Did you know we’re running a Bug Bounty Extravaganza again?
Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!
Last week, there were 280 vulnerabilities disclosed in 220 WordPress Plugins and 22 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 61 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 15,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 220 |
Unpatched | 60 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 4 |
Medium Severity | 227 |
High Severity | 28 |
Critical Severity | 21 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 85 |
Missing Authorization | 82 |
Cross-Site Request Forgery (CSRF) | 23 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 12 |
Information Exposure | 12 |
Server-Side Request Forgery (SSRF) | 12 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 6 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 6 |
Information Exposure Through Log Files | 6 |
Unrestricted Upload of File with Dangerous Type | 5 |
Authorization Bypass Through User-Controlled Key | 4 |
Deserialization of Untrusted Data | 4 |
Improper Privilege Management | 4 |
External Control of Assumed-Immutable Web Parameter | 3 |
Use of Less Trusted Source | 3 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Improper Input Validation | 2 |
Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’) | 2 |
Authentication Bypass Using an Alternate Path or Channel | 1 |
Guessable CAPTCHA | 1 |
Improper Access Control | 1 |
Improper Authorization | 1 |
Improper Neutralization of Alternate XSS Syntax | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
29 | |
23 | |
17 | |
17 | |
13 | |
12 | |
12 | |
11 | |
10 | |
10 | |
7 | |
7 | |
7 | |
7 | |
7 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Academy LMS – eLearning and online course solution for WordPress | academy |
Accessibility Widget | accessibility-widget |
ActiveDEMAND | activedemand |
Admin and Customer Messages After Order for WooCommerce: OrderConvo | admin-and-client-message-after-order-for-woocommerce |
Admin Bar Editor – Hide Toolbar by User Roles | admin-bar |
Advanced Floating Content Lite | advanced-floating-content-lite |
Advanced Local Pickup for WooCommerce | advanced-local-pickup-for-woocommerce |
Advanced Most Recent Posts Mod | advanced-most-recent-posts-mod |
Advanced Post List | advanced-post-list |
Advanced Testimonial Carousel for Elementor | advanced-testimonial-carousel-for-elementor |
AGCA – Custom Dashboard & Login Page | ag-custom-admin |
All-in-one Like Widget | all-in-one-facebook-like-widget |
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) | wp-analytify |
Annual Archive | anual-archive |
Appointment Hour Booking – WordPress Booking Plugin | appointment-hour-booking |
AppPresser – Mobile App Framework | apppresser |
Arconix FAQ | arconix-faq |
Arconix Shortcodes | arconix-shortcodes |
ARforms | arforms |
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | armember-membership |
Assistant – Every Day Productivity Apps | assistant |
Auto Featured Image (Auto Post Thumbnail) | auto-post-thumbnail |
BackUpWordPress | backupwordpress |
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. | barcode-scanner-lite-pos-to-manage-products-inventory-and-orders |
Better Elementor Addons | better-elementor-addons |
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss | bp-better-messages |
BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More. | print-google-cloud-print-gcp-woocommerce |
Blog2Social: Social Media Auto Post & Scheduler | blog2social |
Booking Ultra Pro Appointments Booking Calendar Plugin | booking-ultra-pro |
Brevo for WooCommerce | woocommerce-sendinblue-newsletter-subscription |
Build 5 Star Reviews on Google Reviews, Yelp, Facebook… easily and risk-free | RRatingg | 5-stars-rating-funnel |
Car Dealer (Dealership) and Vehicle sales | cardealer |
CF7 File Download – File Download for CF7 | cf7-file-download |
ChatBot Conversational Forms | conversational-forms |
Classified Listing – Classified ads & Business Directory Plugin | classified-listing |
ClickCease Click Fraud Protection | clickcease-click-fraud-protection |
Client Dash | client-dash |
CM Tooltip Glossary | enhanced-tooltipglossary |
Colibri Page Builder | colibri-page-builder |
Collapse-O-Matic | jquery-collapse-o-matic |
Comments – wpDiscuz | wpdiscuz |
Contact Form 7 Database Addon – CFDB7 | contact-form-cfdb7 |
Contact Form 7 Extension For Mailchimp | contact-form-7-mailchimp-extension |
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder | arforms-form-builder |
Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | content-views-query-and-display-post-page |
Cookie Information | Free GDPR Consent Solution | wp-gdpr-compliance |
CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance) | cookiehub |
Cornerstone | cornerstone |
Coupon & Discount Code Reveal Button | coupon-reveal-button |
Crelly Slider | crelly-slider |
Culqi | culqi-checkout |
Custom field finder | custom-field-finder |
Customify Site Library | customify-sites |
Data Tables Generator by Supsystic | data-tables-generator-by-supsystic |
Database for Contact Form 7, WPforms, Elementor forms | contact-form-entries |
Easy Accept Payments via PayPal | wordpress-easy-paypal-payment-or-donation-accept-plugin |
Easy Property Listings | easy-property-listings |
Easy Set Favicon | easy-set-favicon |
Element Pack Pro – Addon for Elementor Page Builder WordPress Plugin | bdthemes-element-pack |
ElementsKit Elementor addons and Templates Library | elementskit-lite |
ElementsKit Pro | elementskit |
Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! | elespare |
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder | email-customizer-for-woocommerce |
Embed Google Photos album | embed-google-photos-album-easily |
ENL Newsletter | enl-newsletter |
EPROLO Dropshipping | eprolo-dropshipping |
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | essential-addons-for-elementor-lite |
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media | evergreen-content-poster |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Export and Import Users and Customers | users-customers-import-export-for-wp-woocommerce |
FameTheme Demo Importer | famethemes-demo-importer |
Fan Page Widget by ThemeNcode | facebook-fan-page-widget |
Fancy Product Designer | fancy-product-designer |
FG Joomla to WordPress | fg-joomla-to-wordpress |
FileOrganizer – Manage WordPress and Website Files | fileorganizer |
Filterable Portfolio | jungbillig-portfolio-gallery |
Five Star Restaurant Reservations – WordPress Booking Plugin | restaurant-reservations |
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | form-maker |
FOX – Currency Switcher Professional for WooCommerce | woocommerce-currency-switcher |
Frontend Dashboard | frontend-dashboard |
FV Flowplayer Video Player | fv-wordpress-flowplayer |
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory | geodirectory |
Getwid – Gutenberg Blocks | getwid |
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers | rafflepress |
Happy Addons for Elementor | happy-elementor-addons |
Header Footer Code Manager Pro | 99robots-header-footer-code-manager-pro |
Headline Analyzer | headline-analyzer |
Hide Dashboard Notifications | wp-hide-backed-notices |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
Hummingbird – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | hummingbird-performance |
Image Optimizer, Resizer and CDN – Sirv | sirv |
Image Slider | image-slider-widget |
Import and export users and customers | import-users-from-csv-with-meta |
InstaWP Connect – 1-click WP Staging & Migration | instawp-connect |
Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site | integrate-google-drive |
Interactive World Maps | interactive-world-maps |
Jeg Elementor Kit | jeg-elementor-kit |
KB Support – WordPress Help Desk and Knowledge Base | kb-support |
Knowledge Base documentation & wiki plugin – BasePress Docs | basepress |
Leaky Paywall | leaky-paywall |
List Custom Taxonomy Widget | list-custom-taxonomy-widget |
Login with phone number | login-with-phone-number |
Maintenance Mode | hkdev-maintenance-mode |
MainWP Child Reports | mainwp-child-reports |
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | master-addons |
Max Addons Pro for Bricks | max-addons-pro-bricks |
MDTF – Meta Data and Taxonomies Filter | wp-meta-data-filter-and-taxonomy-filter |
Meks Smart Social Widget | meks-smart-social-widget |
Meks ThemeForest Smart Widget | meks-themeforest-smart-widget |
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | metform |
MF Gig Calendar | mf-gig-calendar |
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin | mycred |
Newsletters | newsletters-lite |
Opal Widgets For Elementor | opal-widgets-for-elementor |
Page Builder: Live Composer | live-composer-page-builder |
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | paid-member-subscriptions |
Payment Gateway Based Fees and Discounts for WooCommerce | checkout-fees-for-woocommerce |
PDF Invoices & Packing Slips for WooCommerce | woocommerce-pdf-invoices-packing-slips |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery | photo-gallery |
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery | gt3-photo-video-gallery |
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress | contest-gallery |
Piotnet Addons For Elementor | piotnet-addons-for-elementor |
Piotnet Addons For Elementor Pro | piotnet-addons-for-elementor-pro |
Podlove Podcast Publisher | podlove-podcasting-plugin-for-wordpress |
Poll | Vote | Contest – Best Poll Plugin for WordPress | totalpoll-lite |
Popup Box – Best WordPress Popup Plugin | ays-popup-box |
Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation | optinmonster |
PopupAlly | popupally |
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | buddyforms |
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | ultimate-post |
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | post-grid |
Premium Addons for Elementor | premium-addons-for-elementor |
Pretty Google Calendar | pretty-google-calendar |
Pricing Table by Supsystic | pricing-table-by-supsystic |
Print Invoice & Delivery Notes for WooCommerce | woocommerce-delivery-notes |
Product Addons & Fields for WooCommerce | woocommerce-product-addon |
ProfileGrid – User Profiles, Memberships, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
PropertyHive | propertyhive |
Qi Addons For Elementor | qi-addons-for-elementor |
Quick Featured Images | quick-featured-images |
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress | radio-player |
Radio Station by netmix® – Manage and play your Show Schedule in WordPress! | radio-station |
Rank Math SEO with AI Best SEO Tools | seo-by-rank-math |
Rate My Post – Star Rating Plugin by FeedbackWP | rate-my-post |
Recencio Book Reviews | recencio-book-reviews |
Reviews Plus | reviews-plus |
RomethemeForm For Elementor | romethemeform |
RomethemeKit For Elementor | rometheme-for-elementor |
Royal Elementor Addons and Templates | royal-elementor-addons |
rtMedia for WordPress, BuddyPress and bbPress | buddypress-media |
Salon booking system | salon-booking-system |
Save as PDF Plugin by Pdfcrowd | save-as-pdf-by-pdfcrowd |
SchedulePress – Best Editorial Calendar, Missed Schedule & Auto Social Share | wp-scheduled-posts |
Schema & Structured Data for WP & AMP | schema-and-structured-data-for-wp |
Secure Copy Content Protection and Content Locking | secure-copy-content-protection |
Seers | GDPR & CCPA Cookie Consent & Compliance | seers-cookie-consent-banner-privacy-policy |
Send PDF for Contact Form 7 | send-pdf-for-contact-form-7 |
Serious Slider | cryout-serious-slider |
SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy | woo-aliexpress-dropshipping |
ShortPixel Critical CSS | shortpixel-critical-css |
Simple Membership | simple-membership |
Simply Static | simply-static |
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) | sina-extension-for-elementor |
Slash Admin | slash-admin |
Smart Forms – when you need more than just a contact form | smart-forms |
Smart Maintenance Mode | smart-maintenance-mode |
Smart Recent Posts Widget | smart-recent-posts-widget |
Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap | socialsnap |
Social Sharing Plugin – Social Warfare | social-warfare |
Solid Affiliate | solid-affiliate |
Spectra – WordPress Gutenberg Blocks | ultimate-addons-for-gutenberg |
SSU – WordPress Amazon S3 & Wasabi Smart File Uploads Plugin | wp-s3-smart-upload |
Sticky Anything | toast-stick-anything |
StreamWeasels Twitch Integration | streamweasels-twitch-integration |
Table Rate Shipping Method for WooCommerce by Flexible Shipping | flexible-shipping |
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) | the-pack-addon |
The Plus Addons for Elementor | the-plus-addons-for-elementor-page-builder |
The Plus Blocks for Block Editor | Gutenberg | the-plus-addons-for-block-editor |
Timetable and Event Schedule by MotoPress | mp-timetable |
Tutor LMS – eLearning and online course solution | tutor |
Ultimate 410 Gone Status Code | ultimate-410 |
User Meta – User Profile Builder and User management plugin | user-meta |
USPS Shipping for WooCommerce – Live Rates | flexible-shipping-usps |
Video Conferencing with Zoom | video-conferencing-with-zoom-api |
VikRentCar Car Rental Management System | vikrentcar |
Vision – Image Map Builder | vision |
Vitepos – Point of sale (POS) plugin for WooCommerce | vitepos-lite |
VK Block Patterns | vk-block-patterns |
VOD Infomaniak | vod-infomaniak |
Wallet for WooCommerce – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds | woo-wallet |
Widget Post Slider | widget-post-slider |
WooCommerce Amazon Affiliates – WordPress Plugin | woozone |
WooCommerce Shipping Label | shipping-labels-for-woo |
WordPress Ad Widget | ad-widget |
WordPress Backup & Migration | wp-migration-duplicator |
WP ADA Compliance Check Basic – Most Comprehensive Web Accessibility Solution for WordPress | wp-ada-compliance-check-basic |
WP Club Manager – WordPress Sports Club Plugin | wp-club-manager |
WP Datepicker | wp-datepicker |
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress | wp-fusion-lite |
WP GoToWebinar | wp-gotowebinar |
WP LinkedIn Auto Publish | wp-linkedin-auto-publish |
WP Masquerade | wp-masquerade |
WP Media Category Management | wp-media-category-management |
WP Page Post Widget Clone | wp-page-post-widget-clone |
WP SMTP | wp-smtp |
WP STAGING Pro WordPress Backup Plugin | wp-staging-pro |
WP STAGING WordPress Backup Plugin – Migration Backup Restore | wp-staging |
WP Time Slots Booking Form | wp-time-slots-booking-form |
WP Travel Engine – Best Travel Booking WordPress Plugin | wp-travel-engine |
WP ULike – Most Advanced WordPress Marketing Toolkit | wp-ulike |
WP-Lister Lite for eBay | wp-lister-for-ebay |
WP-Members Membership Plugin | wp-members |
WP-Recall – Registration, Profile, Commerce & More | wp-recall |
WPC Composite Products for WooCommerce | wpc-composite-products |
WPCal.io – Easy Meeting Scheduler | wpcal |
WPPizza – A Restaurant Plugin | wppizza |
WPZOOM Addons for Elementor (Templates, Widgets) | wpzoom-elementor-addons |
XforWooCommerce | xforwoocommerce |
XStore Core | et-core-plugin |
YITH WooCommerce Compare | yith-woocommerce-compare |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Accountra | accountra |
Althea WP | althea-wp |
Blocksy | blocksy |
Brite | brite |
Colibri WP | colibri-wp |
ColorNews | colornews |
Elevate WP | elevate-wp |
Financio | financio |
Hugo WP | hugo-wp |
Intrace | intrace |
Pathway | pathway |
Photology | photology |
Royal Elementor Kit | royal-elementor-kit |
Startupzy | startupzy |
Teluro | teluro |
Travey | travey |
uDesign – Responsive WordPress Theme | u-design |
Vertice | vertice |
Virtue | virtue |
WP Portfolio | wp-portfolio |
XStore | xstore |
Zeever | zeever |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-32809
Patched
Apr 22, 2024
ActiveDEMAND
Critical (10.0)
CVE-2024-33644
Unpatched
Apr 25, 2024
Customify Site Library
Critical (10.0)
CVE-2024-33544
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
Critical (10.0)
CVE-2024-32709
Patched
Apr 22, 2024
WP-Recall – Registration, Profile, Commerce & More
Critical (10.0)
CVE-2024-33559
Unpatched
Apr 25, 2024
XStore
Critical (10.0)
CVE-2024-33551
Unpatched
Apr 25, 2024
XStore Core
Critical (9.9)
CVE-2024-33568
Unpatched
Apr 25, 2024
Element Pack Pro – Addon for Elementor Page Builder WordPress Plugin
Timetable and Event Schedule by MotoPress <= 2.4.11 – Authenticated (Contributor+) SQL Injection
Critical (9.9)
CVE-2024-3342
Patched
Apr 26, 2024
Timetable and Event Schedule by MotoPress
Critical (9.9)
CVE-2024-33546
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
Critical (9.9)
CVE-2024-32710
Patched
Apr 22, 2024
WP-Recall – Registration, Profile, Commerce & More
Critical (9.9)
CVE-2024-33556
Unpatched
Apr 25, 2024
XStore Core
Critical (9.8)
CVE-2024-33567
Patched
Apr 25, 2024
Critical (9.8)
CVE-2024-33566
Patched
Apr 25, 2024
Admin and Customer Messages After Order for WooCommerce: OrderConvo
Critical (9.8)
CVE-2024-3962
Patched
Apr 25, 2024
Product Addons & Fields for WooCommerce
Critical (9.8)
CVE-2024-32959
Patched
Apr 23, 2024
Image Optimizer, Resizer and CDN – Sirv
Critical (9.8)
CVE-2024-33560
Unpatched
Apr 25, 2024
XStore
Critical (9.8)
CVE-2024-33553
Unpatched
Apr 25, 2024
XStore Core
Critical (9.8)
CVE-2024-33552
Unpatched
Apr 25, 2024
XStore Core
Critical (9.3)
CVE-2024-32830
Patched
Apr 22, 2024
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
Critical (9.1)
CVE-2024-3060
Unpatched
Apr 26, 2024
ENL Newsletter
Critical (9.1)
CVE-2024-32954
Patched
Apr 22, 2024
Newsletters
High (8.8)
CVE-2024-32706
Patched
Apr 22, 2024
High (8.8)
CVE-2024-33541
Patched
Apr 25, 2024
Better Elementor Addons
High (8.8)
CVE-2024-32960
Patched
Apr 23, 2024
Booking Ultra Pro Appointments Booking Calendar Plugin
High (8.8)
CVE-2024-33641
Patched
Apr 25, 2024
Custom field finder
High (8.8)
CVE-2024-3499
Patched
Apr 22, 2024
ElementsKit Elementor addons and Templates Library
High (8.8)
CVE-2024-3500
Patched
Apr 25, 2024
ElementsKit Pro
High (8.8)
CVE-2024-3293
Patched
Apr 22, 2024
rtMedia for WordPress, BuddyPress and bbPress
High (8.8)
CVE-2024-33549
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
High (8.8)
CVE-2024-3895
Patched
Apr 23, 2024
WP Datepicker
High (8.8)
CVE-2024-33550
Unpatched
Apr 25, 2024
WP Masquerade
High (8.8)
CVE-2024-1797
Patched
Apr 26, 2024
WP ULike – Most Advanced WordPress Marketing Toolkit
High (8.8)
CVE-2024-33628
Unpatched
Apr 25, 2024
XforWooCommerce
High (8.8)
CVE-2024-33564
Unpatched
Apr 25, 2024
XStore
High (8.8)
CVE-2024-33557
Unpatched
Apr 25, 2024
XStore Core
High (8.1)
CVE-2024-32703
Patched
Apr 22, 2024
High (7.5)
CVE-2024-32729
Patched
Apr 22, 2024
ChatBot Conversational Forms
High (7.2)
CVE-2024-3715
Patched
Apr 22, 2024
Database for Contact Form 7, WPforms, Elementor forms
High (7.2)
CVE-2024-32835
Patched
Apr 22, 2024
Export and Import Users and Customers
High (7.2)
CVE-2024-32817
Patched
Apr 22, 2024
Import and export users and customers
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 – Unauthenticated Server-Side Request Forgery
High (7.2)
CVE-2024-3047
Patched
Apr 24, 2024
PDF Invoices & Packing Slips for WooCommerce
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 – Unauthenticated Stored Cross-Site Scripting
High (7.2)
CVE-2024-3045
Patched
Apr 24, 2024
PDF Invoices & Packing Slips for WooCommerce
High (7.2)
CVE-2024-33634
Unpatched
Apr 25, 2024
Piotnet Addons For Elementor Pro
High (7.2)
CVE-2024-33592
Patched
Apr 25, 2024
Sendinblue for WooCommerce <= 4.0.17 – Authenticated (Editor+) Arbitrary File Download and Deletion
High (7.2)
CVE-2024-32807
Patched
Apr 22, 2024
Brevo for WooCommerce
High (7.2)
CVE-2024-33646
Unpatched
Apr 25, 2024
Sticky Anything
High (7.2)
CVE-2024-1789
Patched
Apr 25, 2024
WP SMTP
High (7.2)
CVE-2024-32836
Patched
Apr 22, 2024
WP-Lister Lite for eBay
High (7.1)
CVE-2024-1945
Patched
Apr 25, 2024
Medium (6.5)
CVE-2024-32725
Patched
Apr 22, 2024
Build 5 Star Reviews on Google Reviews, Yelp, Facebook… easily and risk-free | RRatingg
Medium (6.5)
CVE-2024-32814
Patched
Apr 22, 2024
Advanced Local Pickup for WooCommerce
Medium (6.5)
CVE-2024-3734
Patched
Apr 24, 2024
FOX – Currency Switcher Professional for WooCommerce
Medium (6.5)
CVE-2024-32813
Patched
Apr 22, 2024
Medium (6.5)
CVE-2024-2798
Patched
Apr 22, 2024
Royal Elementor Addons and Templates
Medium (6.5)
CVE-2024-3553
Patched
Apr 26, 2024
Tutor LMS – eLearning and online course solution
Medium (6.5)
CVE-2024-33558
Unpatched
Apr 25, 2024
XStore Core
Medium (6.4)
CVE-2024-32831
Patched
Apr 22, 2024
Accessibility Widget
Medium (6.4)
CVE-2024-33643
Unpatched
Apr 25, 2024
Advanced Most Recent Posts Mod
Medium (6.4)
CVE-2024-33629
Unpatched
Apr 25, 2024
Auto Featured Image (Auto Post Thumbnail)
Medium (6.4)
CVE-2024-32961
Patched
Apr 23, 2024
Blocksy
Medium (6.4)
CVE-2024-3747
Patched
Apr 24, 2024
Blocksy
Medium (6.4)
CVE-2024-3337
Patched
Apr 22, 2024
Colibri Page Builder
Collapse-O-Matic <= 1.8.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2023-7030
Patched
Apr 23, 2024
Collapse-O-Matic
Medium (6.4)
CVE-2024-33540
Patched
Apr 25, 2024
ColorNews
Medium (6.4)
CVE-2024-3929
Patched
Apr 24, 2024
Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode)
Medium (6.4)
CVE-2024-32819
Patched
Apr 22, 2024
Culqi
Medium (6.4)
CVE-2024-32775
Patched
Apr 22, 2024
Embed Google Photos album
Medium (6.4)
CVE-2024-4003
Patched
Apr 24, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (6.4)
CVE-2024-3728
Patched
Apr 24, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (6.4)
CVE-2024-2750
Patched
Apr 22, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-3985
Patched
Apr 22, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-3489
Patched
Apr 22, 2024
Exclusive Addons for Elementor
FV Flowplayer Video Player <= 7.5.43.7212 – Authenticated (Subscriber+) Server-side Request Forgery
Medium (6.4)
CVE-2024-32955
Patched
Apr 22, 2024
FV Flowplayer Video Player
Medium (6.4)
CVE-2024-3732
Patched
Apr 22, 2024
Medium (6.4)
CVE-2024-3588
Patched
Apr 26, 2024
Getwid – Gutenberg Blocks
Medium (6.4)
CVE-2024-3890
Patched
Apr 25, 2024
Happy Addons for Elementor
Medium (6.4)
CVE-2024-3819
Patched
Apr 26, 2024
Jeg Elementor Kit
Medium (6.4)
CVE-2024-33590
Patched
Apr 25, 2024
Knowledge Base documentation & wiki plugin – BasePress Docs
Medium (6.4)
CVE-2024-33649
Unpatched
Apr 25, 2024
Opal Widgets For Elementor
Medium (6.4)
CVE-2024-4035
Patched
Apr 24, 2024
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery
Piotnet Addons For Elementor <= 2.4.26 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-33630
Unpatched
Apr 25, 2024
Piotnet Addons For Elementor
Medium (6.4)
CVE-2024-3239
Patched
Apr 22, 2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX
Premium Addons for Elementor <= 4.10.25 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-32791
Patched
Apr 22, 2024
Premium Addons for Elementor
Premium Addons for Elementor <= 4.10.28 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-3885
Patched
Apr 23, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-3647
Patched
Apr 24, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-33640
Unpatched
Apr 25, 2024
Pretty Google Calendar
Medium (6.4)
CVE-2024-3309
Patched
Apr 26, 2024
Qi Addons For Elementor
Medium (6.4)
CVE-2024-29811
Patched
Apr 25, 2024
Medium (6.4)
CVE-2024-3665
Patched
Apr 22, 2024
Rank Math SEO with AI Best SEO Tools
Medium (6.4)
CVE-2024-33648
Unpatched
Apr 25, 2024
Recencio Book Reviews
Medium (6.4)
CVE-2024-32956
Patched
Apr 22, 2024
RomethemeKit For Elementor
Medium (6.4)
CVE-2024-3889
Patched
Apr 22, 2024
Royal Elementor Addons and Templates
Medium (6.4)
CVE-2024-3675
Patched
Apr 22, 2024
Royal Elementor Addons and Templates
Medium (6.4)
CVE-2024-2799
Patched
Apr 22, 2024
Royal Elementor Addons and Templates
Medium (6.4)
CVE-2024-33684
Patched
Apr 26, 2024
Save as PDF Plugin by Pdfcrowd
Medium (6.4)
CVE-2024-3491
Patched
Apr 22, 2024
Schema & Structured Data for WP & AMP
Medium (6.4)
CVE-2024-3988
Patched
Apr 24, 2024
Medium (6.4)
CVE-2024-1959
Patched
Apr 22, 2024
Social Sharing Plugin – Social Warfare
Medium (6.4)
CVE-2024-32718
Patched
Apr 22, 2024
Medium (6.4)
CVE-2024-3199
Patched
Apr 25, 2024
The Plus Addons for Elementor
Medium (6.4)
CVE-2024-3197
Patched
Apr 25, 2024
The Plus Addons for Elementor
Ultimate 410 Gone Status Code <= 1.1.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-3677
Patched
Apr 22, 2024
Ultimate 410 Gone Status Code
Medium (6.4)
CVE-2024-4034
Patched
Apr 25, 2024
Virtue
Medium (6.4)
CVE-2024-33537
Patched
Apr 25, 2024
WP Portfolio
Medium (6.4)
CVE-2024-1572
Patched
Apr 26, 2024
WP ULike – Most Advanced WordPress Marketing Toolkit
Medium (6.4)
CVE-2024-1759
Patched
Apr 26, 2024
WP ULike – Most Advanced WordPress Marketing Toolkit
Medium (6.4)
CVE-2024-2838
Patched
Apr 26, 2024
WPC Composite Products for WooCommerce
Medium (6.4)
CVE-2024-2477
Patched
Apr 22, 2024
Comments – wpDiscuz
Medium (6.4)
CVE-2024-33539
Patched
Apr 25, 2024
WPZOOM Addons for Elementor (Templates, Widgets)
Medium (6.3)
CVE-2024-33555
Unpatched
Apr 25, 2024
XStore Core
Medium (6.1)
CVE-2024-32702
Patched
Apr 22, 2024
Medium (6.1)
CVE-2024-28002
Patched
Apr 26, 2024
Cornerstone
Medium (6.1)
CVE-2024-33645
Unpatched
Apr 25, 2024
Easy Set Favicon
Medium (6.1)
CVE-2024-0905
Patched
Apr 26, 2024
Fancy Product Designer
Medium (6.1)
CVE-2024-3473
Patched
Apr 25, 2024
Header Footer Code Manager Pro
Medium (6.1)
CVE-2024-3681
Patched
Apr 24, 2024
Interactive World Maps
Medium (6.1)
CVE-2024-32952
Patched
Apr 22, 2024
Max Addons Pro for Bricks
Medium (6.1)
CVE-2024-33633
Unpatched
Apr 25, 2024
Piotnet Addons For Elementor Pro
Medium (6.1)
CVE-2024-32789
Patched
Apr 22, 2024
Seers | GDPR & CCPA Cookie Consent & Compliance
Medium (6.1)
CVE-2024-32958
Patched
Apr 23, 2024
Slash Admin
Medium (6.1)
CVE-2024-32785
Patched
Apr 22, 2024
Medium (6.1)
CVE-2024-4077
Unpatched
Apr 23, 2024
uDesign – Responsive WordPress Theme
Medium (6.1)
CVE-2024-33584
Patched
Apr 25, 2024
Video Conferencing with Zoom
Medium (6.1)
CVE-2024-33571
Unpatched
Apr 25, 2024
VOD Infomaniak
Medium (6.1)
CVE-2024-33548
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
Medium (6.1)
CVE-2024-32950
Patched
Apr 22, 2024
WP Media Category Management
Medium (6.1)
CVE-2024-33562
Unpatched
Apr 25, 2024
XStore
Medium (6.1)
CVE-2024-33554
Unpatched
Apr 25, 2024
XStore Core
Medium (5.5)
CVE-2024-33627
Unpatched
Apr 24, 2024
AGCA – Custom Dashboard & Login Page
Medium (5.4)
CVE-2024-32714
Patched
Apr 22, 2024
Academy LMS – eLearning and online course solution for WordPress
Medium (5.4)
CVE-2024-3340
Patched
Apr 22, 2024
Colibri Page Builder
Medium (5.4)
CVE-2024-33542
Unpatched
Apr 25, 2024
Crelly Slider
Medium (5.4)
CVE-2024-32711
Patched
Apr 22, 2024
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin
Simple Membership <= 4.4.3 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (5.4)
CVE-2024-3730
Patched
Apr 24, 2024
Simple Membership
Medium (5.4)
CVE-2024-3994
Patched
Apr 24, 2024
Tutor LMS – eLearning and online course solution
Medium (5.3)
CVE-2024-32783
Patched
Apr 22, 2024
Advanced Testimonial Carousel for Elementor
Medium (5.3)
CVE-2024-1584
Patched
Apr 26, 2024
Medium (5.3)
CVE-2024-32720
Patched
Apr 22, 2024
Appointment Hour Booking – WordPress Booking Plugin
Medium (5.3)
CVE-2024-32776
Patched
Apr 22, 2024
AppPresser – Mobile App Framework
Medium (5.3)
CVE-2024-32948
Patched
Apr 22, 2024
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Assistant – Every Day Productivity Apps <= 1.4.9.1 – Unauthenticated Sensitive Information Exposure
Medium (5.3)
CVE-2024-33538
Patched
Apr 25, 2024
Assistant – Every Day Productivity Apps
Medium (5.3)
CVE-2024-33565
Patched
Apr 25, 2024
Medium (5.3)
CVE-2024-32777
Patched
Apr 22, 2024
BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More.
Medium (5.3)
CVE-2024-3678
Patched
Apr 25, 2024
Blog2Social: Social Media Auto Post & Scheduler
Medium (5.3)
CVE-2024-32802
Patched
Apr 22, 2024
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss
Medium (5.3)
CVE-2024-3893
Patched
Apr 24, 2024
Classified Listing – Classified ads & Business Directory Plugin
Medium (5.3)
CVE-2024-33652
Unpatched
Apr 25, 2024
Client Dash
Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 – Unauthenticated Sensitive Information Exposure
Medium (5.3)
CVE-2024-3870
Patched
Apr 26, 2024
Contact Form 7 Database Addon – CFDB7
Medium (5.3)
CVE-2024-32784
Patched
Apr 22, 2024
Medium (5.3)
CVE-2024-33591
Patched
Apr 25, 2024
Easy Accept Payments via PayPal
Medium (5.3)
CVE-2024-32799
Patched
Apr 22, 2024
Easy Property Listings
Medium (5.3)
CVE-2024-32781
Patched
Apr 22, 2024
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder
Medium (5.3)
CVE-2024-3733
Patched
Apr 24, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (5.3)
CVE-2024-32788
Patched
Apr 22, 2024
FG Joomla to WordPress
Medium (5.3)
CVE-2024-32726
Patched
Apr 22, 2024
Frontend Dashboard
Medium (5.3)
CVE-2024-32827
Patched
Apr 22, 2024
Medium (5.3)
CVE-2024-32792
Patched
Apr 22, 2024
Medium (5.3)
CVE-2024-32949
Patched
Apr 22, 2024
Medium (5.3)
CVE-2024-33594
Patched
Apr 25, 2024
Leaky Paywall
Medium (5.3)
CVE-2024-32832
Patched
Apr 22, 2024
Login with phone number
Medium (5.3)
CVE-2024-32708
Patched
Apr 22, 2024
Maintenance Mode
Medium (5.3)
CVE-2024-32951
Patched
Apr 22, 2024
Max Addons Pro for Bricks
Medium (5.3)
CVE-2024-32953
Patched
Apr 22, 2024
Newsletters
Medium (5.3)
CVE-2024-33586
Patched
Apr 25, 2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Piotnet Addons For Elementor Pro <= 7.1.17 – Missing Authorization to Arbitrary Post/Page Deletion
Medium (5.3)
CVE-2024-33635
Unpatched
Apr 25, 2024
Piotnet Addons For Elementor Pro
Popup Box – Best WordPress Popup Plugin <= 4.3.6 – Missing Authorization to Information Exposure
Medium (5.3)
CVE-2024-3897
Patched
Apr 24, 2024
Popup Box – Best WordPress Popup Plugin
Medium (5.3)
CVE-2024-32816
Patched
Apr 22, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
Medium (5.3)
CVE-2024-32774
Patched
Apr 22, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Medium (5.3)
CVE-2024-32823
Patched
Apr 22, 2024
Rate My Post – Star Rating Plugin by FeedbackWP
Medium (5.3)
CVE-2024-32727
Patched
Apr 22, 2024
RomethemeForm For Elementor
Medium (5.3)
CVE-2024-32786
Patched
Apr 22, 2024
Royal Elementor Addons and Templates
Medium (5.3)
CVE-2024-33587
Patched
Apr 25, 2024
Secure Copy Content Protection and Content Locking
Medium (5.3)
CVE-2024-3585
Patched
Apr 23, 2024
Send PDF for Contact Form 7
Medium (5.3)
CVE-2024-32724
Patched
Apr 22, 2024
SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy
Medium (5.3)
CVE-2024-32825
Patched
Apr 22, 2024
Simply Static
Medium (5.3)
CVE-2024-32805
Patched
Apr 22, 2024
Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap
Medium (5.3)
CVE-2024-33637
Unpatched
Apr 25, 2024
Solid Affiliate
Medium (5.3)
CVE-2024-33597
Patched
Apr 25, 2024
SSU – WordPress Amazon S3 & Wasabi Smart File Uploads Plugin
Medium (5.3)
CVE-2024-32716
Patched
Apr 22, 2024
StreamWeasels Twitch Integration
Medium (5.3)
CVE-2024-33575
Patched
Apr 25, 2024
User Meta – User Profile Builder and User management plugin
Medium (5.3)
CVE-2024-32811
Patched
Apr 22, 2024
USPS Shipping for WooCommerce – Live Rates
Medium (5.3)
CVE-2024-32780
Patched
Apr 22, 2024
VikRentCar Car Rental Management System
Medium (5.3)
CVE-2024-32779
Patched
Apr 22, 2024
Vision – Image Map Builder
Medium (5.3)
CVE-2024-32826
Patched
Apr 22, 2024
VK Block Patterns
Medium (5.3)
CVE-2024-33545
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
Medium (5.3)
CVE-2024-32719
Patched
Apr 22, 2024
WP Club Manager – WordPress Sports Club Plugin
Medium (5.3)
CVE-2024-32796
Patched
Apr 22, 2024
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress
Medium (5.3)
CVE-2024-3682
Patched
Apr 25, 2024
WP STAGING WordPress Backup Plugin – Migration Backup Restore
WP STAGING Pro WordPress Backup Plugin
Medium (5.3)
CVE-2024-33543
Patched
Apr 25, 2024
WP Time Slots Booking Form
Medium (5.3)
CVE-2024-32798
Patched
Apr 22, 2024
WP Travel Engine – Best Travel Booking WordPress Plugin
Medium (5.3)
CVE-2024-2920
Patched
Apr 25, 2024
WP-Members Membership Plugin
Medium (5.3)
CVE-2024-33561
Unpatched
Apr 25, 2024
XStore
Medium (4.4)
CVE-2024-32723
Patched
Apr 22, 2024
Advanced Floating Content Lite
Medium (4.4)
CVE-2024-33642
Unpatched
Apr 25, 2024
Advanced Post List
Medium (4.4)
CVE-2024-32815
Patched
Apr 22, 2024
All-in-one Like Widget
Medium (4.4)
CVE-2024-33598
Unpatched
Apr 25, 2024
Annual Archive
Medium (4.4)
CVE-2024-33697
Unpatched
Apr 26, 2024
CF7 File Download – File Download for CF7
Medium (4.4)
CVE-2024-3338
Patched
Apr 22, 2024
Colibri Page Builder
Coupon & Discount Code Reveal Button <= 1.2.5 – Authenticated (Editor+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-32722
Patched
Apr 22, 2024
Coupon & Discount Code Reveal Button
Medium (4.4)
CVE-2024-33695
Unpatched
Apr 26, 2024
Fan Page Widget by ThemeNcode
Medium (4.4)
CVE-2024-2324
Patched
Apr 23, 2024
FileOrganizer – Manage WordPress and Website Files
Medium (4.4)
CVE-2024-4234
Unpatched
Apr 26, 2024
Filterable Portfolio
Form Maker by 10Web <= 1.15.24 – Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
Medium (4.4)
CVE-2024-2258
Patched
Apr 26, 2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Medium (4.4)
CVE-2024-32707
Patched
Apr 22, 2024
Image Slider
Medium (4.4)
CVE-2024-32833
Patched
Apr 22, 2024
List Custom Taxonomy Widget
Medium (4.4)
CVE-2024-33693
Unpatched
Apr 26, 2024
Meks Smart Social Widget
Medium (4.4)
CVE-2024-33694
Unpatched
Apr 26, 2024
Meks ThemeForest Smart Widget
Medium (4.4)
CVE-2024-33639
Unpatched
Apr 25, 2024
PopupAlly
Medium (4.4)
CVE-2024-33692
Unpatched
Apr 26, 2024
Smart Recent Posts Widget
Medium (4.4)
CVE-2024-32584
Patched
Apr 24, 2024
Medium (4.4)
CVE-2024-32801
Patched
Apr 22, 2024
Widget Post Slider
Medium (4.4)
CVE-2024-33696
Unpatched
Apr 26, 2024
WordPress Ad Widget
Admin Bar Remover <= 1.0.2.2 – Missing Authorization to Authenticated (Subscriber+) Settings Update
Medium (4.3)
CVE-2024-1716
Patched
Apr 26, 2024
Admin Bar Editor – Hide Toolbar by User Roles
Medium (4.3)
CVE-2024-32704
Patched
Apr 22, 2024
Medium (4.3)
CVE-2024-32705
Patched
Apr 22, 2024
Medium (4.3)
CVE-2024-33678
Unpatched
Apr 26, 2024
ClickCease Click Fraud Protection
Medium (4.3)
CVE-2024-4086
Patched
Apr 24, 2024
CM Tooltip Glossary
Medium (4.3)
CVE-2024-33686
Patched
Apr 26, 2024
Medium (4.3)
CVE-2024-33677
Unpatched
Apr 26, 2024
Contact Form 7 Extension For Mailchimp
Medium (4.3)
CVE-2024-32778
Patched
Apr 22, 2024
Medium (4.3)
CVE-2024-32829
Patched
Apr 22, 2024
Data Tables Generator by Supsystic
Medium (4.3)
CVE-2024-0900
Patched
Apr 22, 2024
Medium (4.3)
CVE-2024-33573
Patched
Apr 25, 2024
EPROLO Dropshipping
Medium (4.3)
CVE-2024-32824
Patched
Apr 22, 2024
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
Medium (4.3)
CVE-2024-33679
Unpatched
Apr 26, 2024
FameTheme Demo Importer
Medium (4.3)
CVE-2024-33690
Patched
Apr 25, 2024
Financio
Medium (4.3)
CVE-2024-33596
Patched
Apr 25, 2024
Five Star Restaurant Reservations – WordPress Booking Plugin
Medium (4.3)
CVE-2024-32828
Patched
Apr 22, 2024
Table Rate Shipping Method for WooCommerce by Flexible Shipping
Medium (4.3)
CVE-2024-32806
Patched
Apr 22, 2024
Headline Analyzer
Medium (4.3)
CVE-2024-33683
Patched
Apr 26, 2024
Hide Dashboard Notifications
HT Mega – Absolute Addons For Elementor <= 2.4.7 – Missing Authorization to Information Exposure
Medium (4.3)
CVE-2024-32782
Patched
Apr 22, 2024
HT Mega – Absolute Addons For Elementor
Medium (4.3)
CVE-2024-32701
Patched
Apr 22, 2024
InstaWP Connect – 1-click WP Staging & Migration
Medium (4.3)
CVE-2024-33589
Patched
Apr 25, 2024
KB Support – WordPress Help Desk and Knowledge Base
Medium (4.3)
CVE-2024-33588
Patched
Apr 25, 2024
Knowledge Base documentation & wiki plugin – BasePress Docs
Medium (4.3)
CVE-2024-33680
Patched
Apr 26, 2024
MainWP Child Reports
Medium (4.3)
CVE-2024-33595
Patched
Apr 25, 2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
Medium (4.3)
CVE-2024-33570
Patched
Apr 25, 2024
Medium (4.3)
CVE-2024-33651
Unpatched
Apr 25, 2024
MF Gig Calendar
Multiple Plugins by tychesoftwares <= (Various Versions) – Missing Authorization to Notice Dismissal
Medium (4.3)
CVE-2024-4233
Patched
Apr 26, 2024
Medium (4.3)
CVE-2024-33685
Patched
Apr 26, 2024
Medium (4.3)
CVE-2024-32957
Patched
Apr 23, 2024
Page Builder: Live Composer
Medium (4.3)
CVE-2024-32728
Patched
Apr 22, 2024
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
Medium (4.3)
CVE-2024-33585
Patched
Apr 25, 2024
Payment Gateway Based Fees and Discounts for WooCommerce
Medium (4.3)
CVE-2024-32812
Patched
Apr 22, 2024
Podlove Podcast Publisher
Medium (4.3)
CVE-2024-32712
Patched
Apr 22, 2024
Podlove Podcast Publisher
Medium (4.3)
CVE-2024-33691
Patched
Apr 26, 2024
Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation
Medium (4.3)
CVE-2024-32772
Patched
Apr 22, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Medium (4.3)
CVE-2024-32808
Patched
Apr 22, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Medium (4.3)
CVE-2024-3607
Patched
Apr 24, 2024
PropertyHive
Medium (4.3)
CVE-2024-3664
Patched
Apr 22, 2024
Quick Featured Images
Medium (4.3)
CVE-2024-33689
Patched
Apr 26, 2024
Medium (4.3)
CVE-2024-32822
Patched
Apr 22, 2024
Reviews Plus
Medium (4.3)
CVE-2024-32773
Patched
Apr 22, 2024
Royal Elementor Kit
Medium (4.3)
CVE-2024-2429
Patched
Apr 26, 2024
Salon booking system
Medium (4.3)
CVE-2024-32717
Patched
Apr 22, 2024
Medium (4.3)
CVE-2024-32787
Patched
Apr 22, 2024
Secure Copy Content Protection and Content Locking
Medium (4.3)
CVE-2024-33650
Unpatched
Apr 25, 2024
Serious Slider
Medium (4.3)
CVE-2024-32810
Patched
Apr 22, 2024
ShortPixel Critical CSS
Medium (4.3)
CVE-2024-33593
Patched
Apr 25, 2024
Smart Forms – when you need more than just a contact form
Medium (4.3)
CVE-2024-33638
Unpatched
Apr 25, 2024
Smart Maintenance Mode
Medium (4.3)
CVE-2024-3107
Patched
Apr 26, 2024
Spectra – WordPress Gutenberg Blocks
Medium (4.3)
CVE-2024-33572
Patched
Apr 25, 2024
The Plus Blocks for Block Editor | Gutenberg
Medium (4.3)
CVE-2024-32821
Patched
Apr 22, 2024
Poll | Vote | Contest – Best Poll Plugin for WordPress
Medium (4.3)
CVE-2024-33574
Patched
Apr 25, 2024
Vitepos – Point of sale (POS) plugin for WooCommerce
Medium (4.3)
CVE-2024-3546
Patched
Apr 22, 2024
WordPress Backup & Migration
Medium (4.3)
CVE-2024-32818
Patched
Apr 22, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (4.3)
CVE-2024-32947
Patched
Apr 22, 2024
WP ADA Compliance Check Basic – Most Comprehensive Web Accessibility Solution for WordPress
Medium (4.3)
CVE-2024-33682
Unpatched
Apr 26, 2024
Cookie Information | Free GDPR Consent Solution
Medium (4.3)
CVE-2024-32804
Patched
Apr 22, 2024
WP GoToWebinar
Medium (4.3)
CVE-2024-32797
Patched
Apr 22, 2024
WP LinkedIn Auto Publish
Medium (4.3)
CVE-2024-33636
Unpatched
Apr 25, 2024
WP Page Post Widget Clone
Medium (4.3)
CVE-2024-32795
Patched
Apr 22, 2024
WPCal.io – Easy Meeting Scheduler
Medium (4.3)
CVE-2024-33576
Patched
Apr 25, 2024
WPPizza – A Restaurant Plugin
Medium (4.3)
CVE-2024-33547
Unpatched
Apr 25, 2024
WooCommerce Amazon Affiliates – WordPress Plugin
Medium (4.3)
CVE-2024-33563
Unpatched
Apr 25, 2024
XStore
Medium (4.3)
CVE-2024-32699
Patched
Apr 22, 2024
YITH WooCommerce Compare
Low (3.3)
CVE-2024-32834
Patched
Apr 22, 2024
WooCommerce Shipping Label
Low (2.7)
CVE-2024-3034
Patched
Apr 26, 2024
BackUpWordPress
Low (2.7)
CVE-2024-4214
Patched
Apr 25, 2024
Car Dealer (Dealership) and Vehicle sales
Low (2.7)
CVE-2024-32790
Patched
Apr 22, 2024
Pricing Table by Supsystic
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 22, 2024 to April 28, 2024) appeared first on Wordfence.