Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $10,400, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 225 vulnerabilities disclosed in 186 WordPress Plugins and 14 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 62 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 17,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload
- BookingPress Appointment Booking <= 1.1.5 – Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 93 |
Unpatched | 132 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 1 |
Medium Severity | 173 |
High Severity | 32 |
Critical Severity | 19 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 94 |
Missing Authorization | 39 |
Cross-Site Request Forgery (CSRF) | 29 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 12 |
Information Exposure | 11 |
Unrestricted Upload of File with Dangerous Type | 8 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 6 |
Information Exposure Through Log Files | 5 |
Server-Side Request Forgery (SSRF) | 5 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 4 |
Improper Privilege Management | 3 |
Authentication Bypass Using an Alternate Path or Channel | 2 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Deserialization of Untrusted Data | 1 |
File and Directory Information Exposure | 1 |
Use of Hard-coded Credentials | 1 |
Use of Less Trusted Source | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
18 | |
15 | |
14 | |
13 | |
13 | |
12 | |
10 | |
9 | |
7 | |
7 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Academy LMS – eLearning and online course solution for WordPress | academy |
Admin Dashboard RSS Feed | admin-dashboard-rss-feed |
AdPush | adsense-plugin |
Advanced AJAX Page Loader | advanced-ajax-page-loader |
Advanced File Manager Shortcodes | file-manager-advanced-shortcode |
Advanced post slider | advanced-post-slider |
Amazing Hover Effects | amazing-hover-effects |
Animated Typed JS Shortcode | animated-typed-js-shortcode |
Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps | appmaker-woocommerce-mobile-app-manager |
Arkhe Blocks | arkhe-blocks |
Attachment File Icons (AF Icons) | attachment-file-icons |
Auto Featured Image (Auto Post Thumbnail) | auto-post-thumbnail |
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. | barcode-scanner-lite-pos-to-manage-products-inventory-and-orders |
BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | searchpro |
Blog, Posts and Category Filter for Elementor | blog-posts-and-category-for-elementor |
Booking Ultra Pro Appointments Booking Calendar Plugin | booking-ultra-pro |
Bradmax Player | bradmax-player |
Branda – White Label WordPress, Custom Login Page Customizer | branda-white-labeling |
Calendar.online / Kalender.digital – Plugin | kalender-digital |
Caxton – Create Pro page layouts in Gutenberg | caxton |
Change From Email | wp-from-email |
Cliengo – Chatbot | cliengo |
codoc | codoc |
Coming Soon Page – Responsive Coming Soon & Maintenance Mode | responsive-coming-soon-page |
Comment Images Reloaded | comment-images-reloaded |
ConeBlog – Elementor Blog Widgets | coneblog-widgets |
Contact Form 7 Summary and Print | cf7-summary-and-print |
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | bit-form |
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder | arforms-form-builder |
Default Thumbnail Plus | default-thumbnail-plus |
DirectoryPress – Business Directory And Classified Ad Listing | directorypress |
Download Button for Elementor | download-button-for-elementor |
Duplicator – Migration & Backup Plugin | duplicator |
Dynamic Word Spinner: CSS3 Animated Rotation | css3-rotating-words |
Easy Pixels | easy-pixels-by-jevnet |
EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin | eazydocs |
EleForms – All In One Form Integration including DB for Elementor | all-contact-form-integration-for-elementor |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
EmbedPress – Embed PDF, PDF 3D FlipBook, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor | embedpress |
Event post | event-post |
Event Tickets and Registration | event-tickets |
EventON | eventon-lite |
Events Calendar for Google | events-calendar-for-google |
ExS Widgets | exs-widgets |
Extensions for Elementor | extensions-for-elementor |
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | post-block |
Featured Image Generator | featured-image-generator |
Feeds for YouTube (YouTube video, channel, and gallery plugin) | feeds-for-youtube |
Form Vibes – Database Manager for Forms | form-vibes |
FormFlow: WhatsApp & Social Form Builder for Leads | simple-form |
FULL – Cliente | full-customer |
Fusion Page Builder | fusion |
GD Rating System | gd-rating-system |
Generate PDF using Contact Form 7 | generate-pdf-using-contact-form-7 |
Genesis Blocks | genesis-blocks |
Get Use APIs – JSON Content Importer | json-content-importer |
Goftino | goftino |
Google Adsense & Banner Ads by AdsforWP | ads-for-wp |
Gravity Forms: Multiple Form Instances | gravity-forms-multiple-form-instances |
Gum Elementor Addon | gum-elementor-addon |
Gutenberg Forms – WordPress Form Builder Plugin | forms-gutenberg |
GutSlider – All in One Block Slider | slider-blocks |
HitPay Payment Gateway for WooCommerce | hitpay-payment-gateway |
Houzez CRM | houzez-crm |
Houzez Theme – Functionality | houzez-theme-functionality |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
Image Optimizer, Resizer and CDN – Sirv | sirv |
Import Spreadsheets from Microsoft Excel | import-spreadsheets-from-microsoft-excel |
InstaWP Connect – 1-click WP Staging & Migration | instawp-connect |
Internal Link Juicer: SEO Auto Linker for WordPress | internal-links |
iPanorama 360 – WordPress Virtual Tour Builder | ipanorama-360-virtual-tour-builder-lite |
IQ Testimonials | iq-testimonials |
Job Board Manager | job-board-manager |
JSON API User | json-api-user |
Just Custom Fields | just-custom-fields |
Laposta | laposta |
LearnDash LMS – Reports | wisdm-reports-for-learndash |
Light Poll | light-poll |
Link Library | link-library |
Login by Auth0 | auth0 |
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) | magical-addons-for-elementor |
Magical Posts Display – Elementor Advanced Posts widgets | magical-posts-display |
MakeStories (for Google Web Stories) | makestories-helper |
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | master-addons |
Master Popups | master-popups-lite |
Matomo Analytics – Ethical Stats. Powerful Insights. | matomo |
MBE eShip | mail-boxes-etc |
Media Hygiene: Remove or Delete Unused Images and More! | media-hygiene |
Meks Smart Author Widget | meks-smart-author-widget |
Meks Video Importer | meks-video-importer |
Metorik – Reports & Email Automation for WooCommerce | metorik-helper |
Modern Events Calendar | modern-events-calendar |
Modern Events Calendar Lite | modern-events-calendar-lite |
Moloni | moloni |
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar | mp3-music-player-by-sonaar |
MStore API – Create Native Android & iOS Apps On The Cloud | mstore-api |
oik | oik |
Olive One Click Demo Import | olive-one-click-demo-import |
Openpos – WooCommerce Point Of Sale(POS) | woocommerce-openpos |
OSM – OpenStreetMap | osm |
Packlink PRO shipping module | packlink-pro-shipping |
Panda Video | pandavideo |
Payflex Payment Gateway | payflex-payment-gateway |
PayPlus Payment Gateway | payplus-payment-gateway |
Plugin Name: CodePen Embedded Pens Shortcode | codepen-embedded-pen-shortcode |
Plugin Notes Plus | plugin-notes-plus |
Plum: Spin Wheel & Email Pop-up | qodeblock |
Post Layouts for Gutenberg | post-layouts |
Power BI Embedded for WordPress | embed-power-bi |
PowerPress Podcasting plugin by Blubrry | powerpress |
Predictive Search for WooCommerce | woocommerce-predictive-search |
Premium Addons for Elementor | premium-addons-for-elementor |
Pricing Table | elfsight-pricing-table |
Product Delivery Date for WooCommerce – Lite | product-delivery-date-for-woocommerce-lite |
Product Designer | product-designer |
Product Table by WBW | woo-product-tables |
ProfileGrid – User Profiles, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
Qi Blocks | qi-blocks |
Realtyna Organic IDX plugin + WPL Real Estate | real-estate-listing-realtyna-wpl |
ReCaptcha Integration for WordPress | wp-recaptcha-integration |
Recipe Cards For Your Food Blog from Zip Recipes | zip-recipes |
ReDi Restaurant Reservation | redi-restaurant-reservation |
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction | pie-register |
REVIEWS.io WooCommerce Plugin | reviewscouk-for-woocommerce |
ScrollTo Bottom | scrollto-bottom |
ScrollTo Top | scrollto-top |
SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue | happy-scss-compiler |
Search & Replace | search-and-replace |
Send Users Email | send-users-email |
Seraphinite Accelerator Pro | seraphinite-accelerator-ext |
Seraphinite Post .DOCX Source | seraphinite-post-docx-source |
Simple Alert Boxes | simple-alert-boxes |
Simple Popup Plugin | simple-popup-plugin |
Simple Post Notes | simple-post-notes |
Simple Responsive Slider | simple-responsive-slider |
SKT Addons for Elementor | skt-addons-for-elementor |
SKT Skill Bar | skt-skill-bar |
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) | sky-elementor-addons |
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) | slingblocks |
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer | smartcrawl-seo |
Social Sharing Plugin – Kiwi | kiwi-social-share |
Spiffy Calendar | spiffy-calendar |
Squelch Tabs and Accordions Shortcodes | squelch-tabs-and-accordions-shortcodes |
Tabs For WPBakery Page Builder (formerly Visual Composer) | tabs-for-visual-composer |
Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics | taggbox-widget |
Team Manager – WordPress Showcase Team Members | wp-team-manager |
Team Members | team-members |
Timeline Module for Beaver Builder | timeline-for-beaver-builder |
Titan Anti-spam & Security | anti-spam |
TOCHAT.BE | tochat-be |
Tutor LMS – eLearning and online course solution | tutor |
Typebot | Create advanced chat experiences without coding | typebot |
Ultimate Classified Listings | ultimate-classified-listings |
UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) | ultraaddons-elementor-lite |
Uncanny Automator Pro | uncanny-automator-pro |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | unlimited-elements-for-elementor |
User Activity Log Pro | user-activity-log-pro |
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | userfeedback-lite |
VK All in One Expansion Unit | vk-all-in-one-expansion-unit |
Wallet for WooCommerce | woo-wallet |
Wallet System for WooCommerce – Wallet, Digital Wallet, Cashback, Recharge User Wallets, Partial Payments, Wallet restriction, Refunds | wallet-system-for-woocommerce |
WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute | wapppress-builds-android-app-for-website |
Webico Slider Flatsome Addons | webico-slider-flatsome-addons |
Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More | woocommerce-wholesale-prices |
WooCommerce Report | ithemelandco-woo-report |
WordPress Multisite Content Copier/Updater | wp-multisite-content-copier |
WP Accessibility Helper (WAH) | wp-accessibility-helper |
WP Announcement | Dynamic Announcement, Banner, & Countdown Timer for Effective Promotions | sp-announcement |
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | erp |
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress | wp-event-aggregator |
WP Fast Total Search – The Power of Indexed Search | fulltext-search |
WP GoToWebinar | wp-gotowebinar |
WP Links Page | wp-links-page |
WP Photo Album Plus | wp-photo-album-plus |
WP Popups – WordPress Popup builder | wp-popups-lite |
WP Total Branding – Complete branding solution for WordPress | wp-total-branding |
WP Travel Engine – Tour Booking Plugin – Tour Operator Software | wp-travel-engine |
WP User Switch | wp-user-switch |
WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 | wp2speed |
WPBITS Addons For Elementor Page Builder | wpbits-addons-for-elementor |
WPCS – WordPress Currency Switcher Professional | currency-switcher |
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] | faq-for-woocommerce |
YITH WooCommerce Ajax Product Filter | yith-woocommerce-ajax-navigation |
Zephyr Project Manager | zephyr-project-manager |
Zoho Campaigns | zoho-campaigns |
Zoho CRM Lead Magnet | zoho-crm-forms |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
BuddyBoss Theme | buddyboss-theme |
Counterpoint | counterpoint |
i-amaze | i-amaze |
i-transform | i-transform |
Noo JobMonster | noo-jobmonster |
Oceanic | oceanic |
OnePress | onepress |
Patricia Blog | patricia-blog |
Patricia Lite | patricia-lite |
Point | point |
Popularis Verse | popularis-verse |
Responsive Mobile | responsive-mobile |
SmartMag | smartmag-responsive-retina-wordpress-magazine |
SociallyViral | sociallyviral |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-37933
Unpatched
Jul 9, 2024
Openpos – WooCommerce Point Of Sale(POS)
Critical (9.9)
CVE-2024-38755
Unpatched
Jul 11, 2024
DirectoryPress – Business Directory And Classified Ad Listing
Critical (9.9)
CVE-2024-3604
Unpatched
Jul 8, 2024
OSM – OpenStreetMap
Critical (9.9)
CVE-2024-37564
Unpatched
Jul 9, 2024
PayPlus Payment Gateway
Critical (9.8)
CVE-2024-38717
Unpatched
Jul 11, 2024
Booking Ultra Pro Appointments Booking Calendar Plugin
Critical (9.8)
CVE-2024-38735
Unpatched
Jul 11, 2024
Event post
Critical (9.8)
CVE-2024-6313
Unpatched
Jul 8, 2024
Gutenberg Forms – WordPress Form Builder Plugin
Critical (9.8)
CVE-2024-6397
Patched
Jul 10, 2024
InstaWP Connect – 1-click WP Staging & Migration
Critical (9.8)
CVE-2024-6314
Unpatched
Jul 8, 2024
IQ Testimonials
Critical (9.8)
CVE-2024-37927
Unpatched
Jul 9, 2024
Noo JobMonster
Critical (9.8)
CVE-2024-6624
Patched
Jul 10, 2024
JSON API User
Critical (9.8)
CVE-2024-6328
Patched
Jul 11, 2024
MStore API – Create Native Android & iOS Apps On The Cloud
Critical (9.8)
CVE-2024-6365
Patched
Jul 8, 2024
Product Table by WBW
Critical (9.8)
CVE-2024-38759
Unpatched
Jul 11, 2024
Search & Replace
Import Spreadsheets from Microsoft Excel <= 10.1.4 – Authenticated (Editor+) Arbitrary File Upload
Critical (9.1)
CVE-2024-38734
Unpatched
Jul 11, 2024
Import Spreadsheets from Microsoft Excel
Critical (9.1)
CVE-2024-37928
Unpatched
Jul 9, 2024
Noo JobMonster
Critical (9.1)
CVE-2024-38736
Unpatched
Jul 11, 2024
Realtyna Organic IDX plugin + WPL Real Estate
Critical (9.1)
CVE-2024-38692
Patched
Jul 10, 2024
Spiffy Calendar
Critical (9.1)
CVE-2024-37932
Unpatched
Jul 9, 2024
Openpos – WooCommerce Point Of Sale(POS)
High (8.8)
CVE-2024-6310
Unpatched
Jul 8, 2024
Advanced AJAX Page Loader
High (8.8)
CVE-2023-7061
Unpatched
Jul 8, 2024
Advanced File Manager Shortcodes
High (8.8)
CVE-2023-7062
Unpatched
Jul 8, 2024
Advanced File Manager Shortcodes
High (8.8)
CVE-2024-6309
Unpatched
Jul 8, 2024
Attachment File Icons (AF Icons)
High (8.8)
CVE-2024-6161
Unpatched
Jul 8, 2024
Default Thumbnail Plus
High (8.8)
CVE-2024-38716
Unpatched
Jul 11, 2024
Events Calendar for Google
High (8.8)
CVE-2024-38715
Unpatched
Jul 11, 2024
ExS Widgets
High (8.8)
CVE-2024-5325
Patched
Jul 11, 2024
Form Vibes – Database Manager for Forms
High (8.8)
CVE-2024-38709
Patched
Jul 11, 2024
GD Rating System
Generate PDF using Contact Form 7 <= 4.0.6 – Cross-Site Request Forgery to Arbitrary File Deletion
High (8.8)
CVE-2024-6317
Unpatched
Jul 8, 2024
Generate PDF using Contact Form 7
Generate PDF using Contact Form 7 <= 4.0.6 – Cross-Site Request Forgery to Arbitrary File Upload
High (8.8)
CVE-2024-6316
Unpatched
Jul 8, 2024
Generate PDF using Contact Form 7
High (8.8)
CVE-2024-5792
Patched
Jul 8, 2024
Houzez CRM
High (8.8)
CVE-2024-5793
Patched
Jul 8, 2024
Houzez Theme – Functionality
High (8.8)
CVE-2024-5441
Patched
Jul 8, 2024
High (8.8)
CVE-2024-5456
Unpatched
Jul 8, 2024
Panda Video
High (8.8)
CVE-2024-6069
Unpatched
Jul 8, 2024
High (8.8)
CVE-2024-6411
Patched
Jul 9, 2024
ProfileGrid – User Profiles, Groups and Communities
High (8.8)
CVE-2024-6321
Unpatched
Jul 8, 2024
ScrollTo Bottom
High (8.8)
CVE-2024-6320
Unpatched
Jul 8, 2024
ScrollTo Top
High (8.8)
CVE-2024-6166
Patched
Jul 8, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
High (8.8)
CVE-2024-6353
Patched
Jul 11, 2024
Wallet for WooCommerce
High (8.8)
CVE-2024-38704
Patched
Jul 11, 2024
Team Manager – WordPress Showcase Team Members
High (8.8)
CVE-2024-6666
Patched
Jul 10, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
High (8.8)
CVE-2024-37560
Unpatched
Jul 9, 2024
WP User Switch
Barcode Scanner with Inventory & Order Manager <= 1.6.1 – Authenticated (Subscriber+) SQL Injection
High (8.5)
CVE-2024-38708
Patched
Jul 11, 2024
High (7.2)
CVE-2024-37942
Patched
Jul 10, 2024
High (7.2)
CVE-2024-6123
Patched
Jul 8, 2024
High (7.2)
CVE-2024-5479
Unpatched
Jul 8, 2024
Easy Pixels
High (7.2)
CVE-2024-6180
Unpatched
Jul 8, 2024
High (7.2)
CVE-2024-6447
Patched
Jul 10, 2024
FULL – Cliente
High (7.2)
CVE-2024-37563
Unpatched
Jul 9, 2024
TOCHAT.BE
High (7.2)
CVE-2024-5902
Patched
Jul 12, 2024
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
Medium (6.5)
CVE-2024-5992
Unpatched
Jul 8, 2024
Cliengo – Chatbot
Medium (6.5)
CVE-2024-38700
Unpatched
Jul 10, 2024
WPCS – WordPress Currency Switcher Professional
Medium (6.4)
CVE-2024-38750
Unpatched
Jul 11, 2024
Advanced post slider
Medium (6.4)
CVE-2024-38741
Unpatched
Jul 11, 2024
Amazing Hover Effects
Medium (6.4)
CVE-2024-38679
Unpatched
Jul 10, 2024
Animated Typed JS Shortcode
Medium (6.4)
CVE-2024-38675
Unpatched
Jul 10, 2024
Arkhe Blocks
Medium (6.4)
CVE-2024-4667
Patched
Jul 8, 2024
Blog, Posts and Category Filter for Elementor
Medium (6.4)
CVE-2024-38676
Unpatched
Jul 10, 2024
Booking Ultra Pro Appointments Booking Calendar Plugin
Medium (6.4)
CVE-2024-37957
Unpatched
Jul 10, 2024
Bradmax Player
Medium (6.4)
CVE-2024-38678
Unpatched
Jul 10, 2024
Calendar.online / Kalender.digital – Plugin
Medium (6.4)
CVE-2024-37948
Unpatched
Jul 10, 2024
Caxton – Create Pro page layouts in Gutenberg
CodePen Embedded Pens Shortcode <= 1.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-37960
Unpatched
Jul 10, 2024
Plugin Name: CodePen Embedded Pens Shortcode
Medium (6.4)
CVE-2024-37918
Patched
Jul 9, 2024
ConeBlog – Elementor Blog Widgets
Download Button for Elementor <= 1.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-38718
Unpatched
Jul 11, 2024
Download Button for Elementor
Medium (6.4)
CVE-2024-38720
Unpatched
Jul 11, 2024
Medium (6.4)
CVE-2024-38705
Patched
Jul 11, 2024
ElementInvader Addons for Elementor
Medium (6.4)
CVE-2024-4868
Unpatched
Jul 8, 2024
Extensions for Elementor
Medium (6.4)
CVE-2024-38686
Patched
Jul 10, 2024
Medium (6.4)
CVE-2024-6256
Patched
Jul 10, 2024
Feeds for YouTube (YouTube video, channel, and gallery plugin)
Medium (6.4)
CVE-2024-37962
Unpatched
Jul 10, 2024
Fusion Page Builder
Medium (6.4)
CVE-2024-3563
Patched
Jul 8, 2024
Genesis Blocks
Medium (6.4)
CVE-2024-38697
Patched
Jul 11, 2024
Goftino
Medium (6.4)
CVE-2024-37955
Unpatched
Jul 10, 2024
GutSlider – All in One Block Slider
Medium (6.4)
CVE-2024-38722
Unpatched
Jul 11, 2024
Job Board Manager
Medium (6.4)
CVE-2024-38723
Patched
Jul 11, 2024
Get Use APIs – JSON Content Importer
Magical Addons For Elementor <= 1.1.41 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-38681
Patched
Jul 10, 2024
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
Magical Addons For Elementor <= 1.1.41 – Authenticated (Subscriber+) Server-Side Request Forgery
Medium (6.4)
CVE-2024-38730
Patched
Jul 11, 2024
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
Medium (6.4)
CVE-2024-37951
Unpatched
Jul 10, 2024
Magical Posts Display – Elementor Advanced Posts widgets
Medium (6.4)
CVE-2024-38710
Patched
Jul 11, 2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
Medium (6.4)
CVE-2024-37958
Unpatched
Jul 10, 2024
Meks Smart Author Widget
Medium (6.4)
CVE-2024-5664
Patched
Jul 9, 2024
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
oik <= 4.10.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via bw_button Shortcode
Medium (6.4)
CVE-2024-6391
Patched
Jul 8, 2024
oik
Medium (6.4)
CVE-2024-38739
Unpatched
Jul 11, 2024
OnePress
Medium (6.4)
CVE-2024-3603
Unpatched
Jul 8, 2024
OSM – OpenStreetMap
Medium (6.4)
CVE-2024-5457
Unpatched
Jul 8, 2024
Panda Video
Medium (6.4)
CVE-2024-38682
Unpatched
Jul 10, 2024
Post Layouts for Gutenberg
Power BI Embedded for WordPress <= 1.1.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-37959
Unpatched
Jul 10, 2024
Power BI Embedded for WordPress
Medium (6.4)
CVE-2024-6588
Patched
Jul 11, 2024
PowerPress Podcasting plugin by Blubrry
Medium (6.4)
CVE-2024-6495
Patched
Jul 11, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-38712
Patched
Jul 11, 2024
Qi Blocks
Medium (6.4)
CVE-2024-37949
Unpatched
Jul 10, 2024
Responsive Mobile
Medium (6.4)
CVE-2024-38677
Unpatched
Jul 10, 2024
REVIEWS.io WooCommerce Plugin
Seraphinite Post .DOCX Source <= 2.16.9 – Authenticated (Subscriber+) Server-Side Request Forgery
Medium (6.4)
CVE-2024-38728
Unpatched
Jul 11, 2024
Seraphinite Post .DOCX Source
Medium (6.4)
CVE-2024-5937
Unpatched
Jul 8, 2024
Simple Alert Boxes
Medium (6.4)
CVE-2024-38674
Unpatched
Jul 10, 2024
SKT Addons for Elementor
Medium (6.4)
CVE-2024-38698
Patched
Jul 11, 2024
SKT Skill Bar
Medium (6.4)
CVE-2024-38687
Unpatched
Jul 10, 2024
Medium (6.4)
CVE-2024-38684
Patched
Jul 10, 2024
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
Medium (6.4)
CVE-2024-5946
Patched
Jul 8, 2024
Squelch Tabs and Accordions Shortcodes
Tabs For WPBakery Page Builder <= 1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-37936
Unpatched
Jul 9, 2024
Tabs For WPBakery Page Builder (formerly Visual Composer)
Medium (6.4)
CVE-2024-38670
Patched
Jul 10, 2024
Team Members
Medium (6.4)
CVE-2024-38757
Unpatched
Jul 11, 2024
Typebot | Create advanced chat experiences without coding
Medium (6.4)
CVE-2024-4866
Unpatched
Jul 9, 2024
Medium (6.4)
CVE-2024-6170
Patched
Jul 8, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (6.4)
CVE-2024-6169
Patched
Jul 8, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
VK All in One Expansion Unit <= 9.98.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-37956
Unpatched
Jul 10, 2024
VK All in One Expansion Unit
Medium (6.4)
CVE-2024-38758
Unpatched
Jul 11, 2024
WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute
Medium (6.4)
CVE-2024-5881
Unpatched
Jul 8, 2024
Webico Slider Flatsome Addons
Medium (6.4)
CVE-2024-38703
Patched
Jul 11, 2024
Medium (6.4)
CVE-2024-38671
Unpatched
Jul 10, 2024
WP GoToWebinar
Medium (6.4)
CVE-2024-38713
Patched
Jul 11, 2024
WP Photo Album Plus
Medium (6.4)
CVE-2024-37944
Patched
Jul 10, 2024
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
Medium (6.4)
CVE-2024-4862
Patched
Jul 8, 2024
WPBITS Addons For Elementor Page Builder
Medium (6.4)
CVE-2024-5669
Unpatched
Jul 8, 2024
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]
Medium (6.4)
CVE-2024-38752
Unpatched
Jul 11, 2024
Zoho Campaigns
Medium (6.1)
CVE-2024-38672
Unpatched
Jul 10, 2024
AdPush
Medium (6.1)
CVE-2024-38680
Unpatched
Jul 10, 2024
Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps
Medium (6.1)
CVE-2024-37920
Patched
Jul 9, 2024
Medium (6.1)
CVE-2024-37961
Unpatched
Jul 10, 2024
codoc
Medium (6.1)
CVE-2024-38724
Unpatched
Jul 11, 2024
Contact Form 7 Summary and Print
Medium (6.1)
CVE-2024-37559
Unpatched
Jul 8, 2024
Counterpoint
Medium (6.1)
CVE-2024-38711
Patched
Jul 11, 2024
Link Library
Medium (6.1)
CVE-2023-6813
Patched
Jul 9, 2024
Login by Auth0
Medium (6.1)
CVE-2024-37953
Unpatched
Jul 10, 2024
MBE eShip
Medium (6.1)
CVE-2024-38694
Patched
Jul 11, 2024
Medium (6.1)
CVE-2024-38673
Unpatched
Jul 10, 2024
WordPress Multisite Content Copier/Updater
Medium (6.1)
CVE-2024-38744
Unpatched
Jul 11, 2024
Plum: Spin Wheel & Email Pop-up
Medium (6.1)
CVE-2024-37954
Unpatched
Jul 10, 2024
Simple Responsive Slider
Medium (6.1)
CVE-2024-5883
Patched
Jul 8, 2024
Ultimate Classified Listings
Medium (6.1)
CVE-2024-6529
Patched
Jul 11, 2024
Ultimate Classified Listings
Medium (6.1)
CVE-2024-5882
Patched
Jul 8, 2024
Ultimate Classified Listings
Medium (6.1)
CVE-2024-37117
Patched
Jul 11, 2024
Uncanny Automator Pro
Medium (6.1)
CVE-2024-38669
Unpatched
Jul 10, 2024
Predictive Search for WooCommerce
Medium (6.1)
CVE-2024-38683
Unpatched
Jul 10, 2024
WooCommerce Report
Medium (6.1)
CVE-2024-37943
Patched
Jul 10, 2024
YITH WooCommerce Ajax Product Filter
Medium (6.1)
CVE-2024-38696
Patched
Jul 11, 2024
Zoho CRM Lead Magnet
Medium (5.5)
CVE-2024-37947
Patched
Jul 10, 2024
Tutor LMS – eLearning and online course solution
Medium (5.5)
CVE-2024-6625
Patched
Jul 11, 2024
WP Total Branding – Complete branding solution for WordPress
Medium (5.4)
CVE-2024-5993
Unpatched
Jul 8, 2024
Cliengo – Chatbot
Medium (5.4)
CVE-2024-5600
Unpatched
Jul 8, 2024
SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue
Medium (5.4)
CVE-2024-6392
Patched
Jul 11, 2024
Image Optimizer, Resizer and CDN – Sirv
Medium (5.4)
CVE-2024-5648
Unpatched
Jul 8, 2024
LearnDash LMS – Reports
Medium (5.4)
CVE-2024-4102
Unpatched
Jul 8, 2024
Pricing Table
Medium (5.3)
CVE-2024-6554
Patched
Jul 10, 2024
Branda – White Label WordPress, Custom Login Page Customizer
Medium (5.3)
CVE-2024-38756
Unpatched
Jul 11, 2024
Coming Soon Page – Responsive Coming Soon & Maintenance Mode
Medium (5.3)
CVE-2024-6210
Patched
Jul 10, 2024
Duplicator – Migration & Backup Plugin
Medium (5.3)
CVE-2024-38748
Unpatched
Jul 11, 2024
EleForms – All In One Form Integration including DB for Elementor
Medium (5.3)
CVE-2024-38707
Patched
Jul 11, 2024
Medium (5.3)
CVE-2024-6550
Patched
Jul 9, 2024
Gravity Forms: Multiple Form Instances
Medium (5.3)
CVE-2024-38747
Unpatched
Jul 11, 2024
HitPay Payment Gateway for WooCommerce
Medium (5.3)
CVE-2024-38690
Patched
Jul 10, 2024
iPanorama 360 – WordPress Virtual Tour Builder
Medium (5.3)
CVE-2024-6574
Unpatched
Jul 12, 2024
Laposta
Medium (5.3)
CVE-2024-38742
Unpatched
Jul 11, 2024
MBE eShip
Medium (5.3)
CVE-2024-38749
Unpatched
Jul 11, 2024
Olive One Click Demo Import
Medium (5.3)
CVE-2024-0619
Unpatched
Jul 10, 2024
Payflex Payment Gateway
Medium (5.3)
CVE-2024-38743
Unpatched
Jul 11, 2024
Plum: Spin Wheel & Email Pop-up
Medium (5.3)
CVE-2024-4100
Unpatched
Jul 8, 2024
Pricing Table
Medium (5.3)
CVE-2024-38702
Patched
Jul 11, 2024
Product Delivery Date for WooCommerce – Lite
Product Designer <= 1.0.33 – Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
Medium (5.3)
CVE-2024-3608
Unpatched
Jul 8, 2024
Product Designer
Medium (5.3)
CVE-2024-38688
Unpatched
Jul 10, 2024
Recipe Cards For Your Food Blog from Zip Recipes
Medium (5.3)
CVE-2024-38737
Patched
Jul 11, 2024
ReDi Restaurant Reservation
Medium (5.3)
CVE-2024-38760
Patched
Jul 12, 2024
Send Users Email
Medium (5.3)
CVE-2024-6556
Patched
Jul 9, 2024
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer
Medium (5.3)
CVE-2024-37930
Unpatched
Jul 9, 2024
SmartMag
Medium (5.3)
CVE-2024-3228
Patched
Jul 8, 2024
Social Sharing Plugin – Kiwi
Medium (5.3)
CVE-2024-6171
Patched
Jul 8, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (5.3)
CVE-2024-38699
Patched
Jul 11, 2024
Medium (5.3)
CVE-2024-38745
Patched
Jul 11, 2024
Medium (5.3)
CVE-2024-37935
Unpatched
Jul 9, 2024
Openpos – WooCommerce Point Of Sale(POS)
Medium (5.3)
CVE-2024-37926
Patched
Jul 9, 2024
WP Accessibility Helper (WAH)
Medium (5.3)
CVE-2024-6555
Patched
Jul 11, 2024
WP Popups – WordPress Popup builder
Medium (5.3)
CVE-2024-5810
Unpatched
Jul 8, 2024
WP2Speed Faster – Optimize PageSpeed Insights Score 90-100
Medium (5.3)
CVE-2024-38761
Patched
Jul 12, 2024
Zephyr Project Manager
Medium (4.4)
CVE-2024-38725
Unpatched
Jul 11, 2024
Admin Dashboard RSS Feed
Medium (4.4)
CVE-2024-38738
Unpatched
Jul 11, 2024
Change From Email
Medium (4.4)
CVE-2024-3113
Patched
Jul 9, 2024
FormFlow: WhatsApp & Social Form Builder for Leads
Medium (4.4)
CVE-2024-37565
Patched
Jul 9, 2024
Gum Elementor Addon
Medium (4.4)
CVE-2024-37950
Unpatched
Jul 10, 2024
Master Popups
Medium (4.4)
CVE-2024-37561
Unpatched
Jul 9, 2024
Plugin Notes Plus
Medium (4.4)
CVE-2024-37946
Unpatched
Jul 10, 2024
ReCaptcha Integration for WordPress
Medium (4.4)
CVE-2024-38689
Patched
Jul 10, 2024
Simple Popup Plugin
Medium (4.4)
CVE-2024-37562
Unpatched
Jul 9, 2024
Simple Post Notes
Timeline Module for Beaver Builder <= 1.1.3 – Authenticated (Editor+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37919
Unpatched
Jul 9, 2024
Timeline Module for Beaver Builder
Medium (4.4)
CVE-2024-38685
Patched
Jul 10, 2024
WP Announcement | Dynamic Announcement, Banner, & Countdown Timer for Effective Promotions
Medium (4.3)
CVE-2024-38719
Unpatched
Jul 11, 2024
Auto Featured Image (Auto Post Thumbnail)
Medium (4.3)
CVE-2024-37925
Patched
Jul 9, 2024
BuddyBoss Theme
Medium (4.3)
CVE-2024-5856
Unpatched
Jul 8, 2024
Comment Images Reloaded
Medium (4.3)
CVE-2024-38753
Unpatched
Jul 11, 2024
Dynamic Word Spinner: CSS3 Animated Rotation
Medium (4.3)
CVE-2024-38721
Unpatched
Jul 11, 2024
Medium (4.3)
CVE-2024-1375
Unpatched
Jul 11, 2024
Event post
Medium (4.3)
CVE-2024-38762
Patched
Jul 12, 2024
Event Tickets and Registration
Medium (4.3)
CVE-2024-5677
Patched
Jul 9, 2024
Featured Image Generator
Medium (4.3)
CVE-2024-38751
Unpatched
Jul 11, 2024
Google Adsense & Banner Ads by AdsforWP
Medium (4.3)
CVE-2024-38706
Patched
Jul 11, 2024
HT Mega – Absolute Addons For Elementor
Medium (4.3)
CVE-2024-38731
Unpatched
Jul 11, 2024
i-amaze
Medium (4.3)
CVE-2024-38764
Unpatched
Jul 12, 2024
i-transform
Medium (4.3)
CVE-2024-37941
Patched
Jul 9, 2024
Internal Link Juicer: SEO Auto Linker for WordPress
Medium (4.3)
CVE-2024-6168
Unpatched
Jul 8, 2024
Just Custom Fields
Medium (4.3)
CVE-2024-6167
Unpatched
Jul 8, 2024
Just Custom Fields
Medium (4.3)
CVE-2024-6496
Unpatched
Jul 11, 2024
Light Poll
Medium (4.3)
CVE-2024-38746
Patched
Jul 11, 2024
MakeStories (for Google Web Stories)
Medium (4.3)
CVE-2024-38766
Patched
Jul 12, 2024
Matomo Analytics – Ethical Stats. Powerful Insights.
Medium (4.3)
CVE-2024-38729
Unpatched
Jul 11, 2024
MBE eShip
Medium (4.3)
CVE-2024-5855
Patched
Jul 8, 2024
Media Hygiene: Remove or Delete Unused Images and More!
Medium (4.3)
CVE-2024-38733
Unpatched
Jul 11, 2024
Meks Video Importer
Medium (4.3)
CVE-2024-38691
Patched
Jul 10, 2024
Metorik – Reports & Email Automation for WooCommerce
Medium (4.3)
CVE-2024-38765
Unpatched
Jul 12, 2024
Oceanic
Medium (4.3)
CVE-2024-38740
Unpatched
Jul 11, 2024
Packlink PRO shipping module
Medium (4.3)
CVE-2024-38732
Unpatched
Jul 11, 2024
Patricia Blog
Medium (4.3)
CVE-2024-37939
Unpatched
Jul 9, 2024
Patricia Lite
Medium (4.3)
CVE-2024-37931
Unpatched
Jul 9, 2024
Point
Medium (4.3)
CVE-2024-38763
Unpatched
Jul 12, 2024
Popularis Verse
Medium (4.3)
CVE-2024-6410
Patched
Jul 9, 2024
ProfileGrid – User Profiles, Groups and Communities
Seraphinite Accelerator Premium <= 2.21.13 – Cross-Site Request Forgery to Arbitrary File Deletion
Medium (4.3)
CVE-2024-37940
Patched
Jul 9, 2024
Seraphinite Accelerator Pro
Medium (4.3)
CVE-2024-38727
Unpatched
Jul 11, 2024
Seraphinite Post .DOCX Source
Medium (4.3)
CVE-2024-37938
Unpatched
Jul 9, 2024
SociallyViral
Medium (4.3)
CVE-2024-38754
Unpatched
Jul 11, 2024
Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics
Medium (4.3)
CVE-2024-38777
Unpatched
Jul 11, 2024
Titan Anti-spam & Security
Medium (4.3)
CVE-2024-37929
Unpatched
Jul 9, 2024
User Activity Log Pro
Medium (4.3)
CVE-2024-38714
Patched
Jul 11, 2024
WP Fast Total Search – The Power of Indexed Search
Medium (4.3)
CVE-2024-38695
Unpatched
Jul 11, 2024
WP GoToWebinar
WP Links Page <= 4.9.5 – Missing Authorization to Authenticated (Subscriber+) Limited Image Update
Medium (4.3)
CVE-2024-6465
Patched
Jul 12, 2024
WP Links Page
Medium (4.3)
CVE-2024-5704
Unpatched
Jul 8, 2024
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]
Low (2.7)
CVE-2024-38701
Patched
Jul 11, 2024
Academy LMS – eLearning and online course solution for WordPress
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (July 8, 2024 to July 14, 2024) appeared first on Wordfence.