Did you know we’re running a Bug Bounty Extravaganza again?
Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!
Last week, there were 119 vulnerabilities disclosed in 85 WordPress Plugins and 3 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 44 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 14,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-681 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 69 |
Unpatched | 50 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 104 |
High Severity | 12 |
Critical Severity | 3 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 33 |
Missing Authorization | 23 |
Cross-Site Request Forgery (CSRF) | 21 |
Improper Access Control | 9 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 9 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 6 |
Information Exposure | 4 |
Protection Mechanism Failure | 3 |
Server-Side Request Forgery (SSRF) | 3 |
Incorrect Authorization | 2 |
Authentication Bypass Using an Alternate Path or Channel | 1 |
Authorization Bypass Through User-Controlled Key | 1 |
Deserialization of Untrusted Data | 1 |
Improper Control of Generation of Code (‘Code Injection’) | 1 |
Improper Input Validation | 1 |
Unrestricted Upload of File with Dangerous Type | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
35 | |
11 | |
9 | |
6 | |
5 | |
4 | |
4 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Adsmonetizer | adsensei-b30 |
Advanced iFrame | advanced-iframe |
AI Engine | ai-engine |
ArtiBot Free Chat Bot for WordPress WebSites | artibot |
AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth | aweber-web-form-widget |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Booking for Appointments and Events Calendar – Amelia | ameliabooking |
Bulk Edit Post Titles | bulk-edit-post-titles |
Calculated Fields Form | calculated-fields-form |
Categorify – WordPress Media Library Category & File Manager | categorify |
Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back | chat-bubble |
CodeMirror Blocks | wp-codemirror-block |
Coming Soon Page & Maintenance Mode | responsive-coming-soon |
Comments Extra Fields For Post,Pages and CPT | wp-comment-fields |
Complianz – GDPR/CCPA Cookie Consent | complianz-gdpr |
Configure SMTP | configure-smtp |
Contact Form 7 – PayPal & Stripe Add-on | contact-form-7-paypal-add-on |
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce | enhanced-e-commerce-for-woocommerce-store |
Custom Field Suite | custom-field-suite |
Custom fields shortcode | custom-fields-shortcode |
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan | antihacker |
Download Manager | download-manager |
Download Media | download-media |
Duitku Payment Gateway | duitku-social-payment-gateway |
Easy PayPal & Stripe Buy Now Button | wp-ecommerce-paypal |
Ebook Store | ebook-store |
Elementor Website Builder Pro | elementor-pro |
Envo’s Elementor Templates & Widgets for WooCommerce | envo-elementor-for-woocommerce |
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | essential-blocks |
Events Manager – Calendar, Bookings, Tickets, and more! | events-manager |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Finale Lite – Sales Countdown Timer & Discount for WooCommerce | finale-woocommerce-sales-countdown-timer-discount |
Fontific | Google Fonts | fontific |
Friends | friends |
GenerateBlocks | generateblocks |
Gestpay for WooCommerce | gestpay-for-woocommerce |
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers | rafflepress |
Gutenberg Blocks by Kadence Blocks – Page Builder Features | kadence-blocks |
Image Optimizer, Resizer and CDN – Sirv | sirv |
LifterLMS – WordPress LMS Plugin for eLearning | lifterlms |
LiteSpeed Cache | litespeed-cache |
Login as User or Customer | login-as-customer-or-user |
MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance | mainwp |
Marketing Optimizer | marketing-optimizer |
Master Slider – Responsive Touch Slider | master-slider |
Media Alt Renamer | media-alt-renamer |
Migration, Backup, Staging – WPvivid | wpvivid-backuprestore |
Nextend Social Login and Register | nextend-facebook-connect |
NextMove Lite – Thank You Page for WooCommerce | woo-thank-you-page-nextmove-lite |
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor | notificationx |
Oliver POS – A WooCommerce Point of Sale (POS) | oliver-pos |
Orbit Fox by ThemeIsle | themeisle-companion |
Page Duplicator | wp-page-duplicator |
Page Restrict | pagerestrict |
Page Restriction WordPress (WP) – Protect WP Pages/Post | page-and-post-restriction |
PayU India – Official Plugin | payu-india |
postMash – custom post order | postmash |
Premium Addons for Elementor | premium-addons-for-elementor |
Redirects | redirects |
Restaurant Solutions – Checklist | restaurant-solutions-checklist |
Restrict User Access – Ultimate Membership & Content Protection | restrict-user-access |
Rolo Slider | rolo-slider |
Seraphinite Accelerator | seraphinite-accelerator |
Simple Tweet | simple-tweet |
Slider Responsive Slideshow – Image slider, Gallery slideshow | slider-responsive-slideshow |
Slivery Extender | slivery-extender |
SMS Alert Order Notifications – WooCommerce | sms-alert |
SoundCloud Shortcode | soundcloud-shortcode |
Tainacan | tainacan |
Thank You Page Customizer for WooCommerce – Increase Your Sales | woo-thank-you-page-customizer |
Ultimate Bootstrap Elements for Elementor | ultimate-bootstrap-elements-for-elementor |
Under Construction / Maintenance Mode from Acurax | coming-soon-maintenance-mode-from-acurax |
User Shortcodes Plus | user-shortcodes-plus |
Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages | visualcomposer |
Watermark RELOADED | watermark-reloaded |
WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit | myshopkit-popup-smartbar-slidein |
WordPress Access Control | wordpress-access-control |
WP eCommerce | wp-e-commerce |
WP Private Content Plus | wp-private-content-plus |
WP Shortcodes Plugin — Shortcodes Ultimate | shortcodes-ultimate |
WP Show Posts | wp-show-posts |
Wp Social Login and Register Social Counter | wp-social |
WP Social Widget | wp-social-widget |
WPvivid Backup for MainWP | wpvivid-backup-mainwp |
蜜蜂采集-BeePress 微信公众号今日头条知乎专栏简书等平台文章采集插件 | beepress |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Avada | Website Builder For WordPress & WooCommerce | fusion-builder |
Avada | Website Builder For WordPress & WooCommerce | Avada |
Yuki | yuki |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-1698
Patched
Feb 26, 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor
Critical (9.8)
CVE-2024-1514
Unpatched
Feb 27, 2024
WP eCommerce
Critical (9.8)
CVE-2024-1981
Patched
Feb 28, 2024
Migration, Backup, Staging – WPvivid
High (8.8)
CVE-2024-1468
Patched
Feb 28, 2024
Avada | Website Builder For WordPress & WooCommerce
High (8.8)
CVE-2024-1203
Unpatched
Feb 27, 2024
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce
High (8.8)
CVE-2024-0786
Unpatched
Feb 27, 2024
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce
High (8.8)
CVE-2024-1859
Patched
Feb 29, 2024
Slider Responsive Slideshow – Image slider, Gallery slideshow
High (8.8)
CVE-2024-27191
Unpatched
Feb 26, 2024
Slivery Extender
High (8.2)
CVE-2024-27194
Unpatched
Feb 26, 2024
Fontific | Google Fonts
High (8.2)
CVE-2024-27195
Unpatched
Feb 26, 2024
Watermark RELOADED
High (8.1)
CVE-2023-7247
Unpatched
Feb 27, 2024
Login as User or Customer
High (7.2)
CVE-2024-1793
Patched
Feb 29, 2024
High (7.2)
CVE-2024-2020
Patched
Mar 1, 2024
Calculated Fields Form
High (7.2)
CVE-2024-1935
Patched
Feb 29, 2024
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
LiteSpeed Cache <= 5.7 – Unauthenticated Stored Cross-Site Scripting via ‘nameservers’ and ‘_msg’
High (7.2)
CVE-2023-40000
Patched
Feb 27, 2024
LiteSpeed Cache
Medium (6.5)
CVE-2024-0378
Patched
Mar 1, 2024
AI Engine
Medium (6.5)
CVE-2024-1668
Patched
Mar 1, 2024
Avada | Website Builder For WordPress & WooCommerce
Medium (6.5)
CVE-2024-27197
Unpatched
Feb 26, 2024
蜜蜂采集-BeePress 微信公众号今日头条知乎专栏简书等平台文章采集插件
Medium (6.5)
CVE-2024-1860
Patched
Feb 27, 2024
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan
Medium (6.5)
CVE-2024-1566
Unpatched
Feb 27, 2024
Redirects
Medium (6.5)
CVE-2024-1438
Unpatched
Feb 26, 2024
Rolo Slider
Medium (6.5)
CVE-2024-1763
Patched
Feb 29, 2024
Wp Social Login and Register Social Counter
Medium (6.5)
CVE-2024-1982
Patched
Feb 28, 2024
Migration, Backup, Staging – WPvivid
Medium (6.4)
CVE-2024-1074
Patched
Feb 28, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-1791
Unpatched
Feb 27, 2024
CodeMirror Blocks
Medium (6.4)
CVE-2023-6809
Unpatched
Feb 27, 2024
Custom fields shortcode
Download Manager <= 3.2.85 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2023-6954
Patched
Feb 28, 2024
Download Manager
Medium (6.4)
CVE-2024-1854
Patched
Feb 28, 2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
Exclusive Addons for Elementor <= 2.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-1234
Patched
Feb 29, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-1414
Patched
Feb 29, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-1413
Patched
Feb 29, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-2028
Patched
Feb 29, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-1541
Patched
Mar 1, 2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features
Medium (6.4)
CVE-2024-27949
Patched
Mar 1, 2024
Image Optimizer, Resizer and CDN – Sirv
Medium (6.4)
CVE-2024-1449
Unpatched
Mar 1, 2024
Master Slider – Responsive Touch Slider
Medium (6.4)
CVE-2024-1434
Unpatched
Feb 26, 2024
Media Alt Renamer
Medium (6.4)
CVE-2024-1323
Patched
Feb 26, 2024
Orbit Fox by ThemeIsle
Medium (6.4)
CVE-2024-1499
Patched
Feb 26, 2024
Orbit Fox by ThemeIsle
Medium (6.4)
CVE-2024-1497
Patched
Feb 26, 2024
Orbit Fox by ThemeIsle
Medium (6.4)
CVE-2024-1680
Patched
Feb 28, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-1568
Patched
Feb 27, 2024
Seraphinite Accelerator
Medium (6.4)
CVE-2024-0700
Unpatched
Feb 27, 2024
Simple Tweet
Medium (6.4)
CVE-2024-25936
Unpatched
Feb 26, 2024
SoundCloud Shortcode
Medium (6.4)
CVE-2024-1398
Unpatched
Mar 1, 2024
Ultimate Bootstrap Elements for Elementor
Medium (6.4)
CVE-2024-2132
Unpatched
Mar 1, 2024
Ultimate Bootstrap Elements for Elementor
Medium (6.4)
CVE-2023-6880
Patched
Feb 29, 2024
Medium (6.4)
CVE-2024-1808
Patched
Feb 27, 2024
WP Shortcodes Plugin — Shortcodes Ultimate
WP Social Widget <= 2.2.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Medium (6.4)
CVE-2024-27189
Patched
Feb 28, 2024
WP Social Widget
Medium (6.3)
CVE-2024-1954
Patched
Feb 27, 2024
Oliver POS – A WooCommerce Point of Sale (POS)
Medium (6.1)
CVE-2024-1437
Unpatched
Feb 26, 2024
Adsmonetizer
Booking for Appointments and Events Calendar – Amelia <= 1.0.98 – Reflected Cross-Site Scripting
Medium (6.1)
CVE-2024-1484
Patched
Feb 29, 2024
Booking for Appointments and Events Calendar – Amelia
Medium (6.1)
CVE-2024-27192
Unpatched
Feb 26, 2024
Configure SMTP
Medium (6.1)
CVE-2024-27193
Unpatched
Feb 26, 2024
PayU India – Official Plugin
Medium (6.1)
CVE-2024-27196
Unpatched
Feb 26, 2024
postMash – custom post order
Medium (6.1)
CVE-2024-1383
Patched
Feb 28, 2024
WPvivid Backup for MainWP
Medium (5.5)
CVE-2024-1978
Patched
Feb 28, 2024
Friends
Medium (5.4)
CVE-2023-6326
Unpatched
Mar 1, 2024
Master Slider – Responsive Touch Slider
Medium (5.4)
CVE-2024-1775
Patched
Mar 1, 2024
Nextend Social Login and Register
Medium (5.4)
CVE-2024-1687
Patched
Feb 26, 2024
Thank You Page Customizer for WooCommerce – Increase Your Sales
Medium (5.3)
CVE-2024-1136
Unpatched
Feb 27, 2024
Coming Soon Page & Maintenance Mode
Medium (5.3)
CVE-2023-6785
Patched
Feb 28, 2024
Download Manager
Medium (5.3)
CVE-2024-0631
Unpatched
Feb 26, 2024
Duitku Payment Gateway
LifterLMS – WordPress LMS Plugin for eLearning <= 7.5.1 – Missing Authorization via process_review
Medium (5.3)
CVE-2024-0377
Patched
Feb 27, 2024
LifterLMS – WordPress LMS Plugin for eLearning
Medium (5.3)
CVE-2023-45000
Patched
Feb 27, 2024
LiteSpeed Cache
Medium (5.3)
CVE-2024-1120
Patched
Feb 29, 2024
Medium (5.3)
CVE-2024-1368
Unpatched
Feb 27, 2024
Page Duplicator
Medium (5.3)
CVE-2024-0682
Unpatched
Feb 27, 2024
Page Restrict
Medium (5.3)
CVE-2024-0681
Patched
Feb 27, 2024
Page Restriction WordPress (WP) – Protect WP Pages/Post
Medium (5.3)
CVE-2024-0687
Patched
Feb 26, 2024
Restrict User Access – Ultimate Membership & Content Protection
Medium (5.3)
CVE-2024-1435
Unpatched
Feb 26, 2024
Medium (5.3)
CVE-2024-1686
Patched
Feb 26, 2024
Thank You Page Customizer for WooCommerce – Increase Your Sales
Medium (5.3)
CVE-2024-1476
Unpatched
Feb 27, 2024
Under Construction / Maintenance Mode from Acurax
Medium (5.3)
CVE-2023-6969
Unpatched
Feb 26, 2024
User Shortcodes Plus
Medium (5.3)
CVE-2024-1436
Unpatched
Feb 26, 2024
WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit
Medium (5.3)
CVE-2024-0975
Unpatched
Feb 27, 2024
WordPress Access Control
Medium (5.3)
CVE-2024-1516
Unpatched
Feb 27, 2024
WP eCommerce
Medium (5.3)
CVE-2024-0680
Unpatched
Feb 27, 2024
WP Private Content Plus
Medium (5.3)
CVE-2024-1479
Patched
Mar 1, 2024
WP Show Posts
ArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 – Missing Authorization to Settings Update
Medium (5.0)
CVE-2024-0447
Unpatched
Feb 26, 2024
ArtiBot Free Chat Bot for WordPress WebSites
Medium (4.9)
CVE-2024-1341
Patched
Feb 28, 2024
Advanced iFrame
ArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 – Authenticated (Admin+) Cross-Site Scripting
Medium (4.4)
CVE-2024-0449
Unpatched
Feb 27, 2024
ArtiBot Free Chat Bot for WordPress WebSites
Medium (4.4)
CVE-2024-0898
Unpatched
Feb 27, 2024
Medium (4.4)
CVE-2024-0689
Patched
Feb 28, 2024
Custom Field Suite
Medium (4.4)
CVE-2024-23501
Unpatched
Mar 1, 2024
Ebook Store
Events Manager <= 6.4.6.4 – Authenticated(Administator+) Stored Cross-Site Scripting via settings
Medium (4.4)
CVE-2024-0614
Patched
Feb 28, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (4.4)
CVE-2024-0611
Unpatched
Mar 1, 2024
Master Slider – Responsive Touch Slider
Medium (4.4)
CVE-2024-1977
Unpatched
Feb 28, 2024
Restaurant Solutions – Checklist
Medium (4.3)
CVE-2024-0369
Unpatched
Feb 26, 2024
Bulk Edit Post Titles
Medium (4.3)
CVE-2024-1906
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1910
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1907
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1909
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1912
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-0385
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1652
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1649
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1650
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-1653
Patched
Feb 26, 2024
Categorify – WordPress Media Library Category & File Manager
Medium (4.3)
CVE-2024-0830
Patched
Feb 26, 2024
Comments Extra Fields For Post,Pages and CPT
Medium (4.3)
CVE-2024-0829
Patched
Feb 26, 2024
Comments Extra Fields For Post,Pages and CPT
Complianz – GDPR/CCPA Cookie Consent <= 6.5.6 – Cross-Site Request Forgery to Data Request Deletion
Medium (4.3)
CVE-2024-1592
Patched
Mar 1, 2024
Complianz – GDPR/CCPA Cookie Consent
Medium (4.3)
CVE-2024-1861
Patched
Feb 27, 2024
Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan
Medium (4.3)
CVE-2024-27190
Unpatched
Feb 26, 2024
Download Media
Medium (4.3)
CVE-2024-1719
Patched
Feb 27, 2024
Medium (4.3)
CVE-2024-23523
Patched
Feb 26, 2024
Elementor Website Builder Pro
Medium (4.3)
CVE-2024-0767
Unpatched
Feb 27, 2024
Envo’s Elementor Templates & Widgets for WooCommerce
Medium (4.3)
CVE-2024-0768
Unpatched
Feb 27, 2024
Envo’s Elementor Templates & Widgets for WooCommerce
Medium (4.3)
CVE-2024-0766
Unpatched
Feb 27, 2024
Envo’s Elementor Templates & Widgets for WooCommerce
Medium (4.3)
CVE-2024-1452
Patched
Mar 1, 2024
GenerateBlocks
Medium (4.3)
CVE-2024-0432
Unpatched
Feb 27, 2024
Gestpay for WooCommerce
Gestpay for WooCommerce <= 20221130 – Cross-Site Request Forgery (CSRF) via ajax_set_default_card
Medium (4.3)
CVE-2024-0431
Unpatched
Feb 26, 2024
Gestpay for WooCommerce
Gestpay for WooCommerce <= 20221130 – Cross-Site Request Forgery (CSRF) via ajax_unset_default_card
Medium (4.3)
CVE-2024-0433
Unpatched
Feb 27, 2024
Gestpay for WooCommerce
Medium (4.3)
CVE-2024-27950
Patched
Mar 1, 2024
Image Optimizer, Resizer and CDN – Sirv
Medium (4.3)
CVE-2024-1642
Patched
Feb 27, 2024
MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance
Medium (4.3)
CVE-2024-1976
Unpatched
Feb 28, 2024
Marketing Optimizer
Medium (4.3)
CVE-2024-1489
Patched
Feb 26, 2024
SMS Alert Order Notifications – WooCommerce
Medium (4.3)
CVE-2023-6922
Unpatched
Feb 27, 2024
Under Construction / Maintenance Mode from Acurax
Medium (4.3)
CVE-2024-1388
Patched
Feb 27, 2024
Medium (4.3)
CVE-2024-1943
Patched
Feb 27, 2024
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (February 26, 2024 to March 3, 2024) appeared first on Wordfence.