Wordfence Intelligence Weekly WordPress Vulnerability Report (September 30, 2024 to October 6, 2024)


🦸 👻 Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024:

  • All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
  • Top-tier researchers earn automatic bonuses of between 10% to 120% for valid submissions
  • Pending report limits are increased for all
  • It’s possible to earn up to $31,200 for high impact vulnerabilities!

Last week, there were 166 vulnerabilities disclosed in 152 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 49 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 19,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 139
Unpatched 27


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 146
High Severity 15
Critical Severity 5


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 124
Missing Authorization 9
Cross-Site Request Forgery (CSRF) 5
Deserialization of Untrusted Data 5
Unrestricted Upload of File with Dangerous Type 4
URL Redirection to Untrusted Site ('Open Redirect') 4
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 3
Authentication Bypass Using an Alternate Path or Channel 2
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 2
Improper Control of Generation of Code ('Code Injection') 2
Improper Neutralization of Alternate XSS Syntax 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Improper Privilege Management 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
22
21
12
8
6
6
5
5
4
4
4
4
4
3
3
3
3
3
Leo
3
3
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
123.chat - Video Chat 123-chat-videochat
Addon Elements for Elementor (formerly Elementor Addon Elements) addon-elements-for-elementor-page-builder
Advanced Shipping Rates for WooCommerce: Flexible Table Rate Shipping Rules fish-and-ships
Advanced Woo Labels – Product Labels & Badges for WooCommerce advanced-woo-labels
Affiliate Program Suite — SliceWP Affiliates slicewp
Aggregator Advanced Settings aggregator-advanced-settings
Ajax Load More – Infinite Scroll, Load More, & Lazy Load ajax-load-more
Author Avatars List/Block author-avatars
Auto Amazon Links – Amazon Associates Affiliate Plugin amazon-auto-links
Auto Featured Image from Title auto-featured-image-from-title
Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu
AVIF Uploader avif-support
BA Book Everything ba-book-everything
BerqWP – Automatic WordPress Website Speed Optimization searchpro
BlockSpare – Gutenberg Post Grid Blocks for News, Magazine & Blog Websites blockspare
Bold Page Builder bold-page-builder
Booking Calendar booking
Broken Link Checker broken-link-checker
BSK Forms Blacklist bsk-gravityforms-blacklist
CartBounty – Save and recover abandoned carts for WooCommerce woo-save-abandoned-carts
Checkout Field Editor (Checkout Manager) for WooCommerce woo-checkout-field-editor-pro
Clio Grow Form clio-grow-form
Code Embed simple-embed-code
Confetti Fall Animation confetti-fall-animation
Copyscape Premium copyscape-premium
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 500+ Patterns, 57 Blocks & Templates cozy-addons
Custom Banners custom-banners
Demo Importer Plus demo-importer-plus
Depicter — Popup & Slider Builder depicter
DethemeKit for Elementor dethemekit-for-elementor
Display Medium Posts display-medium-posts
DK PDF – WordPress PDF Generator dk-pdf
Easy Demo Importer – A Modern One-Click Demo Import Solution easy-demo-importer
Easy Load More easy-load-more
Easy WordPress Subscribe – Optin Hound opt-in-hound
Echo RSS Feed Post Generator rss-feed-post-generator-echo
Elastik Page Builder elastik-page-builder
Element Pack – Widgets, Templates & Addons for Elementor bdthemes-element-pack-lite
ElementInvader Addons for Elementor elementinvader-addons-for-elementor
ElementsReady Addons for Elementor element-ready-lite
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress email-subscribers
Enter Addons – Ultimate Template Builder for Elementor enteraddons
EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management
File Manager file-manager
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder fluentform
Gallery Lightbox gallery-lightbox-slider
Geo Mashup geo-mashup
Gravity Forms Toolbar gravity-forms-toolbar
Guten Post Layout – An Advanced Post Grid Collection guten-post-layout
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns essential-blocks
Happy Addons for Elementor happy-elementor-addons
Hash Form – Drag & Drop Form Builder hash-form
Hello World hello-world
Helpie FAQ — Accordion, Docs & Knowledge Base helpie-faq
Ibtana – WordPress Website Builder ibtana-visual-editor
Iconize iconize
Include Fussball.de Widgets include-fussball-de-widgets
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress jeg-elementor-kit
JobSearch WP Job Board wp-jobsearch
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin kb-support
Keap Official Opt-in Forms infusionsoft-official-opt-in-forms
LA-Studio Element Kit for Elementor lastudio-element-kit
LH Copy Media File lh-copy-media-file
LiteSpeed Cache litespeed-cache
LocateAndFilter locateandfilter
Loggedin – Limit Concurrent Sessions loggedin
Login Logout Shortcode login-logout-shortcode
Logo Carousel – Display Brand or Client Logos in Slider responsive-client-logo-carousel-slider
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation gs-logo-slider
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid magazine-blocks
Maspik – Ultimate Spam Protection contact-forms-anti-spam
MaxSlider maxslider
MC4WP: Mailchimp Top Bar – Email Subscribe Notification Bar mailchimp-top-bar
Memberful – Membership Plugin memberful-wp
Move Addons for Elementor move-addons
NEX-Forms – Ultimate Forms Plugin for WordPress nex-forms-express-wp-form-builder
Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita
Page-list page-list
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
Payflex Payment Gateway payflex-payment-gateway
PDF Image Generator pdf-image-generator
Photo Gallery by 10Web – Mobile-Friendly Image Gallery photo-gallery
Popularis Extra popularis-extra
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder popup-maker
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) buddyforms
Premium Blocks – Gutenberg Blocks, Patterns & Templates premium-blocks-for-gutenberg
Price by Quantity & Bulk Quantity Discounts for WooCommerce wholesale-pricing-woocommerce
Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite
PWA — easy way to Progressive Web App iworks-pwa
QS Dark Mode Plugin qs-dark-mode
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes quillforms
R Animated Icon Plugin r-animated-icon
RabbitLoader – AI Speed Optimization, Caching & CDN for WordPress & WooCommerce rabbit-loader
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings seo-by-rank-math
Re:WP rewp
Relogo relogo
Robokassa payment gateway for Woocommerce robokassa
RTMKit rometheme-for-elementor
RumbleTalk Live Group Chat – HTML5 rumbletalk-chat-a-chat-with-themes
Search Analytics for WP search-analytics
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization metasync
SEOPress – AI SEO Plugin & On-site SEO wp-seopress
ShiftController Employee Shift Scheduling shiftcontroller
Shortcodes and extra features for Phlox theme auxin-elements
Simple Membership After Login Redirection simple-membership-after-login-redirection
Slider Revolution revslider
Slideshow Gallery LITE slideshow-gallery
Smart Custom 404 Error Page 404page
Social Auto Poster social-auto-poster
Social Web Suite – Social Media Auto Post, Social Media Auto Publish social-web-suite
Soumettre.fr soumettre-fr
Spice Starter Sites spice-starter-sites
Stars Testimonials — Responsive Reviews & Star Ratings stars-testimonials-with-slider-and-masonry-grid
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers woocommerce-exporter
Strong Testimonials strong-testimonials
SVG Complete svg-complete
Team – Team Members Showcase Plugin tlp-team
The Pack Elementor addon the-pack-addon
Themify Builder themify-builder
TinyPNG – JPEG, PNG & WebP image compression tiny-compress-images
TNC PDF viewer pdf-viewer-by-themencode
TS Poll – Survey, Versus Poll, Image Poll, Video Poll poll-wp
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor ultimate-store-kit
Unlimited Elements For Elementor unlimited-elements-for-elementor
VdoCipher: Secure Video Player and Hosting vdocipher
Visual CSS Style Editor yellow-pencil-visual-theme-customizer
Web Directory Free web-directory-free
Wechat Social login 微信QQ钉钉登录插件 wechat-social-login
WordPress & WooCommerce Affiliate Program wp-wc-affiliate-program
WordPress Captcha Plugin by Captcha Bank captcha-bank
WP Blocks Hub wp-blocks-hub
WP Bulk Delete wp-bulk-delete
WP Cleanup and Basic Functions wp-cleanup-and-basic-functions
WP Compress – Instant Performance & Speed Optimization wp-compress-image-optimizer
WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery
WP Extended – The Ultimate WordPress Toolkit wpextended
WP Hotel Booking wp-hotel-booking
WP MyLinks wp-mylinks
WP Travel Gutenberg Blocks wp-travel-blocks
WP-Lister Lite for eBay wp-lister-for-ebay
WP-WebAuthn wp-webauthn
WPCOM Member wpcom-member
WPMobile.App wpappninja
WPOptin – AI-Powered Top Bars, PopUps & Lead Generation wpoptin
XLTab – Accordions and Tabs for Elementor Page Builder xl-tab
XO Slider xo-liteslider
YITH WooCommerce Ajax Search yith-woocommerce-ajax-search
YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons
YML for Yandex Market yml-for-yandex-market
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More zoho-forms
Zotpress zotpress


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Create create
Empowerment empowerment
Full Frame full-frame
UltraPress ultrapress
Unseen Blog unseen-blog


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Echo RSS Feed Post Generator [rss-feed-post-generator-echo]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Sep 30, 2024
CVSS Rating
9.8 (Critical)
Patch Status
Unpatched
Published
Sep 30, 2024
CVSS Rating
9.8 (Critical)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Empowerment [empowerment]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
MaxSlider [maxslider]
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
UltraPress [ultrapress]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Unseen Blog [unseen-blog]
Researcher
CVSS Rating
8.8 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
8.8 (High)
Patch Status
Patched
Published
Oct 1, 2024
Affected Software
WP Hotel Booking [wp-hotel-booking]
Researcher
CVSS Rating
7.5 (High)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
YITH WooCommerce Ajax Search [yith-woocommerce-ajax-search]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
123.chat - Video Chat [123-chat-videochat]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Iconize [iconize]
Researcher
CVSS Rating
7.2 (High)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
LiteSpeed Cache [litespeed-cache]
Researcher
CVSS Rating
7.1 (High)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Broken Link Checker [broken-link-checker]
Researcher
CVSS Rating
6.5 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Hello World [hello-world]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2024
Affected Software
Aggregator Advanced Settings [aggregator-advanced-settings]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Author Avatars List/Block [author-avatars]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Automatically Hierarchic Categories in Menu [automatically-hierarchic-categories-in-menu]
Researcher(s): Unknown
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
AVIF Uploader [avif-support]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Bold Page Builder [bold-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Code Embed [simple-embed-code]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Confetti Fall Animation [confetti-fall-animation]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Create [create]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 1, 2024
Affected Software
Demo Importer Plus [demo-importer-plus]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
DethemeKit for Elementor [dethemekit-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2024
Affected Software
Display Medium Posts [display-medium-posts]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Elastik Page Builder [elastik-page-builder]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
ElementInvader Addons for Elementor [elementinvader-addons-for-elementor]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Full Frame [full-frame]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Gallery Lightbox [gallery-lightbox-slider]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Geo Mashup [geo-mashup]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Happy Addons for Elementor [happy-elementor-addons]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Include Fussball.de Widgets [include-fussball-de-widgets]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Keap Official Opt-in Forms [infusionsoft-official-opt-in-forms]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
LiteSpeed Cache [litespeed-cache]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
LocateAndFilter [locateandfilter]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2024
Affected Software
Login Logout Shortcode [login-logout-shortcode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Page-list [page-list]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
QS Dark Mode Plugin [qs-dark-mode]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
R Animated Icon Plugin [r-animated-icon]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Re:WP [rewp]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Relogo [relogo]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
RTMKit [rometheme-for-elementor]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
RumbleTalk Live Group Chat – HTML5 [rumbletalk-chat-a-chat-with-themes]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Slider Revolution [revslider]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Stars Testimonials — Responsive Reviews & Star Ratings [stars-testimonials-with-slider-and-masonry-grid]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
SVG Complete [svg-complete]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
The Pack Elementor addon [the-pack-addon]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2024
Affected Software
WP Blocks Hub [wp-blocks-hub]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Oct 4, 2024
Affected Software
WP Cleanup and Basic Functions [wp-cleanup-and-basic-functions]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WP Travel Gutenberg Blocks [wp-travel-blocks]
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WP-WebAuthn [wp-webauthn]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
XO Slider [xo-liteslider]
Researcher
CVSS Rating
6.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Zotpress [zotpress]
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Auto Featured Image from Title [auto-featured-image-from-title]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
BA Book Everything [ba-book-everything]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
BSK Forms Blacklist [bsk-gravityforms-blacklist]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Clio Grow Form [clio-grow-form]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Copyscape Premium [copyscape-premium]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Custom Banners [custom-banners]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Easy Load More [easy-load-more]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
EventPrime – Events Calendar, Bookings and Tickets [eventprime-event-calendar-management]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Gravity Forms Toolbar [gravity-forms-toolbar]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 4, 2024
Affected Software
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
JobSearch WP Job Board [wp-jobsearch]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
LH Copy Media File [lh-copy-media-file]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 1, 2024
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Payflex Payment Gateway [payflex-payment-gateway]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
PDF Image Generator [pdf-image-generator]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Popularis Extra [popularis-extra]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Product Delivery Date for WooCommerce – Lite [product-delivery-date-for-woocommerce-lite]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 1, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Simple Membership After Login Redirection [simple-membership-after-login-redirection]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Social Auto Poster [social-auto-poster]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 4, 2024
Affected Software
Themify Builder [themify-builder]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Unlimited Elements For Elementor [unlimited-elements-for-elementor]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Web Directory Free [web-directory-free]
CVSS Rating
6.1 (Medium)
Patch Status
Unpatched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WP Bulk Delete [wp-bulk-delete]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Search Analytics for WP [search-analytics]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WP-Lister Lite for eBay [wp-lister-for-ebay]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WPCOM Member [wpcom-member]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WPMobile.App [wpappninja]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Visual CSS Style Editor [yellow-pencil-visual-theme-customizer]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
YITH WooCommerce Product Add-Ons [yith-woocommerce-product-add-ons]
Researcher
CVSS Rating
6.1 (Medium)
Patch Status
Patched
Published
Oct 1, 2024
Affected Software
YML for Yandex Market [yml-for-yandex-market]
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
5.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
CVSS Rating
5.3 (Medium)
Patch Status
Unpatched
Published
Sep 30, 2024
Affected Software
Spice Starter Sites [spice-starter-sites]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Oct 2, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Slideshow Gallery LITE [slideshow-gallery]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
TNC PDF viewer [pdf-viewer-by-themencode]
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
Affected Software
Researcher
CVSS Rating
4.4 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
WP MyLinks [wp-mylinks]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
LiteSpeed Cache [litespeed-cache]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Oct 3, 2024
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Soumettre.fr [soumettre-fr]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Strong Testimonials [strong-testimonials]
Researcher
CVSS Rating
4.3 (Medium)
Patch Status
Patched
Published
Sep 30, 2024
Affected Software
Researcher(s): Unknown


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments