Did you know we’re running a Bug Bounty Extravaganza again?
Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!
Last week, there were 159 vulnerabilities disclosed in 123 WordPress Plugins and 1 WordPress Theme that have been added to the Wordfence Intelligence Vulnerability Database, and there were 68 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 14,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-684 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 146 |
Unpatched | 13 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 132 |
High Severity | 21 |
Critical Severity | 6 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 98 |
Missing Authorization | 18 |
Cross-Site Request Forgery (CSRF) | 13 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 7 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 4 |
Deserialization of Untrusted Data | 3 |
Improper Control of Generation of Code (‘Code Injection’) | 2 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 2 |
Server-Side Request Forgery (SSRF) | 2 |
Unrestricted Upload of File with Dangerous Type | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Exposure of Sensitive Data Through Data Queries | 1 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 1 |
Improper Input Validation | 1 |
Incorrect Authorization | 1 |
Information Exposure | 1 |
Insufficiently Protected Credentials | 1 |
Missing Critical Step in Authentication | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
18 | |
11 | |
11 | |
8 | |
8 | |
7 | |
6 | |
5 | |
5 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Accordion | accordions |
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More | advanced-access-manager |
Advanced Sermons | advanced-sermons |
AntiSpam for Contact Form 7 | cf7-antispam |
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | armember-membership |
Auto Affiliate Links | wp-auto-affiliate-links |
Awesome Support – WordPress HelpDesk & Support Plugin | awesome-support |
Backuply – Backup, Restore, Migrate and Clone | backuply |
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. | barcode-scanner-lite-pos-to-manage-products-inventory-and-orders |
Beaver Builder Addons by WPZOOM | wpzoom-addons-for-beaver-builder |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Builder for WooCommerce product reviews shortcodes – ReviewShort | woo-product-reviews-shortcode |
Bulgarisation for WooCommerce | bulgarisation-for-woocommerce |
Burst Statistics – Privacy-Friendly Analytics for WordPress | burst-statistics |
Calendarista Basic Edition – WordPress appointment booking system | calendarista-basic-edition |
Contact Form 7 | contact-form-7 |
Contact Form 7 – PayPal & Stripe Add-on | contact-form-7-paypal-add-on |
Contact Form Builder by Bit Form: Create Contact Form, Multi Step Form, Conversational Form | bit-form |
Contact Form by BestWebSoft – Advanced Contact Us Form Builder for WordPress | contact-form-plugin |
Coupon Affiliates – WooCommerce Affiliate Plugin | woo-coupon-usage |
Crisp – Live Chat and Chatbot | crisp |
Cryptocurrency Widgets – Price Ticker & Coins List | cryptocurrency-price-ticker-widget |
CWW Companion | cww-companion |
Database for Contact Form 7 | cf7-database |
Download Manager Pro | download-manager |
DSGVO All in one for WP | dsgvo-all-in-one-for-wp |
Easiest Sales Funnel Builder For WordPress & WooCommerce by WPFunnels | wpfunnels |
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box | easy-facebook-likebox |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
Elementor Addons by Livemesh | addons-for-elementor |
Elementor Header & Footer Builder | header-footer-elementor |
Elements Plus! | elements-plus |
ElementsKit Elementor addons | elementskit-lite |
Email Subscription Popup | email-subscribe |
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | essential-addons-for-elementor-lite |
Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! | everest-forms |
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media | evergreen-content-poster |
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) | extensions-for-cf7 |
f(x) Private Site | fx-private-site |
Free Downloads WooCommerce | download-now-for-woocommerce |
FV Flowplayer Video Player | fv-wordpress-flowplayer |
GiveWP – Donation Plugin and Fundraising Platform | give |
HT Easy GA4 – Google Analytics WordPress Plugin | ht-easy-google-analytics |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
HUSKY – Products Filter Professional for WooCommerce | woocommerce-products-filter |
Hustle – Email Marketing, Lead Generation, Optins, Popups | wordpress-popup |
JetWidgets For Elementor | jetwidgets-for-elementor |
Knight Lab Timeline | knight-lab-timelinejs |
LA-Studio Element Kit for Elementor | lastudio-element-kit |
LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | ladipage |
Link Library | link-library |
Link Whisper Free | link-whisper |
Malware Scanner | miniorange-malware-protection |
MasterStudy LMS WordPress Plugin – for Online Courses and Education | masterstudy-lms-learning-management-system |
MJM Clinic | mjm-clinic |
Mollie Forms | mollie-forms |
Multiple Page Generator Plugin – MPG | multiple-pages-generator-by-porthas |
News Announcement Scroll | news-announcement-scroll |
Newsletter2Go | newsletter2go |
oik | oik |
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | otter-blocks |
OxyExtras | oxyextras |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | wp-user-avatar |
Permalink Manager Pro | permalink-manager |
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | post-grid |
Premium Addons for Elementor | premium-addons-for-elementor |
Premium Addons Pro for Elementor | premium-addons-pro |
Premmerce Permalink Manager for WooCommerce | woo-permalink-manager |
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) | bdthemes-prime-slider-lite |
PropertyHive | propertyhive |
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress | quiz-master-next |
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction | pie-register |
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | custom-registration-form-builder-with-submission-manager |
Related Posts for WordPress | related-posts-for-wp |
Restaurant Menu and Food Ordering | food-and-drink-menu |
Scrollsequence – Cinematic Scroll Image Animation Plugin | scrollsequence |
Sell Tickets – Event Ticketing and Event Registration – Ticket Tailor for WordPress | ticket-tailor |
Shariff Wrapper | shariff |
ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | woolentor-addons |
Simple Job Board | simple-job-board |
Site Reviews | site-reviews |
Sitekit | sitekit |
Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) | sky-elementor-addons |
Smart Online Order for Clover | clover-online-orders |
Social Media Share Buttons | social-media-builder |
Specific Content For Mobile – Customize the mobile version without redirections | specific-content-for-mobile |
Super Page Cache for Cloudflare | wp-cloudflare-page-cache |
SupportCandy – Helpdesk & Customer Support Ticket System | supportcandy |
Survey Maker – Best WordPress Survey Plugin | survey-maker |
Tablesome – Responsive Table, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Gravity Forms, Fluent, Forminator | tablesome |
Team Circle Image Slider With Lightbox | circle-image-slider-with-lightbox |
The Moneytizer | the-moneytizer |
Tutor LMS – eLearning and online course solution | tutor |
Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates | woo-gift-cards-lite |
User profile | user-profile |
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress | userswp |
Video Conferencing with Zoom | video-conferencing-with-zoom-api |
Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages | visualcomposer |
Visualizer: Tables and Charts Manager for WordPress | visualizer |
WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management | woosquare |
Web Application Firewall – website security | web-application-firewall |
weForms – Easy Drag & Drop Contact Form Builder For WordPress | weforms |
WEN Responsive Columns | wen-responsive-columns |
WooCommerce Google Feed Manager | wp-product-feed-manager |
WooCommerce License Manager | fs-license-manager |
WooThumbs for WooCommerce by Iconic | iconic-woothumbs |
Word Replacer Pro | word-replacer-ultra |
WordPress Automatic Plugin | wp-automatic |
WordPress Contact Forms by Cimatti | contact-forms |
WP Armour – Honeypot Anti Spam | honeypot |
WP Calameo | wp-calameo |
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress | wp-fusion-lite |
WP Go Maps (formerly WP Google Maps) | wp-google-maps |
WP Popups – WordPress Popup builder | wp-popups-lite |
WP Recipe Maker | wp-recipe-maker |
WP Responsive Tabs horizontal vertical and accordion Tabs | responsive-horizontal-vertical-and-accordion-tabs |
WP SendFox | wp-sendfox |
WP Statistics | wp-statistics |
wp-mpdf | wp-mpdf |
WPBakery Page Builder Addons by Livemesh | addons-for-visual-composer |
YITH WooCommerce Product Add-Ons | yith-woocommerce-product-add-ons |
Zippy | zippy |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Blossom Spa | blossom-spa |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-27954
Patched
Mar 13, 2024
WordPress Automatic Plugin
Critical (9.8)
CVE-2024-27956
Patched
Mar 13, 2024
WordPress Automatic Plugin
Critical (9.8)
CVE-2024-2172
Unpatched
Mar 13, 2024
Critical (9.8)
CVE-2024-27957
Unpatched
Mar 13, 2024
Critical (9.8)
CVE-2024-27971
Patched
Mar 13, 2024
Premmerce Permalink Manager for WooCommerce
Critical (9.8)
CVE-2024-1813
Patched
Mar 15, 2024
Simple Job Board
High (8.8)
CVE-2024-27955
Patched
Mar 13, 2024
WordPress Automatic Plugin
HT Mega – Absolute Addons For Elementor <= 2.4.6 – Authenticated (Contributor+) Directory Traversal
High (8.8)
CVE-2024-1974
Patched
Mar 14, 2024
HT Mega – Absolute Addons For Elementor
High (8.8)
CVE-2024-1795
Patched
Mar 14, 2024
HUSKY – Products Filter Professional for WooCommerce
High (8.8)
CVE-2023-5663
Patched
Mar 11, 2024
News Announcement Scroll
High (8.8)
CVE-2024-27985
Patched
Mar 13, 2024
PropertyHive
High (8.8)
CVE-2024-1991
Patched
Mar 14, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
High (8.8)
CVE-2024-1685
Unpatched
Mar 15, 2024
Social Media Share Buttons
High (8.8)
CVE-2024-1751
Patched
Mar 11, 2024
Tutor LMS – eLearning and online course solution
High (8.8)
CVE-2024-27972
Patched
Mar 13, 2024
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress
High (8.6)
CVE-2024-0368
Patched
Mar 12, 2024
Hustle – Email Marketing, Lead Generation, Optins, Popups
Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 – Information Exposure via get_posts API Endpoint
High (7.5)
CVE-2023-7072
Patched
Mar 12, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
High (7.4)
CVE-2024-1536
Patched
Mar 11, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
High (7.3)
CVE-2024-2395
Patched
Mar 12, 2024
Bulgarisation for WooCommerce
High (7.3)
CVE-2024-0683
Patched
Mar 12, 2024
Bulgarisation for WooCommerce
High (7.2)
CVE-2024-29117
Patched
Mar 16, 2024
WordPress Contact Forms by Cimatti
High (7.2)
CVE-2024-1812
Patched
Mar 15, 2024
High (7.2)
CVE-2024-29102
Patched
Mar 15, 2024
High (7.2)
CVE-2024-27951
Patched
Mar 13, 2024
Multiple Page Generator Plugin – MPG
High (7.2)
CVE-2024-0386
Patched
Mar 12, 2024
weForms – Easy Drag & Drop Contact Form Builder For WordPress
High (7.2)
CVE-2024-2194
Patched
Mar 11, 2024
WP Statistics
High (7.2)
CVE-2024-27964
Patched
Mar 13, 2024
Zippy
Medium (6.4)
CVE-2024-1080
Patched
Mar 11, 2024
Beaver Builder – WordPress Page Builder
Medium (6.4)
CVE-2024-2181
Patched
Mar 13, 2024
Beaver Builder Addons by WPZOOM
Medium (6.4)
CVE-2024-2183
Patched
Mar 13, 2024
Beaver Builder Addons by WPZOOM
Medium (6.4)
CVE-2024-2185
Patched
Mar 13, 2024
Beaver Builder Addons by WPZOOM
Medium (6.4)
CVE-2024-2186
Patched
Mar 13, 2024
Beaver Builder Addons by WPZOOM
Medium (6.4)
CVE-2024-2187
Patched
Mar 13, 2024
Beaver Builder Addons by WPZOOM
Medium (6.4)
CVE-2024-1894
Patched
Mar 12, 2024
Burst Statistics – Privacy-Friendly Analytics for WordPress
Medium (6.4)
CVE-2024-27963
Patched
Mar 13, 2024
Crisp – Live Chat and Chatbot
Medium (6.4)
CVE-2024-2130
Patched
Mar 12, 2024
CWW Companion
Medium (6.4)
CVE-2024-29103
Patched
Mar 15, 2024
Database for Contact Form 7
Medium (6.4)
CVE-2024-29114
Patched
Mar 16, 2024
Download Manager Pro
Medium (6.4)
CVE-2024-1278
Patched
Mar 12, 2024
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Medium (6.4)
CVE-2024-2308
Patched
Mar 15, 2024
ElementInvader Addons for Elementor
Medium (6.4)
CVE-2024-29107
Patched
Mar 15, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-1458
Patched
Mar 13, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-1465
Patched
Mar 13, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-1466
Patched
Mar 13, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-1464
Patched
Mar 13, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-1461
Patched
Mar 13, 2024
Elementor Addons by Livemesh
Medium (6.4)
CVE-2024-1237
Patched
Mar 11, 2024
Elementor Header & Footer Builder
Elements Plus! <= 2.16.2 – Authenticated(Contributor+) Stored Cross-Site Scripting via widget links
Medium (6.4)
CVE-2024-2335
Patched
Mar 14, 2024
Elements Plus!
ElementsKit Elementor addons <= 3.0.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-1239
Patched
Mar 15, 2024
ElementsKit Elementor addons
Medium (6.4)
CVE-2024-2042
Patched
Mar 15, 2024
ElementsKit Elementor addons
Medium (6.4)
CVE-2024-1537
Patched
Mar 11, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (6.4)
CVE-2024-29089
Patched
Mar 15, 2024
Restaurant Menu and Food Ordering
Free Downloads WooCommerce <= 3.5.8.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-27969
Patched
Mar 13, 2024
Free Downloads WooCommerce
FV Flowplayer Video Player <= 7.5.41.7212 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-29122
Patched
Mar 16, 2024
FV Flowplayer Video Player
Medium (6.4)
CVE-2024-1421
Patched
Mar 12, 2024
HT Mega – Absolute Addons For Elementor
Medium (6.4)
CVE-2024-1397
Patched
Mar 12, 2024
HT Mega – Absolute Addons For Elementor
Medium (6.4)
CVE-2024-1796
Patched
Mar 14, 2024
HUSKY – Products Filter Professional for WooCommerce
Medium (6.4)
CVE-2024-2138
Patched
Mar 13, 2024
JetWidgets For Elementor
Medium (6.4)
CVE-2024-2287
Patched
Mar 15, 2024
Knight Lab Timeline
Medium (6.4)
CVE-2024-2249
Patched
Mar 14, 2024
LA-Studio Element Kit for Elementor
Medium (6.4)
CVE-2024-1328
Unpatched
Mar 11, 2024
Newsletter2Go
Medium (6.4)
CVE-2024-2256
Patched
Mar 14, 2024
oik
Medium (6.4)
CVE-2024-2226
Patched
Mar 13, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-0326
Patched
Mar 12, 2024
Premium Addons for Elementor
Medium (6.4)
CVE-2024-2399
Patched
Mar 14, 2024
Premium Addons Pro for Elementor
Medium (6.4)
CVE-2024-1508
Patched
Mar 12, 2024
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)
Medium (6.4)
CVE-2024-1507
Patched
Mar 12, 2024
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)
Medium (6.4)
CVE-2024-1535
Patched
Mar 12, 2024
Medium (6.4)
CVE-2024-29118
Patched
Mar 16, 2024
Scrollsequence – Cinematic Scroll Image Animation Plugin
Medium (6.4)
CVE-2024-1450
Patched
Mar 12, 2024
Shariff Wrapper
Medium (6.4)
CVE-2024-0966
Patched
Mar 12, 2024
Shariff Wrapper
Shariff Wrapper <= 4.6.9 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Medium (6.4)
CVE-2023-6500
Patched
Mar 12, 2024
Shariff Wrapper
Medium (6.4)
CVE-2024-1960
Patched
Mar 14, 2024
Site Reviews <= 6.11.4 – Authenticated(Subscriber+) Stored Cross-Site Scripting via display name
Medium (6.4)
CVE-2024-2293
Patched
Mar 11, 2024
Site Reviews
Medium (6.4)
CVE-2024-29095
Patched
Mar 15, 2024
Site Reviews
Medium (6.4)
CVE-2024-29111
Patched
Mar 16, 2024
Medium (6.4)
CVE-2024-2286
Patched
Mar 12, 2024
Smart Online Order for Clover <= 1.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-29115
Patched
Mar 16, 2024
Smart Online Order for Clover
Medium (6.4)
CVE-2024-27991
Patched
Mar 15, 2024
SupportCandy – Helpdesk & Customer Support Ticket System
Medium (6.4)
CVE-2024-27990
Patched
Mar 15, 2024
The Moneytizer
Medium (6.4)
CVE-2024-29104
Patched
Mar 15, 2024
Sell Tickets – Event Ticketing and Event Registration – Ticket Tailor for WordPress
Medium (6.4)
CVE-2024-29097
Patched
Mar 15, 2024
User profile
Medium (6.4)
CVE-2024-2423
Patched
Mar 14, 2024
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress
Medium (6.4)
CVE-2024-2031
Patched
Mar 12, 2024
Video Conferencing with Zoom
Medium (6.4)
CVE-2024-27988
Patched
Mar 15, 2024
WEN Responsive Columns
Medium (6.4)
CVE-2024-29098
Patched
Mar 15, 2024
WP Calameo
Medium (6.4)
CVE-2024-1582
Patched
Mar 12, 2024
WP Go Maps (formerly WP Google Maps)
Medium (6.4)
CVE-2024-27989
Patched
Mar 15, 2024
WP Responsive Tabs horizontal vertical and accordion Tabs
Medium (6.4)
CVE-2024-2079
Patched
Mar 13, 2024
WPBakery Page Builder Addons by Livemesh
Medium (6.1)
CVE-2024-27952
Patched
Mar 13, 2024
Advanced Sermons
Medium (6.1)
CVE-2024-27961
Patched
Mar 13, 2024
AntiSpam for Contact Form 7
Medium (6.1)
CVE-2024-27959
Patched
Mar 13, 2024
Medium (6.1)
CVE-2024-27998
Patched
Mar 15, 2024
Medium (6.1)
CVE-2024-27993
Patched
Mar 15, 2024
Calendarista Basic Edition – WordPress appointment booking system
Medium (6.1)
CVE-2024-29130
Patched
Mar 16, 2024
Contact Form 7 – PayPal & Stripe Add-on
Medium (6.1)
CVE-2024-2242
Patched
Mar 13, 2024
Contact Form 7
Contact Form by BestWebSoft <= 4.2.8 – Reflected Cross-Site Scripting via cntctfrm_contact_address
Medium (6.1)
CVE-2024-2198
Patched
Mar 13, 2024
Contact Form by BestWebSoft <= 4.2.8 – Reflected Cross-Site Scripting via cntctfrm_contact_subject
Medium (6.1)
CVE-2024-2200
Patched
Mar 13, 2024
Medium (6.1)
CVE-2024-29125
Patched
Mar 16, 2024
Coupon Affiliates – WooCommerce Affiliate Plugin
Medium (6.1)
CVE-2024-27960
Patched
Mar 13, 2024
Email Subscription Popup
Medium (6.1)
CVE-2024-29099
Patched
Mar 15, 2024
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
Medium (6.1)
CVE-2024-27987
Patched
Mar 15, 2024
GiveWP – Donation Plugin and Fundraising Platform
Medium (6.1)
CVE-2024-29094
Patched
Mar 15, 2024
HT Easy GA4 – Google Analytics WordPress Plugin
Medium (6.1)
CVE-2024-29123
Patched
Mar 16, 2024
Link Library
Medium (6.1)
CVE-2024-2325
Patched
Mar 13, 2024
Link Library
Medium (6.1)
CVE-2024-27992
Patched
Mar 15, 2024
Link Whisper Free
Medium (6.1)
CVE-2024-29129
Patched
Mar 16, 2024
OxyExtras
Medium (6.1)
CVE-2024-29092
Patched
Mar 15, 2024
Permalink Manager Pro
Medium (6.1)
CVE-2024-29113
Patched
Mar 16, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Medium (6.1)
CVE-2024-29126
Patched
Mar 16, 2024
Medium (6.1)
CVE-2024-29110
Patched
Mar 16, 2024
Medium (6.1)
CVE-2024-27958
Patched
Mar 13, 2024
Visualizer: Tables and Charts Manager for WordPress
Medium (6.1)
CVE-2024-29121
Patched
Mar 16, 2024
WooCommerce License Manager
Medium (6.1)
CVE-2024-29116
Patched
Mar 16, 2024
WooThumbs for WooCommerce by Iconic
Medium (6.1)
CVE-2024-29091
Patched
Mar 15, 2024
WP Armour – Honeypot Anti Spam
Medium (6.1)
CVE-2024-27962
Patched
Mar 13, 2024
wp-mpdf
Medium (6.1)
CVE-2024-27994
Patched
Mar 15, 2024
YITH WooCommerce Product Add-Ons
Medium (5.8)
CVE-2024-2107
Patched
Mar 12, 2024
Blossom Spa
Medium (5.5)
CVE-2024-29124
Patched
Mar 16, 2024
Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More
Medium (5.5)
CVE-2023-6525
Patched
Mar 15, 2024
ElementsKit Elementor addons
Medium (5.5)
CVE-2024-29096
Patched
Mar 15, 2024
MJM Clinic
WooCommerce Google Feed Manager <= 2.2.0 – Authenticated (Shop manager+) Stored Cross-Site Scripting
Medium (5.5)
CVE-2024-29112
Patched
Mar 16, 2024
WooCommerce Google Feed Manager
Medium (5.4)
CVE-2024-1641
Patched
Mar 13, 2024
Medium (5.4)
CVE-2024-1213
Patched
Mar 12, 2024
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Medium (5.4)
CVE-2024-0592
Patched
Mar 13, 2024
Related Posts for WordPress
Medium (5.4)
CVE-2024-1502
Patched
Mar 12, 2024
Tutor LMS – eLearning and online course solution
Medium (5.3)
CVE-2024-1640
Patched
Mar 13, 2024
Contact Form Builder by Bit Form: Create Contact Form, Multi Step Form, Conversational Form
Medium (5.3)
CVE-2024-0906
Unpatched
Mar 11, 2024
f(x) Private Site
Medium (5.3)
CVE-2015-10130
Patched
Mar 12, 2024
Team Circle Image Slider With Lightbox
Medium (5.3)
CVE-2024-1857
Patched
Mar 15, 2024
Medium (5.3)
CVE-2024-1733
Unpatched
Mar 15, 2024
Word Replacer Pro
Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 – Authenticated (Admin+) Directory Traversal
Medium (4.9)
CVE-2024-2294
Patched
Mar 15, 2024
Backuply – Backup, Restore, Migrate and Clone
Medium (4.4)
CVE-2024-27995
Patched
Mar 15, 2024
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Medium (4.4)
CVE-2024-27966
Patched
Mar 13, 2024
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
Medium (4.4)
CVE-2024-27996
Patched
Mar 15, 2024
Survey Maker – Best WordPress Survey Plugin
Medium (4.4)
CVE-2024-27997
Patched
Mar 15, 2024
Medium (4.4)
CVE-2023-4839
Patched
Mar 12, 2024
WP Go Maps (formerly WP Google Maps)
Medium (4.4)
CVE-2024-29105
Patched
Mar 15, 2024
WP Popups – WordPress Popup builder
Medium (4.4)
CVE-2024-1571
Patched
Mar 14, 2024
WP Recipe Maker
Medium (4.4)
CVE-2024-27965
Patched
Mar 13, 2024
Easiest Sales Funnel Builder For WordPress & WooCommerce by WPFunnels
Medium (4.3)
CVE-2024-1843
Patched
Mar 11, 2024
Auto Affiliate Links
Medium (4.3)
CVE-2024-24716
Patched
Mar 12, 2024
Awesome Support – WordPress HelpDesk & Support Plugin
Medium (4.3)
CVE-2024-29093
Patched
Mar 15, 2024
Builder for WooCommerce product reviews shortcodes – ReviewShort
Medium (4.3)
CVE-2024-27953
Patched
Mar 13, 2024
Cryptocurrency Widgets – Price Ticker & Coins List
Medium (4.3)
CVE-2024-27967
Patched
Mar 13, 2024
DSGVO All in one for WP
Medium (4.3)
CVE-2024-1214
Patched
Mar 12, 2024
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Medium (4.3)
CVE-2023-4628
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4629
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4626
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4627
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4731
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4729
Unpatched
Mar 11, 2024
Medium (4.3)
CVE-2023-4728
Unpatched
Mar 11, 2024
MasterStudy LMS <= 3.2.13 – Missing Authorization to Sensitive Information Exposure in search_posts
Medium (4.3)
CVE-2024-1904
Patched
Mar 15, 2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Medium (4.3)
CVE-2024-1645
Patched
Mar 11, 2024
Mollie Forms
Medium (4.3)
CVE-2024-1400
Patched
Mar 11, 2024
Mollie Forms
Medium (4.3)
CVE-2024-27968
Patched
Mar 13, 2024
Super Page Cache for Cloudflare
Medium (4.3)
CVE-2024-1503
Patched
Mar 12, 2024
Tutor LMS – eLearning and online course solution
Medium (4.3)
CVE-2024-27970
Patched
Mar 13, 2024
WP SendFox
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (March 11, 2024 to March 17, 2024) appeared first on Wordfence.