Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $10,400, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest. For a limited time, all high risk issues are in-scope for all researchers!
Last week, there were 121 vulnerabilities disclosed in 91 WordPress Plugins and 18 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 40 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 17,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.44 – Authentication Bypass to Admin
- FULL <= 3.1.12 – Unauthenticated Stored Cross-Site Scripting via License Plan Parameter
- ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 97 |
Unpatched | 24 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 97 |
High Severity | 18 |
Critical Severity | 4 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 58 |
Missing Authorization | 23 |
Cross-Site Request Forgery (CSRF) | 16 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 8 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 3 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 3 |
Unrestricted Upload of File with Dangerous Type | 3 |
Information Exposure | 2 |
Deserialization of Untrusted Data | 1 |
Improper Privilege Management | 1 |
Incorrect Privilege Assignment | 1 |
Uncontrolled Resource Consumption (‘Resource Exhaustion’) | 1 |
Unprotected Alternate Channel | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
15 | |
14 | |
11 | |
9 | |
7 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Advanced Classifieds & Directory Pro | advanced-classifieds-and-directory-pro |
AI Power: Complete AI Pack – Powered by GPT-4 | gpt3-ai-content-generator |
Apollo13 Framework Extensions | apollo13-framework-extensions |
AWSM Team – Team Showcase Plugin | awsm-team |
bbPress Notify (No-Spam) | bbpress-notify-nospam |
Beaver Builder Addons by WPZOOM | wpzoom-addons-for-beaver-builder |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
CC & BCC for Woocommerce Order Emails | cc-bcc-for-woocommerce-order-emails |
Church Admin | church-admin |
Comment Reply Email | comment-reply-email |
CopySafe Web Protection | wp-copysafe-web |
Cost Calculator Builder | cost-calculator-builder |
Create by Mediavine | mediavine-create |
CRM Perks Forms – WordPress Form Builder | crm-perks-forms |
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress | charitable |
Easy Custom Code (LESS/CSS/JS) – Live editing | easy-custom-code |
Easy Google Maps | google-maps-easy |
Elementor Addons by Livemesh | addons-for-elementor |
Elementor Header & Footer Builder | header-footer-elementor |
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | email-subscribers |
Event Manager, Events Calendar, Tickets, Registrations – Eventin | wp-event-solution |
Featured Image from URL (FIFU) | featured-image-from-url |
FileBird Document Library | filebird-document-library |
Floating Social Media Links | floating-social-media-links |
Get Better Reviews for WooCommerce | more-better-reviews-for-woocommerce |
HelloAsso | helloasso |
IdeaPush | ideapush |
IMGspider – 图片采集抓取插件 | imgspider |
JetThemeCore for Elementor | jet-theme-core |
LA-Studio Element Kit for Elementor | lastudio-element-kit |
Leaky Paywall | leaky-paywall |
LearnPress – WordPress LMS Plugin | learnpress |
Link To Bible | link-to-bible |
Login Logo Editor | login-logo-editor-by-oizuled |
MakeCommerce for WooCommerce | makecommerce |
Media Library Assistant | media-library-assistant |
Mega Elements – Addons for Elementor | mega-elements-addons-for-elementor |
Meks Easy Ads Widget | meks-easy-ads-widget |
Motors – Car Dealer, Classifieds & Listing | motors-car-dealership-classified-listings |
Nested Pages | wp-nested-pages |
Newspack Ads | newspack-ads |
Newspack Campaigns | newspack-popups |
Newspack Content Converter | newspack-content-converter |
Newspack Newsletters | newspack-newsletters |
NEX-Forms – Ultimate Form Builder – Contact forms and much more | nex-forms-express-wp-form-builder |
Ninja Forms – The Contact Form Builder That Grows With You | ninja-forms |
Ocean Extra | ocean-extra |
One Click Order Re-Order | one-click-order-reorder |
Online Booking & Scheduling Calendar for WordPress by vcita | meeting-scheduler-by-vcita |
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | paid-memberships-pro |
PayPlus Payment Gateway | payplus-payment-gateway |
Post Meta Data Manager | post-meta-data-manager |
Premium Addons for Elementor | premium-addons-for-elementor |
Premium Blocks – Gutenberg Blocks for WordPress | premium-blocks-for-gutenberg |
ProfileGrid – User Profiles, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
PZ Frontend Manager | pz-frontend-manager |
Rife Elementor Extensions & Templates | rife-elementor-extensions |
Save as PDF Plugin by Pdfcrowd | save-as-pdf-by-pdfcrowd |
ShopBuilder – Elementor WooCommerce Builder Addons | shopbuilder |
Simple Newsletter Plugin – Noptin | newsletter-optin-box |
Simple Social Share | simple-social-share |
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) | sina-extension-for-elementor |
Snippet Shortcodes | shortcode-variables |
Social Media Share Buttons & Social Sharing Icons | ultimate-social-media-icons |
Spectra – WordPress Gutenberg Blocks | ultimate-addons-for-gutenberg |
SuperSaaS – online appointment scheduling | supersaas-appointment-scheduling |
Swift Performance Lite | swift-performance-lite |
Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Forminator | tablesome |
Template Kit – Export | template-kit-export |
Testimonials Widget | testimonials-widget |
The Events Calendar | the-events-calendar |
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | the-plus-addons-for-elementor-page-builder |
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | the-post-grid |
Ultimate Addons for Elementor | ultimate-elementor |
Ultimate Blocks – WordPress Blocks Plugin | ultimate-blocks |
Ultimate Bootstrap Elements for Elementor | ultimate-bootstrap-elements-for-elementor |
Ultimate WordPress Auction Plugin | ultimate-auction |
Void Contact Form 7 Widget For Elementor Page Builder | cf7-widget-elementor |
Woffice Core | woffice-core |
WooCommerce – Social Login | woo-social-login |
WordPress Notification Bar | wordpress-notification-bar |
WP Cookie Law Info | wp-cookie-law-info |
WP Directory Kit | wpdirectorykit |
WP Lightbox 2 | wp-lightbox-2 |
WP To Do | wp-todo |
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | wp-cafe |
WPFavicon | wpfavicon |
WS Contact Form | ws-contact-form |
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] | faq-for-woocommerce |
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | youzify |
Zephyr Project Manager | zephyr-project-manager |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Ashe | ashe |
Bakes And Cakes | bakes-and-cakes |
Bard | bard |
Book Your Travel | bookyourtravel |
Boot Store | boot-store |
Business One Page | business-one-page |
Construction Landing Page | construction-landing-page |
Hestia | hestia |
Highlight | highlight |
Lawyer Landing Page | lawyer-landing-page |
Metro Magazine | metro-magazine |
Newsmatic | newsmatic |
Posterity | posterity |
Rara Business | rara-business |
Rife Free | rife-free |
Trendy News | trendy-news |
Woffice CRM | woffice |
zBench | zbench |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.9)
CVE-2024-37494
Patched
Jul 4, 2024
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
Critical (9.8)
CVE-2024-6172
Patched
Jul 1, 2024
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce
Critical (9.8)
CVE-2024-37502
Patched
Jul 5, 2024
WooCommerce – Social Login
Critical (9.1)
CVE-2024-37486
Patched
Jul 4, 2024
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Advanced Classifieds & Directory Pro <= 3.1.3 – Authenticated (Contributor+) Local File Inclusion
High (8.8)
CVE-2024-37501
Patched
Jul 4, 2024
Advanced Classifieds & Directory Pro
High (8.8)
CVE-2024-37454
Patched
Jul 1, 2024
AWSM Team – Team Showcase Plugin
High (8.8)
CVE-2024-37952
Patched
Jul 4, 2024
Book Your Travel
High (8.8)
CVE-2024-37418
Patched
Jul 4, 2024
Church Admin
High (8.8)
CVE-2024-2385
Unpatched
Jul 3, 2024
Elementor Addons by Livemesh
High (8.8)
CVE-2024-6318
Patched
Jul 3, 2024
IMGspider – 图片采集抓取插件
High (8.8)
CVE-2024-6319
Patched
Jul 3, 2024
IMGspider – 图片采集抓取插件
LA-Studio Element Kit for Elementor <= 1.3.8.1 – Authenticated (Contributor+) Local File Inclusion
High (8.8)
CVE-2024-5349
Patched
Jul 1, 2024
LA-Studio Element Kit for Elementor
High (8.8)
CVE-2024-5943
Patched
Jul 3, 2024
Nested Pages
High (8.8)
CVE-2024-37499
Patched
Jul 4, 2024
Online Booking & Scheduling Calendar for WordPress by vcita
High (8.8)
CVE-2024-37520
Patched
Jul 5, 2024
ShopBuilder – Elementor WooCommerce Builder Addons
High (8.8)
CVE-2024-37455
Patched
Jul 1, 2024
Ultimate Addons for Elementor
High (8.8)
CVE-2024-37462
Patched
Jul 1, 2024
Ultimate Bootstrap Elements for Elementor
High (8.8)
CVE-2024-37513
Patched
Jul 5, 2024
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce
High (8.8)
CVE-2024-37484
Patched
Jul 4, 2024
Zephyr Project Manager
High (8.1)
CVE-2024-37497
Patched
Jul 4, 2024
JetThemeCore for Elementor
High (7.2)
CVE-2024-37464
Patched
Jul 1, 2024
Beaver Builder Addons by WPZOOM
High (7.2)
CVE-2024-37461
Patched
Jul 1, 2024
Medium (6.4)
CVE-2024-37480
Patched
Jul 4, 2024
Apollo13 Framework Extensions
Medium (6.4)
CVE-2024-37500
Patched
Jul 4, 2024
Beaver Builder – WordPress Page Builder
Boot Store <= 1.6.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode
Medium (6.4)
CVE-2024-5938
Unpatched
Jul 1, 2024
Boot Store
Medium (6.4)
CVE-2024-37514
Patched
Jul 5, 2024
CopySafe Web Protection
Medium (6.4)
CVE-2024-37495
Patched
Jul 4, 2024
Create by Mediavine
Medium (6.4)
CVE-2024-5219
Patched
Jul 1, 2024
Easy Google Maps
Medium (6.4)
CVE-2024-33933
Patched
Jul 1, 2024
Elementor Header & Footer Builder
Medium (6.4)
CVE-2024-3638
Unpatched
Jul 3, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-3639
Unpatched
Jul 3, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-2926
Unpatched
Jul 3, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-37507
Patched
Jul 4, 2024
Event Manager, Events Calendar, Tickets, Registrations – Eventin
Medium (6.4)
CVE-2024-37465
Patched
Jul 1, 2024
AI Power: Complete AI Pack – Powered by GPT-4
Medium (6.4)
CVE-2024-37488
Patched
Jul 4, 2024
HelloAsso
Medium (6.4)
CVE-2024-37466
Patched
Jul 1, 2024
Mega Elements – Addons for Elementor
Medium (6.4)
CVE-2024-37474
Patched
Jul 1, 2024
Newspack Ads
Medium (6.4)
CVE-2024-37476
Patched
Jul 1, 2024
Newspack Campaigns
Medium (6.4)
CVE-2024-37512
Patched
Jul 5, 2024
NEX-Forms – Ultimate Form Builder – Contact forms and much more
Medium (6.4)
CVE-2024-37489
Patched
Jul 4, 2024
Ocean Extra
Medium (6.4)
CVE-2024-5641
Patched
Jul 3, 2024
One Click Order Re-Order
Medium (6.4)
CVE-2024-6264
Patched
Jul 1, 2024
Post Meta Data Manager
Medium (6.4)
CVE-2024-6340
Patched
Jul 2, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-37519
Patched
Jul 5, 2024
Premium Blocks – Gutenberg Blocks for WordPress
Medium (6.4)
CVE-2024-5504
Patched
Jul 1, 2024
Rife Elementor Extensions & Templates
Medium (6.4)
CVE-2024-5260
Patched
Jul 1, 2024
Medium (6.4)
CVE-2024-37460
Patched
Jul 1, 2024
SuperSaaS – online appointment scheduling
Medium (6.4)
CVE-2024-37553
Unpatched
Jul 6, 2024
Testimonials Widget
Medium (6.4)
CVE-2024-4482
Patched
Jul 2, 2024
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
Medium (6.4)
CVE-2024-1427
Patched
Jul 1, 2024
Medium (6.4)
CVE-2024-3513
Patched
Jul 1, 2024
Ultimate Blocks – WordPress Blocks Plugin
Medium (6.4)
CVE-2024-4268
Patched
Jul 1, 2024
Ultimate Blocks – WordPress Blocks Plugin
Medium (6.4)
CVE-2024-5419
Patched
Jul 1, 2024
Void Contact Form 7 Widget For Elementor Page Builder
Medium (6.4)
CVE-2024-6263
Patched
Jul 2, 2024
WP Lightbox 2
Medium (6.4)
CVE-2024-37539
Unpatched
Jul 6, 2024
WP To Do
Medium (6.4)
CVE-2024-37521
Unpatched
Jul 5, 2024
zBench
Medium (6.1)
CVE-2024-37485
Patched
Jul 4, 2024
bbPress Notify (No-Spam)
Medium (6.1)
CVE-2024-35773
Patched
Jul 5, 2024
Comment Reply Email
Medium (6.1)
CVE-2024-37509
Patched
Jul 4, 2024
MakeCommerce for WooCommerce
Medium (6.1)
CVE-2024-5544
Patched
Jul 1, 2024
Media Library Assistant
Medium (6.1)
CVE-2024-37459
Patched
Jul 1, 2024
PayPlus Payment Gateway
Medium (6.1)
CVE-2024-37472
Patched
Jul 1, 2024
Woffice CRM
Medium (6.1)
CVE-2024-37471
Patched
Jul 1, 2024
Woffice Core
Medium (6.1)
CVE-2024-37487
Patched
Jul 4, 2024
WP Directory Kit
Medium (6.1)
CVE-2024-37515
Patched
Jul 5, 2024
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]
Medium (5.4)
CVE-2024-37479
Patched
Jul 2, 2024
LA-Studio Element Kit for Elementor
Medium (5.4)
CVE-2024-37453
Patched
Jul 1, 2024
ProfileGrid – User Profiles, Groups and Communities
Medium (5.3)
CVE-2024-37506
Patched
Jul 4, 2024
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
Medium (5.3)
CVE-2024-37510
Patched
Jul 4, 2024
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress
Medium (5.3)
CVE-2024-37463
Patched
Jul 1, 2024
CRM Perks Forms – WordPress Form Builder
Medium (5.3)
CVE-2024-37504
Patched
Jul 4, 2024
FileBird Document Library
Medium (5.3)
CVE-2024-6088
Patched
Jul 1, 2024
LearnPress – WordPress LMS Plugin
Medium (5.3)
CVE-2024-6099
Patched
Jul 1, 2024
LearnPress – WordPress LMS Plugin
Medium (5.3)
CVE-2024-5545
Patched
Jul 1, 2024
Motors – Car Dealer, Classifieds & Listing
Medium (5.3)
CVE-2024-37468
Patched
Jul 1, 2024
Newsmatic
Medium (5.3)
CVE-2024-37475
Patched
Jul 1, 2024
Newspack Newsletters
Medium (5.3)
CVE-2024-37456
Patched
Jul 1, 2024
Simple Newsletter Plugin – Noptin
Medium (5.3)
CVE-2024-37498
Patched
Jul 4, 2024
Medium (5.3)
CVE-2024-37481
Patched
Jul 4, 2024
Medium (5.3)
CVE-2024-37470
Patched
Jul 1, 2024
Woffice Core
Medium (4.4)
CVE-2024-37522
Unpatched
Jul 5, 2024
CC & BCC for Woocommerce Order Emails
Medium (4.4)
CVE-2024-6011
Patched
Jul 1, 2024
Cost Calculator Builder
Medium (4.4)
CVE-2024-37536
Unpatched
Jul 5, 2024
Easy Custom Code (LESS/CSS/JS) – Live editing
Floating Social Media Links <= 1.5.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37545
Unpatched
Jul 6, 2024
Floating Social Media Links
Medium (4.4)
CVE-2024-37538
Unpatched
Jul 6, 2024
Link To Bible
Medium (4.4)
CVE-2024-37523
Unpatched
Jul 5, 2024
Login Logo Editor
Medium (4.4)
CVE-2024-37548
Unpatched
Jul 6, 2024
Meks Easy Ads Widget
Save as PDF plugin by Pdfcrowd <= 4.0.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37549
Patched
Jul 6, 2024
Save as PDF Plugin by Pdfcrowd
Medium (4.4)
CVE-2024-37551
Unpatched
Jul 6, 2024
Simple Social Share
Social Media & Share Icons <= 2.9.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37552
Unpatched
Jul 6, 2024
Social Media Share Buttons & Social Sharing Icons
Medium (4.4)
CVE-2024-37550
Unpatched
Jul 6, 2024
Template Kit – Export
WordPress Notification Bar <= 1.3.10 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37556
Unpatched
Jul 6, 2024
WordPress Notification Bar
Medium (4.4)
CVE-2024-37557
Unpatched
Jul 6, 2024
WP Cookie Law Info
Medium (4.4)
CVE-2024-37537
Unpatched
Jul 5, 2024
WS Contact Form
Medium (4.3)
CVE-2024-37478
Patched
Jul 1, 2024
Ashe
Medium (4.3)
CVE-2024-37490
Patched
Jul 4, 2024
Bard
Medium (4.3)
CVE-2024-37505
Patched
Jul 5, 2024
Business One Page
Medium (4.3)
CVE-2024-6012
Patched
Jul 1, 2024
Cost Calculator Builder
Medium (4.3)
CVE-2024-37516
Patched
Jul 5, 2024
Featured Image from URL (FIFU)
Medium (4.3)
CVE-2024-37544
Unpatched
Jul 6, 2024
Get Better Reviews for WooCommerce
Medium (4.3)
CVE-2024-37467
Patched
Jul 1, 2024
Hestia
Medium (4.3)
CVE-2024-37458
Patched
Jul 1, 2024
Highlight
Medium (4.3)
CVE-2024-37503
Patched
Jul 5, 2024
Lawyer Landing Page
Medium (4.3)
CVE-2024-37540
Unpatched
Jul 6, 2024
Leaky Paywall
Medium (4.3)
CVE-2024-37477
Patched
Jul 1, 2024
Newspack Content Converter
Medium (4.3)
CVE-2024-37934
Patched
Jul 4, 2024
Ninja Forms – The Contact Form Builder That Grows With You
Medium (4.3)
CVE-2024-37493
Patched
Jul 4, 2024
Posterity
Medium (4.3)
CVE-2024-6244
Patched
Jul 1, 2024
PZ Frontend Manager
Medium (4.3)
CVE-2024-37937
Patched
Jul 4, 2024
Rara Business
Medium (4.3)
CVE-2024-37491
Patched
Jul 4, 2024
Rife Free
Medium (4.3)
CVE-2024-4543
Patched
Jul 2, 2024
Snippet Shortcodes
Medium (4.3)
CVE-2024-37517
Patched
Jul 5, 2024
Spectra – WordPress Gutenberg Blocks
Medium (4.3)
CVE-2024-37511
Patched
Jul 5, 2024
Swift Performance Lite
Medium (4.3)
CVE-2024-37518
Patched
Jul 5, 2024
The Events Calendar
Medium (4.3)
CVE-2024-37482
Patched
Jul 4, 2024
Medium (4.3)
CVE-2024-37483
Patched
Jul 4, 2024
Medium (4.3)
CVE-2024-37496
Patched
Jul 4, 2024
Medium (4.3)
CVE-2024-37473
Patched
Jul 1, 2024
Trendy News
Medium (4.3)
CVE-2024-37543
Unpatched
Jul 6, 2024
Ultimate WordPress Auction Plugin
Low (3.1)
CVE-2024-6434
Patched
Jul 3, 2024
Premium Addons for Elementor
Low (3.1)
CVE-2024-37558
Unpatched
Jul 6, 2024
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 1, 2024 to July 7, 2024) appeared first on Wordfence.