|#||IP Address||Blocked Attacks|
|1||User Post Gallery - UPG <= 2.19 - Missing Authorization to Remote Command Execution|
|2||Kaswara Modern VC Addons <= 3.0.1 - Arbitrary File Upload|
|3||Tatsu <= 3.3.12 - Unauthenticated Remote Code Execution|
|4||OptinMonster <= 2.6.4 - Unprotected REST-API Endpoints|
|5||User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) 3.0.0 - 3.1.3 - Unauthenticated Privilege Escalation|
|6||WooCommerce Payments <= 5.6.1 Authentication Bypass and Privilege Escalation|
|7||Rank Math SEO <= 220.127.116.11 - Unprotected REST API Endpoints|
|8||Advanced Access Manager <= 18.104.22.168 - Unauthenticated Arbitrary File Read|
|9||N-Media Post Front-end Form < 1.1 - Arbitrary File Upload|
|10||Social Warfare <= 3.5.2 - Unauthenticated Arbitrary Settings Update|
|1||Feather Login Page 1.0.7 - 1.1.1 - Cross-Site Request Forgery to Privilege Escalation||CVE-2023-2549||Lana Codes||May 30, 2023|
|2||Multiple Themes (Various Versions) - Missing Authorization to Arbitrary Plugin Activation||CVE-2023-33923||Dave Jong||May 30, 2023|
|3||Draw Attention <= 2.0.11 - Missing Authorization to Arbitrary Post Featured Image Modification||CVE-2023-2764||Alex Thomas||May 30, 2023|
|4||bbp style pack <= 5.5.5 - Cross-Site Scripting||May 30, 2023|
|5||Favorites <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-2304||Lana Codes||May 30, 2023|
|6||Blog-in-Blog <= 1.1.1 - Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode||CVE-2023-2436||Lana Codes||May 30, 2023|
|7||Feather Login Page 1.0.7 - 1.1.1 - Missing Authorization to Non-Arbitrary User Deletion||CVE-2023-2547||Lana Codes||May 30, 2023|
|8||Display post meta, term meta, comment meta, and user meta <= 0.4.1 - Authenticated(Contributor+) Stored Cross-Site Scripting||CVE-2023-1661||Francesco Carlucci||May 30, 2023|
|9||Wordapp <= 1.5.0 - Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature||CVE-2023-2987||Lana Codes||May 30, 2023|
|10||Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset||CVE-2023-2434||Lana Codes||May 30, 2023|
Vulnerabilities since May 1, 2023
All the threat data shared in this database is powered by Wordfence Intelligence Enterprise.
Interested in integrating this data into your platform or network?
Contact us now to discuss API access to our Wordfence Intelligence Enterprise Data Feeds.
Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.
The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.Documentation