Wordfence Intelligence Weekly WordPress Vulnerability Report (November 25, 2024 to December 1, 2024)
💥 Time to wrap up this year and kick-off the new year with a bang! We’re wrapping up the year with our End of Year Holiday Extravaganza, High-Risk Bonus Blitz Challenge, and Superhero Challenge for the Wordfence Bug Bounty Program. Through January 6th, 2025:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- All plugins and themes with 50-999 active installs hosted in the WordPress.org repository and updated within the last 2 years are in-scope for all researchers!
- All plugins and themes hosted in the WordPress.org repository with any install count are in scope for our preset list of high threat vulnerabilities.
- $150 bonus awarded when a researcher submits at least 15 valid high threat vulnerabilities, and then a $50 bonus awarded for every 5 submitted thereafter.
- Minimum bounty of $5 for all valid in-scope submissions.
- All researchers earn automatic bonuses of between 5% to 180% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 118 vulnerabilities disclosed in 117 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 20,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- Â WAF-RULE-773 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
| Patch Status | Number of Vulnerabilities |
|---|---|
| Patched | 74 |
| Unpatched | 44 |
Total Vulnerabilities by CVSS Severity Last Week
| Severity Rating | Number of Vulnerabilities |
|---|---|
| Medium Severity | 103 |
| High Severity | 9 |
| Critical Severity | 6 |
Total Vulnerabilities by CWE Type Last Week
| Vulnerability Type by CWE | Number of Vulnerabilities |
|---|---|
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 57 |
| Cross-Site Request Forgery (CSRF) | 25 |
| Missing Authorization | 6 |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 4 |
| Authorization Bypass Through User-Controlled Key | 3 |
| Exposure of Sensitive Information to an Unauthorized Actor | 3 |
| Unrestricted Upload of File with Dangerous Type | 3 |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | 2 |
| Improper Control of Generation of Code ('Code Injection') | 2 |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 2 |
| Authentication Bypass Using an Alternate Path or Channel | 1 |
| Exposure of Sensitive Information Through Data Queries | 1 |
| Generation of Error Message Containing Sensitive Information | 1 |
| Improper Authorization | 1 |
| Improper Check or Handling of Exceptional Conditions | 1 |
| Improper Handling of Missing Values | 1 |
| Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | 1 |
| Incorrect Conversion between Numeric Types | 1 |
| Path Traversal: '.../...//' | 1 |
| Server-Side Request Forgery (SSRF) | 1 |
| Weak Password Recovery Mechanism for Forgotten Password | 1 |
Researchers That Contributed to WordPress Security Last Week
| Researcher Name | Number of Vulnerabilities |
|---|---|
| 26 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
| Software Name | Software Slug |
|---|---|
| Additional Order Filters for WooCommerce | additional-order-filters-for-woocommerce |
| Advanced What should we write next about | advanced-what-should-we-write-about-next |
| AppPresser – Mobile App Framework | apppresser |
| Asset CleanUp: Page Speed Booster | wp-asset-clean-up |
| Automatic Internal Links for SEO by Pagup | automatic-internal-links-for-seo |
| Awesome Event Booking | awesome-event-booking |
| Best Addons for Elementor | best-addons-for-elementor |
| BNE Gallery Extended | bne-gallery-extended |
| Booking & Appointment Plugin for WooCommerce | woocommerce-booking |
| Booking calendar, Appointment Booking System | booking-calendar |
| Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools | woocommerce-jetpack |
| Build App Online | build-app-online |
| Button Plus for Elementor | fd-elementor-button-plus |
| Capitalize My Title WordPress Plugin | capitalize-my-title |
| Chatter | chatter |
| CleanTalk Anti-Spam. Spam Firewall & Bot protection | cleantalk-spam-protect |
| Cleanup – Directory Listing & Classifieds WordPress Plugin | cleanup-light |
| CM Business Directory – Optimise and showcase local business | cm-business-directory |
| CM E-Mail Blacklist – Simple email filtering for safer registration | cm-email-blacklist |
| CM Header and Footer – Add custom scripts and styles to your header and footer with ease | cm-header-footer-script-loader |
| CM Pop-Up – Create engaging popups to capture attention and boost interaction | cm-pop-up-banners |
| CM Search And Replace – Optimize content edits with a powerful search and replace tool | cm-on-demand-search-and-replace |
| CM Tooltip Glossary | enhanced-tooltipglossary |
| CM Video Lessons Manager – Simplify video lessons management for better education | cm-video-lesson-manager |
| Contact Forms by Cimatti | contact-forms |
| Content Audit Exporter | content-audit-exporter |
| Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | contest-gallery |
| Cost Calculator Builder | cost-calculator-builder |
| Countdown Timer for Elementor | countdown-timer-for-elementor |
| Cowidgets – Elementor Addons | cowidgets-elementor-addons |
| Cryptocurrency Widgets For Elementor | cryptocurrency-widgets-for-elementor |
| CultBooking Hotel Booking Engine | cultbooking-booking-engine |
| Custom Post Type to Map Store | cpt-to-map-store |
| DancePress (TRWA) | dancepress-trwa |
| Devnex Addons For Elementor | devnex-addons-for-elementor |
| Donate Me | donate-me |
| Download Manager | download-manager |
| eDoc Easy Tables – Best WordPress Table Maker | edoc-easy-tables |
| Elementor Website Builder – more than just a page builder | elementor |
| EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | embedpress |
| Essential Breadcrumbs | essential-breadcrumbs |
| FAQ Builder AYS | faq-builder-ays |
| FastBook – Responsive Appointment Booking and Scheduling System | fastbook-responsive-appointment-booking-and-scheduling-system |
| File Manager Pro – Filester | filester |
| GTPayment Donations | gtpayment-donation |
| HLS Player | hls-player |
| Hustle – Email Marketing, Lead Generation, Optins, Popups | wordpress-popup |
| Image Alt Text | image-alt-text |
| InPost Gallery | inpost-gallery |
| Intro Tour Tutorial DeepPresentation | dp-intro-tours |
| Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress | jeg-elementor-kit |
| JobSearch WP Job Board | wp-jobsearch |
| Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Receipts | Buttons & Forms | kudos-donations |
| LegalWeb Cloud | legalweb-cloud |
| Lenxel AI LMS – Course Lesson Generator | lenxel-core |
| Load More Posts | load-more-posts |
| Login with Vipps and MobilePay | login-with-vipps |
| MaxButtons – Create buttons | maxbuttons |
| Mins To Read | mins-to-read |
| Multilevel Referral Plugin for WooCommerce | multilevel-referral-plugin-for-woocommerce |
| Ni Cost of Goods for WooCommerce | ni-woocommerce-cost-of-goods |
| Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | otter-blocks |
| Out Of Stock Badge | out-of-stock-badge |
| Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | wp-user-avatar |
| PayPal Responder | paypal-responder |
| Photo Video Store | photo-video-store |
| PickPlugins Mail Picker — Email Marketing & Newsletters | mail-picker |
| Pixobe Cartography | pixobe-cartography |
| Planet Studio Payment Gateway for ArCa | arca-payment-gateway |
| Post Carousel Slider for Elementor | post-carousel-slider-for-elementor |
| Posti Shipping | posti-shipping |
| Pricing Tables For WPBakery Page Builder (formerly Visual Composer) | pricing-tables-for-visual-composer |
| Primary Addon for Elementor | primary-addon-for-elementor |
| Product Input Fields for WooCommerce | product-input-fields-for-woocommerce |
| Ragic Shortcode | ragic-shortcode |
| Random Banner | random-banner |
| Restaurant & Cafe Addon for Elementor | restaurant-cafe-addon-for-elementor |
| RingCentral Communications Plugin – FREE | rccp-free |
| Royal Addons for Elementor – Addons and Templates Kit for Elementor | royal-elementor-addons |
| Security Plugin, Firewall & Malware Scanner with Auto Removal | security-malware-firewall |
| SEO Landing Page Generator | seo-landing-page-generator |
| Serious Slider | cryout-serious-slider |
| Simple Header and Footer | simple-header-and-footer |
| Simple Popup Plugin | simple-popup-plugin |
| SimpleSchema Free | simpleschema-free |
| Skt NURCaptcha | skt-nurcaptcha |
| Skyboot Portfolio Gallery for Elementor | skyboot-portfolio-gallery |
| Smart Marketing SMS and Newsletters Forms | smart-marketing-for-wp |
| Social Sharing Plugin – Sassy Social Share | sassy-social-share |
| Softtemplates For Elementor | softtemplates-for-elementor |
| Sp*tify Play Button for WordPress | spotify-play-button-for-wordpress |
| Sparkle Elementor Kit | sparkle-elementor-kit |
| SpatialMatch IDX | spatialmatch-free-lifestyle-search |
| StreamWeasels YouTube Integration | streamweasels-youtube-integration |
| Stripe Donation | bin-stripe-donation |
| Support SVG – Upload svg files in wordpress without hassle | support-svg |
| The Events Calendar | the-events-calendar |
| Third Party Cookie Eraser | third-party-cookie-eraser |
| Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid | boldgrid-backup |
| Tumult Hype Animations | tumult-hype-animations |
| Vertical Carousel | vertical-carousel-slider |
| Video Player for WPBakery | video-player-for-wpbakery |
| Wallet for WooCommerce | woo-wallet |
| Watu Quiz | watu |
| Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets | widget-options |
| WooCommerce Ultimate Gift Card | woocommerce-ultimate-gift-card |
| WordPress Portfolio Builder – Portfolio Gallery | uber-grid |
| WP Admin UI Customize | wp-admin-ui-customize |
| WP Counter Up – Animated Number Counter & Milestone Showcase | wp-counter-up |
| WP Find Your Nearest | wp-find-your-nearest |
| WP MathJax | wp-mathjax-plus |
| WP Mermaid | wp-mermaid |
| WP Revisions Manager | wp-revisions-manager |
| Yahoo! WebPlayer | yahoo-media-player |
| ZnajdĹş PracÄ™ z Praca.pl | znajdz-prace-z-pracapl |
| پارسی دیت – Parsi Date | wp-parsidate |
| 소셜 ęłµěś ë˛„íŠĽ By 코스모스팜 | cosmosfarm-share-buttons |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Comments