Wordfence Weekly Vulnerability Report: 157 Vulnerabilities Disclosed Across 122 Plugins and 27 Themes
Patch any affected plugins or themes immediately; check the Wordfence vulnerability database for the 157 disclosed issues.
Patch any vulnerable plugins or themes immediately and run Wordfence CLI scans to verify patch status.
Summary
Wordfence released its weekly vulnerability report on 26 April 2025, detailing 157 newly disclosed vulnerabilities affecting 122 WordPress plugins and 27 themes. The report lists 69 researchers who contributed to the findings, with 115 vulnerabilities already patched and 42 still unpatched. Severity breakdown shows 104 medium, 47 high, and 6 critical issues, with the most common CWE types being XSS (47), missing authorization (34), deserialization (23), CSRF (12), and file upload (9).
Wordfence’s free vulnerability database now contains over 35,000 entries and offers API, webhook, and CLI tools for automated monitoring. Premium, Care, and Response customers received real‑time firewall rules for the latest threats, while free users will receive the same protection after a 30‑day delay. The team also highlighted 69 active researchers, including Denver Jackson (17), Jakub Herman (12), and others, underscoring community involvement.
The report encourages site owners to review the database and run scans to ensure no unpatched vulnerabilities remain. Wordfence continues to provide free access to its intelligence services for both individuals and enterprises.
Key changes
- 157 vulnerabilities disclosed across 122 plugins and 27 themes
- 115 patched, 42 unpatched
- severity: 104 medium, 47 high, 6 critical
- top CWE types: XSS (47), missing auth (34), deserialization (23), CSRF (12), file upload (9)