|#||IP Address||Blocked Attacks|
|1||WooCommerce Payments <= 5.6.1 Authentication Bypass and Privilege Escalation|
|2||HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation|
|3||Sitemap by click5 <= 1.0.35 - Arbitrary Options Update|
|4||ThemeREX Addons (Various Versions) - Missing Authorization|
|5||Ultimate Member <= 2.1.11 - Unauthenticated Privilege Escalation via User Meta|
|6||Advanced Access Manager <= 188.8.131.52 - Unauthenticated Arbitrary File Read|
|7||Rank Math SEO <= 184.108.40.206 - Unprotected REST API Endpoints|
|8||OptinMonster <= 2.6.4 - Unprotected REST-API Endpoints|
|9||User Post Gallery - UPG <= 2.19 - Missing Authorization to Remote Command Execution|
|10||User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation|
|1||Magic Action Box <= 2.17.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5231||Lana Codes||September 27, 2023|
|2||Font Awesome Integration <= 5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5233||Lana Codes||September 27, 2023|
|3||TM WooCommerce Compare & Wishlist <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5230||Lana Codes||September 27, 2023|
|4||Font Awesome More Icons <= 3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5232||Lana Codes||September 27, 2023|
|5||flowpaper <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5200||Lana Codes||September 26, 2023|
|6||Track The Click <= 0.3.11 - Authenticated (Author+) SQL Injection via 'stats' REST Endpoint||CVE-2023-5041||Karolis Narvilas||September 26, 2023|
|7||Simple Posts Ticker <= 1.1.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode||CVE-2023-4646||Dmitrii Ignatyev||September 25, 2023|
|8||Options for Twenty Seventeen <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-5162||Lana Codes||September 25, 2023|
|9||Simple Membership <= 4.3.4 - Account Takeover via Password Reset||CVE-2023-41956||Rafie Muhammad||September 25, 2023|
|10||Staff / Employee Business Directory for Active Directory <= 1.2.3 - Authenticated (Admin+) LDAP Passback||CVE-2023-4505||Pedro José Navas Pérez||September 25, 2023|
All the threat data shared in this database is powered by Wordfence Intelligence Enterprise.
Interested in integrating this data into your platform or network?
Contact us now to discuss API access to our Wordfence Intelligence Enterprise Data Feeds.
Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.
The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.Documentation