Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 Active Installs are in scope for all researchers. In addition, through October 14th, 2024, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 181 vulnerabilities disclosed in 159 WordPress Plugins and 2 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 69 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- Wechat Social login <= 1.3.0 – Authentication Bypass
- Wechat Social login <= 1.3.0 – Unauthenticated Arbitrary File Upload
- Echo RSS Feed Post Generator <= 5.4.6 – Unauthenticated Privilege Escalation
- WordPress & WooCommerce Affiliate Program <= 8.4.1 – Authentication Bypass to Account Takeover and Privilege Escalation
- WAF-RULE-748 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-749 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-750 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-752 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 129 |
Unpatched | 52 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 134 |
High Severity | 23 |
Critical Severity | 22 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 93 |
Missing Authorization | 25 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 15 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 14 |
Cross-Site Request Forgery (CSRF) | 7 |
Exposure of Sensitive Information to an Unauthorized Actor | 6 |
Authorization Bypass Through User-Controlled Key | 4 |
Deserialization of Untrusted Data | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 4 |
Unrestricted Upload of File with Dangerous Type | 3 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Authentication Bypass Using an Alternate Path or Channel | 1 |
Exposure of Sensitive Information Through Metadata | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
Unverified Password Change | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
19 | |
12 | |
11 | |
10 | |
8 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
012 Ps Multi Languages | 012-ps-multi-languages |
ABC APP CREATOR | abcapp-creator |
Absolute Reviews | absolute-reviews |
Accordion | accordions |
Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads | quick-adsense-reloaded |
Advanced File Manager | file-manager-advanced |
AnWP Football Leagues | football-leagues-by-anwppro |
Appointment & Event Booking Calendar Plugin – Webba Booking | webba-booking-lite |
ARI Fancy Lightbox – Popup for WordPress | ari-fancy-lightbox |
BA Book Everything | ba-book-everything |
Beam me up Scotty – Back to Top Button | beam-me-up-scotty |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Bold Page Builder | bold-page-builder |
Bulk NoIndex & NoFollow Toolkit | bulk-noindex-nofollow-toolkit-by-mad-fish |
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More | charitable |
Charity Addon for Elementor | charity-addon-for-elementor |
Chartify – WordPress Chart Plugin | chart-builder |
Checkout Mestres do WP for WooCommerce | checkout-mestres-wp |
Cities Shipping Zones for WooCommerce | cities-shipping-zones-for-woocommerce |
Classic Editor and Classic Widgets | classic-editor-and-classic-widgets |
ClickSold IDX | clicksold-wordpress-plugin |
Common Tools for Site | common-tools-for-site |
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App | peepso-core |
Confetti Fall Animation | confetti-fall-animation |
Contact Form 7 Campaign Monitor Extension | contact-form-7-campaign-monitor-extension |
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | bit-form |
Contact Form to Any API | contact-form-to-any-api |
Crowdsignal Dashboard – Polls, Surveys & more | polldaddy |
CSS JS Files | css-js-files |
CubeWP Forms – All-in-One Form Builder | cubewp-forms |
Daily Prayer Time | daily-prayer-time-for-mosques |
Directory Listings WordPress plugin – uListing | ulisting |
Download Monitor | download-monitor |
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | easy-digital-downloads |
Easy Mega Menu Plugin for WordPress – ThemeHunk | themehunk-megamenu-plus |
Easy PayPal Events | easy-paypal-events-tickets |
Elementor Addons by Livemesh | addons-for-elementor |
ElementsKit Elementor addons | elementskit-lite |
ElementsReady Addons for Elementor | element-ready-lite |
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | email-subscribers |
EU/UK VAT Manager for WooCommerce | eu-vat-for-woocommerce |
Event Manager, Events Calendar, Tickets, Registrations – Eventin | wp-event-solution |
Fluent Support – Helpdesk & Customer Support Ticket System | fluent-support |
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | form-maker |
Garden Gnome Package | garden-gnome-package |
GEO my WP | geo-my-wp |
GF Custom Style | gf-custom-style |
GiveWP – Donation Plugin and Fundraising Platform | give |
Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) | graphicsly |
GTM Server Side | gtm-server-side |
Gum Elementor Addon | gum-elementor-addon |
GutenGeek Free Gutenberg Blocks for WordPress | gtg-advanced-blocks |
Happy Addons for Elementor | happy-elementor-addons |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
HUSKY – Products Filter Professional for WooCommerce | woocommerce-products-filter |
IdeaPush | ideapush |
Instant Chat Floating Button for WordPress Websites | instant-chat-wp |
JoomSport – for Sports: Team & League, Football, Hockey & more | joomsport-sports-league-results-management |
Joy Of Text Lite – SMS messaging for WordPress. | joy-of-text |
Jupiter X Core | jupiterx-core |
king_IE | king-ie |
Kodex Posts likes | kodex-posts-likes |
Koko Analytics | koko-analytics |
LiteSpeed Cache | litespeed-cache |
Loops & Logic | tangible-loops-and-logic |
Mail logging – WP Mail Catcher | wp-mail-catcher |
Mapplic Lite | mapplic-lite |
MAS Static Content | mas-static-content |
Material Design Icons | material-design-icons |
MDTF – Meta Data and Taxonomies Filter | wp-meta-data-filter-and-taxonomy-filter |
Medical Addon for Elementor | medical-addon-for-elementor |
Mega Elements – Addons for Elementor | mega-elements-addons-for-elementor |
Meta Slider and Carousel with Lightbox | meta-slider-and-carousel-with-lightbox |
MH Board | mh-board |
Move Addons for Elementor | move-addons |
Multi Step for Contact Form 7 | cf7-multi-step |
Multiple Page Generator Plugin – MPG | multiple-pages-generator-by-porthas |
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) | WordPress Plugin | bus-booking-manager |
myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification | mycred |
Newsletters | newsletters-lite |
NiceJob | nicejob |
Ninja Forms – The Contact Form Builder That Grows With You | ninja-forms |
OneElements – Best Elementor Addons | oneelements-ultimate-addons-for-elementor |
OSM – OpenStreetMap | osm |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery | photo-gallery |
Pixel Cat – Conversion Pixel Manager | facebook-conversion-pixel |
Podiant | podiant |
Polls CP | cp-polls |
Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin | mailoptin |
Post Grid and Gutenberg Blocks | post-grid |
Premium Addons for Elementor | premium-addons-for-elementor |
Premium Packages – Sell Digital Products Securely | wpdm-premium-packages |
Primary Addon for Elementor | primary-addon-for-elementor |
Prisna GWT – Google Website Translator | google-website-translator |
Product Enquiry for WooCommerce, WooCommerce product catalog | enquiry-quotation-for-woocommerce |
ProfileGrid – User Profiles, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
PWA for WP & AMP | pwa-for-wp |
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress | radio-player |
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit | wp-marketing-automations |
REST API TO MiniProgram | rest-api-to-miniprogram |
Restaurant & Cafe Addon for Elementor | restaurant-cafe-addon-for-elementor |
Review & testimonial widgets | trustmary |
Revolut Gateway for WooCommerce | revolut-gateway-for-woocommerce |
Salon Booking System | salon-booking-system |
Secure Copy Content Protection and Content Locking | secure-copy-content-protection |
Seriously Simple Stats | seriously-simple-stats |
Share This Image | share-this-image |
ShiftController Employee Shift Scheduling | shiftcontroller |
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | woolentor-addons |
Sight – Professional Image Gallery and Portfolio | sight |
Simple Calendar – Google Calendar Plugin | google-calendar-events |
Simple LDAP Login | simple-ldap-login |
Simple Popup Plugin | simple-popup-plugin |
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) | sky-elementor-addons |
Special Text Boxes | wp-special-textboxes |
Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. | wpgsi |
Starter Templates — Elementor, WordPress & Beaver Builder Templates | astra-sites |
Store Hours for WooCommerce | order-hours-scheduler-for-woocommerce |
Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
Super Testimonials | sola-testimonials |
Templately – Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud! | templately |
Terms descriptions | terms-descriptions |
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam | bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang |
The Events Calendar | the-events-calendar |
Themedy Toolbox | themedy-toolbox |
Themesflat Addons For Elementor | themesflat-addons-for-elementor |
Themify – WooCommerce Product Filter | themify-wc-product-filter |
Truepush – Most Affordable Web Push Notifications | truepush-free-web-push-notifications |
Uncanny Groups for LearnDash | uncanny-learndash-groups |
Use Any Font | Custom Font Uploader | use-any-font |
UsersControl – Users Profile, Free or Paid Subscriptions, User Access Restriction & Members Directory | users-control |
Vmax Project Manager | vmax-project-manager |
VR Calendar | vr-calendar-sync |
W3 Total Cache | w3-total-cache |
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | wc-frontend-manager |
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | coming-soon |
Wheel of Life: Coaching and Assessment Tool for Life Coach | wheel-of-life |
WooEvents – Calendar and Event Booking | woo-events |
WordPress Simple HTML Sitemap | wp-simple-html-sitemap |
WordPress Visitors | nm-visitors |
WP Abstracts | wp-abstracts-manuscripts-manager |
WP Category Dropdown | wp-category-dropdown |
WP Datepicker | wp-datepicker |
WP Easy Gallery – WordPress Gallery Plugin | wp-easy-gallery |
WP Free SSL – Free SSL Certificate for WordPress and force HTTPS | wp-free-ssl |
WP GPX Maps | wp-gpx-maps |
WP MultiTasking – WP Utilities | wp-multitasking |
WP Newsletter Subscription | wp-newsletter-subscription |
WP Ticket Ultra Help Desk & Support Plugin | wp-ticket-ultra |
WP Timeline – Vertical and Horizontal timeline plugin | wp-timelines |
WP Travel – Ultimate Travel Booking System, Tour Management Engine | wp-travel |
WP-DownloadManager | wp-downloadmanager |
WP-WebAuthn | wp-webauthn |
WPExperts Square For GiveWP | wpexperts-square-for-give |
WPSPX | wpspx |
WPZOOM Shortcodes | wpzoom-shortcodes |
WS Form LITE – Drag & Drop Contact Form Builder for WordPress | ws-form |
XT Ajax Add To Cart for WooCommerce | xt-woo-ajax-add-to-cart |
Zoho Flow for WordPress | zoho-flow |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Catch Base | catch-base |
Viala | viala |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 – Unauthenticated PHP Object Injection
Critical (10.0)
CVE-2024-8353
Patched
Sep 27, 2024
GiveWP – Donation Plugin and Fundraising Platform
Critical (9.9)
CVE-2024-8621
Patched
Sep 24, 2024
Daily Prayer Time
Critical (9.9)
CVE-2024-8624
Patched
Sep 23, 2024
MDTF – Meta Data and Taxonomies Filter
Critical (9.9)
CVE-2024-8436
Unpatched
Sep 23, 2024
WP Easy Gallery – WordPress Gallery Plugin
Critical (9.8)
CVE-2024-44023
Unpatched
Sep 24, 2024
ABC APP CREATOR
Critical (9.8)
CVE-2024-44019
Unpatched
Sep 24, 2024
Contact Form 7 Campaign Monitor Extension
Critical (9.8)
CVE-2024-8791
Patched
Sep 23, 2024
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
Instant Chat Floating Button for WordPress Websites <= 1.0.5 – Unauthenticated Local File Inclusion
Critical (9.8)
CVE-2024-44018
Unpatched
Sep 24, 2024
Instant Chat Floating Button for WordPress Websites
Critical (9.8)
CVE-2024-44017
Unpatched
Sep 24, 2024
MH Board
Critical (9.8)
CVE-2024-44016
Unpatched
Sep 24, 2024
Podiant
Critical (9.8)
CVE-2024-8485
Unpatched
Sep 24, 2024
REST API TO MiniProgram
Critical (9.8)
CVE-2024-8275
Patched
Sep 24, 2024
The Events Calendar
Critical (9.8)
CVE-2024-44015
Unpatched
Sep 24, 2024
UsersControl – Users Profile, Free or Paid Subscriptions, User Access Restriction & Members Directory
Critical (9.8)
CVE-2024-44014
Unpatched
Sep 24, 2024
Vmax Project Manager
Critical (9.8)
CVE-2024-44013
Unpatched
Sep 24, 2024
VR Calendar
Critical (9.8)
CVE-2024-44012
Unpatched
Sep 24, 2024
WP Newsletter Subscription
Critical (9.8)
CVE-2024-44011
Unpatched
Sep 24, 2024
WP Ticket Ultra Help Desk & Support Plugin
Critical (9.8)
CVE-2024-47323
Patched
Sep 25, 2024
WP Timeline – Vertical and Horizontal timeline plugin
Critical (9.8)
CVE-2024-44034
Unpatched
Sep 24, 2024
WPSPX
Critical (9.1)
CVE-2024-8514
Patched
Sep 24, 2024
Prisna GWT – Google Website Translator
Critical (9.1)
CVE-2024-8671
Patched
Sep 23, 2024
WooEvents – Calendar and Event Booking
Critical (9.1)
CVE-2024-7385
Patched
Sep 24, 2024
WordPress Simple HTML Sitemap
BA Book Everything <= 1.6.20 – Cross-Site Request Forgery to Email Address Update/Account Takeover
High (8.8)
CVE-2024-8795
Patched
Sep 23, 2024
BA Book Everything
High (8.8)
CVE-2024-7149
Patched
Sep 26, 2024
Event Manager, Events Calendar, Tickets, Registrations – Eventin
High (8.8)
CVE-2024-8922
Patched
Sep 26, 2024
Product Enquiry for WooCommerce, WooCommerce product catalog
High (8.8)
CVE-2024-8290
Patched
Sep 24, 2024
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
High (8.8)
CVE-2024-47324
Patched
Sep 25, 2024
WP Timeline – Vertical and Horizontal timeline plugin
High (8.1)
CVE-2024-7781
Patched
Sep 25, 2024
Jupiter X Core
High (7.5)
CVE-2024-8126
Patched
Sep 25, 2024
Advanced File Manager
High (7.5)
CVE-2024-47331
Patched
Sep 26, 2024
Multi Step for Contact Form 7
High (7.5)
CVE-2024-8484
Unpatched
Sep 24, 2024
REST API TO MiniProgram
MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 – Unauthenticated Arbitrary Shortcode Execution
High (7.3)
CVE-2024-8623
Patched
Sep 23, 2024
MDTF – Meta Data and Taxonomies Filter
High (7.3)
CVE-2024-8481
Unpatched
Sep 24, 2024
Special Text Boxes
High (7.2)
CVE-2024-8704
Patched
Sep 25, 2024
Advanced File Manager
Bit Form – Contact Form Plugin <= 2.13.10 – Authenticated (Administrator+) Arbitrary File Upload
High (7.2)
CVE-2024-47319
Patched
Sep 25, 2024
High (7.2)
CVE-2024-47301
Patched
Sep 24, 2024
High (7.2)
CVE-2024-44030
Patched
Sep 24, 2024
Checkout Mestres do WP for WooCommerce
Cities Shipping Zones for WooCommerce <= 1.2.7 – Authenticated (Shop Manager+) Local File Inclusion
High (7.2)
CVE-2024-47309
Patched
Sep 25, 2024
Cities Shipping Zones for WooCommerce
High (7.2)
CVE-2024-7617
Unpatched
Sep 24, 2024
Contact Form to Any API
High (7.2)
CVE-2024-47300
Patched
Sep 24, 2024
CubeWP Forms – All-in-One Form Builder
High (7.2)
CVE-2022-2439
Patched
Sep 23, 2024
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
High (7.2)
CVE-2024-9130
Patched
Sep 26, 2024
GiveWP – Donation Plugin and Fundraising Platform
High (7.2)
CVE-2024-8914
Unpatched
Sep 23, 2024
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam
High (7.2)
CVE-2024-8349
Patched
Sep 24, 2024
Uncanny Groups for LearnDash
High (7.2)
CVE-2022-4541
Unpatched
Sep 25, 2024
WordPress Visitors
Medium (6.8)
CVE-2024-8725
Patched
Sep 25, 2024
Advanced File Manager
Medium (6.5)
CVE-2024-47312
Patched
Sep 25, 2024
Classic Editor and Classic Widgets
Medium (6.5)
CVE-2024-47304
Patched
Sep 25, 2024
Fluent Support – Helpdesk & Customer Support Ticket System
Medium (6.5)
CVE-2024-47325
Patched
Sep 25, 2024
Multiple Page Generator Plugin – MPG
Medium (6.4)
CVE-2024-8723
Unpatched
Sep 25, 2024
012 Ps Multi Languages
Medium (6.4)
CVE-2024-8965
Patched
Sep 26, 2024
Absolute Reviews
Medium (6.4)
CVE-2024-47342
Patched
Sep 27, 2024
Accordion
Medium (6.4)
CVE-2024-8917
Patched
Sep 23, 2024
AnWP Football Leagues
Medium (6.4)
CVE-2024-47310
Patched
Sep 25, 2024
ARI Fancy Lightbox – Popup for WordPress
Medium (6.4)
CVE-2024-9049
Patched
Sep 26, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-47298
Patched
Sep 24, 2024
Bold Page Builder
Medium (6.4)
CVE-2024-47313
Patched
Sep 25, 2024
Catch Base
Medium (6.4)
CVE-2024-44026
Unpatched
Sep 24, 2024
Charity Addon for Elementor
Medium (6.4)
CVE-2024-9115
Unpatched
Sep 25, 2024
Common Tools for Site
Medium (6.4)
CVE-2024-8919
Unpatched
Sep 23, 2024
Confetti Fall Animation
Medium (6.4)
CVE-2024-8858
Patched
Sep 24, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-8546
Patched
Sep 24, 2024
ElementsKit Elementor addons
Medium (6.4)
CVE-2024-47329
Patched
Sep 25, 2024
ElementsReady Addons for Elementor
Medium (6.4)
CVE-2024-8657
Patched
Sep 23, 2024
Garden Gnome Package
GF Custom Style <= 2.0 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9173
Unpatched
Sep 25, 2024
GF Custom Style
Medium (6.4)
CVE-2024-9069
Unpatched
Sep 24, 2024
Medium (6.4)
CVE-2024-44027
Patched
Sep 24, 2024
Gum Elementor Addon
Medium (6.4)
CVE-2024-44035
Patched
Sep 23, 2024
Gum Elementor Addon
Medium (6.4)
CVE-2024-9073
Unpatched
Sep 24, 2024
GutenGeek Free Gutenberg Blocks for WordPress
Medium (6.4)
CVE-2024-9125
Unpatched
Sep 25, 2024
king_IE
Medium (6.4)
CVE-2024-9117
Unpatched
Sep 25, 2024
Mapplic Lite
Medium (6.4)
CVE-2024-9024
Unpatched
Sep 24, 2024
Material Design Icons
Medium (6.4)
CVE-2024-44024
Unpatched
Sep 24, 2024
Medical Addon for Elementor
Medium (6.4)
CVE-2024-47343
Patched
Sep 27, 2024
Mega Elements – Addons for Elementor
Medium (6.4)
CVE-2024-47307
Patched
Sep 25, 2024
Meta Slider and Carousel with Lightbox
Medium (6.4)
CVE-2024-47396
Patched
Sep 25, 2024
Move Addons for Elementor
Medium (6.4)
CVE-2024-44025
Patched
Sep 24, 2024
NiceJob
Medium (6.4)
CVE-2024-9068
Unpatched
Sep 24, 2024
OneElements – Best Elementor Addons
Medium (6.4)
CVE-2024-8991
Patched
Sep 26, 2024
OSM – OpenStreetMap
Post Grid and Gutenberg Blocks <= 2.2.89 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-47340
Patched
Sep 27, 2024
Post Grid and Gutenberg Blocks
Medium (6.4)
CVE-2024-8681
Patched
Sep 26, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-44033
Patched
Sep 24, 2024
Primary Addon for Elementor
Medium (6.4)
CVE-2024-8861
Patched
Sep 25, 2024
ProfileGrid – User Profiles, Groups and Communities
Medium (6.4)
CVE-2024-8267
Patched
Sep 23, 2024
Medium (6.4)
CVE-2024-44032
Patched
Sep 24, 2024
Restaurant & Cafe Addon for Elementor
Review & testimonial widgets <= 1.0.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-44022
Unpatched
Sep 24, 2024
Review & testimonial widgets
Medium (6.4)
CVE-2024-8668
Patched
Sep 24, 2024
Medium (6.4)
CVE-2024-8547
Unpatched
Sep 27, 2024
Simple Popup Plugin
Medium (6.4)
CVE-2024-47332
Patched
Sep 26, 2024
Medium (6.4)
CVE-2024-47345
Patched
Sep 27, 2024
Starter Templates — Elementor, WordPress & Beaver Builder Templates
Medium (6.4)
CVE-2024-9127
Unpatched
Sep 25, 2024
Super Testimonials
Medium (6.4)
CVE-2024-9177
Patched
Sep 26, 2024
Themedy Toolbox
Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-8515
Unpatched
Sep 24, 2024
Themesflat Addons For Elementor
Medium (6.4)
CVE-2024-8103
Unpatched
Sep 23, 2024
WP Category Dropdown
WP GPX Maps <= 1.7.08 – Authenticated (Contributor+) Stored Cross-Site Scripting via sgpx Shortcode
Medium (6.4)
CVE-2024-9028
Unpatched
Sep 24, 2024
WP GPX Maps
Medium (6.4)
CVE-2024-9023
Unpatched
Sep 27, 2024
WP-WebAuthn
Medium (6.4)
CVE-2024-9027
Unpatched
Sep 24, 2024
WPZOOM Shortcodes
Medium (6.3)
CVE-2024-6590
Unpatched
Sep 24, 2024
Medium (6.1)
CVE-2024-8741
Patched
Sep 24, 2024
Beam me up Scotty – Back to Top Button
Medium (6.1)
CVE-2024-8803
Patched
Sep 25, 2024
Bulk NoIndex & NoFollow Toolkit
Medium (6.1)
CVE-2024-47347
Patched
Sep 27, 2024
Chartify – WordPress Chart Plugin
Medium (6.1)
CVE-2024-47297
Patched
Sep 24, 2024
Medium (6.1)
CVE-2024-8788
Patched
Sep 27, 2024
EU/UK VAT Manager for WooCommerce
Medium (6.1)
CVE-2024-47327
Patched
Sep 25, 2024
GEO my WP
Medium (6.1)
CVE-2024-8712
Patched
Sep 27, 2024
GTM Server Side
Medium (6.1)
CVE-2024-8713
Unpatched
Sep 24, 2024
Kodex Posts likes
Medium (6.1)
CVE-2024-8662
Patched
Sep 23, 2024
Koko Analytics
Medium (6.1)
CVE-2024-47333
Patched
Sep 26, 2024
Loops & Logic
Medium (6.1)
CVE-2024-47346
Patched
Sep 27, 2024
Newsletters
Medium (6.1)
CVE-2024-44028
Patched
Sep 24, 2024
Medium (6.1)
CVE-2024-8544
Patched
Sep 23, 2024
Pixel Cat – Conversion Pixel Manager
Medium (6.1)
CVE-2024-47306
Patched
Sep 25, 2024
Secure Copy Content Protection and Content Locking
Medium (6.1)
CVE-2024-8738
Patched
Sep 23, 2024
Seriously Simple Stats
Medium (6.1)
CVE-2024-47326
Patched
Sep 25, 2024
Share This Image
Medium (6.1)
CVE-2024-8549
Patched
Sep 24, 2024
Simple Calendar – Google Calendar Plugin
Medium (6.1)
CVE-2024-8715
Patched
Sep 27, 2024
Simple LDAP Login
Medium (6.1)
CVE-2024-8872
Patched
Sep 25, 2024
Store Hours for WooCommerce
Medium (6.1)
CVE-2024-44029
Unpatched
Sep 24, 2024
Viala
Medium (6.1)
CVE-2024-47339
Patched
Sep 27, 2024
Mail logging – WP Mail Catcher
Medium (6.1)
CVE-2024-47322
Patched
Sep 25, 2024
WP Timeline – Vertical and Horizontal timeline plugin
Medium (6.1)
CVE-2024-47341
Patched
Sep 27, 2024
WP-DownloadManager
Medium (6.1)
CVE-2024-47320
Patched
Sep 25, 2024
WS Form LITE – Drag & Drop Contact Form Builder for WordPress
Medium (6.1)
CVE-2024-8716
Patched
Sep 23, 2024
XT Ajax Add To Cart for WooCommerce
Medium (5.5)
CVE-2024-8633
Patched
Sep 25, 2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Medium (5.5)
CVE-2024-9169
Patched
Sep 24, 2024
LiteSpeed Cache
Medium (5.4)
CVE-2024-8628
Patched
Sep 23, 2024
Medium (5.3)
CVE-2024-8794
Patched
Sep 23, 2024
BA Book Everything
Medium (5.3)
CVE-2024-7426
Patched
Sep 24, 2024
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App
Medium (5.3)
CVE-2024-9189
Patched
Sep 27, 2024
EU/UK VAT Manager for WooCommerce
Medium (5.3)
CVE-2024-47302
Patched
Sep 25, 2024
Fluent Support – Helpdesk & Customer Support Ticket System
Medium (5.3)
CVE-2024-7491
Patched
Sep 24, 2024
HUSKY – Products Filter Professional for WooCommerce
Medium (5.3)
CVE-2024-8658
Patched
Sep 24, 2024
Medium (5.3)
CVE-2024-8678
Patched
Sep 24, 2024
Revolut Gateway for WooCommerce
Medium (5.3)
CVE-2024-9025
Patched
Sep 25, 2024
Sight – Professional Image Gallery and Portfolio
Medium (5.3)
CVE-2024-44038
Patched
Sep 23, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (5.3)
CVE-2024-47308
Patched
Sep 25, 2024
Templately – Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud!
Medium (5.3)
CVE-2024-44021
Unpatched
Sep 24, 2024
Truepush – Most Affordable Web Push Notifications
Medium (5.3)
CVE-2024-47344
Patched
Sep 27, 2024
Directory Listings WordPress plugin – uListing
Medium (5.3)
CVE-2024-47311
Patched
Sep 25, 2024
Wheel of Life: Coaching and Assessment Tool for Life Coach
Medium (4.9)
CVE-2024-47328
Patched
Sep 25, 2024
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit
Medium (4.9)
CVE-2024-47335
Patched
Sep 26, 2024
Medium (4.9)
CVE-2024-9146
Patched
Sep 24, 2024
CSS JS Files
Medium (4.9)
CVE-2024-47338
Unpatched
Sep 26, 2024
WPExperts Square For GiveWP
Medium (4.9)
CVE-2024-47334
Patched
Sep 26, 2024
Zoho Flow for WordPress
Medium (4.7)
CVE-2024-3866
Patched
Sep 24, 2024
Ninja Forms – The Contact Form Builder That Grows With You
Medium (4.4)
CVE-2024-47299
Patched
Sep 24, 2024
Medium (4.4)
CVE-2024-44041
Patched
Sep 23, 2024
Medium (4.4)
CVE-2024-44036
Unpatched
Sep 23, 2024
Kodex Posts likes
Medium (4.4)
CVE-2024-44037
Unpatched
Sep 23, 2024
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) | WordPress Plugin
Medium (4.4)
CVE-2024-44043
Patched
Sep 23, 2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Medium (4.4)
CVE-2024-44040
Patched
Sep 23, 2024
ShiftController Employee Shift Scheduling
Medium (4.4)
CVE-2024-47336
Unpatched
Sep 26, 2024
Terms descriptions
Medium (4.4)
CVE-2024-44046
Patched
Sep 23, 2024
Themify – WooCommerce Product Filter
Medium (4.4)
CVE-2024-7769
Unpatched
Sep 24, 2024
ClickSold IDX
Medium (4.4)
CVE-2024-44045
Patched
Sep 23, 2024
WP Abstracts
Medium (4.4)
CVE-2024-44042
Patched
Sep 23, 2024
WP Datepicker
Medium (4.4)
CVE-2024-8189
Patched
Sep 27, 2024
WP MultiTasking – WP Utilities
Medium (4.4)
CVE-2024-44039
Patched
Sep 23, 2024
WP Travel – Ultimate Travel Booking System, Tour Management Engine
Medium (4.3)
CVE-2024-47317
Patched
Sep 25, 2024
Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads
Medium (4.3)
CVE-2024-8432
Patched
Sep 23, 2024
Appointment & Event Booking Calendar Plugin – Webba Booking
Medium (4.3)
CVE-2024-43338
Unpatched
Sep 24, 2024
Crowdsignal Dashboard – Polls, Surveys & more
Medium (4.3)
CVE-2024-8552
Patched
Sep 25, 2024
Download Monitor
Medium (4.3)
CVE-2024-8434
Patched
Sep 24, 2024
Easy Mega Menu Plugin for WordPress – ThemeHunk
Medium (4.3)
CVE-2024-8476
Patched
Sep 24, 2024
Easy PayPal Events
Medium (4.3)
CVE-2024-8771
Patched
Sep 25, 2024
Medium (4.3)
CVE-2024-47315
Patched
Sep 25, 2024
GiveWP – Donation Plugin and Fundraising Platform
Happy Addons for Elementor <= 3.12.2 – Authenticated (Contributor+) Sensitive Information Exposure
Medium (4.3)
CVE-2024-8801
Patched
Sep 23, 2024
Happy Addons for Elementor
Medium (4.3)
CVE-2024-8910
Patched
Sep 24, 2024
HT Mega – Absolute Addons For Elementor
Medium (4.3)
CVE-2024-44031
Patched
Sep 24, 2024
JoomSport – for Sports: Team & League, Football, Hockey & more
Medium (4.3)
CVE-2024-47337
Unpatched
Sep 26, 2024
Joy Of Text Lite – SMS messaging for WordPress.
MAS Static Content <= 1.0.8 – Authenticated (Contributor+) Private Static Content Page Disclosure
Medium (4.3)
CVE-2024-8483
Patched
Sep 24, 2024
MAS Static Content
Medium (4.3)
CVE-2024-7386
Patched
Sep 24, 2024
Premium Packages – Sell Digital Products Securely
Medium (4.3)
CVE-2024-47318
Patched
Sep 25, 2024
PWA for WP & AMP
Medium (4.3)
CVE-2024-47316
Patched
Sep 25, 2024
Salon Booking System
Medium (4.3)
CVE-2024-47314
Patched
Sep 25, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (4.3)
CVE-2024-8516
Unpatched
Sep 24, 2024
Themesflat Addons For Elementor
Medium (4.3)
CVE-2024-47305
Patched
Sep 25, 2024
Use Any Font | Custom Font Uploader
Medium (4.3)
CVE-2024-8437
Unpatched
Sep 23, 2024
WP Easy Gallery – WordPress Gallery Plugin
WP Free SSL – Free SSL Certificate for WordPress and force HTTPS <= 1.2.6 – Missing Authorization
Medium (4.3)
CVE-2024-44020
Unpatched
Sep 24, 2024
WP Free SSL – Free SSL Certificate for WordPress and force HTTPS
Low (3.7)
CVE-2023-5359
Patched
Sep 23, 2024
W3 Total Cache
Low (2.7)
CVE-2024-8350
Patched
Sep 24, 2024
Uncanny Groups for LearnDash
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (September 23, 2024 to September 29, 2024) appeared first on Wordfence.