Briefing

Wordfence Intelligence Weekly Vulnerability Report: 250 New Vulnerabilities Disclosed

security
by Chloe Chamberland · WordPress Wordfence CVE-2025-58902 CVE-2025-66076 CVE-2025-69094 CVE-2025-69132 CVE-2025-69133 CVE-2025-69134 CVE-2025-69152 CVE-2025-69153 CVE-2025-69154 CVE-2025-69155 CVE-2025-69156 CVE-2026-10089 CVE-2026-10095

Patch all unpatched WordPress plugins and themes, and enable the new Wordfence firewall rules for Ninja Forms <=3.3.29, WAF‑RULE‑923, and WAF‑RULE‑924 immediately.

What to do now

Patch all unpatched WordPress plugins and themes, enable the new Wordfence firewall rules, and monitor the vulnerability feed via the API or webhook.

Summary

Wordfence Intelligence released its latest weekly vulnerability report, documenting 250 newly disclosed vulnerabilities across 181 WordPress plugins and 41 themes. The database now contains over 35,000 entries, with 162 vulnerabilities patched and 88 still unpatched; severity counts show 152 medium, 89 high, and 9 critical issues. Researchers contributed 101 reports, with João Pedro S Alcântara (36) and PRISM (18) leading the effort.

Wordfence has rolled out new firewall rules, including protection for Ninja Forms <=3.3.29, WAF‑RULE‑923, and WAF‑RULE‑924, which are applied immediately to Premium, Care, and Response customers and after a 30‑day delay for free users. The platform offers free access to its vulnerability API, webhook notifications, and a CLI scanner, enabling automated monitoring of the full vulnerability feed. Site owners are urged to review the report, patch any unpatched plugins or themes, and integrate the new firewall rules to maintain defense‑in‑depth security.

Key changes

  • Wordfence Intelligence added 250 new vulnerabilities (181 plugins, 41 themes) to its database
  • 162 vulnerabilities patched, 88 remain unpatched; severity distribution: 152 medium, 89 high, 9 critical
  • New firewall rules deployed: Ninja Forms <=3.3.29 arbitrary file read, WAF‑RULE‑923, WAF‑RULE‑924
  • Premium, Care, Response customers receive firewall protection immediately; free users delayed 30 days
  • Wordfence offers free API, webhook, and CLI scanner for vulnerability data
  • 101 researchers contributed, with João Pedro S Alcântara (36) and PRISM (18) leading

Affects

wp-customers enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting