Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- Top-tier researchers earn automatic bonuses of between 10% to 120% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 207 vulnerabilities disclosed in 200 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 43 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 19,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-759 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 71 |
Unpatched | 136 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 188 |
High Severity | 10 |
Critical Severity | 9 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 114 |
Cross-Site Request Forgery (CSRF) | 40 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 20 |
Unrestricted Upload of File with Dangerous Type | 9 |
Missing Authorization | 6 |
Exposure of Sensitive Information to an Unauthorized Actor | 4 |
Authentication Bypass Using an Alternate Path or Channel | 2 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 2 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
External Control of File Name or Path | 1 |
Improper Access Control | 1 |
Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
Insertion of Sensitive Information into Log File | 1 |
Missing Authentication for Critical Function | 1 |
Server-Side Request Forgery (SSRF) | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
74 | |
21 | |
14 | |
9 | |
8 | |
8 | |
8 | |
6 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
(dp) AddThis | dp-addthis |
3D Presentation | 3d-presentation |
Aajoda Testimonials | aajoda-testimonials |
Accordion title for Elementor | accordion-title-for-elementor |
Addressbook | addressbook |
Admin SMS Alert | admin-sms-alert |
Administrator Z | administrator-z |
Advanced Control Manager for WordPress by ItalyStrap | advanced-control-manager |
Advanced PDF Generator | advanced-pdf-generator |
affiliate-toolkit | affiliate-toolkit-starter |
AI Power: Complete AI Pack | gpt3-ai-content-generator |
All Post Contact Form | allpost-contactform |
Alley Elementor Widget | alley-elementor-widget |
AmaDiscount Plugin | amadiscount |
amazing neo icon font for elementor | amazing-neo-icon-font-for-elementor |
Amazon Associate Filter | amazon-associate-filter |
AMP Img Shortcode | amp-img-shortcode |
Ancient World Linked Data for WordPress | ancient-world-linked-data-for-wordpress |
APK Downloader | apk-downloader |
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress | bookingpress-appointment-booking |
Appointmind | appointmind |
Arconix Shortcodes | arconix-shortcodes |
aThemes Addons for Elementor | athemes-addons-for-elementor-lite |
Audio Comparison Lite | audio-comparison-lite |
Awesome Progress Bar | awesome-progess-bar |
Awesome Shortcodes For Genesis | awesome-shortcodes-for-genesis |
AwesomePress | awesomepress |
BBP Core – Expand bbPress powered forums with useful features | bbp-core |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Beds24 Online Booking | beds24-online-booking |
BetterLinks – An Advanced Plugin for Affiliate Links, Link Shortening, Link Tracking, Link Branding & Marketing | betterlinks |
Bigmart Elements | bigmart-elements |
Black Widgets For Elementor | black-widgets |
Blrt WP Embed | blrt-wp-embed |
Bonway Static Block Editor | bonway-static-block-editor |
bpmn.io | bpmnio |
Bricksable for Bricks Builder | bricksable |
Build 5 Star Reviews on Google Reviews, Yelp, Facebook… easily and risk-free | RRatingg | 5-stars-rating-funnel |
Classy Addons for Elementor | classy-addons-for-elementor |
Clever Addons for Elementor | cafe-lite |
Clyp | clyp |
CM Table Of Contents – WordPress TOC Plugin | cm-table-of-content |
Code Explorer | code-explorer |
Cresta Addons for Elementor | cresta-addons-for-elementor |
Crypto Tool | crypto |
Custom Admin Menu | custom-admin-menu |
Custom Author URL | author-slug |
Custom post type templates for Elementor | custom-post-type-templates-for-elementor |
DataMentor – Best DataTables Plugin for Elementor | datamentor |
Definitive Addons for Elementor | definitive-addons-for-elementor |
Delisho – Recipe Widgets and Blocks | dr-widgets-blocks |
Display Terms Shortcode | display-terms-shortcode |
Domain Sharding | domain-sharding |
Download Monitor | download-monitor |
Download-Mirror-Counter | wp-download-mirror-counter |
Dynamic Widgets | dynamic-widgets |
e-shopsカート2 | e-shops-cart2 |
Easy Accordion Gutenberg Block | easy-accordion-block |
Easy Gallery | simple-gallery-odihost |
Easy SVG Upload | easy-svg-upload |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
Elementary Addons | elementary-addons |
Elo Rating Shortcode | elo-rating-shortcode |
Emoji Shortcode | emoji-shortcode |
Enable Shortcodes inside Widgets,Comments and Experts | enable-shortcodes-inside-widgetscomments-and-experts |
EndomondoWP | endomondowp |
Events Manager Pro – extended | events-manager-pro-extended |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Extender All In One For Elementor | extender-all-in-one-for-elementor |
EzyOnlineBookings Online Booking System Widget | ezyonlinebookings-online-booking-system |
Featured Posts Scroll | featured-posts-scroll |
FileOrganizer – Manage WordPress and Website Files | fileorganizer |
Flash Show And Hide Box | flash-show-and-hide-box |
Forminator Forms – Contact Form, Payment Form & Custom Form Builder | forminator |
FraudLabs Pro SMS Verification | fraudlabs-pro-sms-verification |
GDReseller | gdreseller |
Genoo | genoo |
Get Quote For Woocommerce – Request A Quote For Woocommerce | get-a-quote-for-woocommerce |
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | gift-voucher |
Gmap Point List | gmap-point-list |
Golf Tracker | golf-tracker |
Group Chat & Video Chat by AtomChat | atomchat |
Gutenberg Blocks with AI by Kadence WP – Page Builder Features | kadence-blocks |
Header Footer Composer for Elementor | header-footer-composer |
Hoo Addons for Elementor | hoo-addons-for-elementor |
Hover Video Preview | hover-video-preview |
HT Builder – WordPress Theme Builder for Elementor | ht-builder |
HT Politic – For Political WordPress Themes / Website | wp-politic |
ID-SK Toolkit | idsk-toolkit |
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation | zero-bs-crm |
Jetpackcrm Ext Woo Connect | jetpackcrm-ext-woo-connect |
Jigoshop – Store Exporter | jigoshop-exporter |
JS Help Desk – The Ultimate Help Desk & Support Plugin | js-support-ticket |
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates | kata-plus |
Kento Ads Rotator | kento-ads-rotator |
Knowledge Base | knowledgebase |
LH QR Codes | lh-qr-codes |
Lodgix.com Vacation Rental Website Builder | lodgixcom-vacation-rental-listing-management-booking-plugin |
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) | magical-addons-for-elementor |
Manage User Columns | manage-user-columns |
Market 360 Viewer | market-360-viewer |
Marquee Elementor with Posts | marquee-elementor |
MasterBip para Elementor | masterbip-for-elementor |
Masteriyo LMS – eLearning and Online Course Builder for WordPress | learning-management-system |
MDR Webmaster Tools | mdr-webmaster-tools |
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO – Media Library Tools | media-library-tools |
Media Library Assistant | media-library-assistant |
Media Modal | media-modal |
Meta Store Elements | meta-store-elements |
ML Responsive Audio player with playlist Shortcode | mlr-audio |
Mobilize | mobilize |
Move Addons for Elementor | move-addons |
Multi Purpose Mail Form | multi-purpose-mail-form |
Multiple Page Generator Plugin – MPG | multiple-pages-generator-by-porthas |
MyCurator Content Curation | mycurator |
MyOrderDesk | myorderdesk |
Naver Blog | naver-blog-api |
Newsletters | newsletters-lite |
NMR Strava activities | nmr-strava-activities |
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | otter-blocks |
Paytium: Mollie payment forms & donations | paytium |
Platform.ly Official | platformly |
Plug your WooCommerce into the largest catalog of customized print products from Helloprint | helloprint |
Plugin Name: GMO Social Connection | gmo-social-connection |
Porsline | porsline |
Post Status Notifier | post-status-notifier |
Post Status Notifier Lite | post-status-notifier-lite |
Premium Addons for Elementor | premium-addons-for-elementor |
Pricer Ninja: Create and add responsive Pricing Tables to your website on-the-fly | pricer-ninja-pricing-tables |
Pricing Tables WordPress Plugin – Easy Pricing Tables | easy-pricing-tables |
Quran Shortcode | quran-shortcode |
Random Featured Post | random-featured-post-plugin |
ReCaptcha Integration for WordPress | wp-recaptcha-integration |
Reftagger Shortcode | reftagger-shortcode |
Responsive Flickr Gallery | responsive-flickr-gallery |
Restaurant & Cafe Addon for Elementor | restaurant-cafe-addon-for-elementor |
RLM Elementor Widgets Pack | rlm-elementor-widgets-pack |
RSVP ME | rsvp-me |
RSVPMaker for Toastmasters | rsvpmaker-for-toastmasters |
Sales Page Addon – Elementor & Beaver Builder | sales-page-addon |
Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates | sastra-essential-addons-for-elementor |
Selar.co Widget | selar-co-widget |
Seo Free | seo-free |
SEUR Oficial | seur |
SH Slideshow | sh-slideshow |
Show Visitor IP Address | show-visitor-ip-address |
Sided | sided |
Simple Business Manager | simple-business-manager |
Simple Goods | simple-goods |
Simple Job Manager | simple-job-manager |
Simple Page Specific Sidebars | page-specific-sidebars |
SIP Reviews Shortcode for WooCommerce | sip-reviews-shortcode-woocommerce |
Skip To | skip-to |
SKSDEV Toolkit | sksdev-toolkit |
Slicko | slicko-for-elementor |
Smart Mockups | smart-mockups |
SmartLink Dynamic URLs | smartlink-dinamic-urls |
SMS Alert Order Notifications – WooCommerce | sms-alert |
Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder | stacks-mobile-app-builder |
Stars SMTP Mailer | stars-smtp-mailer |
Step by Step | step-by-step |
Sticky Social Bar | sticky-social-bar |
StreamWeasels Kick Integration | streamweasels-kick-integration |
StreamWeasels YouTube Integration | streamweasels-youtube-integration |
Subscribe to Comments | subscribe-to-comments |
Super Addons for Elementor | super-addons-for-elementor |
T(-) Countdown | t-countdown |
Themedy Toolbox | themedy-toolbox |
ThemeFuse Maintenance Mode | themefuse-maintenance-mode |
ThemeShark Templates & Widgets for Elementor | themeshark-elementor |
TradeMe widgets | trademe-widget |
Training – Courses | training |
Twitter @Anywhere Plus | twitter-anywhere-plus |
Ultimate TinyMCE | ultimate-tinymce |
UPDATE NOTIFICATIONS | update-notifications |
W3P SEO | wp-perfect-plugin |
W3SPEEDSTER | w3speedster-wp |
Webriti Custom Login | webriti-custom-login-page |
Website price calculator | price-calculator-to-your-website |
WeChat Subscribers Lite 微信公众订阅号插件 | wechat-subscribers-lite |
While Loading | while-it-is-loading |
Widget or Sidebar Shortcode | widget-or-sidebar-per-shortcode |
WM Zoom | wm-zoom |
Woo Manage Fraud Orders | woo-manage-fraud-orders |
Woocommerce Quote Calculator | woo-quote-calculator-order |
WordPress Business Plugin | business |
World Prayer Time | world-prayer-time |
WP Baidu Map | wp-baidu-map |
WP Course Manager | wp-course-manager |
WP EASY RECIPE | wp-easy-recipe |
WP EIS | wp-eis |
WP Feature Box | wp-feature-box |
WP Hotel Booking | wp-hotel-booking |
WP Pocket URLs | wp-pocket-urls |
WP Simple Anchors Links | wp-simple-anchors-links |
WP Team – WordPress Team Member Plugin | ht-team-member |
WPAdverts – Classifieds Plugin | wpadverts |
WPC Smart Messages for WooCommerce | wpc-smart-messages |
WPGlobus Translate Options | wpglobus-translate-options |
Курс валют UAH | ukrainian-currency |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-10392
Patched
Oct 30, 2024
AI Power: Complete AI Pack
Critical (9.8)
CVE-2024-50523
Unpatched
Oct 30, 2024
All Post Contact Form
Critical (9.8)
CVE-2024-9989
Unpatched
Oct 28, 2024
Crypto Tool
Critical (9.8)
CVE-2024-9988
Unpatched
Oct 28, 2024
Crypto Tool
Critical (9.8)
CVE-2024-50526
Unpatched
Oct 30, 2024
Multi Purpose Mail Form
Critical (9.8)
CVE-2024-50525
Unpatched
Oct 30, 2024
Plug your WooCommerce into the largest catalog of customized print products from Helloprint
Critical (9.8)
CVE-2024-50531
Patched
Oct 30, 2024
RSVPMaker for Toastmasters
Critical (9.8)
CVE-2024-50527
Unpatched
Oct 30, 2024
Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder
Critical (9.1)
CVE-2024-8512
Patched
Oct 29, 2024
W3SPEEDSTER
High (8.8)
CVE-2024-9990
Unpatched
Oct 28, 2024
Crypto Tool
High (8.8)
CVE-2024-10008
Patched
Oct 28, 2024
Masteriyo LMS – eLearning and Online Course Builder for WordPress
High (8.8)
CVE-2024-50530
Unpatched
Oct 30, 2024
Stars SMTP Mailer
High (8.8)
CVE-2024-50529
Unpatched
Oct 30, 2024
Training – Courses
High (8.8)
CVE-2024-51582
Unpatched
Oct 31, 2024
WP Hotel Booking
High (8.8)
CVE-2024-10436
Patched
Oct 28, 2024
WPC Smart Messages for WooCommerce
High (7.5)
CVE-2024-7985
Patched
Oct 29, 2024
FileOrganizer – Manage WordPress and Website Files
High (7.3)
CVE-2024-9846
Unpatched
Oct 29, 2024
Enable Shortcodes inside Widgets,Comments and Experts
High (7.2)
CVE-2024-51661
Patched
Nov 1, 2024
Media Library Assistant
High (7.2)
CVE-2024-10108
Patched
Oct 29, 2024
WPAdverts – Classifieds Plugin
Medium (6.5)
CVE-2024-51579
Unpatched
Oct 31, 2024
Build 5 Star Reviews on Google Reviews, Yelp, Facebook… easily and risk-free | RRatingg
Medium (6.5)
CVE-2024-50524
Unpatched
Oct 30, 2024
Administrator Z
Medium (6.5)
CVE-2024-51608
Unpatched
Oct 31, 2024
AmaDiscount Plugin
Medium (6.5)
CVE-2024-51606
Unpatched
Oct 31, 2024
Blrt WP Embed
Medium (6.5)
CVE-2024-51621
Unpatched
Oct 31, 2024
Download-Mirror-Counter
Medium (6.5)
CVE-2024-51570
Unpatched
Oct 31, 2024
Easy Gallery
Medium (6.5)
CVE-2024-51607
Unpatched
Oct 31, 2024
Golf Tracker
Lodgix.com Vacation Rental Website Builder <= 3.9.73 – Authenticated (Contributor+) SQL Injection
Medium (6.5)
CVE-2024-50539
Unpatched
Oct 31, 2024
Lodgix.com Vacation Rental Website Builder
Medium (6.5)
CVE-2024-51619
Unpatched
Oct 31, 2024
Market 360 Viewer
Medium (6.5)
CVE-2024-51620
Unpatched
Oct 31, 2024
Porsline
Medium (6.5)
CVE-2024-51625
Unpatched
Oct 31, 2024
Quran Shortcode
Medium (6.5)
CVE-2024-50544
Unpatched
Oct 31, 2024
RSVP ME
Medium (6.5)
CVE-2024-51602
Unpatched
Oct 31, 2024
Simple Job Manager
Medium (6.5)
CVE-2024-6479
Unpatched
Oct 31, 2024
SIP Reviews Shortcode for WooCommerce
Medium (6.5)
CVE-2024-51601
Unpatched
Oct 31, 2024
Website price calculator
Medium (6.5)
CVE-2024-51626
Unpatched
Oct 31, 2024
Woocommerce Quote Calculator
Medium (6.5)
CVE-2024-51623
Unpatched
Oct 31, 2024
WP EIS
Medium (6.4)
CVE-2024-50540
Unpatched
Oct 31, 2024
(dp) AddThis
Medium (6.4)
CVE-2024-51578
Unpatched
Oct 31, 2024
3D Presentation
Medium (6.4)
CVE-2024-51614
Unpatched
Oct 31, 2024
Aajoda Testimonials
Medium (6.4)
CVE-2024-51685
Patched
Nov 1, 2024
Accordion title for Elementor
Medium (6.4)
CVE-2024-50541
Unpatched
Oct 31, 2024
Advanced Control Manager for WordPress by ItalyStrap
Medium (6.4)
CVE-2024-10227
Patched
Oct 28, 2024
affiliate-toolkit
Medium (6.4)
CVE-2024-50521
Unpatched
Oct 30, 2024
Alley Elementor Widget
Medium (6.4)
CVE-2024-50543
Unpatched
Oct 31, 2024
amazing neo icon font for elementor
Medium (6.4)
CVE-2024-51576
Unpatched
Oct 31, 2024
AMP Img Shortcode
Medium (6.4)
CVE-2024-50520
Unpatched
Oct 30, 2024
Ancient World Linked Data for WordPress
Medium (6.4)
CVE-2024-10226
Patched
Oct 29, 2024
Arconix Shortcodes
aThemes Addons for Elementor <= 1.0.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51675
Patched
Nov 1, 2024
aThemes Addons for Elementor
AtomChat <= 1.1.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via atomchat Shortcode
Medium (6.4)
CVE-2024-10232
Patched
Oct 31, 2024
Group Chat & Video Chat by AtomChat
Medium (6.4)
CVE-2024-51627
Unpatched
Oct 31, 2024
Audio Comparison Lite
Medium (6.4)
CVE-2024-50548
Unpatched
Oct 31, 2024
Awesome Progress Bar
Medium (6.4)
CVE-2024-51616
Unpatched
Oct 31, 2024
AwesomePress
Medium (6.4)
CVE-2024-9505
Patched
Oct 29, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-51589
Unpatched
Oct 31, 2024
Bigmart Elements
Medium (6.4)
CVE-2024-51662
Patched
Nov 1, 2024
Black Widgets For Elementor
Medium (6.4)
CVE-2024-9388
Patched
Oct 29, 2024
Black Widgets For Elementor
Medium (6.4)
CVE-2024-50549
Unpatched
Oct 31, 2024
Bonway Static Block Editor
Medium (6.4)
CVE-2024-51577
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-51596
Unpatched
Oct 31, 2024
WordPress Business Plugin
Medium (6.4)
CVE-2024-50553
Unpatched
Oct 31, 2024
Classy Addons for Elementor
Medium (6.4)
CVE-2024-51580
Unpatched
Oct 31, 2024
Clever Addons for Elementor
Medium (6.4)
CVE-2024-51617
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-51680
Patched
Nov 1, 2024
Cresta Addons for Elementor
Medium (6.4)
CVE-2024-51618
Unpatched
Oct 31, 2024
Custom Admin Menu
Medium (6.4)
CVE-2024-51683
Patched
Nov 1, 2024
Custom post type templates for Elementor
Medium (6.4)
CVE-2024-50545
Unpatched
Oct 31, 2024
DataMentor – Best DataTables Plugin for Elementor
Definitive Addons for Elementor <= 1.5.16 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51587
Unpatched
Oct 31, 2024
Definitive Addons for Elementor
Medium (6.4)
CVE-2024-51676
Patched
Nov 1, 2024
Delisho – Recipe Widgets and Blocks
Medium (6.4)
CVE-2024-51610
Unpatched
Oct 31, 2024
Display Terms Shortcode
Easy SVG Upload <= 1.0 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-9708
Unpatched
Oct 30, 2024
Easy SVG Upload
Medium (6.4)
CVE-2024-10310
Patched
Nov 1, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (6.4)
CVE-2024-51586
Unpatched
Oct 31, 2024
Elementary Addons
Medium (6.4)
CVE-2024-51678
Patched
Nov 1, 2024
Elo Rating Shortcode
Medium (6.4)
CVE-2024-51609
Unpatched
Oct 31, 2024
Emoji Shortcode
Medium (6.4)
CVE-2024-50551
Unpatched
Oct 31, 2024
EndomondoWP
Medium (6.4)
CVE-2024-51575
Unpatched
Oct 31, 2024
Extender All In One For Elementor
Medium (6.4)
CVE-2024-51628
Unpatched
Nov 1, 2024
EzyOnlineBookings Online Booking System Widget
Medium (6.4)
CVE-2024-50536
Unpatched
Oct 31, 2024
GDReseller
Medium (6.4)
CVE-2024-51605
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-9165
Unpatched
Oct 30, 2024
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Medium (6.4)
CVE-2024-51594
Unpatched
Oct 31, 2024
Gmap Point List
Medium (6.4)
CVE-2024-9655
Patched
Oct 31, 2024
Gutenberg Blocks with AI by Kadence WP – Page Builder Features
Medium (6.4)
CVE-2024-51629
Unpatched
Nov 1, 2024
Header Footer Composer for Elementor
Medium (6.4)
CVE-2024-51590
Unpatched
Oct 31, 2024
Hoo Addons for Elementor
Medium (6.4)
CVE-2024-50552
Unpatched
Oct 31, 2024
Hover Video Preview
Medium (6.4)
CVE-2024-51682
Patched
Nov 1, 2024
HT Builder – WordPress Theme Builder for Elementor
Medium (6.4)
CVE-2024-51673
Patched
Nov 1, 2024
HT Politic – For Political WordPress Themes / Website
Medium (6.4)
CVE-2024-10223
Patched
Oct 29, 2024
WP Team – WordPress Team Member Plugin
Medium (6.4)
CVE-2024-50517
Unpatched
Oct 30, 2024
ID-SK Toolkit
Medium (6.4)
CVE-2024-9376
Patched
Oct 28, 2024
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates
Medium (6.4)
CVE-2024-51583
Unpatched
Oct 31, 2024
Kento Ads Rotator
Medium (6.4)
CVE-2024-51677
Patched
Nov 1, 2024
Knowledge Base
Medium (6.4)
CVE-2024-51572
Unpatched
Oct 31, 2024
LH QR Codes
Medium (6.4)
CVE-2024-51665
Patched
Nov 1, 2024
Marquee Elementor with Posts <= 1.2.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51584
Unpatched
Oct 31, 2024
Marquee Elementor with Posts
Medium (6.4)
CVE-2024-51571
Unpatched
Oct 31, 2024
MasterBip para Elementor
Medium (6.4)
CVE-2024-10000
Patched
Oct 28, 2024
Masteriyo LMS – eLearning and Online Course Builder for WordPress
Medium (6.4)
CVE-2024-10482
Patched
Oct 31, 2024
Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO – Media Library Tools
Medium (6.4)
CVE-2024-51604
Unpatched
Oct 31, 2024
Media Modal
Medium (6.4)
CVE-2024-51592
Unpatched
Oct 31, 2024
Meta Store Elements
Medium (6.4)
CVE-2024-51573
Unpatched
Oct 31, 2024
ML Responsive Audio player with playlist Shortcode
Medium (6.4)
CVE-2024-50546
Unpatched
Oct 31, 2024
MyOrderDesk
Medium (6.4)
CVE-2024-10181
Patched
Oct 28, 2024
Newsletters
Medium (6.4)
CVE-2024-51603
Unpatched
Oct 31, 2024
NMR Strava activities
Medium (6.4)
CVE-2024-10367
Patched
Oct 31, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-10266
Patched
Oct 28, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-50518
Unpatched
Oct 30, 2024
Medium (6.4)
CVE-2024-51612
Unpatched
Oct 31, 2024
Reftagger Shortcode
Medium (6.4)
CVE-2024-51581
Patched
Oct 31, 2024
Restaurant & Cafe Addon for Elementor
Medium (6.4)
CVE-2024-50542
Patched
Oct 31, 2024
RLM Elementor Widgets Pack
Medium (6.4)
CVE-2024-51585
Unpatched
Oct 31, 2024
Sales Page Addon – Elementor & Beaver Builder
Medium (6.4)
CVE-2024-51674
Patched
Nov 1, 2024
Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates
Medium (6.4)
CVE-2024-51598
Unpatched
Oct 31, 2024
Selar.co Widget
Medium (6.4)
CVE-2024-50538
Unpatched
Oct 31, 2024
Show Visitor IP Address
Medium (6.4)
CVE-2024-50554
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-51599
Unpatched
Oct 31, 2024
Simple Business Manager
Medium (6.4)
CVE-2024-51574
Unpatched
Oct 31, 2024
Simple Goods
SIP Reviews Shortcode for WooCommerce <= 1.2.3 – Authenticated (Contributor+) Cross-Site Scripting
Medium (6.4)
CVE-2024-6480
Unpatched
Oct 31, 2024
SIP Reviews Shortcode for WooCommerce
Medium (6.4)
CVE-2024-51595
Unpatched
Oct 31, 2024
SKSDEV Toolkit
Medium (6.4)
CVE-2024-51591
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-50537
Unpatched
Oct 31, 2024
Smart Mockups
Medium (6.4)
CVE-2024-10233
Patched
Oct 28, 2024
SMS Alert Order Notifications – WooCommerce
Medium (6.4)
CVE-2024-50535
Unpatched
Oct 30, 2024
Step by Step
Medium (6.4)
CVE-2024-10185
Patched
Oct 28, 2024
StreamWeasels YouTube Integration
Medium (6.4)
CVE-2024-51588
Unpatched
Oct 31, 2024
Super Addons for Elementor
Medium (6.4)
CVE-2024-10184
Patched
Oct 28, 2024
StreamWeasels Kick Integration
T(-) Countdown <= 2.4.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2024-9884
Unpatched
Oct 29, 2024
T(-) Countdown
Medium (6.4)
CVE-2024-50547
Unpatched
Oct 31, 2024
Themedy Toolbox
Medium (6.4)
CVE-2024-51597
Unpatched
Oct 31, 2024
ThemeShark Templates & Widgets for Elementor
Medium (6.4)
CVE-2024-51613
Unpatched
Oct 31, 2024
TradeMe widgets
Medium (6.4)
CVE-2024-8627
Unpatched
Oct 29, 2024
Ultimate TinyMCE
Medium (6.4)
CVE-2024-9885
Unpatched
Oct 29, 2024
Widget or Sidebar Shortcode
Medium (6.4)
CVE-2024-50556
Unpatched
Oct 31, 2024
Medium (6.4)
CVE-2024-9886
Unpatched
Oct 29, 2024
WP Baidu Map
Medium (6.4)
CVE-2024-51622
Unpatched
Oct 31, 2024
WP EASY RECIPE
Medium (6.4)
CVE-2024-51611
Unpatched
Oct 31, 2024
WP Feature Box
Medium (6.4)
CVE-2024-51681
Patched
Nov 1, 2024
WP Pocket URLs
Medium (6.4)
CVE-2024-9446
Unpatched
Oct 30, 2024
WP Simple Anchors Links
Medium (6.4)
CVE-2024-51593
Unpatched
Oct 31, 2024
Курс валют UAH
Medium (6.1)
CVE-2024-51644
Unpatched
Nov 1, 2024
Addressbook
Medium (6.1)
CVE-2024-51637
Unpatched
Nov 1, 2024
Admin SMS Alert
Medium (6.1)
CVE-2024-51641
Unpatched
Nov 1, 2024
Advanced PDF Generator
Medium (6.1)
CVE-2024-51643
Unpatched
Nov 1, 2024
Amazon Associate Filter
Medium (6.1)
CVE-2024-51654
Unpatched
Nov 1, 2024
APK Downloader
Medium (6.1)
CVE-2024-51679
Patched
Nov 1, 2024
Appointmind
Medium (6.1)
CVE-2024-51638
Unpatched
Nov 1, 2024
Awesome Shortcodes For Genesis
Medium (6.1)
CVE-2024-9896
Patched
Nov 1, 2024
BBP Core – Expand bbPress powered forums with useful features
Medium (6.1)
CVE-2024-51655
Unpatched
Nov 1, 2024
Custom Author URL
Medium (6.1)
CVE-2024-50533
Unpatched
Oct 30, 2024
Domain Sharding
Medium (6.1)
CVE-2024-51648
Unpatched
Nov 1, 2024
e-shopsカート2
Events Manager Pro – extended <= 0.1 – Cross-Site Request Forgery to Reflected Cross-Site Scripting
Medium (6.1)
CVE-2024-50532
Unpatched
Oct 30, 2024
Events Manager Pro – extended
Medium (6.1)
CVE-2024-10922
Unpatched
Nov 1, 2024
Featured Posts Scroll
Medium (6.1)
CVE-2024-51656
Unpatched
Nov 1, 2024
Flash Show And Hide Box
FraudLabs Pro SMS Verification <= 1.10.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting
Medium (6.1)
CVE-2024-51688
Patched
Nov 1, 2024
FraudLabs Pro SMS Verification
Medium (6.1)
CVE-2024-51636
Unpatched
Nov 1, 2024
Plugin Name: GMO Social Connection
Medium (6.1)
CVE-2024-50519
Unpatched
Oct 30, 2024
Jigoshop – Store Exporter
Medium (6.1)
CVE-2024-51640
Unpatched
Nov 1, 2024
MDR Webmaster Tools
Medium (6.1)
CVE-2024-51649
Unpatched
Nov 1, 2024
Medium (6.1)
CVE-2024-51639
Unpatched
Nov 1, 2024
Naver Blog
Medium (6.1)
CVE-2024-51687
Patched
Nov 1, 2024
Platform.ly Official
Medium (6.1)
CVE-2024-10048
Patched
Oct 28, 2024
Medium (6.1)
CVE-2024-8871
Patched
Oct 29, 2024
Pricing Tables WordPress Plugin – Easy Pricing Tables
Medium (6.1)
CVE-2024-51650
Unpatched
Nov 1, 2024
Random Featured Post
Medium (6.1)
CVE-2024-8739
Patched
Nov 1, 2024
ReCaptcha Integration for WordPress
Medium (6.1)
CVE-2024-51630
Unpatched
Nov 1, 2024
Responsive Flickr Gallery
Medium (6.1)
CVE-2024-51642
Unpatched
Nov 1, 2024
Medium (6.1)
CVE-2024-9438
Patched
Oct 28, 2024
SEUR Oficial
Medium (6.1)
CVE-2024-51632
Unpatched
Nov 1, 2024
SH Slideshow
Simple Page Specific Sidebars <= 2.14.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting
Medium (6.1)
CVE-2024-51633
Unpatched
Nov 1, 2024
Simple Page Specific Sidebars
Medium (6.1)
CVE-2024-51652
Unpatched
Nov 1, 2024
Medium (6.1)
CVE-2024-51657
Patched
Nov 1, 2024
SmartLink Dynamic URLs
Medium (6.1)
CVE-2024-51631
Unpatched
Nov 1, 2024
Sticky Social Bar
Medium (6.1)
CVE-2024-8792
Patched
Oct 29, 2024
Subscribe to Comments
Medium (6.1)
CVE-2024-51645
Unpatched
Nov 1, 2024
ThemeFuse Maintenance Mode
Medium (6.1)
CVE-2024-51659
Unpatched
Nov 1, 2024
Twitter @Anywhere Plus
Medium (6.1)
CVE-2024-51653
Unpatched
Nov 1, 2024
UPDATE NOTIFICATIONS
Medium (6.1)
CVE-2024-51684
Patched
Nov 1, 2024
Medium (6.1)
CVE-2024-51634
Unpatched
Nov 1, 2024
Webriti Custom Login
Medium (6.1)
CVE-2024-50522
Unpatched
Oct 30, 2024
WeChat Subscribers Lite 微信公众订阅号插件
Medium (6.1)
CVE-2024-51635
Unpatched
Nov 1, 2024
While Loading
Medium (6.1)
CVE-2024-50534
Unpatched
Oct 30, 2024
World Prayer Time
Medium (6.1)
CVE-2024-51658
Unpatched
Nov 1, 2024
WP Course Manager
Medium (6.1)
CVE-2024-9434
Unpatched
Oct 30, 2024
WPGlobus Translate Options
Medium (5.4)
CVE-2024-9868
Patched
Nov 1, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (5.4)
CVE-2024-7424
Patched
Oct 31, 2024
Multiple Page Generator Plugin – MPG
Medium (5.3)
CVE-2024-10540
Patched
Nov 1, 2024
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress
Medium (5.3)
CVE-2024-9700
Patched
Oct 30, 2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Medium (5.3)
CVE-2024-9430
Unpatched
Oct 30, 2024
Get Quote For Woocommerce – Request A Quote For Woocommerce
Medium (5.3)
Unknown
Patched
Oct 28, 2024
Jetpackcrm Ext Woo Connect
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
Medium (5.3)
CVE-2024-50528
Unpatched
Oct 30, 2024
Stacks Mobile App Builder – The most powerful Mobile Applications Drag and Drop builder
Medium (5.3)
CVE-2024-10544
Unpatched
Oct 30, 2024
Woo Manage Fraud Orders
Medium (4.9)
CVE-2024-51672
Patched
Nov 1, 2024
Medium (4.9)
CVE-2023-5816
Unpatched
Oct 29, 2024
Code Explorer
Medium (4.4)
CVE-2024-51664
Patched
Nov 1, 2024
Beds24 Online Booking
Bricksable for Bricks Builder <= 1.6.59 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-51663
Patched
Nov 1, 2024
Bricksable for Bricks Builder
Medium (4.4)
CVE-2024-51670
Patched
Nov 1, 2024
JS Help Desk – The Ultimate Help Desk & Support Plugin
Medium (4.4)
CVE-2024-51668
Patched
Nov 1, 2024
MyCurator Content Curation
Medium (4.3)
CVE-2024-5030
Patched
Oct 28, 2024
CM Table Of Contents – WordPress TOC Plugin
Medium (4.3)
CVE-2024-10399
Patched
Oct 29, 2024
Download Monitor
Medium (4.3)
CVE-2024-51669
Patched
Nov 1, 2024
Dynamic Widgets
Medium (4.3)
CVE-2024-51660
Patched
Nov 1, 2024
Easy Accordion Gutenberg Block
Medium (4.3)
CVE-2024-10312
Patched
Oct 28, 2024
Exclusive Addons for Elementor
Medium (4.3)
CVE-2024-51686
Patched
Nov 1, 2024
Manage User Columns
Medium (4.3)
CVE-2024-10360
Patched
Oct 28, 2024
Move Addons for Elementor
Medium (4.3)
CVE-2024-51671
Patched
Nov 1, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (4.3)
CVE-2024-51667
Patched
Nov 1, 2024
Paytium: Mollie payment forms & donations
Medium (4.3)
CVE-2024-10437
Patched
Oct 28, 2024
WPC Smart Messages for WooCommerce
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (October 28, 2024 to November 3, 2024) appeared first on Wordfence.