Did you know we’re running a Bug Bounty Extravaganza again?
Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!
Last week, there were 202 vulnerabilities disclosed in 185 WordPress Plugins, 21 WordPress Themes, and one in WordPress Core that have been added to the Wordfence Intelligence Vulnerability Database, and there were 63 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 15,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
- WordPress Core < 6.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block
- WAF-RULE-690 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 160 |
Unpatched | 42 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 178 |
High Severity | 11 |
Critical Severity | 13 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Cross-Site Request Forgery (CSRF) | 92 |
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 49 |
Missing Authorization | 24 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 14 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 6 |
Deserialization of Untrusted Data | 3 |
Information Exposure | 3 |
Server-Side Request Forgery (SSRF) | 3 |
Improper Authorization | 2 |
Improper Input Validation | 2 |
Unrestricted Upload of File with Dangerous Type | 2 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 2 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
51 | |
12 | |
11 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
5 star review funnel for Google Reviews, Trustpilot, ProvenExpert and more | RRatingg | 5-stars-rating-funnel |
Account Engagement | pardot |
ActiveCampaign – Forms, Site Tracking, Live Chat | activecampaign-subscription-forms |
Ads.txt Admin | ads-txt-admin |
Advanced Cron Manager – debug & control | advanced-cron-manager |
Advanced iFrame | advanced-iframe |
Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress | advanced-page-visit-counter |
Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page | advanced-post-block |
AffiEasy | affieasy |
AIKit – WordPress AI Automatic Writer, Chatbot, Writing Assistant & Content Repurposer / OpenAI GPT | aikit-wordpress-ai-writing-assistant-using-gpt3 |
All-in-One Addons for Elementor – WidgetKit | widgetkit-for-elementor |
Appointment Bookings for Zoom GoogleMeet and more – Wappointment | wappointment |
AppPresser – Mobile App Framework | apppresser |
Asgaros Forum | asgaros-forum |
Aspose.Words – Import and Export word documents | aspose-doc-exporter |
BA Book Everything | ba-book-everything |
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | woo-bulk-editor |
Before And After: Lead Capture Forms For WordPress | before-and-after |
Benchmark Email Lite | benchmark-email-lite |
Better Chat Support – Chat Bubble and Chat Button with Gutenberg, Elementor and Shortcode | chat-help |
BizCalendar Web | bizcalendar-web |
Blocksy Companion | blocksy-companion |
Bold Page Builder | bold-page-builder |
Booking for Appointments and Events Calendar – Amelia | ameliabooking |
Boostify Header Footer Builder for Elementor | boostify-header-footer-builder |
bunny.net – WordPress CDN Plugin | bunnycdn |
BWL Advanced FAQ Manager | bwl-advanced-faq-manager |
Calendarista Basic Edition – WordPress appointment booking system | calendarista-basic-edition |
Carousel Slider | carousel-slider |
Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce | wp-carousel-free |
CBX Bookmark & Favorite | cbxwpbookmark |
Church Admin | church-admin |
Church Content – Sermons, Events and More | church-theme-content |
Citadela Directory | citadela-directory |
Clone | wp-clone-by-wp-academy |
Contact Form Plugin | contact-form-lite |
Convert Post Types | convert-post-types |
Crony Cronjob Manager | crony |
Currency per Product for WooCommerce | currency-per-product-for-woocommerce |
Customily Product Personalizer | customily-v2 |
Dashboard To-Do List | dashboard-to-do-list |
Dashboard Welcome for Elementor | dashboard-welcome-for-elementor |
Disable Comments | WPZest | disable-comments-wpz |
Download Manager | downloadmanager |
E2Pdf – Export To Pdf Tool for WordPress | e2pdf |
Easy Logo | easylogo |
eCommerce Product Catalog Plugin for WordPress | ecommerce-product-catalog |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
Elementor Addons by Livemesh | addons-for-elementor |
ELEX WooCommerce Dynamic Pricing and Discounts | elex-woocommerce-dynamic-pricing-and-discounts |
Email Marketing for WooCommerce by Omnisend | omnisend-connect |
eRoom – Zoom Meetings & Webinars | eroom-zoom-meetings-webinar |
Essential Grid Gallery WordPress Plugin | essential-grid |
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | mage-eventpress |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Extra Product Options Builder for WooCommerce | additional-product-fields-for-woocommerce |
EZ Form Calculator | ez-form-calculator |
F4 Improvements | f4-improvements |
Favicon by RealFaviconGenerator | favicon-by-realfavicongenerator |
Filter Custom Fields & Taxonomies Light | filter-custom-fields-taxonomies-light |
Finale Lite – Sales Countdown Timer & Discount for WooCommerce | finale-woocommerce-sales-countdown-timer-discount |
Find Duplicates | find-duplicates |
Forminator – Contact Form, Payment Form & Custom Form Builder | forminator |
Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook | forms-to-zapier |
Freshdesk (official) | freshdesk-support |
FV Flowplayer Video Player | fv-wordpress-flowplayer |
Gallery Box | gallery-box |
GEO my WordPress | geo-my-wp |
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | gift-voucher |
GiveWP – Donation Plugin and Fundraising Platform | give |
GP Unique ID | gp-unique-id |
Gutenberg | gutenberg |
Gutenberg Blocks by Kadence Blocks – Page Builder Features | kadence-blocks |
Import any XML or CSV File to WordPress | wp-all-import |
Import Users from CSV | import-users-from-csv |
Inline Related Posts | intelly-related-posts |
InstaWP Connect – 1-click WP Staging & Migration | instawp-connect |
Intagrate Lite | instagrate-to-wordpress |
IP2Location Country Blocker | ip2location-country-blocker |
Ivory Search – WordPress Search Plugin | add-search-to-menu |
Jobs for WordPress | job-postings |
Kimili Flash Embed | kimili-flash-embed |
Language Translate Widget for WordPress – ConveyThis | conveythis-translate |
Leadinfo | leadinfo |
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) | leaflet-maps-marker |
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator | legal-pages |
Libsyn Publisher Hub | libsyn-podcasting |
LifterLMS – WordPress LMS Plugin for eLearning | lifterlms |
Link Whisper Free | link-whisper |
Load More Anything | ajax-load-more-anything |
Login With Ajax – Fast Logins, 2FA, Redirects | login-with-ajax |
Login with phone number | login-with-phone-number |
Login | Login Page | Login Logo | Rename Login Page | Custom Login Page | Temporary Users | Rebrand Login | Login Captcha | feather-login-page |
Mail logging – WP Mail Catcher | wp-mail-catcher |
MailChimp Forms by MailMunch | mailchimp-forms-by-mailmunch |
Marker.io – Visual Website Feedback | marker-io |
Membership Plugin – Restrict Content | restrict-content |
Migration, Backup, Staging – WPvivid | wpvivid-backuprestore |
MihanPanel – User Login , Registration and Dashboard | mihanpanel-lite |
MultiParcels Shipping For WooCommerce | multiparcels-shipping-for-woocommerce |
MWW Disclaimer Buttons | mww-disclaimer-buttons |
Newsletter – Send awesome emails from WordPress | newsletter |
NextMove Lite – Thank You Page for WooCommerce | woo-thank-you-page-nextmove-lite |
No-Bot Registration | no-bot-registration |
Novelist | novelist |
Ocean Extra | ocean-extra |
Order Delivery Date for WooCommerce | order-delivery-date-for-woocommerce |
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | otter-blocks |
Ovic Addon Toolkit | ovic-addon-toolkit |
Page Builder: Live Composer | live-composer-page-builder |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | wp-user-avatar |
Podlove Podcast Publisher | podlove-podcasting-plugin-for-wordpress |
POEditor | poeditor |
Popup by Supsystic | popup-by-supsystic |
Popup Like box – Page Plugin | ays-facebook-popup-likebox |
Post Type Builder | themify-ptb |
Premium Addons for Elementor | premium-addons-for-elementor |
Premmerce Product Filter for WooCommerce | premmerce-woocommerce-product-filter |
Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More | purple-xmls-google-product-feed-for-woocommerce |
Product Input Fields for WooCommerce | product-input-fields-for-woocommerce |
ProfileGrid – User Profiles, Memberships, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
Realtyna Organic IDX plugin + WPL Real Estate | real-estate-listing-realtyna-wpl |
ReDi Restaurant Reservation | redi-restaurant-reservation |
Redirection | redirect-redirection |
Remove Footer Credit | remove-footer-credit |
Responsive Contact Form Builder & Lead Generation Plugin | lead-form-builder |
Responsive Slider – Sangar Slider | sangar-slider-lite |
RestroPress – Online Food Ordering System | restropress |
Save as Image Plugin by Pdfcrowd | save-as-image-by-pdfcrowd |
Search Keyword Redirect | wp-search-keyword-redirect |
SEO Booster | seo-booster |
Shopkeeper Extender | shopkeeper-extender |
Shopping Cart & eCommerce Store | wp-easycart |
Short URL | shorten-url |
Simple Post Notes | simple-post-notes |
Siteimprove | siteimprove |
Slider Revolution | revslider |
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows | ml-slider |
Smart Slider 3 | smart-slider-3 |
Smash Balloon Social Post Feed | custom-facebook-feed |
Spotlight Social Feeds [Block, Shortcode, and Widget] | spotlight-social-photo-feeds |
Subscribe2 – Form, Email Subscribers & Newsletters | subscribe2 |
Sync Post With Other Site | sync-post-with-other-site |
Table Plugin for WordPress with Google Sheets Integration – Sheets to WP Table Live Sync | sheets-to-wp-table-live-sync |
Tablesome – Responsive Table, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Gravity Forms, Fluent, Forminator | tablesome |
TempTool [Show Current Template Info] | current-template-name |
The Events Calendar | the-events-calendar |
Top Bar | top-bar |
TOP Table Of Contents | top-table-of-contents |
TWIPLA (Visitor Analytics IO) – Privacy-First Website Stats, Session Recordings, Heatmaps, Polls and Surveys | visitor-analytics-io |
Ultimate Before After Image Slider & Gallery – BEAF | beaf-before-and-after-gallery |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | ultimate-member |
Ultimate Product Catalog | ultimate-product-catalogue |
Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider | ultimate-store-kit |
UNKNOWN-CVE-2014-4663 | UNKNOWN-CVE-2014-4663 |
Unlimited Elementor Inner Sections By BoomDevs | unlimited-elementor-inner-sections-by-boomdevs |
User Activity Log Pro | user-activity-log-pro |
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress | userswp |
USPS Shipping for WooCommerce – Live Rates | flexible-shipping-usps |
Wallet System for WooCommerce – Digital Wallet, Cashback Rewards, Recharge User Wallets, View Transaction History | wallet-system-for-woocommerce |
Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition | webinar-ignition |
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | coming-soon |
Welcart e-Commerce | usc-e-shop |
WOLF – WordPress Posts Bulk Editor and Manager Professional | bulk-editor |
WooCommerce UPS Shipping – Live Rates and Access Points | flexible-shipping-ups |
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds | another-wordpress-classifieds-plugin |
WordPress Flipbook by Supsystic | digital-publications-by-supsystic |
WordPress Hosting Benchmark tool | wpbenchmark |
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly | tour-booking-manager |
WP Accessibility Helper (WAH) | wp-accessibility-helper |
WP Activity Log Premium | wp-security-audit-log-premium |
WP Client Reports | wp-client-reports |
WP Compress – Image Optimizer [All-In-One] | wp-compress-image-optimizer |
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, Security+ | wp-letsencrypt-ssl |
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress | wp-event-aggregator |
WP Google Analytics Events – No-Code Custom Event Tracking for Google Analytics | wp-google-analytics-events |
WP Login and Logout Redirect | wp-login-and-logout-redirect |
WP Matterport Shortcode | shortcode-gallery-for-matterport-showcase |
WP Radio – Worldwide Online Radio Stations Directory for WordPress | wp-radio |
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden | wp2leads |
WPBakery Visual Composer | js_composer |
WPC Smart Quick View for WooCommerce | woo-smart-quick-view |
WPZOOM Social Feed Widget & Block | instagram-widget-by-wpzoom |
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] | faq-for-woocommerce |
Zoho Campaigns | zoho-campaigns |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Blocksy | blocksy |
CityLogic | citylogic |
Default Mag | default-mag |
Emmet Lite | emmet-lite |
Gridsby | gridsby |
HappenStance | happenstance |
i-excel | i-excel |
i-max | i-max |
Lightning | lightning |
Namaha | namaha |
NewsXpress | newsxpress |
Panoramic | panoramic |
PopularFX | popularfx |
Sarada Lite | sarada-lite |
Sensible WP | sensible-wp |
Shopstar! | shopstar |
Sliding Door | sliding-door |
Soledad | soledad |
Spa and Salon | spa-and-salon |
The Conference | the-conference |
X-T9 | x-t9 |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-32128
Unpatched
Apr 12, 2024
Realtyna Organic IDX plugin + WPL Real Estate
Critical (9.9)
CVE-2024-31370
Unpatched
Apr 9, 2024
Critical (9.9)
CVE-2024-32125
Patched
Apr 12, 2024
BA Book Everything
Critical (9.9)
CVE-2024-32127
Unpatched
Apr 12, 2024
Find Duplicates
Critical (9.9)
CVE-2024-32139
Patched
Apr 12, 2024
Podlove Podcast Publisher
Critical (9.9)
CVE-2024-32137
Unpatched
Apr 12, 2024
User Activity Log Pro
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 – Unauthenticated Arbitrary File Upload
Critical (9.8)
CVE-2024-2667
Patched
Apr 12, 2024
InstaWP Connect – 1-click WP Staging & Migration
Critical (9.1)
CVE-2024-32098
Unpatched
Apr 11, 2024
Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress
Critical (9.1)
CVE-2024-32136
Patched
Apr 12, 2024
BWL Advanced FAQ Manager
Critical (9.1)
CVE-2024-32132
Unpatched
Apr 12, 2024
CBX Bookmark & Favorite
Critical (9.1)
CVE-2024-32135
Unpatched
Apr 12, 2024
Disable Comments | WPZest
Critical (9.1)
CVE-2024-32134
Unpatched
Apr 12, 2024
Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook
Critical (9.1)
CVE-2024-32087
Unpatched
Apr 11, 2024
Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and More
High (8.8)
CVE-2024-3211
Patched
Apr 11, 2024
Shopping Cart & eCommerce Store
High (8.8)
CVE-2024-2018
Patched
Apr 9, 2024
WP Activity Log Premium
High (8.5)
CVE-2023-6964
Patched
Apr 9, 2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features
High (7.5)
CVE-2024-32086
Unpatched
Apr 11, 2024
Citadela Directory
High (7.5)
CVE-2023-7046
Patched
Apr 9, 2024
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, Security+
High (7.2)
CVE-2024-3020
Patched
Apr 9, 2024
High (7.2)
CVE-2024-1774
Unpatched
Apr 9, 2024
Customily Product Personalizer
High (7.2)
CVE-2024-32431
Patched
Apr 12, 2024
Import Users from CSV
High (7.2)
CVE-2023-6811
Patched
Apr 10, 2024
Language Translate Widget for WordPress – ConveyThis
High (7.2)
Unknown
Patched
Apr 9, 2024
WordPress
High (7.2)
CVE-2024-3054
Patched
Apr 11, 2024
Migration, Backup, Staging – WPvivid
Medium (6.5)
CVE-2024-2665
Patched
Apr 9, 2024
Premium Addons for Elementor
Advanced iFrame <= 2024.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2024-32079
Patched
Apr 11, 2024
Advanced iFrame
Medium (6.4)
CVE-2024-2137
Unpatched
Apr 11, 2024
All-in-One Addons for Elementor – WidgetKit
Medium (6.4)
CVE-2024-2735
Patched
Apr 9, 2024
Bold Page Builder
Medium (6.4)
CVE-2024-2734
Patched
Apr 9, 2024
Bold Page Builder
Bold Page Builder <= 4.8.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags
Medium (6.4)
CVE-2024-2736
Patched
Apr 9, 2024
Bold Page Builder
Medium (6.4)
CVE-2024-32147
Patched
Apr 12, 2024
Contact Form Plugin
Medium (6.4)
CVE-2024-2655
Patched
Apr 9, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-2539
Patched
Apr 9, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-3053
Patched
Apr 8, 2024
Forminator – Contact Form, Payment Form & Custom Form Builder
Medium (6.4)
CVE-2024-1957
Patched
Apr 12, 2024
GiveWP – Donation Plugin and Fundraising Platform
Medium (6.4)
Unknown
Patched
Apr 9, 2024
Gutenberg
Medium (6.4)
CVE-2024-3670
Patched
Apr 8, 2024
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
Medium (6.4)
CVE-2024-32140
Unpatched
Apr 12, 2024
Libsyn Publisher Hub
Medium (6.4)
CVE-2024-3167
Patched
Apr 8, 2024
Ocean Extra
Medium (6.4)
CVE-2024-3344
Patched
Apr 10, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-3343
Patched
Apr 10, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-2867
Patched
Apr 11, 2024
Medium (6.4)
CVE-2024-3210
Patched
Apr 9, 2024
Medium (6.4)
CVE-2024-0376
Patched
Apr 9, 2024
Premium Addons for Elementor
Premium Addons for Elementor <= 4.10.24 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-2664
Patched
Apr 9, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-2306
Patched
Apr 8, 2024
Slider Revolution
Medium (6.4)
CVE-2024-2801
Unpatched
Apr 11, 2024
Shopkeeper Extender
Medium (6.4)
CVE-2024-3285
Patched
Apr 10, 2024
Medium (6.4)
CVE-2024-3027
Patched
Apr 12, 2024
Smart Slider 3
Medium (6.4)
CVE-2024-31357
Patched
Apr 8, 2024
Medium (6.4)
CVE-2024-1041
Unpatched
Apr 9, 2024
WP Radio – Worldwide Online Radio Stations Directory for WordPress
Medium (6.4)
CVE-2024-1042
Unpatched
Apr 9, 2024
WP Radio – Worldwide Online Radio Stations Directory for WordPress
Medium (6.4)
CVE-2024-1805
Patched
Apr 11, 2024
WPBakery Visual Composer
Medium (6.4)
CVE-2024-1842
Patched
Apr 11, 2024
WPBakery Visual Composer
Medium (6.4)
CVE-2024-1840
Patched
Apr 11, 2024
WPBakery Visual Composer
Medium (6.4)
CVE-2024-1841
Patched
Apr 11, 2024
WPBakery Visual Composer
Medium (6.1)
CVE-2024-1780
Unpatched
Apr 9, 2024
BizCalendar Web
Medium (6.1)
CVE-2024-32133
Unpatched
Apr 12, 2024
EZ Form Calculator
Medium (6.1)
CVE-2024-32129
Unpatched
Apr 12, 2024
Freshdesk (official)
Medium (6.1)
CVE-2024-32149
Patched
Apr 12, 2024
Jobs for WordPress
Medium (6.1)
CVE-2024-31365
Unpatched
Apr 9, 2024
Post Type Builder
Medium (6.1)
CVE-2024-32138
Unpatched
Apr 12, 2024
Short URL
Medium (6.1)
CVE-2024-32145
Patched
Apr 12, 2024
Medium (5.8)
CVE-2024-32107
Patched
Apr 11, 2024
Finale Lite – Sales Countdown Timer & Discount for WooCommerce
Medium (5.5)
CVE-2024-32430
Patched
Apr 12, 2024
ActiveCampaign – Forms, Site Tracking, Live Chat
Medium (5.5)
CVE-2024-32454
Unpatched
Apr 12, 2024
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
Medium (5.4)
CVE-2024-2733
Patched
Apr 9, 2024
Bold Page Builder
Medium (5.4)
CVE-2024-32078
Patched
Apr 11, 2024
FV Flowplayer Video Player
Medium (5.4)
CVE-2024-2666
Patched
Apr 9, 2024
Premium Addons for Elementor
Medium (5.4)
CVE-2024-2765
Patched
Apr 10, 2024
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Medium (5.4)
CVE-2024-31943
Patched
Apr 10, 2024
USPS Shipping for WooCommerce – Live Rates
Medium (5.4)
CVE-2024-32144
Patched
Apr 12, 2024
Welcart e-Commerce
Medium (5.3)
CVE-2024-31358
Patched
Apr 8, 2024
5 star review funnel for Google Reviews, Trustpilot, ProvenExpert and more | RRatingg
Medium (5.3)
CVE-2024-0908
Unpatched
Apr 11, 2024
Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page
Medium (5.3)
CVE-2024-31430
Patched
Apr 10, 2024
Medium (5.3)
CVE-2024-31932
Patched
Apr 10, 2024
Blocksy Companion
Medium (5.3)
CVE-2024-32131
Patched
Apr 12, 2024
Download Manager
Medium (5.3)
CVE-2024-2966
Patched
Apr 10, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (5.3)
CVE-2024-32105
Patched
Apr 11, 2024
ELEX WooCommerce Dynamic Pricing and Discounts
Medium (5.3)
CVE-2024-3235
Patched
Apr 9, 2024
Essential Grid Gallery WordPress Plugin
Medium (5.3)
CVE-2024-0710
Patched
Apr 10, 2024
GP Unique ID
Medium (5.3)
CVE-2024-32112
Unpatched
Apr 11, 2024
Leadinfo
Medium (5.3)
CVE-2024-31359
Patched
Apr 8, 2024
Premmerce Product Filter for WooCommerce
Medium (5.3)
CVE-2024-31432
Patched
Apr 10, 2024
Membership Plugin – Restrict Content
Medium (5.3)
CVE-2024-31368
Patched
Apr 9, 2024
Soledad
Medium (4.4)
CVE-2024-31926
Patched
Apr 10, 2024
Advanced Cron Manager – debug & control
Medium (4.4)
CVE-2024-31361
Patched
Apr 8, 2024
bunny.net – WordPress CDN Plugin
Medium (4.4)
CVE-2024-3703
Patched
Apr 12, 2024
Carousel Slider
Medium (4.4)
CVE-2024-32083
Unpatched
Apr 11, 2024
Medium (4.4)
CVE-2024-31925
Patched
Apr 10, 2024
F4 Improvements
Medium (4.4)
CVE-2024-31929
Patched
Apr 10, 2024
Intagrate Lite
Medium (4.4)
CVE-2024-32428
Patched
Apr 12, 2024
MWW Disclaimer Buttons
Medium (4.4)
CVE-2024-32453
Patched
Apr 12, 2024
POEditor
Medium (4.4)
CVE-2024-31387
Patched
Apr 10, 2024
Popup Like box – Page Plugin
Medium (4.4)
CVE-2024-32429
Patched
Apr 12, 2024
Remove Footer Credit
Medium (4.4)
CVE-2024-31931
Patched
Apr 10, 2024
Save as Image Plugin by Pdfcrowd
Medium (4.4)
CVE-2024-32080
Unpatched
Apr 11, 2024
Search Keyword Redirect
Medium (4.4)
CVE-2024-31928
Patched
Apr 10, 2024
Top Bar
Medium (4.4)
CVE-2024-31937
Patched
Apr 10, 2024
Medium (4.4)
CVE-2024-31927
Patched
Apr 10, 2024
WP Login and Logout Redirect
Medium (4.4)
CVE-2023-6494
Patched
Apr 12, 2024
WPC Smart Quick View for WooCommerce
Medium (4.3)
CVE-2024-32448
Unpatched
Apr 12, 2024
Ads.txt Admin
Medium (4.3)
CVE-2024-32435
Patched
Apr 12, 2024
AffiEasy
Medium (4.3)
CVE-2024-31425
Patched
Apr 10, 2024
Booking for Appointments and Events Calendar – Amelia
Medium (4.3)
CVE-2024-31374
Patched
Apr 10, 2024
AppPresser – Mobile App Framework
Medium (4.3)
CVE-2024-32110
Patched
Apr 11, 2024
Subscribe2 – Form, Email Subscribers & Newsletters
Table Plugin for WordPress with Google Sheets Integration – Sheets to WP Table Live Sync
Dashboard Welcome for Elementor
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]
Load More Anything
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin
TempTool [Show Current Template Info]
Exclusive Addons for Elementor
TOP Table Of Contents
Better Chat Support – Chat Bubble and Chat Button with Gutenberg, Elementor and Shortcode
and 3 more…
Medium (4.3)
CVE-2024-32440
Patched
Apr 12, 2024
Asgaros Forum
Medium (4.3)
CVE-2024-32146
Unpatched
Apr 12, 2024
Aspose.Words – Import and Export word documents
Medium (4.3)
CVE-2024-32447
Patched
Apr 12, 2024
Medium (4.3)
CVE-2024-32433
Patched
Apr 12, 2024
Ultimate Before After Image Slider & Gallery – BEAF
Medium (4.3)
CVE-2024-32084
Unpatched
Apr 11, 2024
Before And After: Lead Capture Forms For WordPress
Medium (4.3)
CVE-2024-31360
Patched
Apr 8, 2024
Benchmark Email Lite
Medium (4.3)
CVE-2024-31382
Patched
Apr 10, 2024
Blocksy
Medium (4.3)
CVE-2024-31942
Patched
Apr 10, 2024
Calendarista Basic Edition – WordPress appointment booking system
Medium (4.3)
CVE-2024-32090
Patched
Apr 11, 2024
Church Admin
Church Content – Sermons, Events and More <= 2.6 – Cross-Site Request Forgery to Notice Dismissal
Medium (4.3)
CVE-2024-32094
Patched
Apr 11, 2024
Church Content – Sermons, Events and More
Medium (4.3)
CVE-2024-32085
Unpatched
Apr 11, 2024
Citadela Directory
Medium (4.3)
CVE-2024-32088
Patched
Apr 11, 2024
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
Medium (4.3)
CVE-2024-32108
Unpatched
Apr 11, 2024
Convert Post Types
Medium (4.3)
CVE-2024-32102
Unpatched
Apr 11, 2024
Crony Cronjob Manager
Medium (4.3)
CVE-2024-31920
Patched
Apr 10, 2024
Currency per Product for WooCommerce
Medium (4.3)
CVE-2024-31376
Patched
Apr 10, 2024
Dashboard To-Do List
Medium (4.3)
CVE-2024-32089
Patched
Apr 11, 2024
WordPress Flipbook by Supsystic
Medium (4.3)
CVE-2024-32443
Patched
Apr 12, 2024
IP2Location Country Blocker
Medium (4.3)
CVE-2024-31373
Patched
Apr 10, 2024
E2Pdf – Export To Pdf Tool for WordPress
Medium (4.3)
CVE-2024-32437
Patched
Apr 12, 2024
eCommerce Product Catalog Plugin for WordPress
Medium (4.3)
CVE-2024-31364
Patched
Apr 8, 2024
ELEX WooCommerce Dynamic Pricing and Discounts
Medium (4.3)
CVE-2024-32101
Patched
Apr 11, 2024
Email Marketing for WooCommerce by Omnisend
Medium (4.3)
CVE-2024-3275
Patched
Apr 12, 2024
eRoom – Zoom Meetings & Webinars
Medium (4.3)
CVE-2024-31940
Patched
Apr 10, 2024
Extra Product Options Builder for WooCommerce
Medium (4.3)
CVE-2024-31422
Patched
Apr 10, 2024
Favicon by RealFaviconGenerator
Medium (4.3)
CVE-2024-31923
Patched
Apr 10, 2024
Medium (4.3)
CVE-2024-32081
Unpatched
Apr 11, 2024
Filter Custom Fields & Taxonomies Light
Medium (4.3)
CVE-2024-32097
Patched
Apr 11, 2024
GEO my WordPress
Medium (4.3)
CVE-2024-32436
Patched
Apr 12, 2024
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Import any XML or CSV File to WordPress <= 3.7.3 – Cross-Site Request Forgery to Notice Dismissal
Medium (4.3)
CVE-2024-31939
Patched
Apr 10, 2024
Import any XML or CSV File to WordPress
Medium (4.3)
CVE-2024-31435
Patched
Apr 10, 2024
Medium (4.3)
CVE-2024-31426
Patched
Apr 10, 2024
Inline Related Posts
Medium (4.3)
CVE-2024-3233
Patched
Apr 12, 2024
Ivory Search – WordPress Search Plugin
Medium (4.3)
CVE-2024-32092
Unpatched
Apr 11, 2024
Kimili Flash Embed
Medium (4.3)
CVE-2024-32451
Patched
Apr 12, 2024
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
Medium (4.3)
CVE-2024-32141
Unpatched
Apr 12, 2024
Libsyn Publisher Hub
Medium (4.3)
CVE-2024-31363
Patched
Apr 8, 2024
LifterLMS – WordPress LMS Plugin for eLearning
Medium (4.3)
CVE-2024-31934
Patched
Apr 10, 2024
Link Whisper Free
Medium (4.3)
CVE-2024-30546
Patched
Apr 10, 2024
Login With Ajax – Fast Logins, 2FA, Redirects
Medium (4.3)
CVE-2024-31424
Patched
Apr 10, 2024
Login with phone number
Medium (4.3)
CVE-2024-31378
Patched
Apr 10, 2024
MailChimp Forms by MailMunch
Medium (4.3)
CVE-2024-31427
Patched
Apr 10, 2024
Marker.io – Visual Website Feedback
Medium (4.3)
CVE-2024-31389
Patched
Apr 10, 2024
MihanPanel – User Login , Registration and Dashboard
Medium (4.3)
CVE-2024-32095
Patched
Apr 11, 2024
MultiParcels Shipping For WooCommerce
Medium (4.3)
CVE-2024-31386
Patched
Apr 10, 2024
Sliding Door
CityLogic
Lightning
i-max
Default Mag
Shopstar!
HappenStance
Emmet Lite
X-T9
i-excel
and 5 more…
Medium (4.3)
CVE-2024-31434
Patched
Apr 10, 2024
Newsletter – Send awesome emails from WordPress
Medium (4.3)
CVE-2024-31938
Patched
Apr 10, 2024
NewsXpress
Medium (4.3)
CVE-2024-32104
Patched
Apr 11, 2024
NextMove Lite – Thank You Page for WooCommerce
Medium (4.3)
CVE-2024-31372
Patched
Apr 9, 2024
No-Bot Registration
Medium (4.3)
CVE-2024-32093
Patched
Apr 11, 2024
Novelist
Medium (4.3)
CVE-2024-32434
Patched
Apr 12, 2024
Order Delivery Date for WooCommerce
Medium (4.3)
CVE-2024-32432
Unpatched
Apr 12, 2024
Ovic Addon Toolkit
Medium (4.3)
CVE-2024-31933
Patched
Apr 10, 2024
Page Builder: Live Composer
Medium (4.3)
CVE-2024-32148
Patched
Apr 12, 2024
Account Engagement
Medium (4.3)
CVE-2024-32143
Patched
Apr 12, 2024
Podlove Podcast Publisher
Medium (4.3)
CVE-2024-31383
Patched
Apr 10, 2024
PopularFX
Medium (4.3)
CVE-2024-31421
Patched
Apr 10, 2024
Popup by Supsystic
Medium (4.3)
CVE-2024-31366
Unpatched
Apr 9, 2024
Post Type Builder
Medium (4.3)
CVE-2024-31431
Patched
Apr 10, 2024
Product Input Fields for WooCommerce
Medium (4.3)
CVE-2024-31362
Patched
Apr 8, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Medium (4.3)
CVE-2024-31385
Patched
Apr 10, 2024
ReDi Restaurant Reservation
Medium (4.3)
CVE-2024-1415
Unpatched
Apr 11, 2024
Responsive Contact Form Builder & Lead Generation Plugin
Medium (4.3)
CVE-2024-1416
Unpatched
Apr 11, 2024
Responsive Contact Form Builder & Lead Generation Plugin
RestroPress <= 3.1.2 – Cross-Site Request Forgery via rpress_orders_list_table_process_bulk_actions
Medium (4.3)
CVE-2024-32449
Patched
Apr 12, 2024
RestroPress – Online Food Ordering System
Medium (4.3)
CVE-2024-32091
Unpatched
Apr 11, 2024
Responsive Slider – Sangar Slider
Medium (4.3)
CVE-2024-31429
Patched
Apr 10, 2024
Sarada Lite
Medium (4.3)
CVE-2024-32438
Patched
Apr 12, 2024
SEO Booster
Medium (4.3)
CVE-2024-31935
Patched
Apr 10, 2024
Simple Post Notes
Medium (4.3)
CVE-2024-32103
Patched
Apr 11, 2024
Siteimprove
Medium (4.3)
CVE-2024-31379
Patched
Apr 10, 2024
Smash Balloon Social Post Feed
Medium (4.3)
CVE-2024-31369
Patched
Apr 9, 2024
Soledad
Medium (4.3)
CVE-2024-31367
Patched
Apr 9, 2024
Soledad
Medium (4.3)
CVE-2024-31384
Patched
Apr 10, 2024
Spa and Salon
Medium (4.3)
CVE-2024-31381
Patched
Apr 10, 2024
Spotlight Social Feeds [Block, Shortcode, and Widget]
Medium (4.3)
CVE-2024-32082
Unpatched
Apr 11, 2024
Sync Post With Other Site
Medium (4.3)
CVE-2024-31388
Patched
Apr 10, 2024
Medium (4.3)
CVE-2024-31428
Patched
Apr 10, 2024
The Conference
Medium (4.3)
CVE-2024-31433
Patched
Apr 10, 2024
The Events Calendar
Medium (4.3)
CVE-2024-31921
Patched
Apr 10, 2024
Ultimate Product Catalog
Medium (4.3)
CVE-2024-31936
Patched
Apr 10, 2024
Medium (4.3)
CVE-2024-32446
Patched
Apr 12, 2024
Medium (4.3)
CVE-2024-32445
Patched
Apr 12, 2024
Medium (4.3)
CVE-2024-31944
Patched
Apr 11, 2024
WooCommerce UPS Shipping – Live Rates and Access Points
Medium (4.3)
CVE-2024-31922
Patched
Apr 10, 2024
WordPress Hosting Benchmark tool
Medium (4.3)
CVE-2024-31423
Patched
Apr 10, 2024
WP Accessibility Helper (WAH)
Medium (4.3)
CVE-2024-32439
Patched
Apr 12, 2024
WP Client Reports
Medium (4.3)
CVE-2024-32106
Patched
Apr 11, 2024
WP Compress – Image Optimizer [All-In-One]
Medium (4.3)
CVE-2024-32452
Patched
Apr 12, 2024
Shopping Cart & eCommerce Store
Medium (4.3)
CVE-2024-31371
Patched
Apr 9, 2024
Medium (4.3)
CVE-2024-32099
Patched
Apr 11, 2024
Mail logging – WP Mail Catcher
Medium (4.3)
CVE-2024-32109
Unpatched
Apr 11, 2024
WP Matterport Shortcode
Medium (4.3)
CVE-2024-31375
Patched
Apr 8, 2024
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden
Medium (4.3)
CVE-2024-32450
Patched
Apr 12, 2024
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly
Medium (4.3)
CVE-2024-3662
Patched
Apr 12, 2024
WPZOOM Social Feed Widget & Block
Medium (4.3)
CVE-2024-32442
Patched
Apr 12, 2024
Zoho Campaigns
Medium (4.3)
CVE-2024-32441
Patched
Apr 12, 2024
Zoho Campaigns
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (April 8, 2024 to April 14, 2024) appeared first on Wordfence.