Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 14th, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 127 vulnerabilities disclosed in 110 WordPress Plugins and 6 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- ElementsKit Elementor addons <= 3.2.0 – Unauthenticated Information Exposure via ekit_widgetarea_content Function
- WAF-RULE-723 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-724 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 93 |
Unpatched | 34 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 1 |
Medium Severity | 96 |
High Severity | 20 |
Critical Severity | 10 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 51 |
Missing Authorization | 28 |
Information Exposure | 11 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 8 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 8 |
Cross-Site Request Forgery (CSRF) | 4 |
Deserialization of Untrusted Data | 4 |
Unrestricted Upload of File with Dangerous Type | 3 |
Authentication Bypass Using an Alternate Path or Channel | 2 |
Improper Input Validation | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Improper Control of Generation of Code (‘Code Injection’) | 1 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 1 |
Improper Privilege Management | 1 |
Server-Side Request Forgery (SSRF) | 1 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
11 | |
10 | |
9 | |
7 | |
7 | |
5 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
140+ Widgets | Xpro Addons For Elementor – FREE | xpro-elementor-addons |
3D FlipBook – PDF Flipbook WordPress | interactive-3d-flipbook-powered-physics-engine |
Accept Stripe Payments | stripe-payments |
Advanced Cron Manager – debug & control | advanced-cron-manager |
affiliate-toolkit – WordPress Affiliate Plugin | affiliate-toolkit-starter |
AMP for WP – Accelerated Mobile Pages | accelerated-mobile-pages |
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress | bookingpress-appointment-booking |
Aruba HiSpeed Cache | aruba-hispeed-cache |
BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | searchpro |
BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg | betterdocs |
Bitly’s WordPress Plugin | wp-bitly |
Blox Page Builder | blox-page-builder |
Booking for Appointments and Events Calendar – Amelia | ameliabooking |
Brizy – Page Builder | brizy |
BSK Forms Blacklist | bsk-gravityforms-blacklist |
Card Elements for Elementor | card-elements-for-elementor |
Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot | chatbot-support-ai |
Christmasify! | christmasify |
CM Tooltip Glossary | enhanced-tooltipglossary |
Cost Calculator Builder | cost-calculator-builder |
CRM Perks Forms – WordPress Form Builder | crm-perks-forms |
DL Robots.txt | dl-robotstxt |
DL Verification | dl-verification |
DL Yandex Metrika | dl-yandex-metrika |
Docket (WooCommerce Collections / Wishlist / Watchlist) | woocommerce-collections |
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | easy-digital-downloads |
Easy PayPal & Stripe Buy Now Button | wp-ecommerce-paypal |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
Enter Addons – Ultimate Template Builder for Elementor | enteraddons |
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | mage-eventpress |
EventPrime – Events Calendar, Bookings and Tickets | eventprime-event-calendar-management |
Falang multilanguage for WordPress | falang |
Filr – Secure document library | filr-protection |
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | folders |
Football Pool | football-pool |
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | form-maker |
FormCraft – Form Builder | formcraft-form-builder |
Fuse Social Floating Sidebar | fuse-social-floating-sidebar |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | geodirectory |
Graphina – Elementor Charts and Graphs | graphina-elementor-charts-and-graphs |
Gutenberg Blocks, Page Builder – ComboBlocks | post-grid |
Gutenberg Page Builder Blocks & Ready-Made Patterns Library for Blogs, Magazines, Newspapers, and Business Websites. Easy One-Click Import, No Coding Needed! – Blockspare | blockspare |
Horizontal scrolling announcements | horizontal-scrolling-announcements |
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN | hummingbird-performance |
HUSKY – Products Filter Professional for WooCommerce | woocommerce-products-filter |
Import and export users and customers | import-users-from-csv-with-meta |
JetGridBuilder — Grid Builder for Elementor and Gutenberg | jetgridbuilder |
Kodex Posts likes | kodex-posts-likes |
LA-Studio Element Kit for Elementor | lastudio-element-kit |
LearnPress – WordPress LMS Plugin | learnpress |
Lightbox & Modal Popup WordPress Plugin – FooBox | foobox-image-lightbox |
Linkify Text | linkify-text |
MainWP Child Reports | mainwp-child-reports |
Masteriyo LMS – eLearning and Online Course Builder for WordPress | learning-management-system |
Mediavine Control Panel | mediavine-control-panel |
Meta Box – WordPress Custom Fields Framework | meta-box |
Modern Events Calendar | modern-events-calendar |
Modern Events Calendar Lite | modern-events-calendar-lite |
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution | dc-woocommerce-multi-vendor |
My Custom CSS PHP & ADS | my-custom-css |
myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification | mycred |
No Update Nag | no-update-nag |
Obfuscate Email | obfuscate-email |
Opal Membership | opal-membership |
Organization chart | organization-chart |
Paid Memberships Pro – Membership Maps Add On | pmpro-membership-maps |
ParcelPanel (Free to install) – Shipment Tracking, Tracking, and Order Tracking for WooCommerce | parcelpanel |
Participants Database | participants-database |
PDF Builder for WPForms | pdf-builder-for-wpforms |
Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder | ajax-filter-posts |
Premium Addons for Elementor | premium-addons-for-elementor |
Products, Order & Customers Export for WooCommerce | export-woocommerce |
Registrations for the Events Calendar – Event Registration Plugin | registrations-for-the-events-calendar |
Reveal Template | reveal-template |
Robin image optimizer — save money on image compression | robin-image-optimizer |
Selection Lite | selection-lite |
Send Emails with Mandrill | send-emails-with-mandrill |
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | sender-net-automated-emails |
Shared Files – Frontend File Upload Form & Secure File Sharing | shared-files |
Simple Local Avatars | simple-local-avatars |
Simple Share | dts-simple-share |
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel | depicter |
Slider by 10Web – Responsive Image Slider | slider-wd |
Slider by Soliloquy – Responsive Image Slider for WordPress | soliloquy-lite |
Social Slider Feed | instagram-slider-widget |
Spectra – WordPress Gutenberg Blocks | ultimate-addons-for-gutenberg |
StreamCast – Radio Player for WordPress | streamcast |
Sunshine Photo Cart: Free Client Photo Galleries for Photographers | sunshine-photo-cart |
Themify Shortcodes | themify-shortcodes |
Timeline and History slider | timeline-and-history-slider |
Tutor LMS – eLearning and online course solution | tutor |
TypeSquare Webfonts for エックスサーバー | xserver-typesquare-webfonts |
Ultimate Addons for Beaver Builder – Lite | ultimate-addons-for-beaver-builder-lite |
Ultimate Bootstrap Elements for Elementor | ultimate-bootstrap-elements-for-elementor |
Unite Gallery Lite | unite-gallery-lite |
Viral Signup – limited opt-in with viral refferal sharing | viral-signup |
Visual Website Collaboration, Feedback & Project Management – Atarim | atarim-visual-collaboration |
Waitlist Woocommerce ( Back in stock notifier ) | waitlist-woocommerce |
WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute | wapppress-builds-android-app-for-website |
WooCommerce – Social Login | woo-social-login |
WooCommerce Product Table Lite | wc-product-table-lite |
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly | tour-booking-manager |
WP Dashboard Notes | wp-dashboard-notes |
WP Search Analytics | search-analytics |
WP Table Builder – WordPress Table Plugin | wp-table-builder |
WPBakery Visual Composer | js_composer |
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | wp-cafe |
WPSection | wpsection |
YaMaps for WordPress Plugin | yamaps |
ووکامرس فارسی | persian-woocommerce |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
MDx | MDx |
MultiPurpose | multipurpose |
News Flash | news-flash |
Orchid Store | orchid-store |
The Next | the-next |
Woffice CRM | woffice |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-43144
Patched
Aug 7, 2024
Cost Calculator Builder
Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 – Unauthenticated SQL Injection
Critical (10.0)
CVE-2024-43132
Patched
Aug 7, 2024
Docket (WooCommerce Collections / Wishlist / Watchlist)
Critical (10.0)
CVE-2024-6926
Unpatched
Aug 7, 2024
Viral Signup – limited opt-in with viral refferal sharing
Critical (9.9)
CVE-2024-43138
Patched
Aug 7, 2024
Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin
Critical (9.9)
CVE-2024-43145
Patched
Aug 7, 2024
Critical (9.9)
CVE-2024-43207
Unpatched
Aug 9, 2024
Unite Gallery Lite
Critical (9.8)
CVE-2024-7350
Patched
Aug 7, 2024
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress
Critical (9.8)
CVE-2024-43160
Patched
Aug 7, 2024
Critical (9.8)
CVE-2024-43153
Patched
Aug 7, 2024
Woffice CRM
Critical (9.8)
CVE-2024-7503
Patched
Aug 9, 2024
WooCommerce – Social Login
High (8.8)
CVE-2024-43129
Patched
Aug 7, 2024
High (8.8)
CVE-2024-6315
Unpatched
Aug 5, 2024
Blox Page Builder
Horizontal scrolling announcements <= 2.4 – Authenticated (Contributor+) SQL Injection via Shortcode
High (8.8)
CVE-2023-5000
Patched
Aug 5, 2024
Horizontal scrolling announcements
High (8.8)
CVE-2024-43221
Patched
Aug 9, 2024
JetGridBuilder — Grid Builder for Elementor and Gutenberg
High (8.8)
CVE-2024-7548
Patched
Aug 7, 2024
LearnPress – WordPress LMS Plugin
High (8.8)
CVE-2024-7492
Patched
Aug 7, 2024
MainWP Child Reports
High (8.8)
CVE-2024-7486
Unpatched
Aug 7, 2024
MultiPurpose
High (8.8)
CVE-2024-7150
Patched
Aug 7, 2024
Slider by 10Web – Responsive Image Slider
High (8.8)
CVE-2024-7561
Unpatched
Aug 7, 2024
The Next
High (8.8)
CVE-2024-43232
Patched
Aug 9, 2024
Timeline and History slider
High (8.8)
CVE-2024-43140
Patched
Aug 7, 2024
Ultimate Bootstrap Elements for Elementor
High (8.8)
CVE-2024-5709
Patched
Aug 5, 2024
WPBakery Visual Composer
High (8.8)
CVE-2024-43135
Patched
Aug 7, 2024
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce
High (8.8)
CVE-2024-43165
Patched
Aug 7, 2024
WPSection
High (8.5)
CVE-2024-6522
Patched
Aug 6, 2024
High (8.1)
CVE-2024-43141
Patched
Aug 7, 2024
Participants Database
High (7.2)
CVE-2024-7484
Patched
Aug 5, 2024
CRM Perks Forms – WordPress Form Builder
High (7.2)
CVE-2024-43236
Patched
Aug 9, 2024
Easy PayPal & Stripe Buy Now Button
High (7.2)
CVE-2024-43121
Patched
Aug 7, 2024
HUSKY – Products Filter Professional for WooCommerce
High (7.2)
CVE-2024-7560
Unpatched
Aug 7, 2024
News Flash
Medium (6.5)
CVE-2024-43131
Patched
Aug 7, 2024
Docket (WooCommerce Collections / Wishlist / Watchlist)
Medium (6.5)
CVE-2024-4359
Unpatched
Aug 8, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (6.4)
CVE-2024-43227
Patched
Aug 9, 2024
Medium (6.4)
CVE-2024-43164
Patched
Aug 7, 2024
Medium (6.4)
CVE-2024-43123
Patched
Aug 7, 2024
Card Elements for Elementor
Medium (6.4)
CVE-2024-43149
Patched
Aug 7, 2024
CM Tooltip Glossary
Medium (6.4)
CVE-2024-43155
Patched
Aug 7, 2024
Gutenberg Blocks, Page Builder – ComboBlocks
Medium (6.4)
CVE-2024-4360
Unpatched
Aug 8, 2024
Medium (6.4)
CVE-2024-43225
Unpatched
Aug 9, 2024
Enter Addons – Ultimate Template Builder for Elementor
Medium (6.4)
CVE-2024-7317
Patched
Aug 5, 2024
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager
Medium (6.4)
CVE-2024-43139
Patched
Aug 7, 2024
Football Pool
Medium (6.4)
CVE-2024-5226
Patched
Aug 7, 2024
Fuse Social Floating Sidebar
Medium (6.4)
CVE-2024-43124
Patched
Aug 7, 2024
Graphina – Elementor Charts and Graphs
Medium (6.4)
CVE-2024-43210
Unpatched
Aug 9, 2024
LA-Studio Element Kit for Elementor
Medium (6.4)
CVE-2024-5668
Patched
Aug 7, 2024
Lightbox & Modal Popup WordPress Plugin – FooBox
MDx <= 2.0.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via mdx_list_item Shortcode
Medium (6.4)
CVE-2024-6639
Patched
Aug 9, 2024
MDx
Medium (6.4)
CVE-2024-43218
Unpatched
Aug 9, 2024
Mediavine Control Panel
Medium (6.4)
CVE-2024-43147
Patched
Aug 7, 2024
Selection Lite
Medium (6.4)
CVE-2024-35775
Patched
Aug 7, 2024
Slider by Soliloquy – Responsive Image Slider for WordPress
Medium (6.4)
CVE-2024-7590
Patched
Aug 7, 2024
Spectra – WordPress Gutenberg Blocks
Medium (6.4)
CVE-2024-43133
Patched
Aug 7, 2024
Themify Shortcodes
Medium (6.4)
CVE-2024-43151
Patched
Aug 7, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-43226
Patched
Aug 9, 2024
WP Dashboard Notes
Medium (6.4)
CVE-2024-43125
Patched
Aug 7, 2024
WP Table Builder – WordPress Table Plugin
Medium (6.4)
CVE-2024-5708
Patched
Aug 5, 2024
WPBakery Visual Composer
Medium (6.4)
CVE-2024-43150
Patched
Aug 7, 2024
140+ Widgets | Xpro Addons For Elementor – FREE
Medium (6.4)
CVE-2024-43224
Unpatched
Aug 9, 2024
YaMaps for WordPress Plugin
Medium (6.1)
CVE-2024-43233
Patched
Aug 9, 2024
BSK Forms Blacklist
Medium (6.1)
CVE-2024-7574
Patched
Aug 9, 2024
Christmasify!
Medium (6.1)
CVE-2024-43220
Unpatched
Aug 9, 2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Medium (6.1)
CVE-2024-43217
Unpatched
Aug 9, 2024
Kodex Posts likes
Medium (6.1)
CVE-2024-7649
Unpatched
Aug 9, 2024
Opal Membership
Medium (6.1)
CVE-2024-43163
Patched
Aug 7, 2024
ParcelPanel (Free to install) – Shipment Tracking, Tracking, and Order Tracking for WooCommerce
Medium (6.1)
CVE-2024-43156
Patched
Aug 7, 2024
Medium (6.1)
CVE-2024-43127
Patched
Aug 7, 2024
Products, Order & Customers Export for WooCommerce
Medium (6.1)
CVE-2024-43126
Patched
Aug 7, 2024
Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce
Medium (6.1)
CVE-2024-43213
Unpatched
Aug 9, 2024
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution
Medium (5.5)
CVE-2024-43231
Patched
Aug 9, 2024
Tutor LMS – eLearning and online course solution
Medium (5.4)
CVE-2024-7353
Patched
Aug 6, 2024
Accept Stripe Payments
Medium (5.4)
CVE-2024-6869
Patched
Aug 7, 2024
Falang multilanguage for WordPress
Medium (5.4)
CVE-2024-7621
Patched
Aug 9, 2024
Visual Website Collaboration, Feedback & Project Management – Atarim
Medium (5.3)
CVE-2024-6562
Unpatched
Aug 8, 2024
affiliate-toolkit – WordPress Affiliate Plugin
Medium (5.3)
CVE-2024-43209
Unpatched
Aug 9, 2024
Bitly’s WordPress Plugin
Booking for Appointments and Events Calendar – Amelia <= 1.2 – Unauthenticated Full Path Disclosure
Medium (5.3)
CVE-2024-6552
Patched
Aug 7, 2024
Booking for Appointments and Events Calendar – Amelia
Medium (5.3)
CVE-2024-43223
Patched
Aug 9, 2024
EventPrime – Events Calendar, Bookings and Tickets
Medium (5.3)
CVE-2024-38787
Patched
Aug 7, 2024
Import and export users and customers
Medium (5.3)
CVE-2024-7382
Unpatched
Aug 8, 2024
Linkify Text
Medium (5.3)
CVE-2024-43158
Patched
Aug 7, 2024
Masteriyo LMS – eLearning and Online Course Builder for WordPress
Medium (5.3)
CVE-2024-43159
Patched
Aug 7, 2024
Masteriyo LMS – eLearning and Online Course Builder for WordPress
Medium (5.3)
CVE-2024-7410
Unpatched
Aug 8, 2024
My Custom CSS PHP & ADS
Medium (5.3)
CVE-2024-43214
Patched
Aug 9, 2024
Medium (5.3)
CVE-2024-7412
Unpatched
Aug 8, 2024
No Update Nag
Medium (5.3)
CVE-2024-7413
Unpatched
Aug 8, 2024
Obfuscate Email
Medium (5.3)
CVE-2024-7414
Patched
Aug 8, 2024
PDF Builder for WPForms
Medium (5.3)
CVE-2024-43219
Patched
Aug 9, 2024
ووکامرس فارسی
Medium (5.3)
CVE-2024-7416
Unpatched
Aug 8, 2024
Reveal Template
Medium (5.3)
CVE-2024-43230
Patched
Aug 9, 2024
Shared Files – Frontend File Upload Form & Secure File Sharing
Medium (5.3)
CVE-2024-43142
Patched
Aug 7, 2024
Tutor LMS – eLearning and online course solution
Medium (5.3)
CVE-2024-43120
Patched
Aug 7, 2024
TypeSquare Webfonts for エックスサーバー
Medium (5.3)
CVE-2024-43212
Unpatched
Aug 9, 2024
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly
Medium (4.9)
CVE-2024-7355
Patched
Aug 7, 2024
Organization chart
Medium (4.8)
CVE-2024-43128
Patched
Aug 7, 2024
WooCommerce Product Table Lite
Medium (4.4)
CVE-2024-43152
Patched
Aug 7, 2024
3D FlipBook – PDF Flipbook WordPress
Medium (4.4)
CVE-2024-6722
Unpatched
Aug 6, 2024
Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot
Medium (4.4)
CVE-2024-43161
Patched
Aug 7, 2024
Medium (4.4)
CVE-2024-6797
Unpatched
Aug 10, 2024
DL Robots.txt
Medium (4.4)
CVE-2024-6798
Unpatched
Aug 10, 2024
DL Verification
Medium (4.4)
CVE-2024-6462
Unpatched
Aug 6, 2024
DL Yandex Metrika
Medium (4.4)
CVE-2024-6691
Patched
Aug 9, 2024
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
Medium (4.4)
CVE-2024-43216
Unpatched
Aug 9, 2024
Filr – Secure document library
Medium (4.4)
CVE-2024-43130
Patched
Aug 7, 2024
Football Pool
Medium (4.4)
CVE-2024-43148
Patched
Aug 7, 2024
StreamCast – Radio Player for WordPress
Medium (4.4)
CVE-2024-6927
Unpatched
Aug 7, 2024
Viral Signup – limited opt-in with viral refferal sharing
Medium (4.4)
CVE-2024-43137
Patched
Aug 7, 2024
WappPress – Create Mobile App for any WordPress site with our Mobile App Builder in just 1 minute
Medium (4.4)
CVE-2024-7556
Unpatched
Aug 10, 2024
Simple Share
Medium (4.3)
CVE-2024-43154
Patched
Aug 7, 2024
Advanced Cron Manager – debug & control
Medium (4.3)
CVE-2024-43146
Patched
Aug 7, 2024
AMP for WP – Accelerated Mobile Pages
Medium (4.3)
CVE-2024-43119
Patched
Aug 7, 2024
Aruba HiSpeed Cache
Medium (4.3)
CVE-2024-6254
Patched
Aug 7, 2024
Brizy – Page Builder
Medium (4.3)
CVE-2024-43162
Patched
Aug 7, 2024
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
Medium (4.3)
CVE-2024-43157
Patched
Aug 7, 2024
FormCraft – Form Builder
Medium (4.3)
CVE-2024-43117
Patched
Aug 7, 2024
Medium (4.3)
CVE-2024-43118
Patched
Aug 7, 2024
Medium (4.3)
CVE-2024-43235
Patched
Aug 9, 2024
Meta Box – WordPress Custom Fields Framework
Medium (4.3)
CVE-2024-7648
Unpatched
Aug 9, 2024
Opal Membership
Medium (4.3)
CVE-2024-6987
Patched
Aug 7, 2024
Orchid Store
Medium (4.3)
CVE-2024-1286
Patched
Aug 9, 2024
Paid Memberships Pro – Membership Maps Add On
Medium (4.3)
CVE-2024-6824
Patched
Aug 7, 2024
Premium Addons for Elementor
Medium (4.3)
CVE-2024-43143
Patched
Aug 7, 2024
Registrations for the Events Calendar – Event Registration Plugin
Medium (4.3)
CVE-2024-43122
Patched
Aug 7, 2024
Robin image optimizer — save money on image compression
Medium (4.3)
CVE-2024-43208
Unpatched
Aug 9, 2024
Send Emails with Mandrill
Medium (4.3)
CVE-2024-43116
Patched
Aug 7, 2024
Simple Local Avatars
Medium (4.3)
CVE-2024-43215
Unpatched
Aug 9, 2024
Social Slider Feed
Medium (4.3)
CVE-2024-43136
Patched
Aug 7, 2024
Sunshine Photo Cart: Free Client Photo Galleries for Photographers
Medium (4.3)
CVE-2024-43134
Patched
Aug 7, 2024
Waitlist Woocommerce ( Back in stock notifier )
Medium (4.3)
CVE-2024-43229
Patched
Aug 9, 2024
WP Search Analytics
Low (3.3)
CVE-2024-6692
Patched
Aug 9, 2024
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (August 5, 2024 to August 11, 2024) appeared first on Wordfence.