(647) 243-4688

Last week, there were 179 vulnerabilities disclosed in 163 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 57 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to implement layered security, aligning with our overarching mission to secure WordPress with defense in depth strategies. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report. As the world’s leading quality vulnerability database provider for WordPress, site owners can rest assured knowing Wordfence has their back.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 31,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 87
Unpatched 92

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 149
High Severity 22
Critical Severity 8

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Missing Authorization 54
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 52
Cross-Site Request Forgery (CSRF) 29
Exposure of Sensitive Information to an Unauthorized Actor 11
Unrestricted Upload of File with Dangerous Type 10
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 7
Authorization Bypass Through User-Controlled Key 3
Improper Authorization 2
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 2
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 2
Improper Privilege Management 2
External Control of File Name or Path 1
Improper Authentication 1
Improper Control of Generation of Code (‘Code Injection’) 1
Incorrect Implementation of Authentication Algorithm 1
Server-Side Request Forgery (SSRF) 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
17
15
14
9
8
6
6
5
5
5
4
4
4
4
3
3
3
3
3
3
3
22a6037721e913c152306d079828a034
Mdr

3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
10Web Booster – Website speed optimization, Cache & Page Speed optimizer tenweb-speed-optimizer
Accessiy by CodeConfig Widget for ADA, EAA & WCAG Compliance codeconfig-accessibility
Actionwear products sync actionwear-products-sync
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript add-custom-codes
Advanced Custom Fields: Extended acf-extended
Advanced FAQ Manager advanced-faq-manager
All-in-One Video Gallery all-in-one-video-gallery
Application Passwords application-passwords
Arconix Shortcodes arconix-shortcodes
ARK Related Posts ark-relatedpost
Auto Alt Text auto-alt-text
Auto Thumbnailer auto-thumbnailer
Autoptimize autoptimize
Backup, Restore and Migrate your sites with XCloner xcloner-backup-and-restore
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library blockart-blocks
Booking Calendar booking
Bread & Butter: Gate content & Improve lead conversion in 60 seconds bread-butter
Business Directory Plugin – Easy Listing Directories for WordPress business-directory-plugin
Canadian Nutrition Facts Label canadian-nutrition-facts-label
Chartify – WordPress Chart Plugin chart-builder
Clik stats clikstats
Constant Contact + WooCommerce constant-contact-woocommerce
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress contact-form-plugin
ContentStudio contentstudio
Cool Tag Cloud cool-tag-cloud
CoSign Single Signon cosign-sso
Cost Calculator Builder cost-calculator-builder
CRM Memberships crm-memberships
CryptX cryptx
CSS3 Buttons css3-buttons
CSSIgniter Shortcodes cssigniter-shortcodes
CSV Sumotto csv-sumotto
Custom Layouts – Post + Product grids made easy custom-layouts
Custom Post Type UI custom-post-type-ui
Custom Sidebars by ProteusThemes custom-sidebars-by-proteusthemes
Cute News Ticker cute-news-ticker
Demo Importer Plus demo-importer-plus
DesignThemes LMS designthemes-lms
dream gallery dream-gallery
Easy Jump Links Menus easy-jump-links-menus
ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system
Envo Extra envo-extra
EPROLO-Dropshipping eprolo-dropshipping
Ergonet Cache ergonet-varnish-cache
Event Booking Manager for WooCommerce mage-eventpress
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup
Export All Posts, Products, Orders, Refunds & Users wp-ultimate-exporter
Extra Post Images extra-post-images
Featured Image via URL featured-image-via-url
Feedback Modal for Website feedback-modal-for-website
Feeds for TikTok – Display Video Feeds in Grid Layouts b-tiktok-feed
FitVids for WordPress fitvids-for-wordpress
Flex QR Code Generator flex-qr-code-generator
Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution fluent-booking
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler fluent-cart
Formstack Online Forms formstack
Frontend Admin by DynamiApps acf-frontend-form-element
FunnelKit – Funnel Builder for WooCommerce Checkout funnel-builder
g-FFL Cockpit g-ffl-cockpit
Generic Elements generic-elements-for-elementor
Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications
GSheetConnector For WPForms gsheetconnector-wpforms
Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news
Happy Addons for Elementor happy-elementor-addons
Hide Categories Or Products On Shop Page hide-categories-or-products-on-shop-page
HUSKY – Products Filter Professional for WooCommerce woocommerce-products-filter
Hype pico
Image Cleanup image-cleanup
Image Gallery – Photo Grid & Video Gallery modula-best-grid-gallery
Image Optimizer by wps.sk image-optimizer-wpssk
Jabbernotification jabberbenachrichtigung
JNews Gallery jnews-gallery
JNews Paywall jnews-paywall
Kadence WooCommerce Email Designer kadence-woocommerce-email-designer
Link Whisper Free link-whisper
List Attachments Shortcode list-attachments-shortcode
Listar – Directory Listing & Classifieds WordPress Plugin listar-directory-listing
Live CSS Preview live-css-preview
Live Sales Notification for Woocommerce – Woomotiv woomotiv
Make Section & Column Clickable For Elementor make-section-column-clickable-elementor
Master Addons For Elementor – White Label, Free Widgets, Hover Effects, Conditions, & Animations master-addons
Media Library Downloader media-library-downloader
MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce
MxChat – AI Chatbot for WordPress mxchat-basic
My auctions allegro my-auctions-allegro-free-edition
My Tickets – Accessible Event Ticketing my-tickets
myLCO mylco
Nexter Extension – Site Enhancements Toolkit nexter-extension
Norby AI norby-ai
Nouri.sh Newsletter newsletters-from-rss-to-email-newsletters-using-nourish
Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto codistoconnect
Omnipress omnipress
Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce
Payaza payaza
Paysera Payment Gateway for WooCommerce woo-payment-gateway-paysera
PDF Catalog for WooCommerce pdf-catalog-for-woocommerce
PDF Invoices & Packing Slips for WooCommerce woocommerce-pdf-invoices-packing-slips
PDF Thumbnail Generator pdf-thumbnail-generator
Photo Gallery by Ays – Responsive Image Gallery gallery-photo-gallery
Plug your WooCommerce into the largest catalog of customized print products from Helloprint helloprint
Portfolio and Projects portfolio-and-projects
Post Cloner post-cloner
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App post-smtp
PostGallery postgallery
Projectopia – WordPress Project Management projectopia-core
Quantic Social Image Hover tw-image-hover-share
Quiz Maker quiz-maker
RevInsite revinsite
Rich Shortcodes for Google Reviews widget-google-reviews
Salon Booking System – Free Version salon-booking-system
Search, Filters & Merchandising for WooCommerce instantsearch-for-woocommerce
Sermon Manager sermon-manager-for-wordpress
ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution shopengine
SMS Alert Order Notifications – WooCommerce sms-alert
SMTP Mail smtp-mail
Social Feed Gallery Portfolio social-feed-gallery-portfolio
SSP Debug ssp-debugging
Starter Templates – AI-Powered Templates for Elementor & Gutenberg astra-sites
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers suremails
SurveyFunnel – Survey Plugin for WordPress surveyfunnel-lite
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity surveyjs
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent tablesome
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI simple-tags
Takeads monetize-link
Thai Lottery Widget thai-lottery-widget
Thank You Page Customizer for WooCommerce – Increase Your Sales woo-thank-you-page-customizer
The7 Elements dt-the7-core
Thim Kit for Elementor – Pre-built Templates & Widgets for Elementor thim-elementor-kit
Time Sheets time-sheets
Torod – The smart shipping and delivery portal for e-shops and retailers torod
TR Timthumb tr-timthumb
Trail Manager trail-manager
Twitscription twitscription
Ultra Skype Button ultra-skype-button
User Generator and Importer user-importer-and-generator
User Spam Remover user-spam-remover
User Verification by PickPlugins user-verification
VikRentCar Car Rental Management System vikrentcar
Visualizer: Tables and Charts Manager for WordPress visualizer
Voidek Employee Portal voidek-employee-portal
WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors wc-vendors
Webcake – Landing Page Builder webcake
WebP Express webp-express
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot wedocs
Weekly Planner weekly-planner
Widgets for Google Reviews wp-reviews-plugin-for-google
WP AI CoPilot – AI content writer plugin, ChatGPT WordPress, GPT-3/4 , Ai assistance ai-co-pilot-for-wp
WP Directory Kit wpdirectorykit
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting erp
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics wp-google-analytics-events
WP Landing Page wp-landing-page
Wp Social Login and Register Social Counter wp-social
WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets wp-social-reviews
WP Ultimate Review wp-ultimate-review
WP-SOS-Donate Donation Sidebar Plugin wp-sos-donate
WPKoi Templates for Elementor wpkoi-templates-for-elementor
Xagio SEO – AI Powered SEO xagio-seo
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons
Yandex.Metrica wp-yandex-metrika
Yet Another WebClap for WordPress yet-another-webclap-for-wordpress
Zigaform – Price Calculator & Cost Estimation Form Builder Lite zigaform-calculator-cost-estimation-form-builder-lite

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AdForest adforest
REHub – Price Comparison, Multi Vendor Marketplace Wordpress Theme rehub-theme

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2025-13390
Patch Status
Patched
Published
Dec 3, 2025

Affected Software
WP Directory Kit
Researcher

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-13486
Patch Status
Patched
Published
Dec 2, 2025

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-13542
Patch Status
Patched
Published
Dec 2, 2025

Affected Software
DesignThemes LMS
Researcher

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-12673
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Flex QR Code Generator
Researcher

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-13342
Patch Status
Patched
Published
Dec 3, 2025

Affected Software
Frontend Admin by DynamiApps
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12966
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
All-in-One Video Gallery
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12154
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Auto Thumbnailer
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12181
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
ContentStudio
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12529
Patch Status
Patched
Published
Dec 1, 2025

Affected Software
Cost Calculator Builder
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-13066
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
Demo Importer Plus
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12153
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Featured Image via URL
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-13543
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
PostGallery
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2025-12879
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
User Generator and Importer
Researcher

CVSS Rating
High (8.1)
CVE-ID
CVE-2025-13614
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Cool Tag Cloud

CVSS Rating
High (8.1)
CVE-ID
CVE-2025-12851
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
My auctions allegro
Researcher

CVSS Rating
High (7.5)
CVE-ID
CVE-2025-13646
Patch Status
Patched
Published
Dec 2, 2025

CVSS Rating
High (7.5)
CVE-ID
CVE-2025-12850
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
My auctions allegro
Researcher

CVSS Rating
High (7.5)
CVE-ID
CVE-2025-63076
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
The7 Elements

CVSS Rating
High (7.5)
CVE-ID
CVE-2025-13724
Patch Status
Patched
Published
Dec 1, 2025

CVSS Rating
High (7.2)
CVE-ID
CVE-2025-13387
Patch Status
Patched
Published
Dec 1, 2025

Researcher

CVSS Rating
High (7.2)
CVE-ID
CVE-2025-13645
Patch Status
Patched
Published
Dec 2, 2025

CVSS Rating
High (7.2)
CVE-ID
CVE-2025-12499
Patch Status
Patched
Published
Dec 5, 2025

Researcher

CVSS Rating
High (7.2)
CVE-ID
CVE-2013-6880
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Time Sheets

CVSS Rating
High (7.2)
CVE-ID
CVE-2025-12510
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Widgets for Google Reviews
Researcher

CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-12483
Patch Status
Patched
Published
Dec 1, 2025

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-67556
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
Advanced FAQ Manager
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13835
Patch Status
Unpatched
Published
Dec 1, 2025

Affected Software
Arconix Shortcodes
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13401
Patch Status
Patched
Published
Dec 3, 2025

Affected Software
Autoptimize

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12804
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
Booking Calendar

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13739
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
CryptX

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13907
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
CSS3 Buttons
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13656
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Cute News Ticker
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13860
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Easy Jump Links Menus
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-66066
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Envo Extra

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13856
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Extra Post Images
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-66067
Patch Status
Patched
Published
Dec 6, 2025

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-62082
Patch Status
Unpatched
Published
Dec 7, 2025

Affected Software
Generic Elements

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-67538
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
JNews Gallery
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12717
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
List Attachments Shortcode

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13731
Patch Status
Patched
Published
Dec 1, 2025

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12163
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
Omnipress
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13863
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
RevInsite
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-12368
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Sermon Manager
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13896
Patch Status
Unpatched
Published
Dec 5, 2025

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13678
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Thai Lottery Widget

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13899
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
TR Timthumb
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-63057
Patch Status
Unpatched
Published
Dec 7, 2025

Affected Software
WP Ultimate Review
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13898
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Ultra Skype Button

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-63044
Patch Status
Unpatched
Published
Dec 6, 2025

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-13857
Patch Status
Unpatched
Published
Dec 5, 2025

Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13513
Patch Status
Unpatched
Published
Dec 3, 2025

Affected Software
Clik stats

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13512
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
CoSign Single Signon

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13894
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
CSV Sumotto

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13621
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
dream gallery
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13622
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Jabbernotification

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-11263
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Link Whisper Free

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13137
Patch Status
Unpatched
Published
Dec 5, 2025

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13626
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
myLCO

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13515
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Nouri.sh Newsletter

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13623
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Twitscription

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-13625
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-13308
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Application Passwords
Researcher

CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-12191
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
PDF Catalog for WooCommerce
Researcher

CVSS Rating
Medium (5.4)
CVE-ID
CVE-2025-12505
Patch Status
Patched
Published
Dec 5, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67569
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
AdForest

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67580
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Constant Contact + WooCommerce
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13312
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
CRM Memberships

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-63008
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-62738
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Formstack Online Forms
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12720
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
g-FFL Cockpit
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12721
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
g-FFL Cockpit
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-63009
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-49348
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Hype
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-62737
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Image Cleanup
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12585
Patch Status
Patched
Published
Dec 2, 2025

Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-63024
Patch Status
Unpatched
Published
Dec 3, 2025

Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12355
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Payaza
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-62865
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
Post Cloner
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67565
Patch Status
Patched
Published
Dec 6, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-66086
Patch Status
Patched
Published
Dec 5, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13494
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
SSP Debug

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-13006
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-66110
Patch Status
Unpatched
Published
Dec 2, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-62735
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
User Spam Remover
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-12093
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-11379
Patch Status
Unpatched
Published
Dec 3, 2025

Affected Software
WebP Express
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-66083
Patch Status
Patched
Published
Dec 4, 2025

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-67570
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
GSheetConnector For WPForms
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-63063
Patch Status
Unpatched
Published
Dec 7, 2025

Affected Software
Yandex.Metrica
Researcher

CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-13090
Patch Status
Patched
Published
Dec 1, 2025

Affected Software
WP Directory Kit
Researcher

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-12124
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
FitVids for WordPress

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-63033
Patch Status
Unpatched
Published
Dec 7, 2025

Researcher

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-13682
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Trail Manager
Researcher

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2025-12186
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Weekly Planner
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-49350
Patch Status
Unpatched
Published
Dec 6, 2025

Affected Software
Actionwear products sync

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62739
Patch Status
Unpatched
Published
Dec 5, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62994
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13684
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
ARK Related Posts

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62866
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
Auto Alt Text
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67596
Patch Status
Patched
Published
Dec 3, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66529
Patch Status
Patched
Published
Dec 3, 2025

Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-63056
Patch Status
Unpatched
Published
Dec 7, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13144
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
ContentStudio

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62996
Patch Status
Unpatched
Published
Dec 5, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62733
Patch Status
Unpatched
Published
Dec 4, 2025

Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12133
Patch Status
Patched
Published
Dec 4, 2025

Affected Software
EPROLO-Dropshipping
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62867
Patch Status
Unpatched
Published
Dec 6, 2025

Affected Software
Ergonet Cache
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62869
Patch Status
Unpatched
Published
Dec 6, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-63077
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Happy Addons for Elementor
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12128
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62736
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Image Cleanup
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12190
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67591
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
JNews Paywall
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12354
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Live CSS Preview
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62734
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Media Library Downloader
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62995
Patch Status
Unpatched
Published
Dec 5, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-64257
Patch Status
Patched
Published
Dec 6, 2025

Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13362
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Norby AI
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67469
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
PDF Thumbnail Generator
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13685
Patch Status
Patched
Published
Dec 1, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67470
Patch Status
Patched
Published
Dec 5, 2025

Affected Software
Portfolio and Projects
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13360
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Quantic Social Image Hover
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67595
Patch Status
Patched
Published
Dec 2, 2025

Affected Software
Quiz Maker
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66531
Patch Status
Patched
Published
Dec 7, 2025

Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12358
Patch Status
Patched
Published
Dec 2, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-62762
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
SMTP Mail
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66526
Patch Status
Patched
Published
Dec 5, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12370
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Takeads
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-66528
Patch Status
Patched
Published
Dec 5, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67594
Patch Status
Patched
Published
Dec 6, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-10055
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Time Sheets

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-12165
Patch Status
Patched
Published
Dec 4, 2025

Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-63015
Patch Status
Unpatched
Published
Dec 4, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-67589
Patch Status
Patched
Published
Dec 7, 2025

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-13629
Patch Status
Unpatched
Published
Dec 5, 2025

Affected Software
WP Landing Page
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-64274
Patch Status
Patched
Published
Dec 6, 2025

Affected Software
WPKoi Templates for Elementor
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-63025
Patch Status
Unpatched
Published
Dec 4, 2025

Affected Software
Xagio SEO – AI Powered SEO
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (December 1, 2025 to December 7, 2025) appeared first on Wordfence.