Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- Top-tier researchers earn automatic bonuses of between 10% to 120% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 161 vulnerabilities disclosed in 147 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 19,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 122 |
Unpatched | 39 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 141 |
High Severity | 15 |
Critical Severity | 5 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 121 |
Missing Authorization | 9 |
Deserialization of Untrusted Data | 5 |
Cross-Site Request Forgery (CSRF) | 4 |
Unrestricted Upload of File with Dangerous Type | 4 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 3 |
Authentication Bypass Using an Alternate Path or Channel | 2 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 2 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 2 |
Improper Neutralization of Alternate XSS Syntax | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
Improper Privilege Management | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
22 | |
21 | |
12 | |
8 | |
6 | |
6 | |
5 | |
5 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
123.chat – Video Chat | 123-chat-videochat |
Advanced Woo Labels – Product Labels for WooCommerce | advanced-woo-labels |
Affiliate Program Suite — SliceWP Affiliates | slicewp |
Aggregator Advanced Settings | aggregator-advanced-settings |
Author Avatars List/Block | author-avatars |
Auto Amazon Links – Amazon Associates Affiliate Plugin | amazon-auto-links |
Auto Featured Image from Title | auto-featured-image-from-title |
Automatically Hierarchic Categories in Menu | automatically-hierarchic-categories-in-menu |
AVIF Uploader | avif-support |
BA Book Everything | ba-book-everything |
BerqWP – Automated All-In-One PageSpeed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | searchpro |
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress | file-manager |
Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed | blockspare |
Bold Page Builder | bold-page-builder |
Broken Link Checker | broken-link-checker |
BSK Forms Blacklist | bsk-gravityforms-blacklist |
CartBounty – Save and recover abandoned carts for WooCommerce | woo-save-abandoned-carts |
Checkout Field Editor (Checkout Manager) for WooCommerce | woo-checkout-field-editor-pro |
Clio Grow | clio-grow-form |
Code Embed | simple-embed-code |
Confetti Fall Animation | confetti-fall-animation |
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | fluentform |
Copyscape Premium | copyscape-premium |
Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library | cozy-addons |
Custom Banners | custom-banners |
Demo Importer Plus | demo-importer-plus |
DethemeKit For Elementor | dethemekit-for-elementor |
Display Medium Posts | display-medium-posts |
DK PDF | dk-pdf |
Easy Demo Importer – A Modern One-Click Demo Import Solution | easy-demo-importer |
Easy Load More | easy-load-more |
Easy WordPress Subscribe – Optin Hound | opt-in-hound |
Echo RSS Feed Post Generator | rss-feed-post-generator-echo |
Elastik Page Builder | elastik-page-builder |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
ElementsReady Addons for Elementor | element-ready-lite |
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | email-subscribers |
Enter Addons – Ultimate Template Builder for Elementor | enteraddons |
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | essential-blocks |
EventPrime – Events Calendar, Bookings and Tickets | eventprime-event-calendar-management |
FAQ / Accordion / Docs – Helpie WordPress FAQ Accordion plugin | helpie-faq |
Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate | fish-and-ships |
Form plugin for WordPress – Zoho Forms | zoho-forms |
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials | stars-testimonials-with-slider-and-masonry-grid |
Gallery Lightbox | gallery-lightbox-slider |
Geo Mashup | geo-mashup |
Gravity Forms Toolbar | gravity-forms-toolbar |
Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg | guten-post-layout |
Happy Addons for Elementor | happy-elementor-addons |
Hash Form – Drag & Drop Form Builder | hash-form |
Hello World | hello-world |
Ibtana – WordPress Website Builder | ibtana-visual-editor |
Iconize | iconize |
Include Fussball.de Widgets | include-fussball-de-widgets |
Jeg Elementor Kit | jeg-elementor-kit |
JobSearch WP Job Board | wp-jobsearch |
KB Support – WordPress Help Desk and Knowledge Base | kb-support |
Keap Official Opt-in Forms | infusionsoft-official-opt-in-forms |
LA-Studio Element Kit for Elementor | lastudio-element-kit |
LH Copy Media File | lh-copy-media-file |
LiteSpeed Cache | litespeed-cache |
LocateAndFilter | locateandfilter |
Loggedin – Limit Active Logins | loggedin |
Login Logout Shortcode | login-logout-shortcode |
Logo Carousel – Clients logo carousel for WP | responsive-client-logo-carousel-slider |
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | magazine-blocks |
MaxSlider | maxslider |
MC4WP: Mailchimp Top Bar | mailchimp-top-bar |
Memberful – Membership Plugin | memberful-wp |
Move Addons for Elementor | move-addons |
NEX-Forms – Ultimate Form Builder – Contact forms and much more | nex-forms-express-wp-form-builder |
Online Booking & Scheduling Calendar for WordPress by vcita | meeting-scheduler-by-vcita |
Page-list | page-list |
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | paid-member-subscriptions |
Payflex Payment Gateway | payflex-payment-gateway |
PDF Image Generator | pdf-image-generator |
Popularis Extra | popularis-extra |
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder | popup-maker |
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | buddyforms |
Premium Blocks – Gutenberg Blocks for WordPress | premium-blocks-for-gutenberg |
Product Delivery Date for WooCommerce – Lite | product-delivery-date-for-woocommerce-lite |
PWA — easy way to Progressive Web App | iworks-pwa |
QS Dark Mode Plugin | qs-dark-mode |
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce | wholesale-pricing-woocommerce |
Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress | quillforms |
R Animated Icon Plugin | r-animated-icon |
RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more | rabbit-loader |
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | seo-by-rank-math |
Re:WP | rewp |
Relogo | relogo |
Robokassa payment gateway for Woocommerce | robokassa |
RomethemeKit For Elementor | rometheme-for-elementor |
RumbleTalk Live Group Chat – HTML5 | rumbletalk-chat-a-chat-with-themes |
Search Analytics for WP | search-analytics |
Search Atlas SEO – Best SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | metasync |
SEOPress – On-site SEO | wp-seopress |
ShiftController Employee Shift Scheduling | shiftcontroller |
Shortcodes and extra features for Phlox theme | auxin-elements |
Simple Membership After Login Redirection | simple-membership-after-login-redirection |
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel | depicter |
Slider Revolution | revslider |
Slideshow Gallery LITE | slideshow-gallery |
Smart Custom 404 Error Page | 404page |
Social Auto Poster | social-auto-poster |
Social Web Suite – Social Media Auto Post, Social Media Auto Publish | social-web-suite |
Soumettre.fr | soumettre-fr |
Spice Starter Sites | spice-starter-sites |
Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More | woocommerce-exporter |
Strong Testimonials | strong-testimonials |
SVG Complete | svg-complete |
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) | the-pack-addon |
The Ultimate WordPress Toolkit – WP Extended | wpextended |
Themify Builder | themify-builder |
TinyPNG – JPEG, PNG & WebP image compression | tiny-compress-images |
TNC PDF viewer | pdf-viewer-by-themencode |
Top Bar – PopUps – by WPOptin | wpoptin |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | ultimate-member |
Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider | ultimate-store-kit |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | unlimited-elements-for-elementor |
VdoCipher: Secure Video Player and Hosting | vdocipher |
Visual CSS Style Editor | yellow-pencil-visual-theme-customizer |
Web Directory Free | web-directory-free |
Wechat Social login 微信QQ钉钉登录插件 | wechat-social-login |
WordPress & WooCommerce Affiliate Program | wp-wc-affiliate-program |
WordPress Captcha Plugin by Captcha Bank | captcha-bank |
WordPress Infinite Scroll – Ajax Load More | ajax-load-more |
WP Blocks Hub | wp-blocks-hub |
WP Booking Calendar | booking |
WP Bulk Delete | wp-bulk-delete |
WP Cleanup and Basic Functions | wp-cleanup-and-basic-functions |
WP Compress – Instant Performance & Speed Optimization | wp-compress-image-optimizer |
WP Easy Gallery – WordPress Gallery Plugin | wp-easy-gallery |
WP Hotel Booking | wp-hotel-booking |
WP MyLinks | wp-mylinks |
WP Travel Gutenberg Blocks | wp-travel-blocks |
WP-Lister Lite for eBay | wp-lister-for-ebay |
WP-WebAuthn | wp-webauthn |
WPCOM Member | wpcom-member |
WPMobile.App — Android and iOS Mobile Application | wpappninja |
XLTab – Accordions and Tabs for Elementor Page Builder | xl-tab |
XO Slider | xo-liteslider |
YITH WooCommerce Ajax Search | yith-woocommerce-ajax-search |
YITH WooCommerce Product Add-Ons | yith-woocommerce-product-add-ons |
YML for Yandex Market | yml-for-yandex-market |
Zotpress | zotpress |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Create | create |
Empowerment | empowerment |
Full Frame | full-frame |
UltraPress | ultrapress |
Unseen Blog | unseen-blog |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-9265
Patched
Sep 30, 2024
Echo RSS Feed Post Generator
Critical (9.8)
CVE-2024-47636
Patched
Sep 30, 2024
JobSearch WP Job Board
Critical (9.8)
CVE-2024-9106
Unpatched
Sep 30, 2024
Wechat Social login 微信QQ钉钉登录插件
Critical (9.8)
CVE-2024-9108
Unpatched
Sep 30, 2024
Wechat Social login 微信QQ钉钉登录插件
Critical (9.8)
CVE-2024-9289
Patched
Sep 30, 2024
WordPress & WooCommerce Affiliate Program
High (8.8)
CVE-2024-7433
Unpatched
Sep 30, 2024
Empowerment
High (8.8)
CVE-2024-47351
Patched
Sep 30, 2024
MaxSlider
High (8.8)
CVE-2024-7434
Unpatched
Sep 30, 2024
UltraPress
High (8.8)
CVE-2024-7432
Unpatched
Sep 30, 2024
Unseen Blog
High (8.8)
CVE-2024-9018
Unpatched
Sep 30, 2024
WP Easy Gallery – WordPress Gallery Plugin
High (8.8)
CVE-2024-7855
Patched
Oct 1, 2024
WP Hotel Booking
High (8.1)
CVE-2024-8548
Unpatched
Sep 30, 2024
KB Support – WordPress Help Desk and Knowledge Base
High (8.1)
CVE-2024-47645
Patched
Sep 30, 2024
Top Bar – PopUps – by WPOptin
High (7.5)
CVE-2024-8352
Patched
Oct 2, 2024
Social Web Suite – Social Media Auto Post, Social Media Auto Publish
High (7.5)
CVE-2024-47350
Patched
Sep 30, 2024
YITH WooCommerce Ajax Search
High (7.2)
CVE-2024-7869
Unpatched
Sep 30, 2024
123.chat – Video Chat
High (7.2)
CVE-2024-47649
Unpatched
Sep 30, 2024
High (7.2)
CVE-2024-47374
Patched
Sep 30, 2024
LiteSpeed Cache
High (7.2)
CVE-2024-9314
Patched
Oct 4, 2024
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
High (7.1)
CVE-2024-8981
Patched
Sep 30, 2024
Broken Link Checker
Medium (6.8)
CVE-2024-8743
Patched
Oct 4, 2024
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress
Medium (6.5)
CVE-2024-9224
Patched
Sep 30, 2024
Hello World
Medium (6.5)
CVE-2024-8632
Unpatched
Sep 30, 2024
KB Support – WordPress Help Desk and Knowledge Base
Medium (6.5)
CVE-2024-9161
Patched
Oct 4, 2024
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
Medium (6.4)
CVE-2024-47622
Patched
Sep 30, 2024
Advanced Woo Labels – Product Labels for WooCommerce
Medium (6.4)
CVE-2024-9368
Unpatched
Oct 3, 2024
Aggregator Advanced Settings
Medium (6.4)
CVE-2024-47370
Patched
Sep 30, 2024
Author Avatars List/Block
Medium (6.4)
CVE-2024-47365
Patched
Sep 30, 2024
Automatically Hierarchic Categories in Menu
Medium (6.4)
CVE-2024-9060
Patched
Sep 30, 2024
AVIF Uploader
Medium (6.4)
CVE-2024-47363
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-47391
Patched
Sep 30, 2024
Bold Page Builder
Medium (6.4)
CVE-2024-8804
Patched
Oct 3, 2024
Code Embed
Medium (6.4)
CVE-2024-47641
Unpatched
Sep 30, 2024
Confetti Fall Animation
Medium (6.4)
CVE-2024-47355
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-47356
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-9172
Patched
Oct 1, 2024
Demo Importer Plus
Medium (6.4)
CVE-2024-47632
Patched
Sep 30, 2024
DethemeKit For Elementor
Medium (6.4)
CVE-2024-9445
Unpatched
Oct 3, 2024
Display Medium Posts
Medium (6.4)
CVE-2024-9071
Patched
Oct 3, 2024
Easy Demo Importer – A Modern One-Click Demo Import Solution
Medium (6.4)
CVE-2024-9274
Unpatched
Sep 30, 2024
Elastik Page Builder
Element Pack Elementor Addons <= 5.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-47392
Patched
Sep 30, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (6.4)
CVE-2024-47630
Patched
Sep 30, 2024
ElementInvader Addons for Elementor
Medium (6.4)
CVE-2024-47366
Patched
Sep 30, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-47625
Patched
Sep 30, 2024
Enter Addons – Ultimate Template Builder for Elementor
Essential Blocks for Gutenberg <= 4.8.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-47385
Patched
Sep 30, 2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
Medium (6.4)
CVE-2024-44010
Patched
Sep 30, 2024
Full Frame
Medium (6.4)
CVE-2024-47623
Patched
Sep 30, 2024
Gallery Lightbox
Medium (6.4)
CVE-2024-8990
Patched
Sep 30, 2024
Geo Mashup
Medium (6.4)
CVE-2024-8288
Unpatched
Sep 30, 2024
Medium (6.4)
CVE-2024-47357
Patched
Sep 30, 2024
Happy Addons for Elementor
Medium (6.4)
CVE-2024-8282
Patched
Oct 1, 2024
Ibtana – WordPress Website Builder
Medium (6.4)
CVE-2024-47643
Unpatched
Sep 30, 2024
Include Fussball.de Widgets
Medium (6.4)
CVE-2024-47390
Patched
Sep 30, 2024
Jeg Elementor Kit
Medium (6.4)
CVE-2024-47642
Unpatched
Sep 30, 2024
Keap Official Opt-in Forms
Medium (6.4)
CVE-2024-47628
Patched
Sep 30, 2024
LA-Studio Element Kit for Elementor
Medium (6.4)
CVE-2024-47373
Patched
Sep 30, 2024
LiteSpeed Cache
LocateAndFilter <= 1.6.14 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9304
Unpatched
Sep 30, 2024
LocateAndFilter
Medium (6.4)
CVE-2024-9421
Unpatched
Oct 3, 2024
Login Logout Shortcode
Medium (6.4)
CVE-2024-47631
Patched
Sep 30, 2024
Logo Carousel – Clients logo carousel for WP
Memberful – Membership Plugin <= 1.73.7 – Authenticated (contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-9242
Patched
Oct 3, 2024
Memberful – Membership Plugin
Medium (6.4)
CVE-2024-47364
Patched
Sep 30, 2024
Move Addons for Elementor
Medium (6.4)
CVE-2024-47382
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-47368
Patched
Sep 30, 2024
Premium Blocks – Gutenberg Blocks for WordPress
Medium (6.4)
CVE-2024-8967
Patched
Oct 1, 2024
PWA — easy way to Progressive Web App
QS Dark Mode Plugin <= 2.9 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9118
Patched
Sep 30, 2024
QS Dark Mode Plugin
Medium (6.4)
CVE-2024-47393
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-9272
Unpatched
Sep 30, 2024
R Animated Icon Plugin
Medium (6.4)
CVE-2024-9271
Patched
Oct 3, 2024
Re:WP
Medium (6.4)
CVE-2024-9269
Unpatched
Sep 30, 2024
Relogo
Medium (6.4)
CVE-2024-47626
Patched
Sep 30, 2024
RomethemeKit For Elementor
Medium (6.4)
CVE-2024-8720
Patched
Sep 30, 2024
RumbleTalk Live Group Chat – HTML5
Medium (6.4)
CVE-2024-8486
Patched
Oct 4, 2024
Shortcodes and extra features for Phlox theme
Medium (6.4)
CVE-2024-8107
Patched
Sep 30, 2024
Slider Revolution
Medium (6.4)
CVE-2024-8989
Patched
Sep 30, 2024
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials
Medium (6.4)
CVE-2024-9119
Unpatched
Sep 30, 2024
SVG Complete
Medium (6.4)
CVE-2024-47383
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-8519
Patched
Oct 3, 2024
Medium (6.4)
CVE-2024-47629
Patched
Sep 30, 2024
Medium (6.4)
CVE-2024-47639
Unpatched
Sep 30, 2024
VdoCipher: Secure Video Player and Hosting
Medium (6.4)
CVE-2024-8505
Patched
Oct 1, 2024
WordPress Infinite Scroll – Ajax Load More
WP Blocks Hub <= 1.0.2 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9372
Unpatched
Oct 3, 2024
WP Blocks Hub
Medium (6.4)
CVE-2024-9455
Unpatched
Oct 4, 2024
WP Cleanup and Basic Functions
Medium (6.4)
CVE-2024-47627
Patched
Sep 30, 2024
WP Travel Gutenberg Blocks
Medium (6.4)
CVE-2024-47650
Patched
Sep 30, 2024
WP-WebAuthn
Medium (6.4)
CVE-2024-47375
Patched
Sep 30, 2024
XLTab – Accordions and Tabs for Elementor Page Builder
Medium (6.4)
CVE-2024-8324
Unpatched
Sep 30, 2024
XO Slider
Medium (6.4)
CVE-2024-47633
Patched
Sep 30, 2024
Form plugin for WordPress – Zoho Forms
Medium (6.4)
CVE-2024-47621
Patched
Sep 30, 2024
Zotpress
Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.2 – Reflected Cross-Site Scripting
Medium (6.1)
CVE-2024-9349
Patched
Oct 3, 2024
Auto Amazon Links – Amazon Associates Affiliate Plugin
Medium (6.1)
CVE-2024-8786
Unpatched
Sep 30, 2024
Auto Featured Image from Title
Medium (6.1)
CVE-2024-47360
Patched
Sep 30, 2024
BA Book Everything
Medium (6.1)
CVE-2024-9344
Patched
Oct 1, 2024
BerqWP – Automated All-In-One PageSpeed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
Medium (6.1)
CVE-2024-47624
Patched
Sep 30, 2024
BSK Forms Blacklist
Medium (6.1)
CVE-2024-8802
Unpatched
Oct 3, 2024
Medium (6.1)
CVE-2024-47644
Unpatched
Sep 30, 2024
Copyscape Premium
Medium (6.1)
CVE-2024-8799
Unpatched
Sep 30, 2024
Custom Banners
Medium (6.1)
CVE-2024-8727
Patched
Sep 30, 2024
Medium (6.1)
CVE-2024-8728
Unpatched
Sep 30, 2024
Easy Load More
Medium (6.1)
CVE-2024-9267
Unpatched
Sep 30, 2024
Easy WordPress Subscribe – Optin Hound
Medium (6.1)
CVE-2024-47353
Patched
Sep 30, 2024
ElementsReady Addons for Elementor
Medium (6.1)
CVE-2024-47648
Patched
Sep 30, 2024
EventPrime – Events Calendar, Bookings and Tickets
Medium (6.1)
CVE-2024-9237
Patched
Oct 3, 2024
Medium (6.1)
CVE-2024-8718
Unpatched
Sep 30, 2024
Gravity Forms Toolbar
Medium (6.1)
CVE-2024-9417
Patched
Oct 4, 2024
Hash Form – Drag & Drop Form Builder
Medium (6.1)
CVE-2024-47394
Patched
Sep 30, 2024
JobSearch WP Job Board
Medium (6.1)
CVE-2024-9220
Patched
Sep 30, 2024
LH Copy Media File
Medium (6.1)
CVE-2024-9228
Patched
Sep 30, 2024
Loggedin – Limit Active Logins
Medium (6.1)
CVE-2024-9218
Patched
Oct 1, 2024
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid
Medium (6.1)
CVE-2024-9210
Patched
Oct 1, 2024
MC4WP: Mailchimp Top Bar
Medium (6.1)
CVE-2024-47389
Patched
Sep 30, 2024
NEX-Forms – Ultimate Form Builder – Contact forms and much more
Medium (6.1)
CVE-2024-47638
Unpatched
Sep 30, 2024
Online Booking & Scheduling Calendar for WordPress by vcita
Medium (6.1)
CVE-2024-9222
Patched
Oct 1, 2024
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
Medium (6.1)
CVE-2024-47646
Unpatched
Sep 30, 2024
Payflex Payment Gateway
Medium (6.1)
CVE-2024-9241
Unpatched
Sep 30, 2024
PDF Image Generator
Medium (6.1)
CVE-2024-9353
Patched
Oct 3, 2024
Popularis Extra
Medium (6.1)
CVE-2024-9345
Patched
Oct 3, 2024
Product Delivery Date for WooCommerce – Lite
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 – Reflected Cross-Site Scripting
Medium (6.1)
CVE-2024-9384
Patched
Oct 3, 2024
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce
Medium (6.1)
CVE-2024-8800
Patched
Oct 1, 2024
Medium (6.1)
CVE-2024-47395
Patched
Sep 30, 2024
Robokassa payment gateway for Woocommerce
Medium (6.1)
CVE-2024-9225
Patched
Oct 1, 2024
SEOPress – On-site SEO
Medium (6.1)
CVE-2024-9435
Patched
Oct 3, 2024
ShiftController Employee Shift Scheduling
Medium (6.1)
CVE-2024-47354
Patched
Sep 30, 2024
Simple Membership After Login Redirection
Medium (6.1)
CVE-2024-47388
Patched
Sep 30, 2024
Affiliate Program Suite — SliceWP Affiliates
Medium (6.1)
CVE-2024-9204
Patched
Oct 3, 2024
Smart Custom 404 Error Page
Medium (6.1)
CVE-2024-47369
Patched
Sep 30, 2024
Social Auto Poster
Medium (6.1)
CVE-2024-8793
Unpatched
Sep 30, 2024
Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More
Medium (6.1)
CVE-2024-47386
Patched
Sep 30, 2024
The Ultimate WordPress Toolkit – WP Extended
Medium (6.1)
CVE-2024-9385
Patched
Oct 4, 2024
Themify Builder
Medium (6.1)
CVE-2024-45454
Patched
Sep 30, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (6.1)
CVE-2024-47379
Patched
Sep 30, 2024
Web Directory Free
Medium (6.1)
CVE-2024-9375
Unpatched
Oct 3, 2024
WordPress Captcha Plugin by Captcha Bank
Medium (6.1)
CVE-2024-47352
Patched
Sep 30, 2024
WP Bulk Delete
Medium (6.1)
CVE-2024-47384
Patched
Sep 30, 2024
WP Compress – Instant Performance & Speed Optimization
Medium (6.1)
CVE-2024-9209
Patched
Sep 30, 2024
Search Analytics for WP
Medium (6.1)
CVE-2024-47380
Patched
Sep 30, 2024
WP-Lister Lite for eBay
Medium (6.1)
CVE-2024-47378
Patched
Sep 30, 2024
WPCOM Member
Medium (6.1)
CVE-2024-47349
Patched
Sep 30, 2024
WPMobile.App — Android and iOS Mobile Application
Medium (6.1)
CVE-2024-47348
Patched
Sep 30, 2024
Visual CSS Style Editor
Medium (6.1)
CVE-2024-47367
Patched
Sep 30, 2024
YITH WooCommerce Product Add-Ons
Medium (6.1)
CVE-2024-9378
Patched
Oct 1, 2024
YML for Yandex Market
Medium (5.4)
CVE-2024-8254
Patched
Oct 1, 2024
Medium (5.3)
CVE-2024-47359
Patched
Sep 30, 2024
Medium (5.3)
CVE-2024-47358
Patched
Sep 30, 2024
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
Medium (5.3)
CVE-2024-8430
Unpatched
Sep 30, 2024
Spice Starter Sites
Medium (5.3)
CVE-2024-8520
Patched
Oct 3, 2024
Medium (4.9)
CVE-2024-9528
Patched
Oct 4, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
Medium (4.7)
CVE-2024-8499
Patched
Oct 3, 2024
Checkout Field Editor (Checkout Manager) for WooCommerce
Medium (4.4)
CVE-2024-47647
Patched
Sep 30, 2024
FAQ / Accordion / Docs – Helpie WordPress FAQ Accordion plugin
Medium (4.4)
CVE-2024-47377
Patched
Sep 30, 2024
Medium (4.4)
CVE-2024-47381
Patched
Sep 30, 2024
Medium (4.4)
CVE-2024-47387
Patched
Sep 30, 2024
Search Atlas SEO – Best SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
Medium (4.4)
CVE-2024-47376
Patched
Sep 30, 2024
Slideshow Gallery LITE
Medium (4.4)
CVE-2024-47372
Patched
Sep 30, 2024
TNC PDF viewer
Medium (4.4)
CVE-2024-9306
Patched
Oct 3, 2024
WP Booking Calendar
Medium (4.4)
CVE-2024-47371
Patched
Sep 30, 2024
WP MyLinks
CartBounty – Save and recover abandoned carts for WooCommerce <= 8.2 – Cross-Site Request Forgery
Medium (4.3)
CVE-2024-47634
Patched
Sep 30, 2024
CartBounty – Save and recover abandoned carts for WooCommerce
Medium (4.3)
CVE-2024-47361
Patched
Sep 30, 2024
Elementor Addon Elements
Medium (4.3)
CVE-2024-47637
Patched
Sep 30, 2024
LiteSpeed Cache
Medium (4.3)
CVE-2024-8675
Patched
Sep 30, 2024
Soumettre.fr
Medium (4.3)
CVE-2024-47362
Patched
Sep 30, 2024
Strong Testimonials
Medium (4.3)
CVE-2024-47635
Patched
Sep 30, 2024
TinyPNG – JPEG, PNG & WebP image compression
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (September 30, 2024 to October 6, 2024) appeared first on Wordfence.