RSFirewall!

RSFirewall! has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Path Traversal, Use Of Less Trusted Source.

Every one of the 3 issues recorded for RSFirewall! has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. RSFirewall! is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.2/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all RSFirewall! vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-25341

RSFirewall! <= 1.1.45 - Unauthenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
RSFirewall! banner
Latestv1.1.48

RSFirewall!

RSJoomla!

Author

RSJoomla!

5.0(5)
100/100
Last Updated
2026-08-20 (24d ago)
Active Installs
4,000+
Downloads
37,343
Requires WP
4.5.15+
Requires PHP
5.4+
Tested up to
WP 7.1
Created
2019-07-09 (7y ago)

The RSFirewall! WordPress plugin is the optimal solution for securing your website, helping you stay one step ahead of malicious users that wish to harm your website. The plugin is backed by a team of professionals with a long history in website security that are up to date with the latest known vulnerabilities and security updates. RSFIREWALL FREE VERSION FEATURES: Free WordPress Firewall for your website Active protections against local file and remote file inclusion attacks SQL injection protections ReCAPTCHA for registration, login and commenting forms Filter uploaded files for possible malware and improper extensions Active monitoring WordPress core files integrity Active monitoring for your own files XML-RPC blocking REST API blocking with proper exceptions that you can define Protect the wp-admin/ slug with an extra password Change the wp-admin/ slug into a custom one Disallow direct access to PHP files in (wp-content, wp-content/uploads, wp-includes) with proper exceptions that you can define Receive email notifications on detected threats Automatically block repeated offenders IP addresses Perform a System check (WordPress and server configuration checks) Disable the creation of new Administrator accounts RSFIREWALL PAID VERSION FEATURES: Two Factor Authentication Country blocking Convert email addresses to images Protect forms from abusive IPs File integrity check Convert email addresses from plain text to images More control over the system check Whitelist blocked PHP files Protect admin users from changes 3rd Party services RSFirewall! will compare the MD5 hash of files with the original ones from the WordPress installation package. If differences are found (ie files have been modified) RSFirewall! upon request can download the original files from the GitHub synchronised repository of WordPress: https://github.com/WordPress/WordPress/ All connections are made with wp_remote_get and the following information will be sent along with the request: – WordPress version – WordPress user agent along with your WordPress website address – Your server’s IP address

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C