Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 Active Installs are in scope for all researchers. In addition, through October 14th, 2024, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 145 vulnerabilities disclosed in 100 WordPress Plugins and 23 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 – Missing Authorization to Arbitrary Vendor Creation/Update/Deletion
- WAF-RULE-729 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-730 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-731 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-733 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 91 |
Unpatched | 54 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 118 |
High Severity | 14 |
Critical Severity | 13 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 70 |
Missing Authorization | 27 |
Cross-Site Request Forgery (CSRF) | 13 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 10 |
Deserialization of Untrusted Data | 6 |
Information Exposure | 6 |
Use of Less Trusted Source | 3 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 2 |
Argument Injection or Modification | 1 |
Authorization Bypass Through User-Controlled Key | 1 |
Improper Authorization | 1 |
Improper Control of Generation of Code (‘Code Injection’) | 1 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 1 |
Protection Mechanism Failure | 1 |
Server-Side Request Forgery (SSRF) | 1 |
Unrestricted Upload of File with Dangerous Type | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
19 | |
9 | |
9 | |
8 | |
7 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
140+ Widgets | Xpro Addons For Elementor – FREE | xpro-elementor-addons |
Animated Number Counters | animated-number-counters |
azurecurve Toggle Show/Hide | azurecurve-toggle-showhide |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Brickscore | brickscore |
Bus Ticket Booking with Seat Reservation – WpBusTicketly | WordPress plugin | bus-ticket-booking-with-seat-reservation |
Classic Addons – WPBakery Page Builder | classic-addons-wpbakery-page-builder-addons |
Clean Login | clean-login |
Collapsing Archives | collapsing-archives |
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | fluentform |
Custom Query Blocks | post-type-archive-mapping |
Droip | droip |
DSGVO All in one for WP | dsgvo-all-in-one-for-wp |
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg | easyjobs |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
Email Address Encoder | email-address-encoder |
EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor | embedpress |
Enhanced Search Box | extended-search-plugin |
EU/UK VAT Manager for WooCommerce | eu-vat-for-woocommerce |
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms | happyforms |
Front End Users | front-end-only-users |
FunnelKit Funnel Builder Pro | funnel-builder-pro |
Gallery Plugin for WordPress – Envira Photo Gallery | envira-gallery-lite |
Generate Images – Magic Post Thumbnail | magic-post-thumbnail |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | geodirectory |
GHActivity | ghactivity |
GiveWP – Donation Plugin and Fundraising Platform | give |
Greenshift Query and Meta Addon | greenshiftquery |
Gutenverse – Ultimate Block Addons and Page Builder for Site Editor | gutenverse |
HelloAsso | helloasso |
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics | leadin |
infolinks Ad Wrap | infolinks-ad-wrap |
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | funnelforms-free |
Jeg Elementor Kit | jeg-elementor-kit |
JobSearch WP Job Board | wp-jobsearch |
Justified Image Grid – Premium WordPress Gallery | justified-image-grid |
LatePoint Plugin | LatePoint |
Like Button Rating LikeBtn | likebtn-like-button |
Login As Users | login-as-users |
Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | logo-showcase-ultimate |
Maintenance & Coming Soon Redirect Animation | maintenance-coming-soon-redirect-animation |
Media Library Folders | media-library-plus |
Memberpress | memberpress |
Mollie Payments for WooCommerce | mollie-payments-for-woocommerce |
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar | mp3-music-player-by-sonaar |
Name Directory | name-directory |
Ninja Forms – The Contact Form Builder That Grows With You | ninja-forms |
Ninja Tables – Easiest Data Table Builder | ninja-tables |
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN | nitropack |
Oxygen Builder | oxygenbuilder |
Page Builder: Pagelayer – Drag and Drop website builder | pagelayer |
Payment forms, Buy now buttons, and Invoicing System | GetPaid | invoicing |
Permalink Manager Lite | permalink-manager |
Podlove Podcast Publisher | podlove-podcasting-plugin-for-wordpress |
Popup Builder – Create highly converting, mobile friendly marketing popups. | popup-builder |
Premium Portfolio Features for Phlox theme | auxin-portfolio |
Premium SEO Pack – WP SEO Plugin | premium-seo-pack |
Propovoice Pro | propovoice-pro |
Relevanssi Live Ajax Search | relevanssi-live-ajax-search |
Review Ratings | ratings-shorttags |
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More | reviews-feed |
Royal Elementor Addons and Templates | royal-elementor-addons |
SendGrid for WordPress | wp-sendgrid-mailer |
Share This Image | share-this-image |
SKT Blocks – Gutenberg based Page Builder | skt-blocks |
Special Feed Items | special-feed-items |
Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
Super Store Finder | superstorefinder-wp |
Super Testimonials | super-testimonial |
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments | surecart |
tagDiv Composer | td-composer |
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab | ecab-taxi-booking-manager |
The Events Calendar Pro | events-calendar-pro |
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | the-plus-addons-for-elementor-page-builder |
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | the-post-grid |
Theme Editor | theme-editor |
Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking | tourfic |
Tutor LMS Pro | tutor-pro |
Two-factor authentication (formerly IP Vault) | ip-vault-wp-firewall |
Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider | ultimate-store-kit |
Vikinghammer Tweet | vikinghammer-tweet |
Visual CSS Style Editor | yellow-pencil-visual-theme-customizer |
Visual Sound (old) | visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams |
Web and WooCommerce Addons for WPBakery Builder | vc-addons-by-bit14 |
Web Application Firewall – website security | web-application-firewall |
Woocommerce Addon Greenshift | greenshiftwoo |
WP Accessibility Helper (WAH) | wp-accessibility-helper |
WP Armour Extended | wp-armour-extended |
WP Booking Calendar | booking |
WP Cerber Security, Anti-spam & Malware Scan | wp-cerber |
WP Crowdfunding | wp-crowdfunding |
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) | delicious-recipes |
WP Events Manager | wp-events-manager |
WP Testimonial Widget | wp-testimonial-widget |
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin | timetics |
WP To Do | wp-todo |
WPMobile.App — Android and iOS Mobile Application | wpappninja |
WPZOOM Portfolio Lite – Filterable Portfolio Plugin | wpzoom-portfolio |
YARPP – Yet Another Related Posts Plugin | yet-another-related-posts-plugin |
Zynith SEO | zynith-seo |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Attire | attire |
Betheme | betheme |
Blockbooster | blockbooster |
Blogpoet | blogpoet |
Enfold – Responsive Multi-Purpose Theme | enfold |
Esotera | esotera |
Filmix | filmix |
Fluida | fluida |
FotaWP | fotawp |
Hotel Galaxy | hotel-galaxy |
IntoTheDark | intothedark |
Kahuna | kahuna |
Liquido | liquido |
Mantra | mantra |
Masterstudy – Education WordPress Theme | ms-lms-starter-theme |
Mystique | mystique |
Nirvana | nirvana |
Opor Ayam | opor-ayam |
Parabola | parabola |
Posterity | posterity |
ReviveNews | revivenews |
Sliding Door | sliding-door |
Tempera | tempera |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-43931
Patched
Aug 26, 2024
JobSearch WP Job Board
Critical (10.0)
CVE-2024-43941
Unpatched
Aug 26, 2024
Propovoice Pro
Critical (10.0)
CVE-2024-43965
Unpatched
Aug 26, 2024
SendGrid for WordPress
Critical (10.0)
CVE-2024-43978
Patched
Aug 28, 2024
Super Store Finder
Critical (9.9)
CVE-2024-43942
Patched
Aug 26, 2024
Greenshift Query and Meta Addon
Critical (9.9)
CVE-2024-43976
Patched
Aug 28, 2024
Super Store Finder
Critical (9.9)
CVE-2024-43943
Patched
Aug 26, 2024
Woocommerce Addon Greenshift
Critical (9.8)
CVE-2024-7857
Patched
Aug 28, 2024
Media Library Folders
Critical (9.8)
CVE-2024-8030
Patched
Aug 27, 2024
Critical (9.1)
CVE-2024-7856
Patched
Aug 28, 2024
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
Critical (9.1)
CVE-2024-8016
Patched
Aug 29, 2024
The Events Calendar Pro
Critical (9.1)
CVE-2024-43966
Unpatched
Aug 26, 2024
WP Testimonial Widget
Critical (9.1)
CVE-2024-43939
Unpatched
Aug 26, 2024
Zynith SEO
High (8.8)
CVE-2024-43957
Unpatched
Aug 26, 2024
Animated Number Counters
High (8.8)
CVE-2024-7435
Patched
Aug 30, 2024
Attire
High (8.8)
CVE-2024-2694
Unpatched
Aug 29, 2024
Betheme
High (8.8)
CVE-2024-8252
Patched
Aug 29, 2024
Clean Login
High (8.8)
CVE-2024-7607
Patched
Aug 28, 2024
Front End Users
High (8.8)
CVE-2024-43982
Patched
Aug 28, 2024
Login As Users
High (8.8)
CVE-2024-43984
Patched
Aug 28, 2024
Podlove Podcast Publisher
High (8.8)
CVE-2024-7717
Patched
Aug 30, 2024
WP Events Manager
High (7.3)
CVE-2024-43922
Patched
Aug 26, 2024
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN
High (7.2)
CVE-2024-43950
Unpatched
Aug 26, 2024
Brickscore
High (7.2)
CVE-2024-6311
Patched
Aug 27, 2024
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
High (7.2)
CVE-2024-43975
Patched
Aug 28, 2024
Super Store Finder
High (7.2)
CVE-2022-2440
Patched
Aug 28, 2024
Theme Editor
High (7.1)
CVE-2024-5784
Patched
Aug 29, 2024
Tutor LMS Pro
Medium (6.5)
CVE-2024-6312
Patched
Aug 27, 2024
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
Medium (6.5)
CVE-2024-43989
Unpatched
Aug 29, 2024
Justified Image Grid – Premium WordPress Gallery
Medium (6.4)
CVE-2024-7791
Patched
Aug 26, 2024
140+ Widgets | Xpro Addons For Elementor – FREE
Medium (6.4)
CVE-2024-43961
Unpatched
Aug 26, 2024
azurecurve Toggle Show/Hide
Medium (6.4)
CVE-2024-7895
Patched
Aug 28, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-3998
Unpatched
Aug 29, 2024
Medium (6.4)
CVE-2024-43953
Unpatched
Aug 26, 2024
Classic Addons – WPBakery Page Builder
Medium (6.4)
CVE-2024-43934
Patched
Aug 26, 2024
Collapsing Archives
Medium (6.4)
CVE-2024-44059
Unpatched
Aug 29, 2024
Custom Query Blocks
Medium (6.4)
CVE-2024-43935
Patched
Aug 26, 2024
Medium (6.4)
CVE-2024-43964
Unpatched
Aug 26, 2024
DSGVO All in one for WP
Medium (6.4)
CVE-2024-4401
Patched
Aug 29, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-7122
Patched
Aug 29, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-43936
Patched
Aug 26, 2024
Medium (6.4)
CVE-2024-5061
Unpatched
Aug 29, 2024
Enfold – Responsive Multi-Purpose Theme
Medium (6.4)
CVE-2024-43952
Unpatched
Aug 26, 2024
Esotera
Medium (6.4)
CVE-2024-44054
Unpatched
Aug 29, 2024
Fluida
Front End Users <= 3.2.28 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2024-7606
Patched
Aug 28, 2024
Front End Users
Medium (6.4)
CVE-2024-1056
Patched
Aug 28, 2024
FunnelKit Funnel Builder Pro
Medium (6.4)
CVE-2024-43949
Unpatched
Aug 26, 2024
GHActivity
Medium (6.4)
CVE-2024-43920
Patched
Aug 26, 2024
Gutenverse – Ultimate Block Addons and Page Builder for Site Editor
Medium (6.4)
CVE-2024-44063
Patched
Aug 29, 2024
Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms
Medium (6.4)
CVE-2024-43991
Unpatched
Aug 29, 2024
Hotel Galaxy
Medium (6.4)
CVE-2024-5879
Patched
Aug 29, 2024
HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics
Medium (6.4)
CVE-2024-6804
Patched
Aug 26, 2024
Jeg Elementor Kit
Medium (6.4)
CVE-2024-43994
Unpatched
Aug 29, 2024
Kahuna
Medium (6.4)
CVE-2024-43992
Unpatched
Aug 29, 2024
LatePoint Plugin
Medium (6.4)
CVE-2024-43993
Unpatched
Aug 29, 2024
Liquido
Medium (6.4)
CVE-2024-8046
Patched
Aug 26, 2024
Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid
Medium (6.4)
CVE-2024-44056
Unpatched
Aug 29, 2024
Mantra
Medium (6.4)
CVE-2024-43988
Unpatched
Aug 29, 2024
Mystique
Medium (6.4)
CVE-2024-7304
Patched
Aug 26, 2024
Ninja Tables – Easiest Data Table Builder
Medium (6.4)
CVE-2024-44057
Unpatched
Aug 29, 2024
Nirvana
Medium (6.4)
CVE-2024-44058
Unpatched
Aug 29, 2024
Parabola
Medium (6.4)
CVE-2024-43983
Patched
Aug 28, 2024
Podlove Podcast Publisher
Medium (6.4)
CVE-2024-43995
Unpatched
Aug 29, 2024
Posterity
Medium (6.4)
CVE-2024-1384
Unpatched
Aug 28, 2024
Premium Portfolio Features for Phlox theme
Medium (6.4)
CVE-2024-44001
Patched
Aug 29, 2024
Royal Elementor Addons and Templates
Medium (6.4)
CVE-2024-8108
Patched
Aug 30, 2024
Share This Image
Medium (6.4)
CVE-2024-43946
Unpatched
Aug 26, 2024
SKT Blocks – Gutenberg based Page Builder
Medium (6.4)
CVE-2024-43987
Unpatched
Aug 29, 2024
Sliding Door
Medium (6.4)
CVE-2024-43951
Unpatched
Aug 26, 2024
Tempera
Medium (6.4)
CVE-2024-43977
Patched
Aug 28, 2024
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
Medium (6.4)
CVE-2024-8276
Patched
Aug 30, 2024
WPZOOM Portfolio Lite – Filterable Portfolio Plugin
Medium (6.3)
CVE-2024-7858
Patched
Aug 29, 2024
Media Library Folders
Medium (6.1)
CVE-2024-43926
Patched
Aug 26, 2024
Beaver Builder – WordPress Page Builder
Medium (6.1)
CVE-2024-43997
Patched
Aug 29, 2024
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg
Medium (6.1)
CVE-2024-44061
Unpatched
Aug 29, 2024
EU/UK VAT Manager for WooCommerce
Medium (6.1)
CVE-2024-44060
Unpatched
Aug 29, 2024
Filmix
Medium (6.1)
CVE-2024-43958
Unpatched
Aug 26, 2024
IntoTheDark
Medium (6.1)
CVE-2024-44064
Unpatched
Aug 29, 2024
Like Button Rating LikeBtn
Medium (6.1)
CVE-2024-43921
Patched
Aug 26, 2024
Generate Images – Magic Post Thumbnail
MemberPress <= 1.11.29 – Reflected Cross-Site Scripting via mepr_screenname and mepr_key Parameters
Medium (6.1)
CVE-2024-5024
Unpatched
Aug 29, 2024
Memberpress
Medium (6.1)
CVE-2024-43938
Patched
Aug 26, 2024
Name Directory
Medium (6.1)
CVE-2024-44053
Unpatched
Aug 29, 2024
Opor Ayam
Medium (6.1)
CVE-2024-8052
Unpatched
Aug 27, 2024
Review Ratings
Medium (6.1)
CVE-2024-8051
Unpatched
Aug 27, 2024
Special Feed Items
Medium (6.1)
CVE-2024-43971
Patched
Aug 28, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (6.1)
CVE-2024-43970
Patched
Aug 28, 2024
Medium (6.1)
CVE-2024-5212
Patched
Aug 30, 2024
tagDiv Composer
Medium (6.1)
CVE-2024-3886
Patched
Aug 30, 2024
tagDiv Composer
Medium (6.1)
CVE-2024-43959
Unpatched
Aug 26, 2024
Super Testimonials
Medium (6.1)
CVE-2024-8043
Unpatched
Aug 27, 2024
Vikinghammer Tweet
Medium (6.1)
CVE-2024-43948
Patched
Aug 26, 2024
WP Armour Extended
Medium (6.1)
CVE-2024-8274
Patched
Aug 29, 2024
WP Booking Calendar
Medium (6.1)
CVE-2024-43933
Patched
Aug 26, 2024
WPMobile.App — Android and iOS Mobile Application
Medium (6.1)
CVE-2024-43963
Patched
Aug 26, 2024
Visual CSS Style Editor
Medium (5.4)
CVE-2024-5987
Patched
Aug 28, 2024
WP Accessibility Helper (WAH)
Medium (5.3)
CVE-2024-43979
Patched
Aug 28, 2024
Blockbooster
Medium (5.3)
CVE-2024-43998
Patched
Aug 29, 2024
Blogpoet
Medium (5.3)
CVE-2024-43980
Patched
Aug 28, 2024
FotaWP
Medium (5.3)
CVE-2024-6551
Patched
Aug 28, 2024
GiveWP – Donation Plugin and Fundraising Platform
Medium (5.3)
CVE-2024-5857
Patched
Aug 28, 2024
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
Medium (5.3)
CVE-2024-7447
Patched
Aug 27, 2024
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
Medium (5.3)
CVE-2022-4536
Patched
Aug 30, 2024
Two-factor authentication (formerly IP Vault)
Medium (5.3)
CVE-2024-43929
Patched
Aug 26, 2024
JobSearch WP Job Board
Medium (5.3)
CVE-2024-43944
Unpatched
Aug 26, 2024
Maintenance & Coming Soon Redirect Animation
Medium (5.3)
CVE-2024-43990
Patched
Aug 29, 2024
Masterstudy – Education WordPress Theme
Medium (5.3)
CVE-2024-43956
Unpatched
Aug 26, 2024
Memberpress
Medium (5.3)
CVE-2024-6448
Patched
Aug 27, 2024
Mollie Payments for WooCommerce
Medium (5.3)
CVE-2024-8195
Patched
Aug 27, 2024
Permalink Manager Lite
Medium (5.3)
CVE-2024-2541
Unpatched
Aug 28, 2024
Medium (5.3)
CVE-2024-3679
Unpatched
Aug 28, 2024
Premium SEO Pack – WP SEO Plugin
Medium (5.3)
CVE-2024-7573
Patched
Aug 27, 2024
Relevanssi Live Ajax Search
Medium (5.3)
CVE-2024-43974
Patched
Aug 28, 2024
ReviveNews
Medium (5.3)
CVE-2024-43923
Patched
Aug 26, 2024
Medium (5.3)
CVE-2022-4539
Patched
Aug 30, 2024
Web Application Firewall – website security
Medium (5.3)
CVE-2022-4100
Patched
Aug 30, 2024
WP Cerber Security, Anti-spam & Malware Scan
Medium (5.3)
CVE-2024-43937
Patched
Aug 26, 2024
WP Crowdfunding
Medium (5.3)
CVE-2024-43919
Unpatched
Aug 26, 2024
YARPP – Yet Another Related Posts Plugin
Medium (5.3)
CVE-2024-43940
Unpatched
Aug 26, 2024
Zynith SEO
Medium (4.4)
CVE-2024-43985
Patched
Aug 28, 2024
Medium (4.4)
CVE-2024-43999
Patched
Aug 28, 2024
Ninja Forms – The Contact Form Builder That Grows With You
Medium (4.4)
CVE-2024-43972
Patched
Aug 28, 2024
Page Builder: Pagelayer – Drag and Drop website builder
Medium (4.4)
CVE-2024-43960
Unpatched
Aug 26, 2024
Web and WooCommerce Addons for WPBakery Builder
Medium (4.4)
CVE-2024-43967
Unpatched
Aug 26, 2024
WP Testimonial Widget
Medium (4.4)
CVE-2024-3944
Unpatched
Aug 28, 2024
WP To Do
Medium (4.3)
CVE-2024-43954
Unpatched
Aug 26, 2024
Medium (4.3)
CVE-2024-43927
Patched
Aug 26, 2024
Email Address Encoder
Medium (4.3)
CVE-2024-8091
Unpatched
Aug 27, 2024
Enhanced Search Box
Medium (4.3)
CVE-2024-43925
Patched
Aug 26, 2024
Gallery Plugin for WordPress – Envira Photo Gallery
Medium (4.3)
CVE-2024-43981
Patched
Aug 28, 2024
Medium (4.3)
CVE-2024-43973
Patched
Aug 28, 2024
Payment forms, Buy now buttons, and Invoicing System | GetPaid
Medium (4.3)
CVE-2024-44052
Patched
Aug 29, 2024
HelloAsso
Medium (4.3)
CVE-2024-8044
Unpatched
Aug 27, 2024
infolinks Ad Wrap
Medium (4.3)
CVE-2024-43930
Patched
Aug 26, 2024
JobSearch WP Job Board
Medium (4.3)
CVE-2024-43928
Patched
Aug 26, 2024
JobSearch WP Job Board
Medium (4.3)
CVE-2024-43945
Unpatched
Aug 26, 2024
LatePoint Plugin
Oxygen Builder <= 4.8.3 – Missing Authorization to Authenticated (Subscriber+) Stylesheet Update
Medium (4.3)
CVE-2024-6688
Patched
Aug 26, 2024
Oxygen Builder
Medium (4.3)
CVE-2024-8200
Patched
Aug 26, 2024
Medium (4.3)
CVE-2024-8199
Patched
Aug 26, 2024
Medium (4.3)
CVE-2024-43932
Patched
Aug 26, 2024
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
Medium (4.3)
CVE-2024-7418
Patched
Aug 28, 2024
Medium (4.3)
CVE-2024-8319
Patched
Aug 29, 2024
Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking
Medium (4.3)
CVE-2024-8047
Unpatched
Aug 27, 2024
Visual Sound (old)
Medium (4.3)
CVE-2024-43947
Patched
Aug 26, 2024
WP Armour Extended
Medium (4.2)
CVE-2024-5053
Patched
Aug 31, 2024
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
Medium (4.0)
CVE-2024-43986
Patched
Aug 29, 2024
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024) appeared first on Wordfence.