Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- Top-tier researchers earn automatic bonuses of between 10% to 120% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 234 vulnerabilities disclosed in 206 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 56 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 19,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-757 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-758 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 133 |
Unpatched | 101 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 165 |
High Severity | 35 |
Critical Severity | 34 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 116 |
Missing Authorization | 37 |
Unrestricted Upload of File with Dangerous Type | 18 |
Authentication Bypass Using an Alternate Path or Channel | 13 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 9 |
Cross-Site Request Forgery (CSRF) | 8 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 7 |
Exposure of Sensitive Information to an Unauthorized Actor | 6 |
Improper Control of Generation of Code (‘Code Injection’) | 5 |
Deserialization of Untrusted Data | 3 |
Improper Authentication | 2 |
Improper Authorization | 2 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 2 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Improper Restriction of XML External Entity Reference | 1 |
Incorrect Privilege Assignment | 1 |
Weak Password Recovery Mechanism for Forgotten Password | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
25 | |
23 | |
22 | |
22 | |
13 | |
10 | |
8 | |
8 | |
7 | |
7 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
1-Click Login: Passwordless Authentication | swoop-password-free-authentication |
10Web Social Post Feed | wd-facebook-feed |
3D Work In Progress | renee-work-in-progress |
Accept Stripe Donation and Payments – AidWP | wp-stripe-donation |
ACL Floating Cart for WooCommerce | acl-floating-cart-for-woocommerce |
Acnoo Flutter API | acnoo-flutter-api |
aDirectory – Directory Listing WordPress Plugin | adirectory |
Ads.txt & App-ads.txt Manager for WordPress | app-ads-txt |
Advanced Online Ordering and Delivery Platform | advanced-online-ordering-and-delivery-platform |
Advanced Sermons | advanced-sermons |
Affiliate Platform | smdp-affiliate-platform |
AffiliateX – Affiliate Blocks for WordPress, Amazon, eBay, AliExpress Affiliates | affiliatex |
Agile Video Player Lite | agile-video-player |
AI Image Generator for Your Content & Featured Images – AI Postpix | ai-postpix |
Ajar in5 Embed | ajar-productions-in5-embed |
All-in-One WP Migration and Backup | all-in-one-wp-migration |
Amilia Store | amilia-store |
AMP for WP – Accelerated Mobile Pages | accelerated-mobile-pages |
Anchor Episodes Index (Spotify for Podcasters) | anchor-episodes-index |
App Builder – Create Native Android & iOS Apps On The Flight | app-builder |
AR For WordPress | ar-for-wordpress |
Astra Widgets | astra-widgets |
Auto Login using a secure tokenized url. Role wise login restriction. | token-login |
Automatic Translation | automatic-translation |
Awesome buttons | wp-awesome-buttons |
Backup and Staging by WP Time Capsule | wp-time-capsule |
Bamazoo – Button Generator | bamazoo-button-generator |
Banner Slider | banner-slider |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Beek Widget Extention | beek-widget-extention |
Bet WC 2018 Russia | bet-wc-2018-russia |
Bold Page Builder | bold-page-builder |
Booking Plugin for Your WordPress Appointments – Time Slot | timeslot |
BP Member Type Manager | bp-member-type-manager |
Breeze – WordPress Cache Plugin | breeze |
Bstone Demo Importer | bstone-demo-importer |
BuddyPress | buddypress |
BuddyPress Greeting Message | bp-greeting-message |
Call / Contact Button | button-contact-vr |
Campus Explorer Widget | campus-explorer-widget |
Category and Taxonomy Image | wp-custom-taxonomy-image |
Category and Taxonomy Meta Fields | wp-custom-taxonomy-meta |
chatplusjp | chatplusjp |
Church Admin | church-admin |
Clever Addons for Elementor | cafe-lite |
Client Power Tools Portal | client-power-tools |
Code Generate | code-generator |
CodePen Embedded Pens Shortcode | codepen-embedded-pen-shortcode |
Comments – wpDiscuz | wpdiscuz |
Compact WP Audio Player | compact-wp-audio-player |
Conditional Fields for Contact Form 7 | cf7-conditional-fields |
Contact Form 7 + Telegram | cf7-telegram |
Contact Form 7 – Repeatable Fields | cf7-repeatable-fields |
Coub | coub |
Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library | cozy-addons |
Custom Icons for Elementor | custom-icons-for-elementor |
Custom Twitter Feeds – A Tweets Widget or X Feed Widget | custom-twitter-feeds |
CWD 3D Image Gallery | cwd-3d-image-gallery |
DarkMySite – Advanced Dark Mode Plugin for WordPress | darkmysite |
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer | 3d-flipbook-dflip-lite |
DocumentPress | documentpress-display-any-document-on-your-site |
Download Monitor | download-monitor |
Download Plugin | download-plugin |
Editor Custom Color Palette | editor-custom-color-palette |
Editorial Assistant by Sovrn | zemanta |
EKC Tournament Manager | ekc-tournament-manager |
ElementsKit Elementor addons | elementskit-lite |
EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor | embedpress |
Envo’s Elementor Templates & Widgets for WooCommerce | envo-elementor-for-woocommerce |
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | mage-eventpress |
EventPrime – Events Calendar, Bookings and Tickets | eventprime-event-calendar-management |
Exam Matrix | exam-matrix |
Extensions by HocWP Team | sb-core |
Extra Privacy for Elementor | extra-privacy-for-elementor |
Extra Product Options Builder for WooCommerce | additional-product-fields-for-woocommerce |
File Upload Types by WPForms | file-upload-types |
Firelight Lightbox | easy-fancybox |
FormFacade – WordPress plugin for Google Forms | formfacade |
Forminator Forms – Contact Form, Payment Form & Custom Form Builder | forminator |
Forms for Mailchimp by Optin Cat – Grow Your MailChimp List | mailchimp-wp |
Futurio Extra | futurio-extra |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | geodirectory |
Google Docs RSVP, WordPress Plugin | google-docs-rsvp-guestlist |
Great Restaurant Menu WP | best-restaurant-menu-by-pricelisto |
Greenshift – animation and page builder blocks | greenshift-animation-and-page-builder-blocks |
GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! | spendino |
HD Quiz – Save Results Light | hd-quiz-save-results-light |
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce | hurrytimer |
ID-SK Toolkit | idsk-toolkit |
Image Map Pro – Drag-and-drop Builder for Interactive Images | image-map-pro |
Import and export users and customers | import-users-from-csv-with-meta |
INK Official | ink-official |
Interactive World Map | interactive-world-map |
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates | kata-plus |
Kodex Posts likes | kodex-posts-likes |
Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages | landing-page-cat |
LaTeX2HTML | latex2html |
League of Legends Shortcodes | league-of-legends-shortcodes |
leenk.me | leenkme |
Local Business Addons For Elementor (Formally Waze Map) | map-addons-for-elementor-waze-map |
MaanStore API | maanstore-api |
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | magazine-blocks |
Mapster WP Maps | mapster-wp-maps |
Marketing Automation by AZEXO | marketing-automation-by-azexo |
MDTF – Meta Data and Taxonomies Filter | wp-meta-data-filter-and-taxonomy-filter |
Meetup | meetup |
Mega Elements – Addons for Elementor | mega-elements-addons-for-elementor |
Monitor.chat – Monitor WordPress with Instant Messages | monitor-chat |
Monkee-Boy Essentials | monkee-boy-wp-essentials |
Multi Purpose Mail Form | multi-purpose-mail-form |
Multi Step Form | multi-step-form |
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | dc-woocommerce-multi-vendor |
My Wp Brand – Hide menu & Hide Plugin | my-wp-brand |
myCred Elementor | mycred-for-elementor |
Namaste! LMS | namaste-lms |
News Kit Elementor Addons | news-kit-elementor-addons |
Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates | the-plus-addons-for-block-editor |
Order Notification for Telegram | order-notification-for-telegram |
PDF Generator Addon for Elementor Page Builder | pdf-generator-addon-for-elementor-page-builder |
PDF Invoices & Packing Slips for WooCommerce | woocommerce-pdf-invoices-packing-slips |
PegaPoll | pegapoll |
Photo Gallery, Images, Slider in Rbs Image Gallery | robo-gallery |
Plugin Name: iBryl Switch User | ibryl-switch-user |
Plugin Propagator | wp-propagator |
Poll Maker – Versus Polls, Anonymous Polls, Image Polls | poll-maker |
Portfolleo | portfolleo |
Post Grid and Gutenberg Blocks | post-grid |
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | ultimate-post |
Premium SEO Pack – WP SEO Plugin | premium-seo-pack |
PriPre | pripre |
Product Filter by WBW | woo-product-filter |
ProfilePress Pro | profilepress-pro |
Qi Addons For Elementor | qi-addons-for-elementor |
Qi Blocks | qi-blocks |
Qode Essential Addons | qode-essential-addons |
Raptor Editor | wp-raptor |
Realty Workstation | realty-workstation |
Risk Warning Bar | risk-warning-bar |
Rover IDX | rover-idx |
Royal Elementor Addons and Templates | royal-elementor-addons |
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | wp-rss-aggregator |
RSVP ME | rsvp-me |
Schema & Structured Data for WP & AMP | schema-and-structured-data-for-wp |
School Management System – WPSchoolPress | wpschoolpress |
Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin | scrollbar-by-webxapp |
Selection Lite | selection-lite |
SEOPress – On-site SEO | wp-seopress |
Shoutcast Icecast HTML5 Radio Player | shoutcast-icecast-html5-radio-player |
Signup Page | signup-page |
Simple Custom Admin | simple-custom-admin |
Simple Load More | simple-load-more |
Simple Membership | simple-membership |
Simple News | simple-news |
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) | sky-elementor-addons |
Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder | stacks-mobile-app-builder |
Sudan Payment Gateway for WooCommerce | wc-sudan-payment-gateway |
Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
Survey Maker | survey-maker |
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | surveyjs |
SVG Captcha | svg-captcha |
Templately – Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud! | templately |
TeploBot – Telegram Bot for WP | green-wp-telegram-bot-by-teplitsa |
Terms descriptions | terms-descriptions |
Textboxes | textboxes |
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) | the-pack-addon |
Themes4WP YouTube External Subtitles | themes4wp-youtube-external-subtitles |
Tida URL Screenshot | tida-url-screenshot |
Todo Custom Field | todo-custom-field |
Transients Manager | transients-manager |
Trip Plan | tripplan |
uCAT – Next Story | ucat-next-story |
Uix Shortcodes – Compatible with Gutenberg | uix-shortcodes |
User Toolkit | user-toolkit |
Verbalize WP | verbalize-wp |
WatchTowerHQ | watchtowerhq |
Web Bricks Addons for Elementor: Elite-Designed Elementor & eCommerce Widgets | webbricks-addons |
Whitelist | fifthsegment-whitelist |
WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) – Smart Manager | smart-manager-for-wp-e-commerce |
Woocommerce Custom Profile Picture | woo-custom-profile-picture |
WooCommerce Maintenance Mode (Free) | woocommerce-maintenance-mode |
WooCommerce Order Proposal | wooCommerce-order-proposal |
Woocommerce Product Design | woo-product-design |
Woocommerce Quote Calculator | woo-quote-calculator-order |
WooCommerce UPS Shipping – Live Rates and Access Points | flexible-shipping-ups |
WordPress eCommerce – ScottCart | scottcart |
WordPress Post Grid Layouts with Pagination – Sogrid | sogrid |
WP Abstracts | wp-abstracts-manuscripts-manager |
WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer | adminify |
WP Awesome Login | wp-awesome-login |
WP Booking System – Booking Calendar | wp-booking-system |
WP Crowdfunding | wp-crowdfunding |
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | erp |
WP Flow Plus | wp-imageflow2 |
WP Query Console | wp-query-console |
WP Recipe Maker | wp-recipe-maker |
WP Sessions Time Monitoring Full Automatic | activitytime |
WP Shortcodes Plugin — Shortcodes Ultimate | shortcodes-ultimate |
WP show more | wp-show-more |
Wp Social Login and Register Social Counter | wp-social |
WP VR – 360 Panorama and Virtual Tour Builder For WordPress | wpvr |
WP-Members Membership Plugin | wp-members |
WPC Shop as a Customer for WooCommerce | wpc-shop-as-customer |
WPKoi Templates for Elementor | wpkoi-templates-for-elementor |
WPS Telegram Chat | wps-telegram-chat |
Wux Blog Editor | wux-blog-editor |
YITH WooCommerce Product Add-Ons | yith-woocommerce-product-add-ons |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Clean Retina | clean-retina |
Js Paper | js-paper |
Mags | mags |
Meta News | meta-news |
NewsCard | newscard |
Nioland – SaaS & Software Startup Tech WordPress Theme | nioland |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-50478
Unpatched
Oct 25, 2024
1-Click Login: Passwordless Authentication
Critical (9.8)
CVE-2024-50486
Unpatched
Oct 25, 2024
Acnoo Flutter API
Critical (9.8)
CVE-2024-50420
Patched
Oct 24, 2024
aDirectory – Directory Listing WordPress Plugin
Critical (9.8)
CVE-2024-50497
Unpatched
Oct 25, 2024
Advanced Online Ordering and Delivery Platform
Critical (9.8)
CVE-2024-50473
Unpatched
Oct 25, 2024
Ajar in5 Embed
Critical (9.8)
CVE-2024-50496
Unpatched
Oct 25, 2024
AR For WordPress
Critical (9.8)
CVE-2024-50493
Unpatched
Oct 25, 2024
Automatic Translation
Critical (9.8)
CVE-2024-50436
Patched
Oct 24, 2024
Clean Retina
Critical (9.8)
CVE-2024-9488
Patched
Oct 24, 2024
Comments – wpDiscuz
Critical (9.8)
CVE-2024-50485
Unpatched
Oct 25, 2024
Exam Matrix
Critical (9.8)
CVE-2024-9930
Unpatched
Oct 25, 2024
Extensions by HocWP Team
Critical (9.8)
CVE-2024-50476
Unpatched
Oct 25, 2024
GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit!
Critical (9.8)
CVE-2024-50487
Unpatched
Oct 25, 2024
MaanStore API
Critical (9.8)
CVE-2024-49701
Patched
Oct 21, 2024
Mags
Critical (9.8)
CVE-2024-50483
Unpatched
Oct 25, 2024
Critical (9.8)
CVE-2024-50435
Patched
Oct 24, 2024
Meta News
Critical (9.8)
CVE-2024-50484
Unpatched
Oct 25, 2024
Multi Purpose Mail Form
Critical (9.8)
CVE-2024-50434
Patched
Oct 24, 2024
NewsCard
Critical (9.8)
CVE-2024-50490
Unpatched
Oct 25, 2024
Critical (9.8)
CVE-2024-50495
Unpatched
Oct 25, 2024
Plugin Propagator
Critical (9.8)
CVE-2024-49653
Unpatched
Oct 21, 2024
Portfolleo
Critical (9.8)
CVE-2024-50489
Unpatched
Oct 25, 2024
Realty Workstation
Critical (9.8)
CVE-2024-50492
Unpatched
Oct 25, 2024
WordPress eCommerce – ScottCart
Critical (9.8)
CVE-2024-50475
Unpatched
Oct 25, 2024
Signup Page
Critical (9.8)
CVE-2024-50477
Unpatched
Oct 25, 2024
Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder
Critical (9.8)
CVE-2024-50494
Unpatched
Oct 25, 2024
Sudan Payment Gateway for WooCommerce
Critical (9.8)
CVE-2024-49668
Unpatched
Oct 21, 2024
Verbalize WP
WatchTowerHQ <= 3.10.1 – Authentication Bypass to Administrator due to Missing Empty Value Check
Critical (9.8)
CVE-2024-9933
Patched
Oct 25, 2024
WatchTowerHQ
Critical (9.8)
CVE-2024-49658
Unpatched
Oct 21, 2024
Woocommerce Custom Profile Picture
Critical (9.8)
CVE-2024-50482
Unpatched
Oct 25, 2024
Woocommerce Product Design
Critical (9.8)
CVE-2024-50498
Unpatched
Oct 25, 2024
WP Query Console
Critical (9.8)
CVE-2024-9501
Patched
Oct 25, 2024
Wp Social Login and Register Social Counter
Critical (9.8)
CVE-2024-9931
Unpatched
Oct 25, 2024
Wux Blog Editor
Critical (9.8)
CVE-2024-9932
Unpatched
Oct 25, 2024
Wux Blog Editor
High (8.8)
CVE-2024-49657
Unpatched
Oct 21, 2024
3D Work In Progress
High (8.8)
CVE-2024-49652
Unpatched
Oct 21, 2024
3D Work In Progress
High (8.8)
CVE-2024-49671
Unpatched
Oct 21, 2024
AI Image Generator for Your Content & Featured Images – AI Postpix
High (8.8)
CVE-2024-9598
Patched
Oct 24, 2024
AMP for WP – Accelerated Mobile Pages
High (8.8)
CVE-2024-50481
Unpatched
Oct 25, 2024
Bstone Demo Importer
High (8.8)
CVE-2024-49674
Unpatched
Oct 21, 2024
EKC Tournament Manager
iBryl Switch User <= 1.0.1 – Authenticated (Subscriber+) Privilege Escalation via Account Takeover
High (8.8)
CVE-2024-49675
Unpatched
Oct 21, 2024
Plugin Name: iBryl Switch User
High (8.8)
CVE-2024-49669
Unpatched
Oct 21, 2024
INK Official
High (8.8)
CVE-2024-9235
Patched
Oct 24, 2024
Mapster WP Maps
High (8.8)
CVE-2024-50480
Unpatched
Oct 25, 2024
Marketing Automation by AZEXO
High (8.8)
CVE-2024-50408
Patched
Oct 24, 2024
Namaste! LMS
High (8.8)
CVE-2024-49690
Patched
Oct 21, 2024
Qi Blocks
High (8.8)
CVE-2024-50457
Patched
Oct 24, 2024
Qode Essential Addons
High (8.8)
CVE-2024-10002
Patched
Oct 21, 2024
Rover IDX
High (8.8)
CVE-2024-9637
Patched
Oct 25, 2024
School Management System – WPSchoolPress
High (8.8)
CVE-2024-50427
Patched
Oct 24, 2024
SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity
High (8.8)
CVE-2024-50453
Patched
Oct 24, 2024
High (8.8)
CVE-2024-50488
Unpatched
Oct 25, 2024
Auto Login using a secure tokenized url. Role wise login restriction.
High (8.8)
CVE-2024-9890
Patched
Oct 25, 2024
User Toolkit
WPC Shop as a Customer for WooCommerce <= 1.2.6 – Authenticated (Subscriber+) PHP Object Injection
High (8.8)
CVE-2024-50416
Patched
Oct 24, 2024
WPC Shop as a Customer for WooCommerce
High (8.6)
CVE-2024-9627
Unpatched
Oct 21, 2024
TeploBot – Telegram Bot for WP
High (8.1)
CVE-2024-9302
Patched
Oct 24, 2024
App Builder – Create Native Android & iOS Apps On The Flight
High (8.1)
CVE-2024-10011
Patched
Oct 24, 2024
BuddyPress
High (8.1)
CVE-2024-9947
Patched
Oct 22, 2024
ProfilePress Pro
High (7.5)
CVE-2024-10402
Patched
Oct 25, 2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
High (7.5)
CVE-2024-50491
Unpatched
Oct 25, 2024
RSVP ME
High (7.5)
CVE-2024-50479
Unpatched
Oct 25, 2024
Woocommerce Quote Calculator
High (7.5)
CVE-2024-49681
Patched
Oct 21, 2024
WP Sessions Time Monitoring Full Automatic
Uix Shortcodes – Compatible with Gutenberg <= 1.9.9 – Unauthenticated Arbitrary Shortcode Execution
High (7.3)
CVE-2024-9772
Unpatched
Oct 25, 2024
Uix Shortcodes – Compatible with Gutenberg
High (7.3)
CVE-2024-50450
Patched
Oct 24, 2024
MDTF – Meta Data and Taxonomies Filter
High (7.2)
CVE-2024-9162
Patched
Oct 27, 2024
All-in-One WP Migration and Backup
High (7.2)
CVE-2024-49684
Patched
Oct 21, 2024
Backup and Staging by WP Time Capsule
High (7.2)
CVE-2024-49676
Patched
Oct 21, 2024
Custom Icons for Elementor
High (7.2)
CVE-2024-9927
Patched
Oct 22, 2024
WooCommerce Order Proposal
High (7.2)
CVE-2024-8392
Patched
Oct 25, 2024
WordPress Post Grid Layouts with Pagination – Sogrid
Medium (6.5)
CVE-2024-9829
Patched
Oct 22, 2024
Download Plugin
League of Legends Shortcodes <= 1.0.1 – Authenticated (Contributor+) SQL Injection via Shortcode
Medium (6.5)
CVE-2024-10341
Unpatched
Oct 24, 2024
League of Legends Shortcodes
Medium (6.5)
CVE-2024-50465
Patched
Oct 24, 2024
Premium SEO Pack – WP SEO Plugin
Medium (6.5)
CVE-2024-9650
Patched
Oct 23, 2024
WP Recipe Maker
Medium (6.4)
CVE-2024-50458
Patched
Oct 24, 2024
Advanced Sermons
Medium (6.4)
CVE-2024-49692
Patched
Oct 21, 2024
Medium (6.4)
CVE-2024-50472
Unpatched
Oct 24, 2024
Amilia Store
Medium (6.4)
CVE-2024-10189
Patched
Oct 21, 2024
Anchor Episodes Index (Spotify for Podcasters)
Medium (6.4)
CVE-2024-50439
Patched
Oct 24, 2024
Astra Widgets
Awesome buttons <= 1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via btn2 Shortcode
Medium (6.4)
CVE-2024-10148
Unpatched
Oct 24, 2024
Awesome buttons
Medium (6.4)
CVE-2024-10150
Unpatched
Oct 24, 2024
Bamazoo – Button Generator
Medium (6.4)
CVE-2024-50430
Patched
Oct 24, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-10343
Unpatched
Oct 24, 2024
Beek Widget Extention
CodePen Embedded Pens Shortcode <= 1.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-50440
Patched
Oct 24, 2024
CodePen Embedded Pens Shortcode
Medium (6.4)
CVE-2024-10176
Patched
Oct 23, 2024
Compact WP Audio Player
Medium (6.4)
CVE-2024-10180
Patched
Oct 23, 2024
Contact Form 7 – Repeatable Fields
Medium (6.4)
CVE-2024-49659
Unpatched
Oct 21, 2024
Medium (6.4)
CVE-2024-50441
Patched
Oct 24, 2024
Medium (6.4)
CVE-2024-50502
Patched
Oct 25, 2024
Medium (6.4)
CVE-2024-9642
Unpatched
Oct 25, 2024
Editor Custom Color Palette
Medium (6.4)
CVE-2024-10091
Patched
Oct 25, 2024
ElementsKit Elementor addons
Medium (6.4)
CVE-2024-50461
Patched
Oct 24, 2024
Medium (6.4)
CVE-2024-50447
Patched
Oct 24, 2024
Envo’s Elementor Templates & Widgets for WooCommerce
Event Manager for WooCommerce <= 4.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-49703
Patched
Oct 21, 2024
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin
Medium (6.4)
CVE-2024-10016
Patched
Oct 24, 2024
File Upload Types by WPForms
Medium (6.4)
CVE-2024-50460
Patched
Oct 24, 2024
Firelight Lightbox
Medium (6.4)
CVE-2024-50446
Patched
Oct 24, 2024
Futurio Extra
Medium (6.4)
CVE-2024-50437
Patched
Oct 24, 2024
ID-SK Toolkit <= 1.7.2 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9853
Unpatched
Oct 25, 2024
ID-SK Toolkit
Medium (6.4)
CVE-2024-9585
Patched
Oct 24, 2024
Image Map Pro – Drag-and-drop Builder for Interactive Images
Medium (6.4)
CVE-2024-50462
Patched
Oct 24, 2024
Interactive World Map
Medium (6.4)
CVE-2024-50501
Patched
Oct 25, 2024
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates
Medium (6.4)
CVE-2024-50464
Unpatched
Oct 24, 2024
Kodex Posts likes
Medium (6.4)
CVE-2024-10342
Unpatched
Oct 24, 2024
League of Legends Shortcodes
Medium (6.4)
CVE-2024-49667
Unpatched
Oct 21, 2024
Local Business Addons For Elementor (Formally Waze Map)
Medium (6.4)
CVE-2024-50429
Patched
Oct 24, 2024
Medium (6.4)
CVE-2024-49693
Patched
Oct 21, 2024
Mega Elements – Addons for Elementor
Medium (6.4)
CVE-2024-9116
Unpatched
Oct 25, 2024
Monkee-Boy Essentials
Medium (6.4)
CVE-2024-49702
Patched
Oct 21, 2024
myCred Elementor
Medium (6.4)
CVE-2024-50409
Patched
Oct 24, 2024
Namaste! LMS
Medium (6.4)
CVE-2024-50410
Patched
Oct 24, 2024
Namaste! LMS
Medium (6.4)
CVE-2024-50452
Patched
Oct 24, 2024
Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates
Medium (6.4)
CVE-2024-50449
Patched
Oct 24, 2024
PDF Generator Addon for Elementor Page Builder
Post Grid and Gutenberg Blocks <= 2.2.93 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-50432
Patched
Oct 24, 2024
Post Grid and Gutenberg Blocks
Medium (6.4)
CVE-2024-50443
Patched
Oct 24, 2024
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX
Medium (6.4)
CVE-2024-9454
Unpatched
Oct 25, 2024
PriPre
Medium (6.4)
CVE-2024-50468
Unpatched
Oct 24, 2024
Raptor Editor
Medium (6.4)
CVE-2024-49696
Patched
Oct 21, 2024
Photo Gallery, Images, Slider in Rbs Image Gallery
Medium (6.4)
CVE-2024-50467
Unpatched
Oct 24, 2024
Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin
Medium (6.4)
CVE-2024-50445
Patched
Oct 24, 2024
Selection Lite
Medium (6.4)
CVE-2024-8666
Unpatched
Oct 24, 2024
Shoutcast Icecast HTML5 Radio Player
Simple News <= 2.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via news Shortcode
Medium (6.4)
CVE-2024-10112
Unpatched
Oct 24, 2024
Simple News
Medium (6.4)
CVE-2024-50433
Patched
Oct 24, 2024
Medium (6.4)
CVE-2024-50469
Unpatched
Oct 24, 2024
Medium (6.4)
CVE-2024-50470
Unpatched
Oct 24, 2024
Themes4WP YouTube External Subtitles
Medium (6.4)
CVE-2024-50418
Patched
Oct 24, 2024
Booking Plugin for Your WordPress Appointments – Time Slot
Medium (6.4)
CVE-2024-50471
Unpatched
Oct 24, 2024
Web Bricks Addons for Elementor <= 1.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-49665
Unpatched
Oct 21, 2024
Medium (6.4)
CVE-2024-50451
Patched
Oct 24, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (6.4)
CVE-2024-8959
Patched
Oct 23, 2024
WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer
WP Awesome Login <= 0.4.0 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9456
Unpatched
Oct 25, 2024
WP Awesome Login
Medium (6.4)
CVE-2024-10117
Patched
Oct 25, 2024
WP Crowdfunding
Medium (6.4)
CVE-2024-49695
Patched
Oct 21, 2024
WP Flow Plus
Medium (6.4)
CVE-2024-9967
Unpatched
Oct 25, 2024
WP show more
Medium (6.4)
CVE-2024-10374
Patched
Oct 24, 2024
WP-Members Membership Plugin
WPKoi Templates for Elementor <= 3.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-49679
Patched
Oct 21, 2024
WPKoi Templates for Elementor
Medium (6.3)
CVE-2024-9943
Patched
Oct 23, 2024
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution
Rover IDX <= 3.0.0.2903 – Authenticated (Subscriber+) Missing Authorization via Multiple Functions
Medium (6.3)
CVE-2024-10003
Patched
Oct 21, 2024
Rover IDX
Medium (6.3)
CVE-2024-50424
Patched
Oct 24, 2024
Templately – Elementor & Gutenberg Template Library: 5000+ Free & Pro Ready Templates & Cloud!
WPS Telegram Chat <= 4.6.0 – Authenticated (Subscriber+) Unauthorized Access to Telegram Bot API
Medium (6.3)
CVE-2024-9628
Unpatched
Oct 24, 2024
WPS Telegram Chat
Medium (6.1)
CVE-2024-9607
Unpatched
Oct 24, 2024
10Web Social Post Feed
Medium (6.1)
CVE-2024-49640
Unpatched
Oct 21, 2024
ACL Floating Cart for WooCommerce
Medium (6.1)
CVE-2024-49645
Unpatched
Oct 21, 2024
Affiliate Platform
Medium (6.1)
CVE-2024-49636
Unpatched
Oct 21, 2024
Agile Video Player Lite
Medium (6.1)
CVE-2024-49635
Unpatched
Oct 21, 2024
Banner Slider
Medium (6.1)
CVE-2024-49637
Unpatched
Oct 21, 2024
Bet WC 2018 Russia
Medium (6.1)
CVE-2024-49634
Unpatched
Oct 21, 2024
BP Member Type Manager
Medium (6.1)
CVE-2024-49650
Unpatched
Oct 21, 2024
BuddyPress Greeting Message
Medium (6.1)
CVE-2024-49660
Unpatched
Oct 21, 2024
Campus Explorer Widget
Medium (6.1)
CVE-2024-49664
Unpatched
Oct 21, 2024
chatplusjp
Medium (6.1)
CVE-2024-50438
Patched
Oct 24, 2024
Church Admin
Medium (6.1)
CVE-2024-49670
Patched
Oct 21, 2024
Client Power Tools Portal
Medium (6.1)
CVE-2024-49646
Unpatched
Oct 21, 2024
Code Generate
Medium (6.1)
CVE-2024-49632
Unpatched
Oct 21, 2024
CWD 3D Image Gallery
Medium (6.1)
CVE-2024-49656
Unpatched
Oct 21, 2024
DocumentPress
Medium (6.1)
CVE-2024-9864
Patched
Oct 23, 2024
EventPrime – Events Calendar, Bookings and Tickets
Medium (6.1)
CVE-2024-9865
Patched
Oct 23, 2024
EventPrime – Events Calendar, Bookings and Tickets
Medium (6.1)
CVE-2024-49654
Unpatched
Oct 21, 2024
Extra Privacy for Elementor
Medium (6.1)
CVE-2024-9214
Patched
Oct 23, 2024
Extra Product Options Builder for WooCommerce
Medium (6.1)
CVE-2024-9613
Unpatched
Oct 25, 2024
FormFacade – WordPress plugin for Google Forms
Medium (6.1)
CVE-2024-8870
Unpatched
Oct 25, 2024
Forms for Mailchimp by Optin Cat – Grow Your MailChimp List
Medium (6.1)
CVE-2024-49672
Unpatched
Oct 21, 2024
Google Docs RSVP, WordPress Plugin
Medium (6.1)
CVE-2024-49678
Unpatched
Oct 21, 2024
Js Paper
Medium (6.1)
CVE-2024-49673
Patched
Oct 21, 2024
LaTeX2HTML
Medium (6.1)
CVE-2024-49661
Unpatched
Oct 21, 2024
leenk.me
Medium (6.1)
CVE-2024-49639
Unpatched
Oct 21, 2024
Monitor.chat – Monitor WordPress with Instant Messages
Medium (6.1)
CVE-2024-50407
Patched
Oct 24, 2024
Namaste! LMS
Medium (6.1)
CVE-2024-10250
Patched
Oct 22, 2024
Nioland – SaaS & Software Startup Tech WordPress Theme
Medium (6.1)
CVE-2024-8717
Patched
Oct 23, 2024
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
Medium (6.1)
CVE-2024-49638
Unpatched
Oct 21, 2024
Risk Warning Bar
Medium (6.1)
CVE-2024-49647
Unpatched
Oct 21, 2024
Simple Custom Admin
Medium (6.1)
CVE-2024-49662
Unpatched
Oct 21, 2024
Simple Load More
Medium (6.1)
CVE-2024-49682
Patched
Oct 21, 2024
Simple Membership
Medium (6.1)
CVE-2024-50463
Patched
Oct 24, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (6.1)
CVE-2024-49648
Unpatched
Oct 21, 2024
SVG Captcha
Medium (6.1)
CVE-2024-9374
Patched
Oct 23, 2024
Terms descriptions
Medium (6.1)
CVE-2024-49641
Unpatched
Oct 21, 2024
Tida URL Screenshot
Medium (6.1)
CVE-2024-49642
Unpatched
Oct 21, 2024
Todo Custom Field
Medium (6.1)
CVE-2024-49663
Unpatched
Oct 21, 2024
uCAT – Next Story
Medium (6.1)
CVE-2024-49643
Unpatched
Oct 21, 2024
Medium (6.1)
CVE-2024-49651
Unpatched
Oct 21, 2024
WooCommerce Maintenance Mode (Free)
Medium (6.1)
CVE-2024-47640
Patched
Oct 21, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
Medium (6.1)
CVE-2024-9231
Patched
Oct 21, 2024
WP-Members Membership Plugin
Medium (6.1)
CVE-2024-50448
Patched
Oct 24, 2024
YITH WooCommerce Product Add-Ons
Medium (5.5)
CVE-2024-50415
Patched
Oct 24, 2024
Ads.txt & App-ads.txt Manager for WordPress
Medium (5.5)
CVE-2024-50414
Patched
Oct 24, 2024
Call / Contact Button
Medium (5.5)
CVE-2024-9591
Unpatched
Oct 21, 2024
Category and Taxonomy Image
Medium (5.5)
CVE-2024-9589
Unpatched
Oct 21, 2024
Category and Taxonomy Meta Fields
Category and Taxonomy Meta Fields <= 1.0.0 – Authenticated (Editor+) Stored Cross-Site Scripting
Medium (5.5)
CVE-2024-9590
Unpatched
Oct 21, 2024
Category and Taxonomy Meta Fields
Medium (5.5)
CVE-2024-9462
Patched
Oct 25, 2024
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
Category and Taxonomy Meta Fields <= 1.0.0 – Cross-Site Request Forgery to Taxonomy Meta Add/Delete
Medium (5.4)
CVE-2024-9588
Unpatched
Oct 21, 2024
Category and Taxonomy Meta Fields
Medium (5.4)
CVE-2024-9629
Patched
Oct 27, 2024
Contact Form 7 + Telegram
Medium (5.4)
CVE-2024-9584
Patched
Oct 24, 2024
Image Map Pro – Drag-and-drop Builder for Interactive Images
Medium (5.4)
CVE-2024-50442
Patched
Oct 24, 2024
Royal Elementor Addons and Templates
Medium (5.4)
CVE-2024-8500
Patched
Oct 22, 2024
WP Shortcodes Plugin — Shortcodes Ultimate
Medium (5.4)
CVE-2024-9630
Unpatched
Oct 24, 2024
WPS Telegram Chat
All-in-One WP Migration and Backup <= 7.86 – Unauthenticated Information Disclosure via Error Logs
Medium (5.3)
CVE-2024-8852
Patched
Oct 21, 2024
All-in-One WP Migration and Backup
Medium (5.3)
CVE-2024-50422
Patched
Oct 24, 2024
Breeze – WordPress Cache Plugin
Medium (5.3)
CVE-2024-50419
Patched
Oct 24, 2024
Greenshift – animation and page builder blocks
Medium (5.3)
CVE-2024-50428
Patched
Oct 24, 2024
Multi Step Form
Medium (5.3)
CVE-2024-49694
Patched
Oct 21, 2024
My Wp Brand – Hide menu & Hide Plugin
Medium (5.3)
CVE-2024-9686
Unpatched
Oct 24, 2024
Order Notification for Telegram
Medium (5.3)
CVE-2024-49683
Patched
Oct 21, 2024
Schema & Structured Data for WP & AMP
Medium (5.3)
CVE-2024-50454
Patched
Oct 24, 2024
SEOPress – On-site SEO
Medium (5.3)
CVE-2024-50421
Patched
Oct 24, 2024
PDF Invoices & Packing Slips for WooCommerce
Medium (5.3)
CVE-2024-50459
Patched
Oct 24, 2024
Accept Stripe Donation and Payments – AidWP
Medium (4.9)
CVE-2024-9475
Patched
Oct 25, 2024
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
Medium (4.9)
CVE-2024-49691
Patched
Oct 21, 2024
Product Filter by WBW
Medium (4.4)
CVE-2024-50431
Patched
Oct 24, 2024
Breeze – WordPress Cache Plugin
Medium (4.4)
CVE-2024-50412
Patched
Oct 24, 2024
Conditional Fields for Contact Form 7
Medium (4.4)
CVE-2024-50413
Patched
Oct 24, 2024
Import and export users and customers
Medium (4.4)
CVE-2024-50426
Patched
Oct 24, 2024
Survey Maker
Medium (4.4)
CVE-2024-50411
Patched
Oct 24, 2024
WP Abstracts
Medium (4.3)
CVE-2024-49698
Patched
Oct 21, 2024
Great Restaurant Menu WP
Medium (4.3)
CVE-2024-50417
Patched
Oct 24, 2024
Bold Page Builder
Medium (4.3)
CVE-2024-10357
Unpatched
Oct 25, 2024
Clever Addons for Elementor
Medium (4.3)
CVE-2024-49685
Patched
Oct 21, 2024
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
Medium (4.3)
CVE-2024-50466
Unpatched
Oct 24, 2024
DarkMySite – Advanced Dark Mode Plugin for WordPress
Medium (4.3)
CVE-2024-10092
Patched
Oct 25, 2024
Download Monitor
Medium (4.3)
CVE-2024-9626
Unpatched
Oct 25, 2024
Editorial Assistant by Sovrn
Medium (4.3)
CVE-2024-49689
Patched
Oct 21, 2024
HD Quiz – Save Results Light
Medium (4.3)
CVE-2024-8667
Patched
Oct 23, 2024
Medium (4.3)
CVE-2024-49686
Patched
Oct 21, 2024
Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages
Medium (4.3)
CVE-2024-9531
Patched
Oct 23, 2024
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution
Medium (4.3)
CVE-2024-9541
Patched
Oct 21, 2024
News Kit Elementor Addons
Medium (4.3)
CVE-2024-9530
Patched
Oct 22, 2024
Qi Addons For Elementor
Medium (4.3)
CVE-2024-9583
Patched
Oct 22, 2024
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
Medium (4.3)
CVE-2024-50455
Patched
Oct 24, 2024
SEOPress – On-site SEO
Medium (4.3)
CVE-2024-50456
Patched
Oct 24, 2024
SEOPress – On-site SEO
Medium (4.3)
CVE-2024-49687
Patched
Oct 21, 2024
WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) – Smart Manager
Medium (4.3)
CVE-2024-49697
Patched
Oct 21, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (4.3)
CVE-2024-10045
Patched
Oct 22, 2024
Transients Manager
Medium (4.3)
CVE-2024-9109
Patched
Oct 24, 2024
WooCommerce UPS Shipping – Live Rates and Access Points
Medium (4.3)
CVE-2024-50425
Patched
Oct 24, 2024
WP Booking System – Booking Calendar
Medium (4.3)
CVE-2024-49680
Patched
Oct 21, 2024
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (October 21, 2024 to October 27, 2024) appeared first on Wordfence.