Wordfence Intelligence Weekly WordPress Vulnerability Report (April 1, 2024 to April 7, 2024)


🎉 Did you know we’re running a Bug Bounty Extravaganza again?

Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!


Last week, there were 195 vulnerabilities disclosed in 156 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 73 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 15,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 182
Unpatched 13


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 161
High Severity 18
Critical Severity 15


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 71
Missing Authorization 33
Cross-Site Request Forgery (CSRF) 28
Exposure of Sensitive Information to an Unauthorized Actor 13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 9
Unrestricted Upload of File with Dangerous Type 7
Authorization Bypass Through User-Controlled Key 5
Deserialization of Untrusted Data 4
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 4
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
Incorrect Privilege Assignment 2
Server-Side Request Forgery (SSRF) 2
URL Redirection to Untrusted Site ('Open Redirect') 2
Absolute Path Traversal 1
Exposure of Private Personal Information to an Unauthorized Actor 1
External Control of Assumed-Immutable Web Parameter 1
Guessable CAPTCHA 1
Improper Access Control 1
Improper Authorization 1
Improper Control of Generation of Code ('Code Injection') 1
Improper Neutralization of Alternate XSS Syntax 1
Improper Neutralization of Formula Elements in a CSV File 1
Incorrect Authorization 1
Incorrect Behavior Order: Early Validation 1
Insertion of Sensitive Information into Log File 1
Path Traversal: '.../...//' 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
14
9
9
8
8
7
7
7
7
7
6
5
4
4
4
4
4
4
4
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
ST
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Advanced Order Export For WooCommerce woo-order-export-lite
Advanced Search advance-search
AGCA – Custom Dashboard & Login Page ag-custom-admin
All-in-One Video Gallery all-in-one-video-gallery
Announce from the Dashboard announce-from-the-dashboard
Announcer – Sticky Message Banner & Notification Bar announcer
App Builder – Create Native Android & iOS Apps On The Flight app-builder
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress bookingpress-appointment-booking
AppPresser – Mobile App Framework apppresser
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup armember-membership
Auto Poster auto-poster
AWP Classifieds another-wordpress-classifieds-plugin
Bannerlid bannerlid
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
Beaver Themer beaver-themer
Better Comments better-comments
Bold Page Builder bold-page-builder
BoldGrid Easy SEO – Simple and Effective SEO boldgrid-easy-seo
Bricksforge bricksforge
Call Now Button – The #1 Click to Call Button for WordPress call-now-button
Captcha by BestWebSoft – Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms captcha-bws
Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel wp-carousel-free
CGC Maintenance Mode cgc-maintenance-mode
Checkout Field Editor (Checkout Page Manager) for WooCommerce woo-checkout-regsiter-field-editor
Church Admin church-admin
Classified Listing – AI-Powered Classified ads & Business Directory classified-listing
CMB2 cmb2
Colibri Page Builder colibri-page-builder
Comments Import & Export comments-import-export-woocommerce
Contact Form Email contact-form-to-email
Contact Form, Survey, Quiz & Popup Form Builder – ARForms arforms-form-builder
Creative Addons for Elementor creative-addons-for-elementor
Custom post types, Custom Fields & more custom-post-types
Demo My WordPress demo-my-wordpress
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy easy-digital-downloads
Easy Google Maps google-maps-easy
Easy Login Styler – White Label Admin Login Page for WordPress easy-login-styler
Easy Social Share Buttons for WordPress easy-social-share-buttons3
Edwiser Bridge – WordPress Moodle Integration edwiser-bridge
Element Pack – Widgets, Templates & Addons for Elementor bdthemes-element-pack-lite
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor elementskit-lite
ELEX WooCommerce Dynamic Pricing and Discounts elex-woocommerce-dynamic-pricing-and-discounts
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more embedpress
ENL Newsletter enl-newsletter
EnvĂ­aloSimple: Email Marketing y Newsletters envialosimple-email-marketing-y-newsletters-gratis
ePoll – Best WordPress Voting Plugin for Poll & Contest epoll-wp-voting
EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management
FancyBox for WordPress fancybox-for-wordpress
FG Drupal to WordPress fg-drupal-to-wp
File Manager wp-file-manager
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager flexible-checkout-fields
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty chaty
Form to Chat App ⚡️ form-to-chat
Formsite | Embed online forms to collect orders, registrations, leads, and surveys formsite
Generate Child Theme generate-child-theme
Genesis Blocks genesis-blocks
Global Elementor Buttons global-elementor-buttons
Gradient Text Widget for Elementor gradient-text-widget-for-elementor
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns essential-blocks
Happy Addons for Elementor happy-elementor-addons
Image Watermark image-watermark
Import WP – Export and Import CSV and XML files to WordPress jc-importer
Import XML and RSS Feeds import-xml-feed
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress jeg-elementor-kit
JS Help Desk – AI-Powered Support & Ticketing System js-support-ticket
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor kadence-blocks
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages convertkit
LayerSlider LayerSlider
LearnPress – Backup & Migration Tool learnpress-import-export
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses learnpress
MailMunch – Grow your Email List mailmunch
Masteriyo LMS – LMS Course Builder, Quizzes & Certificates learning-management-system
MasterStudy LMS WordPress Plugin – for Online Courses and Education masterstudy-lms-learning-management-system
Media Library Folders media-library-plus
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor metform
MM-email2image mm-email2image
Modal Popup Box — Popup Maker & Popup Builder modal-popup-box
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar mp3-music-player-by-sonaar
MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO multiple-pages-generator-by-porthas
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions dc-woocommerce-multi-vendor
Nudgify Social Proof nudgify
Passster – Password Protect Pages and Content content-protector
Photo Gallery by 10Web – Mobile-Friendly Image Gallery photo-gallery
Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel foogallery
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery nextgen-gallery
PickPlugins Product Designer for WooCommerce product-designer
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX ultimate-post
Post Views Counter post-views-counter
Powerkit – Supercharge your WordPress Site powerkit
Premium Addons for Elementor – Powerful Elementor Templates & Widgets premium-addons-for-elementor
Product Sort and Display for WooCommerce woocommerce-product-sort-and-display
ProfileGrid – User Profiles, Groups and Communities profilegrid-user-profiles-groups-and-communities
Quick Interest Slider quick-interest-slider
RapidLoad AI – Optimize Web Vitals Automatically unusedcss
ReDi Restaurant Reservation – Instant Availability & Confirmation redi-restaurant-reservation
reHub Framework rehub-framework
Relevanssi Premium relevanssi-premium
Relevanssi – A Better Search relevanssi
Responsive Lightbox & Gallery responsive-lightbox
Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator feedzy-rss-feeds
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions s2member
Salon Booking System – Free Version salon-booking-system
Save as Image Plugin by PDFCrowd save-as-image-by-pdfcrowd
SearchIQ – The Search Solution searchiq
SecuPress with Simple SSL – Simple and Performant Security secupress
Sharkdropship & affiliate for AliExpress wooshark-aliexpress-importer
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin woolentor-addons
Shortcodes Ultimate – Content Elements shortcodes-ultimate
ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization shortpixel-adaptive-images
Sign-up Sheets sign-up-sheets
Slideshow Gallery LITE slideshow-gallery
Smart Online Order for Clover clover-online-orders
Smart Post – Post Grid, Post Carousel, Post Slider Gutenberg Blocks for Blog & News post-carousel
Social Sharing Plugin – Sassy Social Share sassy-social-share
Spectra Gutenberg Blocks – Website Builder for the Block Editor ultimate-addons-for-gutenberg
Squelch Tabs and Accordions Shortcodes squelch-tabs-and-accordions-shortcodes
Stax Addons for Elementor stax-addons-for-elementor
Strong Testimonials strong-testimonials
Subscribe To Comments Reloaded subscribe-to-comments-reloaded
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress super-testimonial
Sydney Toolbox sydney-toolbox
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms simple-tags
Template Kit – Import template-kit-import
Tickera – Sell Tickets & Manage Events tickera-event-ticketing-system
Tooltips for WordPress wordpress-tooltips
Tracking Code Manager tracking-code-manager
Transcoder transcoder
Ultimate Bootstrap Elements for Elementor ultimate-bootstrap-elements-for-elementor
Ultimate Maps by Supsystic ultimate-maps-by-supsystic
User Activity Log user-activity-log
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor profile-builder
User Spam Remover user-spam-remover
Watu Quiz watu
WebinarPress – Webinar System for WordPress wp-webinarsystem
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation sumome
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels print-invoices-packing-slip-labels-for-woocommerce
WebToffee WP Backup and Migration wp-migration-duplicator
Wholesale For WooCommerce woocommerce-wholesale-pricing
WooCommerce woocommerce
WooCommerce Customers Manager woocommerce-customers-manager
WordPress Gallery Exporter – Export your NextGen, Envira and FooGallery galleries to your computer wp-gallery-exporter
WP Chat App wp-whatsapp
WP Directory Kit wpdirectorykit
WP Google Review Slider wp-google-places-review-slider
WP Import Export Lite wp-import-export-lite
WP OAuth Server (OAuth Authentication) oauth2-provider
WP Photo Album Plus wp-photo-album-plus
WP Server Health Stats wp-server-stats
WP Sort Order wp-sort-order
WP-Members Membership Plugin wp-members
WP-Stateless – Google Cloud Storage wp-stateless
WPFront User Role Editor wpfront-user-role-editor
WPvivid Backup for MainWP wpvivid-backup-mainwp
Zorem Local Pickup advanced-local-pickup-for-woocommerce


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Hello Elementor hello-elementor
REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme rehub-theme


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.9 (Critical)
Patch Status
Patched
Published
Apr 7, 2024
Affected Software
Slideshow Gallery LITE [slideshow-gallery]
Researcher
CVSS Rating
9.9 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Photo Album Plus [wp-photo-album-plus]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Demo My WordPress [demo-my-wordpress]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 2, 2024
Affected Software
LayerSlider [LayerSlider]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Apr 3, 2024
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
Auto Poster [auto-poster]
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Import XML and RSS Feeds [import-xml-feed]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Apr 7, 2024
Affected Software
User Activity Log [user-activity-log]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Church Admin [church-admin]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Easy Social Share Buttons for WordPress [easy-social-share-buttons3]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
EnvĂ­aloSimple: Email Marketing y Newsletters [envialosimple-email-marketing-y-newsletters-gratis]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 3, 2024
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
reHub Framework [rehub-framework]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
WP Directory Kit [wpdirectorykit]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Apr 5, 2024
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
CMB2 [cmb2]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 3, 2024
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Apr 4, 2024
Affected Software
Advanced Search [advance-search]
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Import Export Lite [wp-import-export-lite]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Researcher
CVSS Rating
6.8 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
File Manager [wp-file-manager]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Zorem Local Pickup [advanced-local-pickup-for-woocommerce]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
Beaver Themer [beaver-themer]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Product Sort and Display for WooCommerce [woocommerce-product-sort-and-display]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 6, 2024
Affected Software
Beaver Themer [beaver-themer]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
Better Comments [better-comments]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Colibri Page Builder [colibri-page-builder]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Creative Addons for Elementor [creative-addons-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Apr 4, 2024
Affected Software
Stax Addons for Elementor [stax-addons-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Genesis Blocks [genesis-blocks]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Apr 4, 2024
Affected Software
Global Elementor Buttons [global-elementor-buttons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
Gradient Text Widget for Elementor [gradient-text-widget-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
MM-email2image [mm-email2image]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Squelch Tabs and Accordions Shortcodes [squelch-tabs-and-accordions-shortcodes]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
Strong Testimonials [strong-testimonials]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Sydney Toolbox [sydney-toolbox]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Template Kit – Import [template-kit-import]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Ultimate Bootstrap Elements for Elementor [ultimate-bootstrap-elements-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Watu Quiz [watu]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
Bannerlid [bannerlid]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
ELEX WooCommerce Dynamic Pricing and Discounts [elex-woocommerce-dynamic-pricing-and-discounts]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
ENL Newsletter [enl-newsletter]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
MM-email2image [mm-email2image]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
WooCommerce Customers Manager [woocommerce-customers-manager]
Researcher
CVSS Rating
5.8 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Relevanssi Premium [relevanssi-premium]
CVSS Rating
5.8 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Wholesale For WooCommerce [woocommerce-wholesale-pricing]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Bricksforge [bricksforge]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Bricksforge [bricksforge]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Bricksforge [bricksforge]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Apr 3, 2024
Affected Software
CGC Maintenance Mode [cgc-maintenance-mode]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Contact Form Email [contact-form-to-email]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
FG Drupal to WordPress [fg-drupal-to-wp]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Sharkdropship & affiliate for AliExpress [wooshark-aliexpress-importer]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 7, 2024
Affected Software
Slideshow Gallery LITE [slideshow-gallery]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Subscribe To Comments Reloaded [subscribe-to-comments-reloaded]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
Tickera – Sell Tickets & Manage Events [tickera-event-ticketing-system]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
User Spam Remover [user-spam-remover]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WebToffee WP Backup and Migration [wp-migration-duplicator]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
WordPress [wordpress]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
Announce from the Dashboard [announce-from-the-dashboard]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 3, 2024
Affected Software
Better Comments [better-comments]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
FancyBox for WordPress [fancybox-for-wordpress]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 2, 2024
Affected Software
Save as Image Plugin by PDFCrowd [save-as-image-by-pdfcrowd]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Chat App [wp-whatsapp]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Google Review Slider [wp-google-places-review-slider]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WPvivid Backup for MainWP [wpvivid-backup-mainwp]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
All-in-One Video Gallery [all-in-one-video-gallery]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
AWP Classifieds [another-wordpress-classifieds-plugin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Church Admin [church-admin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Easy Google Maps [google-maps-easy]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Easy Social Share Buttons for WordPress [easy-social-share-buttons3]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Apr 5, 2024
Affected Software
ENL Newsletter [enl-newsletter]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Generate Child Theme [generate-child-theme]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Hello Elementor [hello-elementor]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Image Watermark [image-watermark]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Quick Interest Slider [quick-interest-slider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Media Library Folders [media-library-plus]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Post Views Counter [post-views-counter]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Responsive Lightbox & Gallery [responsive-lightbox]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Sign-up Sheets [sign-up-sheets]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 7, 2024
Affected Software
Slideshow Gallery LITE [slideshow-gallery]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Smart Online Order for Clover [clover-online-orders]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Tracking Code Manager [tracking-code-manager]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Transcoder [transcoder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Ultimate Maps by Supsystic [ultimate-maps-by-supsystic]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 4, 2024
Affected Software
Watu Quiz [watu]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WooCommerce [woocommerce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 2, 2024
Affected Software
WooCommerce Customers Manager [woocommerce-customers-manager]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Comments Import & Export [comments-import-export-woocommerce]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
Tooltips for WordPress [wordpress-tooltips]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Server Health Stats [wp-server-stats]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 5, 2024
Affected Software
WP Sort Order [wp-sort-order]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Apr 1, 2024
Affected Software
WPFront User Role Editor [wpfront-user-role-editor]
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments