Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $10,400, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest. For a limited time, all high risk issues are in-scope for all researchers!
Last week, there were 121 vulnerabilities disclosed in 99 WordPress Plugins, 20 WordPress Themes, and 3 in WordPress Core that have been added to the Wordfence Intelligence Vulnerability Database, and there were 58 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 17,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WordPress Core < 6.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API
- WAF-RULE-710 – data redacted while we work with the vendor on a patch.
- WAF-RULE-711 – data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 111 |
Unpatched | 10 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 104 |
High Severity | 8 |
Critical Severity | 7 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 66 |
Missing Authorization | 16 |
Cross-Site Request Forgery (CSRF) | 15 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 4 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 3 |
Authorization Bypass Through User-Controlled Key | 2 |
Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’) | 2 |
Information Exposure | 2 |
Unrestricted Upload of File with Dangerous Type | 2 |
Embedded Malicious Code | 1 |
Insecure Storage of Sensitive Information | 1 |
Protection Mechanism Failure | 1 |
Server-Side Request Forgery (SSRF) | 1 |
Use of Less Trusted Source | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
16 | |
12 | |
8 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Ad Invalid Click Protector (AICP) | ad-invalid-click-protector |
Advanced File Manager | file-manager-advanced |
All In One Redirection | all-in-one-redirection |
All-in-One Addons for Elementor – WidgetKit | widgetkit-for-elementor |
Auto Featured Image | auto-featured-image |
BLAZE Retail Widget | blaze-widget |
Branda – White Label WordPress, Custom Login Page Customizer | branda-white-labeling |
Britetechs Companion | britetechs-companion |
Cards for Beaver Builder | bb-bootstrap-cards |
Chained Quiz | chained-quiz |
Church Admin | church-admin |
Contact Form 7 Multi-Step Addon | contact-form-7-multi-step-addon |
Conversios – Google Analytics 4 (GA4), Google Ads, Meta Pixel & more for WooCommerce | enhanced-e-commerce-for-woocommerce-store |
Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) | gdpr-cookie-consent |
Create by Mediavine | mediavine-create |
Defender Security – Malware Scanner, Login Security & Firewall | defender-security |
DethemeKit For Elementor | dethemekit-for-elementor |
Digital River Global Commerce | digital-river-global-commerce |
E2Pdf – Export To Pdf Tool for WordPress | e2pdf |
Easy Affiliate Links | easy-affiliate-links |
Easy Age Verify | easy-age-verify |
Easy Image Collage | easy-image-collage |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
Elementor Website Builder Pro | elementor-pro |
Elementor Website Builder – More than Just a Page Builder | elementor |
ElementsKit Elementor addons | elementskit-lite |
Enter Addons – Ultimate Template Builder for Elementor | enteraddons |
Events Manager – Calendar, Bookings, Tickets, and more! | events-manager |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Extensions for Elementor | extensions-for-elementor |
Featured Image from URL (FIFU) | featured-image-from-url |
File Manager | wp-file-manager |
Filter & Grids | ymc-smart-filter |
Floating Social Buttons | floating-social-buttons |
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells | funnel-builder |
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery | simply-gallery-block |
Gallery Slideshow | gallery-slideshow |
Gutenberg Blocks with AI by Kadence WP – Page Builder Features | kadence-blocks |
Happy Addons for Elementor | happy-elementor-addons |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
HTML5 Audio Player- Audio Player Plugin | html5-audio-player |
IdeaPush | ideapush |
Login with phone number | login-with-phone-number |
Mailster – Email Newsletter Plugin for WordPress | mailster |
Masterstudy Elementor Widgets | masterstudy-elementor-widgets |
Newspack Blocks | newspack-blocks |
NextScripts: Social Networks Auto-Poster | social-networks-auto-poster-facebook-twitter-g |
Online Booking & Scheduling Calendar for WordPress by vcita | meeting-scheduler-by-vcita |
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) | stepbyteservice-openstreetmap |
Page and Post Clone | page-or-post-clone |
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | paid-memberships-pro |
Patreon WordPress | patreon-connect |
PayPlus Payment Gateway | payplus-payment-gateway |
Permalink Manager Lite | permalink-manager |
Photo Gallery by Ays – Responsive Image Gallery | gallery-photo-gallery |
Pixel Manager for WooCommerce – Track Google Analytics, Google Ads, TikTok and more | woocommerce-google-adwords-conversion-tracking-tag |
PixelYourSite – Your smart PIXEL (TAG) & API Manager | pixelyoursite |
Pods – Custom Content Types and Fields | pods |
Portfolio Gallery – Image Gallery Plugin | portfolio-filter-gallery |
PowerPack Lite for Beaver Builder | powerpack-addon-for-beaver-builder |
PowerPress Podcasting plugin by Blubrry | powerpress |
Print My Blog – Print, PDF, & eBook Converter WordPress Plugin | print-my-blog |
Progress Planner | progress-planner |
Qualified Electronic Signatures by eID Easy | eid-easy-qualified-electonic-signature |
Quiz Maker | quiz-maker |
Seo Optimized Images | seo-optimized-images |
SEO SIMPLE PACK | seo-simple-pack |
Simply Show Hooks | simply-show-hooks |
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel | depicter |
Slider Revolution | revslider |
Social Rocket – Social Sharing Plugin | social-rocket |
Social Sharing Plugin – Social Warfare | social-warfare |
Stackable – Page Builder Gutenberg Blocks | stackable-ultimate-gutenberg-blocks |
Stock Ticker | stock-ticker |
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | the-plus-addons-for-elementor-page-builder |
The Ultimate WordPress Toolkit – WP Extended | wpextended |
TrustedLogin Vendor | vendor |
Tutor LMS – eLearning and online course solution | tutor |
Twenty20 Image Before-After | twenty20 |
Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) | ultimate-post-kit |
Uncanny Automator Pro | uncanny-automator-pro |
Uncanny Toolkit Pro for LearnDash | uncanny-toolkit-pro |
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress | userswp |
Visual Website Collaboration, Feedback & Project Management – Atarim | atarim-visual-collaboration |
weForms – Easy Drag & Drop Contact Form Builder For WordPress | weforms |
WooCommerce | woocommerce |
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg | groundhogg |
WP eStore | wp-cart-for-digital-products |
WP Job Manager – Resume Manager | wp-job-manager-resumes |
WP Maps – Display Google Maps Perfectly with Ease | wp-google-map-plugin |
WP Mobile Menu – The Mobile-Friendly Responsive Menu | mobile-menu |
WP Photo Album Plus | wp-photo-album-plus |
WP Server Health Stats | wp-server-stats |
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin | wp-user-frontend |
WP-Lister Lite for Amazon | wp-lister-for-amazon |
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | wp-cafe |
WPCOM Member | wpcom-member |
Wrapper Link Elementor | wrapper-link-elementor |
Zita Elementor Site Library | zita-site-library |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Anima | anima |
Blossom Shop | blossom-shop |
Coachify | coachify |
Elegant Pink | elegant-pink |
Esteem | esteem |
Foxiz | foxiz |
Goya | goya |
Infinite | infinite |
JobScout | jobscout |
Mesmerize | mesmerize |
NewsMash | newsmash |
OnePress | onepress |
Perfect Portfolio | perfect-portfolio |
Preschool and Kindergarten | preschool-and-kindergarten |
Scylla lite | scylla-lite |
Silesia | silesia |
Striking | striking-r |
The7 — Website and eCommerce Builder for WordPress | dt-the7 |
Theron Lite | theron-lite |
Travel Monster | travel-monster |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-6205
Patched
Jun 28, 2024
PayPlus Payment Gateway
Critical (10.0)
CVE-2024-6297
Patched
Jun 24, 2024
Social Sharing Plugin – Social Warfare
Contact Form 7 Multi-Step Addon
Simply Show Hooks
Wrapper Link Elementor
BLAZE Retail Widget
PowerPress Podcasting plugin by Blubrry
Ad Invalid Click Protector (AICP)
WP Server Health Stats
Seo Optimized Images
Twenty20 Image Before-After
and 3 more…
Critical (9.9)
CVE-2024-37424
Patched
Jun 28, 2024
Newspack Blocks
Critical (9.9)
CVE-2024-37420
Patched
Jun 28, 2024
Zita Elementor Site Library
Critical (9.8)
CVE-2024-6164
Patched
Jun 27, 2024
Filter & Grids
Critical (9.8)
CVE-2024-6028
Patched
Jun 24, 2024
Quiz Maker
Critical (9.8)
CVE-2024-6265
Patched
Jun 28, 2024
High (8.8)
CVE-2024-6054
Unpatched
Jun 26, 2024
Auto Featured Image
High (8.8)
CVE-2024-37268
Patched
Jun 27, 2024
Striking
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 – Authenticated (Contributor+) SQL Injection
High (8.8)
CVE-2024-2386
Patched
Jun 28, 2024
WP Maps – Display Google Maps Perfectly with Ease
High (8.8)
CVE-2024-5431
Patched
Jun 24, 2024
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce
High (7.5)
CVE-2024-5598
Patched
Jun 28, 2024
Advanced File Manager
High (7.2)
CVE-2024-37260
Patched
Jun 27, 2024
Foxiz
High (7.2)
CVE-2024-37410
Patched
Jun 28, 2024
PowerPack Lite for Beaver Builder
High (7.2)
CVE-2024-4869
Patched
Jun 25, 2024
Medium (6.5)
CVE-2024-37423
Patched
Jun 28, 2024
Newspack Blocks
Medium (6.4)
CVE-2024-37248
Unpatched
Jun 25, 2024
Anima
Medium (6.4)
CVE-2024-5601
Patched
Jun 26, 2024
Create by Mediavine
Medium (6.4)
CVE-2024-4569
Patched
Jun 26, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-4570
Patched
Jun 26, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-37437
Patched
Jun 28, 2024
Elementor Website Builder – More than Just a Page Builder
Medium (6.4)
CVE-2024-37263
Patched
Jun 27, 2024
Enter Addons – Ultimate Template Builder for Elementor
Medium (6.4)
CVE-2024-37432
Patched
Jun 28, 2024
Medium (6.4)
CVE-2024-5332
Patched
Jun 25, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-5666
Patched
Jun 28, 2024
Extensions for Elementor
Medium (6.4)
CVE-2024-5192
Patched
Jun 28, 2024
Medium (6.4)
CVE-2024-5424
Patched
Jun 27, 2024
Medium (6.4)
CVE-2024-37246
Unpatched
Jun 25, 2024
Gallery Slideshow
Medium (6.4)
CVE-2024-5289
Patched
Jun 26, 2024
Gutenberg Blocks with AI by Kadence WP – Page Builder Features
Medium (6.4)
CVE-2024-5819
Patched
Jun 28, 2024
Gutenberg Blocks with AI by Kadence WP – Page Builder Features
Medium (6.4)
CVE-2024-5790
Patched
Jun 28, 2024
Happy Addons for Elementor
Medium (6.4)
CVE-2024-5215
Patched
Jun 25, 2024
HT Mega – Absolute Addons For Elementor
Medium (6.4)
CVE-2024-5173
Patched
Jun 25, 2024
HT Mega – Absolute Addons For Elementor
Medium (6.4)
CVE-2024-37445
Patched
Jun 28, 2024
HTML5 Audio Player- Audio Player Plugin
Medium (6.4)
CVE-2024-37265
Patched
Jun 27, 2024
Medium (6.4)
CVE-2024-5796
Unpatched
Jun 27, 2024
Infinite
Medium (6.4)
CVE-2024-6262
Patched
Jun 26, 2024
Portfolio Gallery – Image Gallery Plugin
Medium (6.4)
CVE-2024-37271
Patched
Jun 27, 2024
Print My Blog – Print, PDF, & eBook Converter WordPress Plugin
Medium (6.4)
CVE-2024-37422
Patched
Jun 27, 2024
Progress Planner
Scylla lite <= 1.8.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode
Medium (6.4)
CVE-2024-5922
Unpatched
Jun 27, 2024
Scylla lite
Silesia <= 1.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode
Medium (6.4)
CVE-2024-5788
Unpatched
Jun 27, 2024
Silesia
Medium (6.4)
CVE-2024-6296
Patched
Jun 27, 2024
Stackable – Page Builder Gutenberg Blocks
Medium (6.4)
CVE-2024-6363
Patched
Jun 28, 2024
Stock Ticker
Medium (6.4)
CVE-2024-4983
Patched
Jun 26, 2024
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
Medium (6.4)
CVE-2024-5451
Patched
Jun 24, 2024
The7 — Website and eCommerce Builder for WordPress
Theron Lite <= 2.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode
Medium (6.4)
CVE-2024-5925
Unpatched
Jun 27, 2024
Theron Lite
Medium (6.4)
CVE-2024-5662
Patched
Jun 27, 2024
Medium (6.4)
CVE-2024-37428
Patched
Jun 28, 2024
All-in-One Addons for Elementor – WidgetKit
Medium (6.4)
CVE-2024-6307
Patched
Jun 24, 2024
WordPress
Medium (6.4)
CVE-2024-31111
Patched
Jun 24, 2024
WordPress
Medium (6.1)
CVE-2024-37245
Unpatched
Jun 25, 2024
All In One Redirection
Medium (6.1)
CVE-2024-35656
Patched
Jun 28, 2024
Elementor Website Builder Pro
Medium (6.1)
CVE-2024-5889
Patched
Jun 28, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (6.1)
CVE-2024-6405
Unpatched
Jun 28, 2024
Floating Social Buttons
Medium (6.1)
CVE-2023-4017
Patched
Jun 28, 2024
Medium (6.1)
CVE-2024-37264
Patched
Jun 27, 2024
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg
Medium (6.1)
CVE-2024-37433
Patched
Jun 28, 2024
Mailster – Email Newsletter Plugin for WordPress
Medium (6.1)
CVE-2024-37275
Unpatched
Jun 27, 2024
NextScripts: Social Networks Auto-Poster
Medium (6.1)
CVE-2024-37262
Patched
Jun 27, 2024
Online Booking & Scheduling Calendar for WordPress by vcita
Medium (6.1)
CVE-2024-37257
Patched
Jun 27, 2024
Permalink Manager Lite
Medium (6.1)
CVE-2024-37258
Patched
Jun 27, 2024
Social Rocket – Social Sharing Plugin
Medium (6.1)
CVE-2024-37267
Patched
Jun 27, 2024
Striking
The Ultimate WordPress Toolkit – WP Extended <= 2.4.7 – Unauthenticated Stored Cross-Site Scripting
Medium (6.1)
CVE-2024-37259
Patched
Jun 27, 2024
The Ultimate WordPress Toolkit – WP Extended
Medium (6.1)
CVE-2024-37436
Patched
Jun 28, 2024
Uncanny Toolkit Pro for LearnDash
Medium (6.1)
CVE-2024-6076
Patched
Jun 24, 2024
WP eStore
Medium (6.1)
CVE-2024-6074
Patched
Jun 24, 2024
WP eStore
Medium (6.1)
CVE-2024-6073
Patched
Jun 24, 2024
WP eStore
Medium (6.1)
CVE-2024-6072
Patched
Jun 24, 2024
WP eStore
Medium (6.1)
CVE-2024-37416
Patched
Jun 28, 2024
WP Photo Album Plus
Medium (6.1)
CVE-2024-37261
Patched
Jun 27, 2024
WP-Lister Lite for Amazon
Medium (5.4)
CVE-2024-6283
Patched
Jun 26, 2024
DethemeKit For Elementor
Easy Image Collage <= 1.13.5 – Missing Authorization to Authenticated (Contributor+) Data Clearance
Medium (5.4)
CVE-2024-5863
Patched
Jun 27, 2024
Easy Image Collage
Medium (5.3)
CVE-2024-37440
Patched
Jun 28, 2024
Church Admin
Medium (5.3)
CVE-2024-37444
Patched
Jun 28, 2024
Defender Security – Malware Scanner, Login Security & Firewall
Medium (5.3)
CVE-2024-37255
Patched
Jun 27, 2024
ElementsKit Elementor addons
Medium (5.3)
CVE-2024-37276
Patched
Jun 28, 2024
Featured Image from URL (FIFU)
Medium (5.3)
CVE-2024-37269
Patched
Jun 27, 2024
Masterstudy Elementor Widgets
Medium (5.3)
CVE-2024-37277
Patched
Jun 28, 2024
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Medium (5.3)
CVE-2024-37430
Patched
Jun 28, 2024
Patreon WordPress
Medium (5.3)
CVE-2024-37411
Patched
Jun 27, 2024
Progress Planner
Medium (5.3)
CVE-2024-2795
Patched
Jun 27, 2024
SEO SIMPLE PACK
Medium (5.3)
CVE-2024-37270
Patched
Jun 27, 2024
TrustedLogin Vendor
Uncanny Automator Pro < 5.3.0.1 – Missing Authorization to Unauthenticated License Setting Reset
Medium (5.3)
CVE-2024-37119
Patched
Jun 28, 2024
Uncanny Automator Pro
Medium (5.3)
Unknown
Patched
Jun 25, 2024
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer)
Pixel Manager for WooCommerce – Track Google Analytics, Google Ads, TikTok and more
weForms – Easy Drag & Drop Contact Form Builder For WordPress
Qualified Electronic Signatures by eID Easy
Digital River Global Commerce
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin
Medium (4.7)
CVE-2024-6288
Patched
Jun 27, 2024
Conversios – Google Analytics 4 (GA4), Google Ads, Meta Pixel & more for WooCommerce
Medium (4.4)
CVE-2024-37434
Patched
Jun 28, 2024
Visual Website Collaboration, Feedback & Project Management – Atarim
Medium (4.4)
CVE-2024-37239
Patched
Jun 28, 2024
Branda – White Label WordPress, Custom Login Page Customizer
Medium (4.4)
CVE-2024-37278
Patched
Jun 28, 2024
Cards for Beaver Builder
Medium (4.4)
CVE-2024-37446
Patched
Jun 28, 2024
Chained Quiz
Medium (4.4)
CVE-2024-37414
Patched
Jun 28, 2024
Medium (4.4)
CVE-2024-35757
Patched
Jun 27, 2024
Easy Age Verify
Medium (4.4)
CVE-2024-37429
Patched
Jun 28, 2024
Login with phone number
Medium (4.4)
CVE-2024-37442
Patched
Jun 28, 2024
Photo Gallery by Ays – Responsive Image Gallery
Medium (4.4)
CVE-2024-37447
Patched
Jun 28, 2024
PixelYourSite – Your smart PIXEL (TAG) & API Manager
PowerPack Lite for Beaver Builder <= 1.3.0.4 – Authenticated (Editor+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-37409
Patched
Jun 28, 2024
PowerPack Lite for Beaver Builder
Medium (4.4)
CVE-2024-37449
Patched
Jun 28, 2024
Slider Revolution
Medium (4.3)
CVE-2024-37412
Patched
Jun 28, 2024
Blossom Shop
Medium (4.3)
CVE-2024-37417
Patched
Jun 28, 2024
Coachify
Medium (4.3)
CVE-2024-37415
Patched
Jun 28, 2024
E2Pdf – Export To Pdf Tool for WordPress
Easy Affiliate Links <= 3.7.3 – Missing Authorization to Authenticated (Subscriber+) Settings Reset
Medium (4.3)
CVE-2024-5864
Patched
Jun 27, 2024
Easy Affiliate Links
Medium (4.3)
CVE-2024-37426
Patched
Jun 28, 2024
Elegant Pink
Medium (4.3)
CVE-2024-37254
Patched
Jun 27, 2024
File Manager
Medium (4.3)
CVE-2024-37421
Patched
Jun 28, 2024
JobScout
Medium (4.3)
CVE-2024-37431
Patched
Jun 28, 2024
Mesmerize
Medium (4.3)
CVE-2024-37441
Patched
Jun 28, 2024
NewsMash
Medium (4.3)
CVE-2024-37425
Patched
Jun 28, 2024
Newspack Blocks
Medium (4.3)
CVE-2024-37448
Patched
Jun 28, 2024
OnePress
Medium (4.3)
CVE-2024-5942
Patched
Jun 28, 2024
Page and Post Clone
Medium (4.3)
CVE-2024-37435
Patched
Jun 28, 2024
Perfect Portfolio
Medium (4.3)
CVE-2024-37413
Patched
Jun 28, 2024
Preschool and Kindergarten
Medium (4.3)
CVE-2024-37272
Patched
Jun 27, 2024
Travel Monster
Medium (4.3)
CVE-2024-37118
Patched
Jun 28, 2024
Uncanny Automator Pro
Medium (4.3)
CVE-2024-37438
Patched
Jun 28, 2024
Uncanny Toolkit Pro for LearnDash
Medium (4.3)
CVE-2024-37439
Patched
Jun 28, 2024
Uncanny Toolkit Pro for LearnDash
Medium (4.3)
CVE-2024-32111
Patched
Jun 24, 2024
WordPress
Medium (4.3)
CVE-2024-6075
Patched
Jun 24, 2024
WP eStore
Medium (4.3)
CVE-2024-37443
Patched
Jun 28, 2024
WP Job Manager – Resume Manager
Medium (4.3)
CVE-2024-37274
Patched
Jun 27, 2024
WP Mobile Menu – The Mobile-Friendly Responsive Menu
Medium (4.3)
CVE-2024-3249
Patched
Jun 24, 2024
Zita Elementor Site Library
Low (2.7)
CVE-2024-37266
Patched
Jun 27, 2024
Tutor LMS – eLearning and online course solution
Low (2.7)
CVE-2024-35777
Patched
Jun 27, 2024
WooCommerce
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (June 24, 2024 to June 30, 2024) appeared first on Wordfence.