – Order Notifications, OTP Login, Checkout Verifications and Country Code | automation-web-platform |
| Wbcom Designs – Private Community for BuddyPress | lock-my-bp |
| WC Builder – WooCommerce Page Builder for WPBakery | wc-builder |
| WCFM Marketplace – Multivendor Marketplace for WooCommerce | wc-multivendor-marketplace |
| WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | wc-frontend-manager |
| Web and WooCommerce Addons for WPBakery Builder | vc-addons-by-bit14 |
| Web Directory Free | web-directory-free |
| Web to SugarCRM Lead | web-to-sugarcrm-lead |
| WebMan Amplifier | webman-amplifier |
| WeDesignTech Portfolio | wedesigntech-portfolio |
| weForms – Easy Drag & Drop Contact Form Builder For WordPress | weforms |
| WH Tweaks | wh-tweaks |
| Widgets for Social Photo Feed | social-photo-feed-widget |
| WING WordPress Migrator | wing-migrator |
| Wiremo – Product Reviews for WooCommerce | woo-reviews-by-wiremo |
| WishSuite – Wishlist for WooCommerce | wishsuite |
| WooCommerce Parcelas | woocommerce-parcelas |
| WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. | wp_scraper |
| WordPress User Extra Fields | wp-user-extra-fields |
| WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer | adminify |
| WP Advanced PDF | wp-advanced-pdf |
| WP Attachments | wp-attachments |
| WP Custom Admin Interface | wp-custom-admin-interface |
| WP DB Booster | wp-db-booster |
| WP Document Revisions | wp-document-revisions |
| WP eBay Product Feeds | ebay-feeds-for-wordpress |
| WP Export Categories & Taxonomies | wp-export-categories-taxonomies |
| WP Gmail SMTP | wp-gmail-smtp |
| WP Hallo Welt | wp-hallo-welt |
| WP Import – Ultimate CSV XML Importer for WordPress | wp-ultimate-csv-importer |
| WP JobHunt | wp-jobhunt |
| WP Post Signature | wp-post-signature |
| WP Recipe Maker | wp-recipe-maker |
| WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets | wp-social-reviews |
| WP Telegram Widget and Join Link | wptelegram-widget |
| Wp Text Slider Widget | wp-text-slider-widget |
| WP Time Slots Booking Form | wp-time-slots-booking-form |
| WP Visitor Statistics (Real Time Traffic) | wp-stats-manager |
| WP-CalDav2ICS | wp-caldav2ics |
| WP-EasyArchives | wp-easyarchives |
| WP-ShowHide | wp-showhide |
| WPBulky – WordPress Bulk Edit Post Types | wpbulky-wp-bulk-edit-post-types |
| WPCal.io – Easy Meeting Scheduler | wpcal |
| WPCOM Member | wpcom-member |
| WpStream – Live Streaming, Video on Demand, Pay Per View | wpstream |
| XStore Core | et-core-plugin |
| Yaad Sarig Payment Gateway For WC | yaad-sarig-payment-gateway-for-wc |
| Yada Wiki | yada-wiki |
| YITH Slider for page builders | yith-slider-for-page-builders |
| Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | youzify |
| Zephyr Project Manager | zephyr-project-manager |
| Zoho ZeptoMail | transmail |
| پلاگین پرداخت دلخواه | pardakht-delkhah |
WordPress Themes with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| Aora – Home & Lifestyle Elementor WooCommerce Theme | aora |
| Arcane – The Gaming Community Theme | arcane |
| Backpack Traveler – Modern Travel Blog WordPress Theme | backpacktraveler |
| Besa – Elementor Marketplace WooCommerce Theme | besa |
| bookory | bookory |
| Cinerama – A WordPress Theme for Movie Studios and Filmmakers | cinerama |
| Consulting | consulting |
| Diza – Pharmacy Store Elementor WooCommerce Theme | diza |
| ekommart – All-in-one eCommerce WordPress Theme | ekommart |
| Fana – Fashion Shop WordPress Theme | fana |
| Fashion – WooCommerce Responsive WordPress Theme | fashion2 |
| FiveStar – Hotel Booking WordPress Theme | fivestar |
| Genemy – Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing | genemy |
| GreenMart – Organic & Food WooCommerce WordPress Theme | greenmart |
| Hara – Beauty and Cosmetics Shop WooCommerce Theme | hara |
| Lekker – Portfolio WordPress Theme | lekker |
| Medical Equipment eCommerce WordPress Theme | medicalequipment |
| Melos | melos |
| Minamaze | minamaze |
| Nika – Medical Elementor WooCommerce Theme | nika |
| Personal Portfolio Resume Theme | Kerge | kerge |
| Puca – Optimized Mobile WooCommerce Theme | puca |
| sailing | sailing |
| Shuttle | shuttle |
| Struktur – Creative Agency WordPress Theme | struktur |
| Urna – All-in-one WooCommerce WordPress Theme | urna |
| Vireo | vireo |
| Wilmër – Construction WordPress Theme | wilmer |
| Zota – Elementor Multi-Purpose WooCommerce Theme | zota |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (December 15, 2025 to January 4, 2026) appeared first on Wordfence.