Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 Active Installs are in scope for all researchers. In addition, through October 14th, 2024, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 160 vulnerabilities disclosed in 111 WordPress Plugins and 23 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 53 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 125
Unpatched 35


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 132
High Severity 16
Critical Severity 12


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 74
Missing Authorization 31
Cross-Site Request Forgery (CSRF) 17
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 11
Deserialization of Untrusted Data 6
Exposure of Sensitive Information to an Unauthorized Actor 6
Use of Less Trusted Source 3
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
Unrestricted Upload of File with Dangerous Type 2
Authorization Bypass Through User-Controlled Key 1
Improper Authorization 1
Improper Control of Generation of Code ('Code Injection') 1
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
Protection Mechanism Failure 1
Server-Side Request Forgery (SSRF) 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
19
11
10
9
8
7
6
6
5
5
5
4
3
3
Seb
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
Accordion Image Menu accordion-image-menu
Addon Elements for Elementor (formerly Elementor Addon Elements) addon-elements-for-elementor-page-builder
Animated Number Counters animated-number-counters
azurecurve Toggle Show/Hide azurecurve-toggle-showhide
Beaver Builder Page Builder – Drag and Drop Website Builder beaver-builder-lite-version
Booking Calendar booking
Brickscore brickscore
Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation
Carousel Slider carousel-slider
Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons
Clean Login clean-login
Collapsing Archives collapsing-archives
Custom Field Template custom-field-template
Custom Query Blocks post-type-archive-mapping
Droip droip
DSGVO All in one for WP dsgvo-all-in-one-for-wp
E-cab Taxi Booking Manager for Woocommerce ecab-taxi-booking-manager
easy.jobs – AI powered Job Listing, Job Board, Career Page, Recruitment & Hiring Solution easyjobs
Email Address Encoder email-address-encoder
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents embedpress
Enhanced Search Box extended-search-plugin
Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More envira-gallery-lite
EU/UK VAT Validation Manager for WooCommerce eu-vat-for-woocommerce
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
Front End Users front-end-only-users
FunnelKit Funnel Builder Pro funnel-builder-pro
Generate Images (AI) – Magic Post Thumbnail magic-post-thumbnail
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory
GHActivity ghactivity
GiveWP – Donation Plugin and Fundraising Platform give
Greenshift Query and Meta Addon greenshiftquery
Gutenverse – WordPress Blocks, Page Builder & Site Editor gutenverse
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms happyforms
HelloAsso helloasso
HubSpot All-In-One Marketing – Forms, Popups, Live Chat leadin
infolinks Ad Wrap infolinks-ad-wrap
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free funnelforms-free
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress jeg-elementor-kit
JobSearch WP Job Board wp-jobsearch
Justified Image Grid - Premium WordPress Gallery justified-image-grid
LatePoint Plugin latepoint
Like Button Rating ♥ LikeBtn likebtn-like-button
Login As Users login-as-users
Logo Manager For Enamad – لوگوی نماد الکترونیکی logo-manager-for-enamad
Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid logo-showcase-ultimate
LWS Affiliation lws-affiliation
Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation
Media Library Folders media-library-plus
Memberpress memberpress
Mollie Payments for WooCommerce mollie-payments-for-woocommerce
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar mp3-music-player-by-sonaar
Name Directory name-directory
Newspack newspack-plugin
Ninja Forms – The Contact Form Builder That Grows With You ninja-forms
Ninja Tables – Easy Data Table Builder ninja-tables
NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization nitropack
Oxygen Builder oxygenbuilder
Page Builder: Pagelayer – Drag and Drop website builder pagelayer
Payment forms, Buy now buttons, and Invoicing System | GetPaid invoicing
Permalink Manager Lite permalink-manager
Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress
Polls CP cp-polls
Popup Builder – Create highly converting, mobile friendly marketing popups. popup-builder
Posts reminder posts-reminder
Premium Portfolio Features for Phlox theme auxin-portfolio
Premium SEO Pack – WP SEO Plugin premium-seo-pack
Propovoice Pro propovoice-pro
Relevanssi Live Ajax Search relevanssi-live-ajax-search
Responsive Lightbox & Gallery responsive-lightbox
Review Ratings ratings-shorttags
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More reviews-feed
Royal Addons for Elementor – Addons and Templates Kit for Elementor royal-elementor-addons
SendGrid for WordPress wp-sendgrid-mailer
Share This Image share-this-image
SKT Blocks – Gutenberg based Page Builder skt-blocks
Special Feed Items special-feed-items
Spiffy Calendar spiffy-calendar
Sunshine Photo Cart – Client Photo Gallery & Photo Proofing for Photographers sunshine-photo-cart
Super Store Finder superstorefinder-wp
Super Testimonial – Testimonial & Customer Review Slider Plugin for WordPress super-testimonial
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments surecart
tagDiv Composer td-composer
The Events Calendar Pro events-calendar-pro
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce the-plus-addons-for-elementor-page-builder
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid the-post-grid
Theme Editor theme-editor
Timetics – Appointment Booking Calendar & Scheduling timetics
Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin tourfic
Tutor LMS Pro tutor-pro
Two-factor authentication (formerly IP Vault) ip-vault-wp-firewall
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor ultimate-store-kit
Vikinghammer Tweet vikinghammer-tweet
Visual CSS Style Editor yellow-pencil-visual-theme-customizer
Visual Sound (old) visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams
Web and WooCommerce Addons for WPBakery Builder vc-addons-by-bit14
Web Application Firewall – website security web-application-firewall
Woocommerce Addon Greenshift greenshiftwoo
WP Accessibility Helper (WAH) wp-accessibility-helper
WP Armour Extended wp-armour-extended
WP Cerber Security, Anti-spam & Malware Scan wp-cerber
WP Crowdfunding wp-crowdfunding
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes
WP Events Manager wp-events-manager
WP Testimonial Widget wp-testimonial-widget
WP To Do wp-todo
WPMobile.App wpappninja
WPZOOM Portfolio Lite – Filterable Portfolio Plugin wpzoom-portfolio
Xpro Addons — 140+ Widgets for Elementor xpro-elementor-addons
YARPP – Yet Another Related Posts Plugin yet-another-related-posts-plugin
Zippy zippy
Zynith SEO zynith-seo


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Attire attire
Betheme betheme
Blockbooster blockbooster
Blogpoet blogpoet
Enfold - Responsive Multi-Purpose Theme enfold
Esotera esotera
Filmix filmix
Fluida fluida
FotaWP fotawp
Hotel Galaxy hotel-galaxy
IntoTheDark intothedark
Kahuna kahuna
Liquido liquido
Mantra mantra
Masterstudy - Education WordPress Theme ms-lms-starter-theme
Mystique mystique
Nirvana nirvana
Opor Ayam opor-ayam
Parabola parabola
Posterity posterity
ReviveNews revivenews
Sliding Door sliding-door
Tempera tempera


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
10.0 (Critical)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
10.0 (Critical)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Propovoice Pro [propovoice-pro]
Researcher
CVSS Rating
10.0 (Critical)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
SendGrid for WordPress [wp-sendgrid-mailer]
Researcher
CVSS Rating
10.0 (Critical)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder [superstorefinder-wp]
Researcher
CVSS Rating
9.9 (Critical)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Researcher
CVSS Rating
9.9 (Critical)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder [superstorefinder-wp]
Researcher
CVSS Rating
9.9 (Critical)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Droip [droip]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
The Events Calendar Pro [events-calendar-pro]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
WP Testimonial Widget [wp-testimonial-widget]
Researcher
CVSS Rating
9.1 (Critical)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Zynith SEO [zynith-seo]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Animated Number Counters [animated-number-counters]
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Attire [attire]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Betheme [betheme]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Clean Login [clean-login]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Front End Users [front-end-only-users]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Login As Users [login-as-users]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
WP Events Manager [wp-events-manager]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Brickscore [brickscore]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder [superstorefinder-wp]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Theme Editor [theme-editor]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Zippy [zippy]
Researcher
CVSS Rating
7.1 (High)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Tutor LMS Pro [tutor-pro]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Media Library Folders [media-library-plus]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
azurecurve Toggle Show/Hide [azurecurve-toggle-showhide]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Classic Addons – WPBakery Page Builder [classic-addons-wpbakery-page-builder-addons]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Collapsing Archives [collapsing-archives]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Custom Field Template [custom-field-template]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Custom Query Blocks [post-type-archive-mapping]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
DSGVO All in one for WP [dsgvo-all-in-one-for-wp]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Esotera [esotera]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Fluida [fluida]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Front End Users [front-end-only-users]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
FunnelKit Funnel Builder Pro [funnel-builder-pro]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
GHActivity [ghactivity]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Hotel Galaxy [hotel-galaxy]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Kahuna [kahuna]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
LatePoint Plugin [latepoint]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Liquido [liquido]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Mantra [mantra]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Mystique [mystique]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Nirvana [nirvana]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Parabola [parabola]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Podlove Podcast Publisher [podlove-podcasting-plugin-for-wordpress]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Posterity [posterity]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Share This Image [share-this-image]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Sliding Door [sliding-door]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Tempera [tempera]
Researcher
CVSS Rating
6.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Media Library Folders [media-library-plus]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Accordion Image Menu [accordion-image-menu]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Filmix [filmix]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
IntoTheDark [intothedark]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Like Button Rating ♥ LikeBtn [likebtn-like-button]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Memberpress [memberpress]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Name Directory [name-directory]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Opor Ayam [opor-ayam]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Review Ratings [ratings-shorttags]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Special Feed Items [special-feed-items]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
tagDiv Composer [td-composer]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
tagDiv Composer [td-composer]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Vikinghammer Tweet [vikinghammer-tweet]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WP Armour Extended [wp-armour-extended]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WPMobile.App [wpappninja]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Visual CSS Style Editor [yellow-pencil-visual-theme-customizer]
Researcher
CVSS Rating
5.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
WP Accessibility Helper (WAH) [wp-accessibility-helper]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Blockbooster [blockbooster]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Blogpoet [blogpoet]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
FotaWP [fotawp]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Maintenance & Coming Soon Redirect Animation [maintenance-coming-soon-redirect-animation]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Memberpress [memberpress]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Mollie Payments for WooCommerce [mollie-payments-for-woocommerce]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Permalink Manager Lite [permalink-manager]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 28, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Relevanssi Live Ajax Search [relevanssi-live-ajax-search]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Responsive Lightbox & Gallery [responsive-lightbox]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
ReviveNews [revivenews]
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
YARPP – Yet Another Related Posts Plugin [yet-another-related-posts-plugin]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Zynith SEO [zynith-seo]
Researcher
CVSS Rating
4.9 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Spiffy Calendar [spiffy-calendar]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Bus Ticket Booking with Seat Reservation [bus-ticket-booking-with-seat-reservation]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 1, 2024
Affected Software
Polls CP [cp-polls]
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 1, 2024
Affected Software
Polls CP [cp-polls]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
WP Testimonial Widget [wp-testimonial-widget]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
WP To Do [wp-todo]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Carousel Slider [carousel-slider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Carousel Slider [carousel-slider]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Droip [droip]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Droip [droip]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Email Address Encoder [email-address-encoder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Enhanced Search Box [extended-search-plugin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
HelloAsso [helloasso]
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
infolinks Ad Wrap [infolinks-ad-wrap]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
LatePoint Plugin [latepoint]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
LWS Affiliation [lws-affiliation]
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Newspack [newspack-plugin]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Oxygen Builder [oxygenbuilder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Posts reminder [posts-reminder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Visual Sound (old) [visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WP Armour Extended [wp-armour-extended]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WP Crowdfunding [wp-crowdfunding]


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments