Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 Active Installs are in scope for all researchers. In addition, through October 14th, 2024, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Last week, there were 145 vulnerabilities disclosed in 100 WordPress Plugins and 23 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 91
Unpatched 54

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 118
High Severity 14
Critical Severity 13

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) 70
Missing Authorization 27
Cross-Site Request Forgery (CSRF) 13
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) 10
Deserialization of Untrusted Data 6
Information Exposure 6
Use of Less Trusted Source 3
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) 2
Argument Injection or Modification 1
Authorization Bypass Through User-Controlled Key 1
Improper Authorization 1
Improper Control of Generation of Code (‘Code Injection’) 1
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) 1
Protection Mechanism Failure 1
Server-Side Request Forgery (SSRF) 1
Unrestricted Upload of File with Dangerous Type 1

Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
19
9
9
8
7
6
6
6
5
5
4
4
3
3

Seb

3
3
3
3
3
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
140+ Widgets | Xpro Addons For Elementor – FREE xpro-elementor-addons
Animated Number Counters animated-number-counters
azurecurve Toggle Show/Hide azurecurve-toggle-showhide
Beaver Builder – WordPress Page Builder beaver-builder-lite-version
Brickscore brickscore
Bus Ticket Booking with Seat Reservation – WpBusTicketly | WordPress plugin bus-ticket-booking-with-seat-reservation
Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons
Clean Login clean-login
Collapsing Archives collapsing-archives
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder fluentform
Custom Query Blocks post-type-archive-mapping
Droip droip
DSGVO All in one for WP dsgvo-all-in-one-for-wp
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg easyjobs
Elementor Addon Elements addon-elements-for-elementor-page-builder
Email Address Encoder email-address-encoder
EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor embedpress
Enhanced Search Box extended-search-plugin
EU/UK VAT Manager for WooCommerce eu-vat-for-woocommerce
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms happyforms
Front End Users front-end-only-users
FunnelKit Funnel Builder Pro funnel-builder-pro
Gallery Plugin for WordPress – Envira Photo Gallery envira-gallery-lite
Generate Images – Magic Post Thumbnail magic-post-thumbnail
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory
GHActivity ghactivity
GiveWP – Donation Plugin and Fundraising Platform give
Greenshift Query and Meta Addon greenshiftquery
Gutenverse – Ultimate Block Addons and Page Builder for Site Editor gutenverse
HelloAsso helloasso
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics leadin
infolinks Ad Wrap infolinks-ad-wrap
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free funnelforms-free
Jeg Elementor Kit jeg-elementor-kit
JobSearch WP Job Board wp-jobsearch
Justified Image Grid – Premium WordPress Gallery justified-image-grid
LatePoint Plugin LatePoint
Like Button Rating ♥ LikeBtn likebtn-like-button
Login As Users login-as-users
Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid logo-showcase-ultimate
Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation
Media Library Folders media-library-plus
Memberpress memberpress
Mollie Payments for WooCommerce mollie-payments-for-woocommerce
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar mp3-music-player-by-sonaar
Name Directory name-directory
Ninja Forms – The Contact Form Builder That Grows With You ninja-forms
Ninja Tables – Easiest Data Table Builder ninja-tables
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN nitropack
Oxygen Builder oxygenbuilder
Page Builder: Pagelayer – Drag and Drop website builder pagelayer
Payment forms, Buy now buttons, and Invoicing System | GetPaid invoicing
Permalink Manager Lite permalink-manager
Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress
Popup Builder – Create highly converting, mobile friendly marketing popups. popup-builder
Premium Portfolio Features for Phlox theme auxin-portfolio
Premium SEO Pack – WP SEO Plugin premium-seo-pack
Propovoice Pro propovoice-pro
Relevanssi Live Ajax Search relevanssi-live-ajax-search
Review Ratings ratings-shorttags
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More reviews-feed
Royal Elementor Addons and Templates royal-elementor-addons
SendGrid for WordPress wp-sendgrid-mailer
Share This Image share-this-image
SKT Blocks – Gutenberg based Page Builder skt-blocks
Special Feed Items special-feed-items
Sunshine Photo Cart: Free Client Photo Galleries for Photographers sunshine-photo-cart
Super Store Finder superstorefinder-wp
Super Testimonials super-testimonial
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments surecart
tagDiv Composer td-composer
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab ecab-taxi-booking-manager
The Events Calendar Pro events-calendar-pro
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce the-plus-addons-for-elementor-page-builder
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid the-post-grid
Theme Editor theme-editor
Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking tourfic
Tutor LMS Pro tutor-pro
Two-factor authentication (formerly IP Vault) ip-vault-wp-firewall
Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider ultimate-store-kit
Vikinghammer Tweet vikinghammer-tweet
Visual CSS Style Editor yellow-pencil-visual-theme-customizer
Visual Sound (old) visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams
Web and WooCommerce Addons for WPBakery Builder vc-addons-by-bit14
Web Application Firewall – website security web-application-firewall
Woocommerce Addon Greenshift greenshiftwoo
WP Accessibility Helper (WAH) wp-accessibility-helper
WP Armour Extended wp-armour-extended
WP Booking Calendar booking
WP Cerber Security, Anti-spam & Malware Scan wp-cerber
WP Crowdfunding wp-crowdfunding
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) delicious-recipes
WP Events Manager wp-events-manager
WP Testimonial Widget wp-testimonial-widget
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics
WP To Do wp-todo
WPMobile.App — Android and iOS Mobile Application wpappninja
WPZOOM Portfolio Lite – Filterable Portfolio Plugin wpzoom-portfolio
YARPP – Yet Another Related Posts Plugin yet-another-related-posts-plugin
Zynith SEO zynith-seo

WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Attire attire
Betheme betheme
Blockbooster blockbooster
Blogpoet blogpoet
Enfold – Responsive Multi-Purpose Theme enfold
Esotera esotera
Filmix filmix
Fluida fluida
FotaWP fotawp
Hotel Galaxy hotel-galaxy
IntoTheDark intothedark
Kahuna kahuna
Liquido liquido
Mantra mantra
Masterstudy – Education WordPress Theme ms-lms-starter-theme
Mystique mystique
Nirvana nirvana
Opor Ayam opor-ayam
Parabola parabola
Posterity posterity
ReviveNews revivenews
Sliding Door sliding-door
Tempera tempera

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43931
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
JobSearch WP Job Board
Researcher

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43941
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Propovoice Pro
Researcher

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43965
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
SendGrid for WordPress
Researcher

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43978
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Super Store Finder
Researcher

CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43942
Patch Status
Patched
Published
Aug 26, 2024

Researcher

CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43976
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Super Store Finder
Researcher

CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43943
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Woocommerce Addon Greenshift
Researcher

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-7857
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Media Library Folders
Researcher

CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-8016
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
The Events Calendar Pro
Researcher

CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-43966
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
WP Testimonial Widget
Researcher

CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-43939
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Zynith SEO
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43957
Patch Status
Unpatched
Published
Aug 26, 2024

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7435
Patch Status
Patched
Published
Aug 30, 2024

Affected Software
Attire
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-2694
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Betheme
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-8252
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Clean Login
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7607
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Front End Users
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43982
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Login As Users
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43984
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Podlove Podcast Publisher
Researcher

CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7717
Patch Status
Patched
Published
Aug 30, 2024

Affected Software
WP Events Manager
Researcher

CVSS Rating
High (7.2)
CVE-ID
CVE-2024-43950
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Brickscore
Researcher

CVSS Rating
High (7.2)
CVE-ID
CVE-2024-43975
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Super Store Finder
Researcher

CVSS Rating
High (7.2)
CVE-ID
CVE-2022-2440
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Theme Editor
Researcher

CVSS Rating
High (7.1)
CVE-ID
CVE-2024-5784
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Tutor LMS Pro
Researcher

CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-43989
Patch Status
Unpatched
Published
Aug 29, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43961
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
azurecurve Toggle Show/Hide
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7895
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-3998
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Betheme
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43953
Patch Status
Unpatched
Published
Aug 26, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43934
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Collapsing Archives

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44059
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Custom Query Blocks

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43964
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
DSGVO All in one for WP

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-4401
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Elementor Addon Elements
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7122
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Elementor Addon Elements
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-5061
Patch Status
Unpatched
Published
Aug 29, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43952
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Esotera
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44054
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Fluida
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7606
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Front End Users
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-1056
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
FunnelKit Funnel Builder Pro
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43949
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
GHActivity
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43991
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Hotel Galaxy
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-6804
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Jeg Elementor Kit
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43994
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Kahuna
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43992
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
LatePoint Plugin
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43993
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Liquido
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44056
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Mantra
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43988
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Mystique
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44057
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Nirvana
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44058
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Parabola
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43983
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
Podlove Podcast Publisher
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43995
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Posterity
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-1384
Patch Status
Unpatched
Published
Aug 28, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44001
Patch Status
Patched
Published
Aug 29, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-8108
Patch Status
Patched
Published
Aug 30, 2024

Affected Software
Share This Image
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43946
Patch Status
Unpatched
Published
Aug 26, 2024

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43987
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Sliding Door
Researcher

CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43951
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Tempera
Researcher

CVSS Rating
Medium (6.3)
CVE-ID
CVE-2024-7858
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Media Library Folders
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43926
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43997
Patch Status
Patched
Published
Aug 29, 2024

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44061
Patch Status
Unpatched
Published
Aug 29, 2024

Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44060
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Filmix
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43958
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
IntoTheDark
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44064
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Like Button Rating LikeBtn
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43921
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-5024
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Memberpress
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43938
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Name Directory
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44053
Patch Status
Unpatched
Published
Aug 29, 2024

Affected Software
Opor Ayam
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8052
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
Review Ratings
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8051
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
Special Feed Items
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43971
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-5212
Patch Status
Patched
Published
Aug 30, 2024

Affected Software
tagDiv Composer
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-3886
Patch Status
Patched
Published
Aug 30, 2024

Affected Software
tagDiv Composer
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43959
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Super Testimonials
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8043
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
Vikinghammer Tweet
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43948
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
WP Armour Extended
Researcher

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8274
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
WP Booking Calendar

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43933
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43963
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Visual CSS Style Editor
Researcher

CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-5987
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
WP Accessibility Helper (WAH)
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43979
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43998
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
Blogpoet

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43980
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
FotaWP

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-6551
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4536
Patch Status
Patched
Published
Aug 30, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43929
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
JobSearch WP Job Board
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43944
Patch Status
Unpatched
Published
Aug 26, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43990
Patch Status
Patched
Published
Aug 29, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43956
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Memberpress
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-6448
Patch Status
Patched
Published
Aug 27, 2024

Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-8195
Patch Status
Patched
Published
Aug 27, 2024

Affected Software
Permalink Manager Lite
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-2541
Patch Status
Unpatched
Published
Aug 28, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-3679
Patch Status
Unpatched
Published
Aug 28, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-7573
Patch Status
Patched
Published
Aug 27, 2024

Affected Software
Relevanssi Live Ajax Search
Researcher

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43974
Patch Status
Patched
Published
Aug 28, 2024

Affected Software
ReviveNews

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43923
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4539
Patch Status
Patched
Published
Aug 30, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4100
Patch Status
Patched
Published
Aug 30, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43937
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43919
Patch Status
Unpatched
Published
Aug 26, 2024

CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43940
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Zynith SEO
Researcher

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43999
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43972
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43967
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
WP Testimonial Widget
Researcher

CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-3944
Patch Status
Unpatched
Published
Aug 28, 2024

Affected Software
WP To Do

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43954
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
Droip
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43927
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Email Address Encoder
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8091
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
Enhanced Search Box
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43925
Patch Status
Patched
Published
Aug 26, 2024

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43973
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-44052
Patch Status
Patched
Published
Aug 29, 2024

Affected Software
HelloAsso

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8044
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
infolinks Ad Wrap
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43930
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
JobSearch WP Job Board
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43928
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
JobSearch WP Job Board
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43945
Patch Status
Unpatched
Published
Aug 26, 2024

Affected Software
LatePoint Plugin
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-6688
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
Oxygen Builder
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-7418
Patch Status
Patched
Published
Aug 28, 2024

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8319
Patch Status
Patched
Published
Aug 29, 2024

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8047
Patch Status
Unpatched
Published
Aug 27, 2024

Affected Software
Visual Sound (old)
Researcher

CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43947
Patch Status
Patched
Published
Aug 26, 2024

Affected Software
WP Armour Extended
Researcher


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024) appeared first on Wordfence.

More great articles

Critical Vulnerabilities Patched in Adning Advertising Plugin

On June 24, 2020, our Threat Intelligence team was made aware of a possible vulnerability in the Adning Advertising plugin,…

Read Story

Over 40,000 WordPress Sites Affected by Privilege Escalation Vulnerability Patched in Post Grid and Gutenberg Blocks Plugin

📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to…

Read Story

Multiple Vulnerabilities Patched in Shield Security

On March 20, 2023, the Wordfence Threat Intelligence team began the responsible disclosure process for two vulnerabilities in Shield Security,…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.