Did you know we’re running a Bug Bounty Extravaganza again?
Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through May 27th, 2024 when you opt to have Wordfence handle responsible disclosure!
Last week, there were 375 vulnerabilities disclosed in 297 WordPress Plugins and 7 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 75 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 15,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-685 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-687 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 295 |
Unpatched | 80 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 1 |
Medium Severity | 321 |
High Severity | 31 |
Critical Severity | 22 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 220 |
Missing Authorization | 38 |
Cross-Site Request Forgery (CSRF) | 34 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 24 |
Deserialization of Untrusted Data | 7 |
Information Exposure | 7 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 6 |
Unrestricted Upload of File with Dangerous Type | 6 |
Authorization Bypass Through User-Controlled Key | 5 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 5 |
Server-Side Request Forgery (SSRF) | 5 |
Use of Less Trusted Source | 5 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 3 |
Improper Input Validation | 3 |
Guessable CAPTCHA | 1 |
Improper Control of Generation of Code (‘Code Injection’) | 1 |
Improper Neutralization of Special Elements used in a Command (‘Command Injection’) | 1 |
Improper Privilege Management | 1 |
Incomplete Blacklist to Cross-Site Scripting | 1 |
Incorrect Privilege Assignment | 1 |
Use of Insufficiently Random Values | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
46 | |
32 | |
23 | |
23 | |
16 | |
14 | |
14 | |
14 | |
12 | |
11 | |
10 | |
9 | |
9 | |
8 | |
7 | |
6 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
10Web Map Builder for Google Maps | wd-google-maps |
140+ Widgets | Best Addons For Elementor – FREE | xpro-elementor-addons |
A WordPress Testimonial Plugin to Showcase Testimonial Slider, Testimonial Grid and More: Solid Testimonials | gs-testimonial |
Action Network | wp-action-network |
Add Shortcodes Actions And Filters | add-actions-and-filters |
AdsPlace’r – Ad Manager, Inserter, AdSense Ads | adsplacer |
Advanced Sermons | advanced-sermons |
Aesop Story Engine | aesop-story-engine |
affiliate-toolkit – WordPress Affiliate Plugin | affiliate-toolkit-starter |
AI Twitter Feeds (Twitter widget & shortcode) | ai-twitter-feeds |
AI WP Writer – автонаполнение сайта ChatGPT 3.5, GPT 4 и изображениями лучших нейросетей | ai-wp-writer |
All In One Redirection | all-in-one-redirection |
Announcement & Notification Banner – Bulletin | bulletin-announcements |
Aparat for WordPress | wp-aparat |
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | simply-schedule-appointments |
Appointment Calendar | appointment-calendar |
Author Box, Guest Author and Co-Authors for Your Posts – Molongui | molongui-authorship |
Awesome Support – WordPress HelpDesk & Support Plugin | awesome-support |
B Slider – Slider for your block editor | b-slider |
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | woo-bulk-editor |
Better Elementor Addons | better-elementor-addons |
BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg | betterdocs |
BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More. | print-google-cloud-print-gcp-woocommerce |
Bold Page Builder | bold-page-builder |
BoldGrid Easy SEO – Simple and Effective SEO | boldgrid-easy-seo |
Booking Activities | booking-activities |
Booking Package | booking-package |
Booster for WooCommerce | woocommerce-jetpack |
Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content | brave-popup-builder |
Breeze – WordPress Cache Plugin | breeze |
Broken Images | wp-broken-images |
BuddyPress Moderation | youzify-moderation |
Builderall Builder for WordPress | builderall-cheetah-for-wp |
Bulk NoIndex & NoFollow Toolkit | bulk-noindex-nofollow-toolkit-by-mad-fish |
Button | button |
Calculated Fields Form | calculated-fields-form |
Calendarista Basic Edition – WordPress appointment booking system | calendarista-basic-edition |
Carousel Anything For WPBakery Page Builder – Touch Slider and Carousel | carousel-anything |
CGC Maintenance Mode | cgc-maintenance-mode |
Change default login logo,url and title | change-default-login-logo-url-and-title |
Chauffeur Taxi Booking System for WordPress | chauffeur-booking-system |
Check & Log Email | check-email |
Christmas Greetings | christmas-greetings |
Church Admin | church-admin |
CM Download Manager – Document and File Management | cm-download-manager |
CMP – Coming Soon & Maintenance Plugin by NiteoThemes | cmp-coming-soon-maintenance |
Co-marquage service-public.fr | co-marquage-service-public |
Collect.chat – Chatbot | collectchat |
Comic Easel | comic-easel |
Compact WP Audio Player | compact-wp-audio-player |
Contact Form 7 Newsletter | contact-form-7-newsletter |
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce | enhanced-e-commerce-for-woocommerce-store |
Convert Post Types | convert-post-types |
Creative Image Slider – Responsive Slider Plugin | creative-image-slider |
CRM Perks Forms – WordPress Form Builder | crm-perks-forms |
Crypto Converter Widget | crypto-converter-widget |
CubeWP – All-in-One Dynamic Content Framework | cubewp-framework |
Custom Field Bulk Editor | custom-field-bulk-editor |
Custom WooCommerce Checkout Fields Editor | add-fields-to-checkout-page-woocommerce |
DD Rating | dd-rating |
DELUCKS SEO | delucks-seo |
Doneren met Mollie | doneren-met-mollie |
Dracula Dark Mode – Enhanced Accessibility, Dark Mode & Reading Mode for WordPress | dracula-dark-mode |
Dropdown multisite selector | dropdown-multisite-selector |
DX-Watermark | dx-watermark |
Easy Appointments | easy-appointments |
Easy Form Builder | easy-form-builder |
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box | easy-facebook-likebox |
Easy Textillate | easy-textillate |
easy-social-share-buttons3 | easy-social-share-buttons3 |
Ecwid Ecommerce Shopping Cart | ecwid-shopping-cart |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
Elementor Website Builder Pro | elementor-pro |
Elementor Website Builder – More than Just a Page Builder | elementor |
ElementsKit Elementor addons | elementskit-lite |
Email Newsletter, Marketing, Email Automation and CRM Plugin for WordPress by FluentCRM | fluent-crm |
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | email-subscribers |
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | essential-addons-for-elementor-lite |
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates | essential-blocks |
Event Tickets and Registration | event-tickets |
EventPrime – Events Calendar, Bookings and Tickets | eventprime-event-calendar-management |
Events Manager – Calendar, Bookings, Tickets, and more! | events-manager |
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin | everest-backup |
Exchange Rates Widget | exchange-rates-widget |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Export and Import Users and Customers | users-customers-import-export-for-wp-woocommerce |
Falang multilanguage for WordPress | falang |
Fancy Comments WordPress | fancy-facebook-comments |
Favorites | favorites |
FG PrestaShop to WooCommerce | fg-prestashop-to-woocommerce |
Filter Custom Fields & Taxonomies Light | filter-custom-fields-taxonomies-light |
Finale Lite – Sales Countdown Timer & Discount for WooCommerce | finale-woocommerce-sales-countdown-timer-discount |
FlatPM – Ad Manager, AdSense and Custom Code | flatpm-wp |
Forminator – Contact Form, Payment Form & Custom Form Builder | forminator |
FOX – Currency Switcher Professional for WooCommerce | woocommerce-currency-switcher |
Frontend Dashboard | frontend-dashboard |
Fullscreen Galleria | fullscreen-galleria |
FV Flowplayer Video Player | fv-wordpress-flowplayer |
Gallery – Image and Video Gallery with Thumbnails | gallery-album |
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress | gamipress |
Geo Controller | cf-geoplugin |
GetResponse for WordPress | getresponse-integration |
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program | gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce |
Grid Shortcodes | grid-shortcodes |
Gutenberg Block Editor Toolkit – EditorsKit | block-options |
Gutenberg Blocks by Kadence Blocks – Page Builder Features | kadence-blocks |
Hacklog Down As PDF | down-as-pdf |
Hash Elements | hash-elements |
Header Image Slider | header-image-slider |
HeartThis | heart-this |
Hot Random Image | hot-random-image |
HT Mega – Absolute Addons For Elementor | ht-mega-for-elementor |
Hubbub Lite – Fast, Reliable Social Sharing Buttons | social-pug |
HUSKY – Products Filter Professional for WooCommerce | woocommerce-products-filter |
iCalendrier | icalendrier |
iFlyChat – WordPress Chat | iflychat |
Image Hover Effects – Elementor Addon | image-hover-effects-addon-for-elementor |
Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site | integrate-google-drive |
Kanban Boards for WordPress | kanban |
Klarna Payments for WooCommerce | klarna-payments-for-woocommerce |
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages | page-builder-add |
Landingi Landing Pages | landingi-landing-pages |
Layouts for Elementor | layouts-for-elementor |
Lightbox slider – Responsive Lightbox Gallery | simple-lightbox-gallery |
Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms | limit-attempts |
Link Whisper Free | link-whisper |
LionScripts: IP Blocker Lite | ip-address-blocker |
List category posts | list-category-posts |
Locatoraid Store Locator | locatoraid |
Lordicon Animated Icons | lordicon-interactive-icons |
LWS Optimize | lws-optimize |
MailChimp Forms by MailMunch | mailchimp-forms-by-mailmunch |
Mailster WordPress Newsletter Plugin Compatibility Tester | mailster |
Mang Board WP | mangboard |
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | master-addons |
MasterStudy LMS WordPress Plugin – for Online Courses and Education | masterstudy-lms-learning-management-system |
MDTF – Meta Data and Taxonomies Filter | wp-meta-data-filter-and-taxonomy-filter |
Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more | ilab-media-tools |
Media Library Assistant | media-library-assistant |
Media Library Folders | media-library-plus |
Meta Tag Manager | meta-tag-manager |
Mighty Classic Pros And Cons | joomdev-wp-pros-cons |
Move Addons for Elementor | move-addons |
MP3 Audio Player for Music, Radio & Podcast by Sonaar | mp3-music-player-by-sonaar |
Multiple Page Generator Plugin – MPG | multiple-pages-generator-by-porthas |
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution | dc-woocommerce-multi-vendor |
MyBookTable Bookstore by Stormhill Media | mybooktable |
Nelio Content – Best Editorial Calendar & Social Media Scheduling | nelio-content |
New Order Notification for Woocommerce | new-order-notification-for-woocommerce |
News Wall | news-wall |
Newsletter – Send awesome emails from WordPress | newsletter |
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | ninja-forms |
NPS computy | nps-computy |
Off-Canvas Sidebars & Menus (Slidebars) | off-canvas-sidebars |
OpenID | openid |
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) | stepbyteservice-openstreetmap |
OSS Aliyun | oss-aliyun |
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | otter-blocks |
Page Builder: Pagelayer – Drag and Drop website builder | pagelayer |
pageMash > Page Management | pagemash |
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | paid-memberships-pro |
Paid Memberships Pro – Mailchimp Add On | pmpro-mailchimp |
Paid Memberships Pro – Payfast Gateway Add On | pmpro-payfast |
PDF Builder for WPForms | pdf-builder-for-wpforms |
PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip | 3d-flipbook-dflip-lite |
PDF Viewer for Elementor | pdf-viewer-for-elementor |
Photo Gallery by Ays – Responsive Image Gallery | gallery-photo-gallery |
Photo Gallery by Supsystic | gallery-by-supsystic |
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress | contest-gallery |
Platinum SEO | platinum-seo-pack |
Pocket News Generator | pocket-news-generator |
Podlove Podcast Publisher | podlove-podcasting-plugin-for-wordpress |
Podlove Web Player | podlove-web-player |
Pods – Custom Content Types and Fields | pods |
Popup Builder – Create highly converting, mobile friendly marketing popups. | popup-builder |
Popup Cart Lite for WooCommerce | woocommerce-woocart-popup-lite |
Portfolio Gallery – Image Gallery Plugin | portfolio-filter-gallery |
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | post-and-page-builder |
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | buddyforms |
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | post-grid |
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | post-grid-carousel-ultimate |
Post-Plugin Library | post-plugin-library |
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) | powerpack-lite-for-elementor |
Premium Packages – Sell Digital Products Securely | wpdm-premium-packages |
Prenotazioni | prenotazioni |
Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin | pretty-link |
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) | bdthemes-prime-slider-lite |
Print Page block – Print the entire page or Section. | print-page |
Product Import Export for WooCommerce | product-import-export-for-woo |
ProfileGrid – User Profiles, Memberships, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
PropertyHive | propertyhive |
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress | radio-player |
Real Media Library: Media Library Folder & File Manager | real-media-library-lite |
ReDi Restaurant Reservation | redi-restaurant-reservation |
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | custom-registration-form-builder-with-submission-manager |
Responsive flipbook wordpress plugin free download | wppdf |
ReviewX – Multi-criteria Rating & Reviews for WooCommerce | reviewx |
RoyalSlider | new-royalslider |
RT Easy Builder – Advanced addons for Elementor | rt-easy-builder-advanced-addons-for-elementor |
Salon booking system | salon-booking-system |
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster | sellkit |
SEO Backlink Monitor | seo-backlink-monitor |
SEO Plugin by Squirrly SEO | squirrly-seo |
SEO Title Tag | seo-title-tag |
Shipping with Venipak for WooCommerce | wc-venipak-shipping |
Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension | shortcode-addons |
Shortcodes and extra features for Phlox theme | auxin-elements |
Simple Ajax Chat – Add a Fast, Secure Chat Box | simple-ajax-chat |
Simple Buttons Creator | simple-buttons-creator |
Simple Revisions Delete | simple-revisions-delete |
Simply Static | simply-static |
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) | sina-extension-for-elementor |
Sliced Invoices – WordPress Invoice Plugin | sliced-invoices |
Slider by Supsystic | slider-by-supsystic |
Slider Hero with Animation, Video Background | slider-hero |
Slugs Manager: Delete Old Permalinks from WordPress Database | remove-old-slugspermalinks |
Social Author Bio | social-autho-bio |
Social Icons Widget & Block by WPZOOM | social-icons-widget-by-wpzoom |
SP Project & Document Manager | sp-client-document-manager |
Special Box for Content | special-box-for-content |
SpiderFAQ | spider-faq |
Spiffy Calendar | spiffy-calendar |
Spin 360 deg and 3D Model Viewer | spin360 |
Sponsors | wp-sponsors |
Stackable – Page Builder Gutenberg Blocks | stackable-ultimate-gutenberg-blocks |
Sticky Anything | toast-stick-anything |
Stratum – Elementor Widgets | stratum |
StreamWeasels Twitch Integration | streamweasels-twitch-integration |
Sunshine Photo Cart: Free Client Galleries for Photographers | sunshine-photo-cart |
Survey Maker – Best WordPress Survey Plugin | survey-maker |
Sydney Toolbox | sydney-toolbox |
Tainacan | tainacan |
Tax Rate Upload | tax-rate-upload |
The Plus Addons for Elementor | the-plus-addons-for-elementor-page-builder |
The Plus Blocks for Block Editor | Gutenberg | the-plus-addons-for-block-editor |
Themify Event Post | themify-event-post |
Themify Shortcodes | themify-shortcodes |
Thumbs Rating | thumbs-rating |
Travelers’ Map | travelers-map |
Tumult Hype Animations | tumult-hype-animations |
Tutor LMS Elementor Addons | tutor-lms-elementor-addons |
Ultimate Addons for Beaver Builder – Lite | ultimate-addons-for-beaver-builder-lite |
Ultimate Social Comments – Email Notification & Lazy Load | ultimate-facebook-comments |
underConstruction | underconstruction |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | unlimited-elements-for-elementor |
User Rights Access Manager | user-rights-access-manager |
VK All in One Expansion Unit | vk-all-in-one-expansion-unit |
VS Contact Form | very-simple-contact-form |
WC Builder – WooCommerce Page Builder for WPBakery | wc-builder |
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | wc-frontend-manager |
Web Icons | icon |
Webinar and Video Conference with Jitsi Meet – Create Branded Webinars for WordPress, Meetings & Livestreaming | webinar-and-video-conference-with-jitsi-meet |
Weekly Class Schedule | weekly-class-schedule |
weForms – Easy Drag & Drop Contact Form Builder For WordPress | weforms |
Whizzy | whizzy |
Wholesale For WooCommerce | woocommerce-wholesale-pricing |
WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) | wholesalex |
Woo Viet – WooCommerce for Vietnam | woo-viet |
WooCommerce Bookings Calendar | woo-bookings-calendar |
WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce | cartflows |
WooCommerce Multilingual & Multicurrency with WPML | woocommerce-multilingual |
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | print-invoices-packing-slip-labels-for-woocommerce |
Woocommerce Social Media Share Buttons | woocommerce-social-media-share-buttons |
WordPress Contact Forms by Cimatti | contact-forms |
WordPress CRM Plugin – WP-CRM System | wp-crm-system |
WordPress File Upload | wp-file-upload |
WordPress Infinite Scroll – Ajax Load More | ajax-load-more |
WordPress Page Builder – Zion Builder | zionbuilder |
WP Change Email Sender | wp-change-email-sender |
WP Chat App | wp-whatsapp |
WP Cost Estimation & Payment Forms Builder | wp-estimation-form |
WP Directory Kit | wpdirectorykit |
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | erp |
WP Express Checkout (Accept PayPal Payments Easily) | wp-express-checkout |
WP Fast Total Search – The Power of Indexed Search | fulltext-search |
WP Go Maps (formerly WP Google Maps) | wp-google-maps |
WP Hotel Booking | wp-hotel-booking |
WP Poll Maker – Best WordPress Poll Plugin for Voting Contest | epoll-wp-voting |
WP Post Disclaimer | wp-post-disclaimer |
WP Reset – Most Advanced WordPress Reset Tool | wp-reset |
WP Responsive Tabs horizontal vertical and accordion Tabs | responsive-horizontal-vertical-and-accordion-tabs |
WP Smart Import : Import any XML File to WordPress | wp-smart-import |
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc | wp-sms |
WP Travel Engine – Best Travel Booking WordPress Plugin | wp-travel-engine |
WP Twitter Mega Fan Box Widget | wp-twitter-mega-fan-box |
WP User Profile Avatar | wp-user-profile-avatar |
WP-Eggdrop | wp-eggdrop |
wp-forecast | wp-forecast |
WP-Lister Lite for Amazon | wp-lister-for-amazon |
WPBakery Page Builder Addons by Livemesh | addons-for-visual-composer |
WPC Badge Management for WooCommerce | wpc-badge-management |
WPCS – WordPress Currency Switcher Professional | currency-switcher |
WPFront Notification Bar | wpfront-notification-bar |
YITH WooCommerce Account Funds Premium | yith-woocommerce-account-funds-premium |
Yoo Slider – Image Slider & Video Slider | yoo-slider |
Zotpress | zotpress |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Astra | astra |
Jobeleon WPJobBoard | jobeleon-wpjobboard |
Networker – Tech News WordPress Theme with Dark Mode | networker |
Newsmatic | newsmatic |
Nictitate | nictitate |
OceanWP | oceanwp |
Responsive | responsive |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-31115
Unpatched
Mar 29, 2024
Chauffeur Taxi Booking System for WordPress
Critical (10.0)
CVE-2024-30498
Patched
Mar 28, 2024
CRM Perks Forms – WordPress Form Builder
Critical (10.0)
CVE-2024-2086
Patched
Mar 29, 2024
Critical (10.0)
CVE-2024-30533
Patched
Mar 29, 2024
Layouts for Elementor
Critical (10.0)
CVE-2024-30490
Patched
Mar 28, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Critical (10.0)
CVE-2024-30510
Patched
Mar 28, 2024
Salon booking system
Critical (10.0)
CVE-2024-30502
Patched
Mar 28, 2024
WP Travel Engine – Best Travel Booking WordPress Plugin
Critical (9.9)
CVE-2024-30499
Patched
Mar 28, 2024
CRM Perks Forms – WordPress Form Builder
Critical (9.9)
CVE-2024-30500
Patched
Mar 28, 2024
CubeWP – All-in-One Dynamic Content Framework
Critical (9.9)
CVE-2024-30535
Patched
Mar 29, 2024
Easy Form Builder
Critical (9.9)
CVE-2024-30496
Patched
Mar 28, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Critical (9.9)
CVE-2024-30486
Patched
Mar 28, 2024
Media Library Folders
Critical (9.9)
CVE-2024-30491
Patched
Mar 28, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
WP Cost Estimation & Payment Forms Builder <= 10.1.75 – Authenticated (Contributor+) SQL Injection
Critical (9.9)
CVE-2024-30489
Patched
Mar 28, 2024
WP Cost Estimation & Payment Forms Builder
Critical (9.9)
CVE-2024-30497
Patched
Mar 28, 2024
WP Responsive Tabs horizontal vertical and accordion Tabs
Critical (9.9)
CVE-2024-30488
Patched
Mar 28, 2024
Zotpress
Critical (9.8)
CVE-2024-2411
Patched
Mar 28, 2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education
MasterStudy LMS <= 3.3.1 – Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
Critical (9.8)
CVE-2024-2409
Patched
Mar 28, 2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Critical (9.1)
CVE-2024-31116
Unpatched
Mar 29, 2024
10Web Map Builder for Google Maps
Critical (9.1)
CVE-2024-30494
Patched
Mar 28, 2024
OSS Aliyun
Critical (9.1)
CVE-2024-31114
Unpatched
Mar 29, 2024
Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension
Critical (9.1)
CVE-2024-30504
Patched
Mar 28, 2024
WP Travel Engine – Best Travel Booking WordPress Plugin
High (8.8)
CVE-2024-1872
Unpatched
Mar 28, 2024
Button
High (8.8)
CVE-2024-2047
Patched
Mar 29, 2024
ElementsKit Elementor addons
High (8.8)
CVE-2024-3018
Patched
Mar 29, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Filter Custom Fields & Taxonomies Light <= 1.05 – Authenticated (Contributor+) PHP Object Injection
High (8.8)
CVE-2024-31094
Unpatched
Mar 29, 2024
Filter Custom Fields & Taxonomies Light
High (8.8)
CVE-2024-2693
Patched
Mar 26, 2024
Link Whisper Free
High (8.8)
CVE-2024-1770
Patched
Mar 27, 2024
Meta Tag Manager
High (8.8)
CVE-2023-6999
Patched
Mar 28, 2024
Pods – Custom Content Types and Fields
Pods – Custom Content Types and Fields – Authenticated (Contributor+) SQL Injection via Shortcode
High (8.8)
CVE-2023-6967
Patched
Mar 28, 2024
Pods – Custom Content Types and Fields
High (8.8)
CVE-2024-1990
Patched
Mar 26, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
High (8.8)
CVE-2024-0608
Unpatched
Mar 28, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
High (8.1)
CVE-2024-0866
Patched
Mar 25, 2024
Check & Log Email
High (7.5)
CVE-2024-2501
Patched
Mar 27, 2024
Hubbub Lite – Fast, Reliable Social Sharing Buttons
High (7.5)
CVE-2024-2848
Patched
Mar 28, 2024
Responsive
High (7.2)
CVE-2024-30453
Patched
Mar 28, 2024
Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content
High (7.2)
CVE-2024-30532
Patched
Mar 29, 2024
Builderall Builder for WordPress
High (7.2)
CVE-2023-7201
Patched
Mar 25, 2024
High (7.2)
CVE-2024-30495
Patched
Mar 28, 2024
Falang multilanguage for WordPress
High (7.2)
CVE-2024-2948
Patched
Mar 29, 2024
Favorites
High (7.2)
CVE-2024-1794
Patched
Mar 29, 2024
Forminator – Contact Form, Payment Form & Custom Form Builder
High (7.2)
CVE-2024-3061
Patched
Mar 28, 2024
HUSKY – Products Filter Professional for WooCommerce
High (7.2)
CVE-2024-29788
Patched
Mar 25, 2024
Podlove Web Player
Product Import Export for WooCommerce <= 2.4.1 – Authenticated(Shop Manager+) Arbitrary File Upload
High (7.2)
CVE-2024-30231
Patched
Mar 26, 2024
Product Import Export for WooCommerce
High (7.2)
CVE-2024-2957
Patched
Mar 26, 2024
Simple Ajax Chat – Add a Fast, Secure Chat Box
High (7.2)
CVE-2024-2857
Unpatched
Mar 25, 2024
Simple Buttons Creator
High (7.2)
CVE-2024-30551
Unpatched
Mar 29, 2024
Sticky Anything
High (7.2)
CVE-2024-2954
Unpatched
Mar 26, 2024
Action Network
High (7.2)
CVE-2024-30478
Patched
Mar 28, 2024
Announcement & Notification Banner – Bulletin
High (7.2)
CVE-2024-0913
Unpatched
Mar 28, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
High (7.2)
CVE-2024-0952
Unpatched
Mar 28, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
High (7.2)
CVE-2024-0956
Unpatched
Mar 28, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
High (7.2)
CVE-2024-0609
Unpatched
Mar 28, 2024
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
Medium (6.5)
CVE-2024-2792
Patched
Mar 27, 2024
Elementor Addon Elements
Medium (6.5)
CVE-2024-30509
Patched
Mar 28, 2024
SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster
Medium (6.5)
CVE-2024-2093
Patched
Mar 26, 2024
VK All in One Expansion Unit
Medium (6.5)
CVE-2024-30542
Patched
Mar 29, 2024
WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing)
Medium (6.4)
CVE-2024-2250
Patched
Mar 28, 2024
140+ Widgets | Best Addons For Elementor – FREE
Medium (6.4)
CVE-2024-30557
Unpatched
Mar 29, 2024
Aesop Story Engine
Medium (6.4)
CVE-2024-29817
Patched
Mar 25, 2024
affiliate-toolkit – WordPress Affiliate Plugin
Medium (6.4)
CVE-2024-31101
Unpatched
Mar 29, 2024
AI Twitter Feeds (Twitter widget & shortcode)
Medium (6.4)
CVE-2024-29765
Patched
Mar 25, 2024
Aparat for WordPress
Medium (6.4)
CVE-2024-2347
Patched
Mar 25, 2024
Astra
Medium (6.4)
CVE-2024-30432
Patched
Mar 28, 2024
B Slider – Slider for your block editor
Medium (6.4)
CVE-2024-30423
Patched
Mar 28, 2024
Better Elementor Addons
Medium (6.4)
CVE-2024-2280
Patched
Mar 28, 2024
Better Elementor Addons
Medium (6.4)
CVE-2024-2845
Patched
Mar 25, 2024
Medium (6.4)
CVE-2024-30179
Patched
Mar 25, 2024
Bold Page Builder
Medium (6.4)
CVE-2024-1692
Patched
Mar 29, 2024
BoldGrid Easy SEO – Simple and Effective SEO
Medium (6.4)
CVE-2024-30520
Unpatched
Mar 28, 2024
Carousel Anything For WPBakery Page Builder – Touch Slider and Carousel
Medium (6.4)
CVE-2024-30197
Patched
Mar 25, 2024
Church Admin
Medium (6.4)
CVE-2024-30193
Patched
Mar 25, 2024
Church Admin
Medium (6.4)
CVE-2024-29908
Patched
Mar 25, 2024
Co-marquage service-public.fr
Medium (6.4)
CVE-2024-30436
Patched
Mar 28, 2024
Collect.chat – Chatbot
Medium (6.4)
CVE-2024-29917
Patched
Mar 25, 2024
Compact WP Audio Player
Medium (6.4)
CVE-2024-30446
Patched
Mar 28, 2024
CRM Perks Forms – WordPress Form Builder
Medium (6.4)
CVE-2024-29930
Patched
Mar 25, 2024
Crypto Converter Widget
Medium (6.4)
CVE-2024-30554
Unpatched
Mar 29, 2024
Medium (6.4)
CVE-2024-29807
Patched
Mar 25, 2024
PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip
Medium (6.4)
CVE-2024-29771
Patched
Mar 25, 2024
Dracula Dark Mode – Enhanced Accessibility, Dark Mode & Reading Mode for WordPress
Medium (6.4)
CVE-2024-29910
Patched
Mar 25, 2024
Dropdown multisite selector
Medium (6.4)
CVE-2024-2842
Patched
Mar 28, 2024
Easy Appointments
Easy Social Feed <= 6.5.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via fb_appid
Medium (6.4)
CVE-2024-30180
Patched
Mar 25, 2024
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Medium (6.4)
CVE-2024-2303
Patched
Mar 25, 2024
Easy Textillate
Medium (6.4)
CVE-2024-2456
Patched
Mar 29, 2024
Ecwid Ecommerce Shopping Cart
Medium (6.4)
CVE-2024-30185
Patched
Mar 25, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (6.4)
CVE-2024-30422
Patched
Mar 28, 2024
Elementor Addon Elements
Medium (6.4)
CVE-2024-2117
Patched
Mar 26, 2024
Elementor Website Builder – More than Just a Page Builder
Medium (6.4)
CVE-2024-1364
Patched
Mar 26, 2024
Elementor Website Builder Pro
Medium (6.4)
CVE-2024-2781
Patched
Mar 26, 2024
Elementor Website Builder Pro
Medium (6.4)
CVE-2024-1521
Patched
Mar 26, 2024
Elementor Website Builder Pro
ElementsKit Elementor addons <= 3.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-1238
Patched
Mar 29, 2024
ElementsKit Elementor addons
Medium (6.4)
CVE-2024-2623
Patched
Mar 25, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (6.4)
CVE-2024-2650
Patched
Mar 25, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (6.4)
CVE-2024-2111
Patched
Mar 27, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (6.4)
CVE-2024-29814
Patched
Mar 25, 2024
Exchange Rates Widget
Medium (6.4)
CVE-2024-30177
Patched
Mar 25, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-30232
Patched
Mar 26, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-29804
Patched
Mar 25, 2024
Fancy Comments WordPress
Medium (6.4)
CVE-2024-29803
Patched
Mar 25, 2024
FlatPM – Ad Manager, AdSense and Custom Code
Medium (6.4)
CVE-2024-29775
Patched
Mar 25, 2024
Frontend Dashboard
Medium (6.4)
CVE-2024-29801
Patched
Mar 25, 2024
Fullscreen Galleria
Medium (6.4)
CVE-2024-2783
Patched
Mar 27, 2024
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress
Medium (6.4)
CVE-2024-30451
Patched
Mar 28, 2024
Geo Controller
Medium (6.4)
CVE-2024-31104
Unpatched
Mar 29, 2024
GetResponse for WordPress
Medium (6.4)
CVE-2024-29798
Patched
Mar 25, 2024
Medium (6.4)
CVE-2024-29797
Patched
Mar 25, 2024
Grid Shortcodes
Medium (6.4)
CVE-2024-30443
Patched
Mar 28, 2024
A WordPress Testimonial Plugin to Showcase Testimonial Slider, Testimonial Grid and More: Solid Testimonials
Medium (6.4)
CVE-2024-2794
Patched
Mar 29, 2024
Gutenberg Block Editor Toolkit – EditorsKit
Gutenberg Blocks by Kadence Blocks <= 3.2.25 – Authenticated (Author+) Server-Side Request Forgery
Medium (6.4)
CVE-2024-24888
Patched
Mar 29, 2024
Gutenberg Blocks by Kadence Blocks – Page Builder Features
Medium (6.4)
CVE-2024-30426
Patched
Mar 28, 2024
Hash Elements
Medium (6.4)
CVE-2024-31121
Unpatched
Mar 29, 2024
Medium (6.4)
CVE-2024-29796
Patched
Mar 25, 2024
Hot Random Image
Medium (6.4)
CVE-2024-30182
Patched
Mar 25, 2024
HT Mega – Absolute Addons For Elementor
Medium (6.4)
CVE-2024-29912
Patched
Mar 25, 2024
iCalendrier
Medium (6.4)
CVE-2024-31108
Unpatched
Mar 29, 2024
iFlyChat – WordPress Chat
Medium (6.4)
CVE-2024-29936
Patched
Mar 25, 2024
Image Hover Effects – Elementor Addon
Medium (6.4)
CVE-2024-1051
Patched
Mar 29, 2024
List category posts
Medium (6.4)
CVE-2024-30183
Patched
Mar 25, 2024
WPBakery Page Builder Addons by Livemesh
Medium (6.4)
CVE-2024-30519
Unpatched
Mar 28, 2024
Lordicon Animated Icons
Medium (6.4)
CVE-2024-29793
Patched
Mar 25, 2024
MailChimp Forms by MailMunch
Master Addons for Elementor <= 2.0.5.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-29911
Patched
Mar 25, 2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
Medium (6.4)
CVE-2024-2139
Patched
Mar 26, 2024
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
Medium (6.4)
CVE-2024-29795
Patched
Mar 25, 2024
Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more
Medium (6.4)
CVE-2024-2871
Patched
Mar 25, 2024
Media Library Assistant
Medium (6.4)
CVE-2024-2475
Patched
Mar 28, 2024
Media Library Assistant
Mighty Classic Pros And Cons <= 2.0.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-30556
Unpatched
Mar 29, 2024
Mighty Classic Pros And Cons
Medium (6.4)
CVE-2024-30530
Patched
Mar 29, 2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar
Medium (6.4)
CVE-2024-29772
Patched
Mar 25, 2024
MyBookTable Bookstore by Stormhill Media
Medium (6.4)
CVE-2024-30531
Patched
Mar 29, 2024
Nelio Content – Best Editorial Calendar & Social Media Scheduling
Medium (6.4)
CVE-2024-29762
Patched
Mar 25, 2024
Off-Canvas Sidebars & Menus (Slidebars)
Medium (6.4)
CVE-2024-30450
Patched
Mar 28, 2024
Medium (6.4)
CVE-2024-2841
Patched
Mar 28, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-2729
Patched
Mar 28, 2024
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
Medium (6.4)
CVE-2024-29820
Patched
Mar 25, 2024
PDF Builder for WPForms
Medium (6.4)
CVE-2024-30524
Unpatched
Mar 29, 2024
PDF Viewer for Elementor
Medium (6.4)
CVE-2024-30184
Patched
Mar 25, 2024
Medium (6.4)
CVE-2024-29769
Patched
Mar 25, 2024
Portfolio Gallery – Image Gallery Plugin
Medium (6.4)
CVE-2024-2888
Patched
Mar 25, 2024
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
Medium (6.4)
CVE-2024-29925
Patched
Mar 25, 2024
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget
Medium (6.4)
CVE-2024-2491
Patched
Mar 29, 2024
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)
Medium (6.4)
CVE-2024-2492
Patched
Mar 29, 2024
PowerPack Addons for Elementor (Free Widgets, Extensions and Templates)
Medium (6.4)
CVE-2024-30186
Patched
Mar 25, 2024
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)
Medium (6.4)
CVE-2024-30438
Patched
Mar 28, 2024
Print Page block – Print the entire page or Section.
Medium (6.4)
CVE-2024-2027
Patched
Mar 25, 2024
Real Media Library: Media Library Folder & File Manager
Medium (6.4)
CVE-2024-30552
Unpatched
Mar 29, 2024
Responsive flipbook wordpress plugin free download
Medium (6.4)
CVE-2024-31120
Unpatched
Mar 29, 2024
Gallery – Image and Video Gallery with Thumbnails
Medium (6.4)
CVE-2024-29812
Patched
Mar 25, 2024
ReviewX – Multi-criteria Rating & Reviews for WooCommerce
Sina Extension for Elementor <= 3.5.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-29935
Patched
Mar 25, 2024
Medium (6.4)
CVE-2024-31118
Unpatched
Mar 29, 2024
SP Project & Document Manager
Spin 360 deg and 3D Model Viewer <= 1.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-30559
Unpatched
Mar 29, 2024
Spin 360 deg and 3D Model Viewer
Medium (6.4)
CVE-2024-30483
Unpatched
Mar 28, 2024
Sponsors
Medium (6.4)
CVE-2024-2039
Patched
Mar 28, 2024
Stackable – Page Builder Gutenberg Blocks
Medium (6.4)
CVE-2024-29914
Patched
Mar 25, 2024
Stratum – Elementor Widgets
StreamWeasels Twitch Integration <= 1.7.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-29766
Patched
Mar 25, 2024
StreamWeasels Twitch Integration
Medium (6.4)
CVE-2024-2936
Patched
Mar 28, 2024
Sydney Toolbox
Medium (6.4)
CVE-2024-2203
Patched
Mar 26, 2024
The Plus Addons for Elementor
Medium (6.4)
CVE-2024-2210
Patched
Mar 26, 2024
The Plus Addons for Elementor
Medium (6.4)
CVE-2024-29909
Patched
Mar 25, 2024
Travelers’ Map
Medium (6.4)
CVE-2024-29913
Patched
Mar 25, 2024
Tutor LMS Elementor Addons
Medium (6.4)
CVE-2024-2140
Patched
Mar 29, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-2141
Patched
Mar 29, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-2143
Patched
Mar 29, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-2144
Patched
Mar 29, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-2142
Patched
Mar 29, 2024
Ultimate Addons for Beaver Builder – Lite
Medium (6.4)
CVE-2024-30555
Unpatched
Mar 29, 2024
Ultimate Social Comments – Email Notification & Lazy Load
Medium (6.4)
CVE-2024-0367
Patched
Mar 29, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (6.4)
CVE-2024-2170
Patched
Mar 25, 2024
VK All in One Expansion Unit
Medium (6.4)
CVE-2024-29926
Patched
Mar 25, 2024
WC Builder – WooCommerce Page Builder for WPBakery
Medium (6.4)
CVE-2024-30433
Patched
Mar 28, 2024
MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution
Medium (6.4)
CVE-2024-30445
Patched
Mar 28, 2024
Web Icons
Medium (6.4)
CVE-2024-29933
Patched
Mar 25, 2024
Web Icons
Medium (6.4)
CVE-2024-30437
Patched
Mar 28, 2024
WooCommerce Bookings Calendar <= 1.0.36 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-31117
Unpatched
Mar 29, 2024
WooCommerce Bookings Calendar
Medium (6.4)
CVE-2024-2847
Patched
Mar 29, 2024
WordPress File Upload
Medium (6.4)
CVE-2024-29906
Patched
Mar 25, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (6.4)
CVE-2024-29932
Patched
Mar 25, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (6.4)
CVE-2024-29763
Patched
Mar 25, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (6.4)
CVE-2024-2513
Patched
Mar 29, 2024
WP Chat App
Medium (6.4)
CVE-2024-29799
Patched
Mar 25, 2024
WP Fast Total Search – The Power of Indexed Search
Medium (6.4)
CVE-2024-29761
Patched
Mar 25, 2024
WP Post Disclaimer
Medium (6.4)
CVE-2023-6067
Unpatched
Mar 25, 2024
WP User Profile Avatar
Medium (6.4)
CVE-2024-30429
Patched
Mar 28, 2024
wp-forecast
Medium (6.4)
CVE-2024-29819
Patched
Mar 25, 2024
WPFront Notification Bar
Medium (6.1)
CVE-2024-30558
Unpatched
Mar 29, 2024
Add Shortcodes Actions And Filters
Medium (6.1)
CVE-2024-31088
Unpatched
Mar 29, 2024
AdsPlace’r – Ad Manager, Inserter, AdSense Ads
Medium (6.1)
CVE-2024-29928
Patched
Mar 25, 2024
Advanced Sermons
Medium (6.1)
CVE-2024-30506
Unpatched
Mar 28, 2024
All In One Redirection
Medium (6.1)
CVE-2024-30561
Unpatched
Mar 29, 2024
Appointment Calendar
Medium (6.1)
CVE-2024-29773
Patched
Mar 25, 2024
BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More.
Medium (6.1)
CVE-2024-30449
Patched
Mar 28, 2024
Booking Activities
Medium (6.1)
CVE-2024-29760
Patched
Mar 25, 2024
Booster for WooCommerce
Medium (6.1)
CVE-2024-30198
Patched
Mar 25, 2024
Medium (6.1)
CVE-2024-2864
Unpatched
Mar 25, 2024
BuddyPress Moderation
Bulk NoIndex & NoFollow Toolkit <= 2.01 – Reflected Cross-Site Scripting via tab, order, and orderby
Medium (6.1)
CVE-2024-29791
Patched
Mar 25, 2024
Bulk NoIndex & NoFollow Toolkit
Medium (6.1)
CVE-2024-29759
Patched
Mar 25, 2024
Calculated Fields Form
Medium (6.1)
CVE-2024-2116
Unpatched
Mar 28, 2024
Christmas Greetings
Medium (6.1)
CVE-2024-29758
Patched
Mar 25, 2024
Co-marquage service-public.fr
Medium (6.1)
CVE-2024-31092
Unpatched
Mar 29, 2024
Comic Easel
Medium (6.1)
CVE-2024-31110
Unpatched
Mar 29, 2024
Contact Form 7 Newsletter
Medium (6.1)
CVE-2024-30428
Patched
Mar 28, 2024
Medium (6.1)
CVE-2024-29794
Patched
Mar 25, 2024
Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce
Medium (6.1)
CVE-2024-31112
Unpatched
Mar 29, 2024
Convert Post Types
Medium (6.1)
CVE-2024-30447
Patched
Mar 28, 2024
Creative Image Slider – Responsive Slider Plugin
Medium (6.1)
CVE-2024-31091
Unpatched
Mar 29, 2024
Custom Field Bulk Editor
Medium (6.1)
CVE-2024-29767
Patched
Mar 25, 2024
Doneren met Mollie
Medium (6.1)
CVE-2024-30196
Patched
Mar 25, 2024
easy-social-share-buttons3
Medium (6.1)
CVE-2024-22300
Patched
Mar 26, 2024
Medium (6.1)
CVE-2024-29777
Patched
Mar 25, 2024
Forminator – Contact Form, Payment Form & Custom Form Builder
Medium (6.1)
CVE-2024-22299
Patched
Mar 26, 2024
FV Flowplayer Video Player
Medium (6.1)
CVE-2024-31090
Unpatched
Mar 29, 2024
Hacklog Down As PDF
Medium (6.1)
CVE-2024-30547
Unpatched
Mar 29, 2024
Header Image Slider
Medium (6.1)
CVE-2022-47153
Patched
Mar 28, 2024
Jobeleon WPJobBoard
Medium (6.1)
CVE-2024-31103
Unpatched
Mar 29, 2024
Kanban Boards for WordPress
Medium (6.1)
CVE-2024-30439
Patched
Mar 28, 2024
Limit Attempts by BestWebSoft – WordPress Anti-Bot and Security Plugin for Login and Forms
Medium (6.1)
CVE-2024-30503
Patched
Mar 28, 2024
Mailster WordPress Newsletter Plugin Compatibility Tester
Medium (6.1)
CVE-2024-30431
Patched
Mar 28, 2024
Mang Board WP
Medium (6.1)
CVE-2024-31107
Unpatched
Mar 29, 2024
OpenID
Medium (6.1)
CVE-2024-31087
Unpatched
Mar 29, 2024
pageMash > Page Management
Medium (6.1)
CVE-2024-29919
Patched
Mar 25, 2024
Photo Gallery by Ays – Responsive Image Gallery
Medium (6.1)
CVE-2024-29915
Patched
Mar 25, 2024
Podlove Podcast Publisher
Medium (6.1)
CVE-2024-30441
Patched
Mar 28, 2024
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
Medium (6.1)
CVE-2024-31085
Unpatched
Mar 29, 2024
Post-Plugin Library
Medium (6.1)
CVE-2024-29924
Patched
Mar 25, 2024
Premium Packages – Sell Digital Products Securely
Medium (6.1)
CVE-2024-29923
Patched
Mar 25, 2024
PropertyHive
Medium (6.1)
CVE-2024-29806
Patched
Mar 25, 2024
ReDi Restaurant Reservation
Medium (6.1)
CVE-2024-30550
Unpatched
Mar 29, 2024
Gallery – Image and Video Gallery with Thumbnails
Medium (6.1)
CVE-2024-30195
Patched
Mar 25, 2024
RoyalSlider
Medium (6.1)
CVE-2024-29907
Patched
Mar 25, 2024
SEO Backlink Monitor
Medium (6.1)
CVE-2024-29790
Patched
Mar 25, 2024
SEO Plugin by Squirrly SEO
Medium (6.1)
CVE-2024-31097
Unpatched
Mar 29, 2024
SEO Title Tag
Medium (6.1)
CVE-2024-29805
Patched
Mar 25, 2024
Shipping with Venipak for WooCommerce
Medium (6.1)
CVE-2024-29770
Patched
Mar 25, 2024
Medium (6.1)
CVE-2024-22311
Patched
Mar 26, 2024
Medium (6.1)
CVE-2024-30545
Unpatched
Mar 29, 2024
Social Author Bio
Medium (6.1)
CVE-2024-31123
Unpatched
Mar 29, 2024
SpiderFAQ
Medium (6.1)
CVE-2024-30427
Patched
Mar 28, 2024
Spiffy Calendar
Medium (6.1)
CVE-2024-30194
Patched
Mar 25, 2024
Sunshine Photo Cart: Free Client Galleries for Photographers
Medium (6.1)
CVE-2024-29918
Patched
Mar 25, 2024
Survey Maker – Best WordPress Survey Plugin
Medium (6.1)
CVE-2024-31105
Unpatched
Mar 29, 2024
Tax Rate Upload
Medium (6.1)
CVE-2024-30435
Patched
Mar 28, 2024
The Plus Blocks for Block Editor | Gutenberg
Medium (6.1)
CVE-2024-30461
Patched
Mar 28, 2024
Tumult Hype Animations
Medium (6.1)
CVE-2024-29792
Patched
Mar 25, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (6.1)
CVE-2024-31122
Unpatched
Mar 29, 2024
User Rights Access Manager
Medium (6.1)
CVE-2024-31084
Unpatched
Mar 29, 2024
Weekly Class Schedule
Medium (6.1)
CVE-2024-22288
Patched
Mar 26, 2024
Woocommerce Social Media Share Buttons <= 1.3.0 – Cross-Site Request Forgery to Cross-Site Scripting
Medium (6.1)
CVE-2024-31109
Unpatched
Mar 29, 2024
Woocommerce Social Media Share Buttons
Medium (6.1)
CVE-2024-30201
Patched
Mar 25, 2024
WP Smart Import : Import any XML File to WordPress
Medium (6.1)
CVE-2024-29774
Patched
Mar 25, 2024
WP Directory Kit
Medium (6.1)
CVE-2024-29931
Patched
Mar 25, 2024
WP Go Maps (formerly WP Google Maps)
Medium (6.1)
CVE-2024-30199
Patched
Mar 25, 2024
WP-Lister Lite for Amazon
Medium (6.1)
CVE-2024-31106
Unpatched
Mar 29, 2024
Yoo Slider – Image Slider & Video Slider
Medium (5.9)
CVE-2023-6799
Patched
Mar 26, 2024
WP Reset – Most Advanced WordPress Reset Tool
Medium (5.6)
CVE-2024-30459
Patched
Mar 28, 2024
AI WP Writer – автонаполнение сайта ChatGPT 3.5, GPT 4 и изображениями лучших нейросетей
Medium (5.5)
CVE-2024-29768
Patched
Mar 25, 2024
Astra
Breeze <= 2.1.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via breeze_api_token
Medium (5.5)
CVE-2024-27188
Patched
Mar 25, 2024
Breeze – WordPress Cache Plugin
Medium (5.5)
CVE-2023-50374
Patched
Mar 27, 2024
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
Medium (5.5)
CVE-2024-29776
Patched
Mar 25, 2024
EventPrime – Events Calendar, Bookings and Tickets
Medium (5.5)
CVE-2024-29813
Patched
Mar 25, 2024
WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce
Medium (5.5)
CVE-2024-30181
Patched
Mar 25, 2024
Locatoraid Store Locator
Medium (5.5)
CVE-2024-29764
Patched
Mar 25, 2024
Author Box, Guest Author and Co-Authors for Your Posts – Molongui
Photo Gallery by Supsystic <= 1.15.16 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (5.5)
CVE-2024-29921
Patched
Mar 25, 2024
Photo Gallery by Supsystic
Medium (5.5)
CVE-2024-30178
Patched
Mar 25, 2024
Simply Static
Medium (5.5)
CVE-2024-29922
Patched
Mar 25, 2024
Slider Hero with Animation, Video Background
Medium (5.4)
CVE-2024-2091
Patched
Mar 27, 2024
Elementor Addon Elements
Elementor Website Builder Pro <= 3.20.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (5.4)
CVE-2024-2121
Patched
Mar 26, 2024
Elementor Website Builder Pro
Medium (5.4)
CVE-2024-2120
Patched
Mar 26, 2024
Elementor Website Builder Pro
Medium (5.4)
CVE-2024-30485
Patched
Mar 28, 2024
Finale Lite – Sales Countdown Timer & Discount for WooCommerce
Medium (5.4)
CVE-2024-1858
Unpatched
Mar 28, 2024
Lightbox slider – Responsive Lightbox Gallery
Medium (5.4)
CVE-2024-2964
Unpatched
Mar 28, 2024
Pocket News Generator
Medium (5.4)
CVE-2024-2732
Patched
Mar 25, 2024
Themify Shortcodes
Medium (5.4)
CVE-2024-30543
Unpatched
Mar 29, 2024
Whizzy
Medium (5.4)
CVE-2024-2969
Unpatched
Mar 28, 2024
WP-Eggdrop
Medium (5.3)
CVE-2024-30539
Patched
Mar 29, 2024
Awesome Support – WordPress HelpDesk & Support Plugin
Medium (5.3)
CVE-2024-30463
Patched
Mar 28, 2024
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
Medium (5.3)
CVE-2024-30516
Patched
Mar 28, 2024
Booking Package
Medium (5.3)
CVE-2024-30534
Patched
Mar 29, 2024
Calendarista Basic Edition – WordPress appointment booking system
Medium (5.3)
CVE-2024-30480
Unpatched
Mar 28, 2024
CGC Maintenance Mode
Medium (5.3)
CVE-2024-30538
Patched
Mar 29, 2024
DELUCKS SEO
Medium (5.3)
CVE-2024-2974
Patched
Mar 29, 2024
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
Medium (5.3)
CVE-2024-30511
Patched
Mar 29, 2024
FG PrestaShop to WooCommerce
Medium (5.3)
CVE-2024-30479
Unpatched
Mar 28, 2024
LionScripts: IP Blocker Lite
Medium (5.3)
CVE-2024-30477
Patched
Mar 28, 2024
Klarna Payments for WooCommerce
Medium (5.3)
CVE-2024-30525
Patched
Mar 29, 2024
Move Addons for Elementor
Medium (5.3)
CVE-2024-2962
Patched
Mar 26, 2024
Networker – Tech News WordPress Theme with Dark Mode
Medium (5.3)
CVE-2024-30522
Patched
Mar 28, 2024
Newsletter – Send awesome emails from WordPress
Medium (5.3)
CVE-2024-1587
Patched
Mar 25, 2024
Newsmatic
Medium (5.3)
CVE-2024-30523
Patched
Mar 28, 2024
Paid Memberships Pro – Mailchimp Add On
Medium (5.3)
CVE-2024-30514
Patched
Mar 28, 2024
Paid Memberships Pro – Payfast Gateway Add On
Medium (5.3)
CVE-2024-2906
Patched
Mar 26, 2024
Medium (5.3)
CVE-2024-30484
Patched
Mar 28, 2024
RT Easy Builder – Advanced addons for Elementor
Medium (5.3)
CVE-2024-2858
Unpatched
Mar 25, 2024
Simple Buttons Creator
Medium (5.3)
CVE-2024-30529
Patched
Mar 29, 2024
Tainacan
Medium (5.3)
CVE-2024-31095
Unpatched
Mar 29, 2024
Thumbs Rating
Medium (5.3)
CVE-2024-30540
Patched
Mar 29, 2024
VS Contact Form
Medium (5.3)
CVE-2024-30512
Patched
Mar 28, 2024
weForms – Easy Drag & Drop Contact Form Builder For WordPress
Medium (5.3)
CVE-2024-30544
Unpatched
Mar 29, 2024
Whizzy
Medium (5.3)
CVE-2024-30469
Patched
Mar 28, 2024
Wholesale For WooCommerce
Medium (5.3)
CVE-2024-30527
Patched
Mar 29, 2024
WP Express Checkout (Accept PayPal Payments Easily)
Medium (5.3)
CVE-2024-30508
Patched
Mar 28, 2024
WP Hotel Booking
Medium (4.9)
CVE-2024-1790
Patched
Mar 26, 2024
WordPress Infinite Scroll – Ajax Load More
Medium (4.6)
CVE-2024-2108
Patched
Mar 28, 2024
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Medium (4.4)
Unknown
Patched
Mar 28, 2024
WordPress Infinite Scroll – Ajax Load More
Medium (4.4)
CVE-2024-30549
Unpatched
Mar 29, 2024
WordPress Contact Forms by Cimatti
Medium (4.4)
CVE-2024-30430
Patched
Mar 28, 2024
Email Newsletter, Marketing, Email Automation and CRM Plugin for WordPress by FluentCRM
Medium (4.4)
CVE-2024-30452
Patched
Mar 28, 2024
Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
Medium (4.4)
CVE-2024-1754
Patched
Mar 25, 2024
NPS computy
Medium (4.4)
CVE-2024-31089
Unpatched
Mar 29, 2024
Platinum SEO
Medium (4.4)
CVE-2024-2963
Unpatched
Mar 28, 2024
Pocket News Generator
Medium (4.4)
CVE-2024-31102
Unpatched
Mar 29, 2024
Prenotazioni
Medium (4.4)
CVE-2024-2956
Patched
Mar 26, 2024
Simple Ajax Chat – Add a Fast, Secure Chat Box
Medium (4.4)
CVE-2024-30448
Patched
Mar 28, 2024
Slider by Supsystic
Medium (4.4)
CVE-2024-31119
Unpatched
Mar 29, 2024
Special Box for Content
Medium (4.4)
CVE-2024-30440
Patched
Mar 28, 2024
Themify Event Post
Medium (4.4)
CVE-2024-30548
Patched
Mar 29, 2024
underConstruction
Medium (4.4)
CVE-2024-29929
Patched
Mar 25, 2024
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
Medium (4.4)
CVE-2024-29816
Patched
Mar 25, 2024
Woo Viet – WooCommerce for Vietnam
WordPress Page Builder – Zion Builder <= 3.6.9 – Authenticated (Editor+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-30444
Patched
Mar 28, 2024
WordPress Page Builder – Zion Builder
Medium (4.4)
CVE-2024-29815
Patched
Mar 25, 2024
WP Change Email Sender
Medium (4.4)
CVE-2024-29818
Patched
Mar 25, 2024
WP Poll Maker – Best WordPress Poll Plugin for Voting Contest
WP Twitter Mega Fan Box Widget <= 1.0 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-30553
Unpatched
Mar 29, 2024
WP Twitter Mega Fan Box Widget
Medium (4.4)
CVE-2024-30434
Patched
Mar 28, 2024
WordPress CRM Plugin – WP-CRM System
Medium (4.4)
CVE-2024-2968
Unpatched
Mar 28, 2024
WP-Eggdrop
WP-Lister Lite for Amazon <= 2.6.11 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-2889
Patched
Mar 26, 2024
WP-Lister Lite for Amazon
Medium (4.3)
CVE-2024-31093
Unpatched
Mar 29, 2024
Broken Images
Medium (4.3)
CVE-2024-31086
Unpatched
Mar 29, 2024
Change default login logo,url and title
Medium (4.3)
CVE-2024-30505
Patched
Mar 28, 2024
Church Admin
Medium (4.3)
CVE-2024-30493
Patched
Mar 28, 2024
Church Admin
Medium (4.3)
CVE-2024-1232
Patched
Mar 25, 2024
CM Download Manager – Document and File Management
Medium (4.3)
CVE-2024-1231
Patched
Mar 25, 2024
CM Download Manager – Document and File Management
Medium (4.3)
CVE-2024-1962
Patched
Mar 25, 2024
CM Download Manager – Document and File Management
Medium (4.3)
CVE-2024-30518
Patched
Mar 28, 2024
Custom WooCommerce Checkout Fields Editor
Medium (4.3)
CVE-2024-30560
Unpatched
Mar 29, 2024
DX-Watermark
Medium (4.3)
CVE-2024-2844
Patched
Mar 28, 2024
Easy Appointments
Medium (4.3)
CVE-2024-30526
Patched
Mar 29, 2024
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
Medium (4.3)
CVE-2024-30467
Patched
Mar 28, 2024
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
Medium (4.3)
CVE-2024-2261
Patched
Mar 26, 2024
Event Tickets and Registration
Medium (4.3)
CVE-2024-30515
Patched
Mar 28, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (4.3)
CVE-2024-30421
Patched
Mar 28, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (4.3)
CVE-2024-2110
Patched
Mar 27, 2024
Events Manager – Calendar, Bookings, Tickets, and more!
Medium (4.3)
CVE-2024-30455
Patched
Mar 28, 2024
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress
Medium (4.3)
CVE-2024-30462
Patched
Mar 28, 2024
HUSKY – Products Filter Professional for WooCommerce
Medium (4.3)
CVE-2024-30521
Patched
Mar 28, 2024
Landingi Landing Pages
Medium (4.3)
CVE-2024-30541
Patched
Mar 29, 2024
LWS Optimize
Medium (4.3)
CVE-2024-30507
Patched
Mar 28, 2024
Author Box, Guest Author and Co-Authors for Your Posts – Molongui
Medium (4.3)
CVE-2024-30487
Patched
Mar 28, 2024
MP3 Audio Player for Music, Radio & Podcast by Sonaar
Multiple Page Generator Plugin – MPG <= 3.4.0 – Missing Authorization via mpg_get_log_by_project_id
Medium (4.3)
CVE-2024-30235
Patched
Mar 26, 2024
Multiple Page Generator Plugin – MPG
Medium (4.3)
CVE-2024-31098
Unpatched
Mar 29, 2024
New Order Notification for Woocommerce
Medium (4.3)
CVE-2024-2970
Unpatched
Mar 28, 2024
News Wall
Medium (4.3)
CVE-2024-31096
Unpatched
Mar 29, 2024
Nictitate
Medium (4.3)
CVE-2024-2113
Patched
Mar 28, 2024
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Medium (4.3)
CVE-2024-1755
Patched
Mar 25, 2024
NPS computy
Medium (4.3)
CVE-2024-2476
Patched
Mar 28, 2024
OceanWP
Medium (4.3)
CVE-2024-30465
Patched
Mar 28, 2024
Page Builder: Pagelayer – Drag and Drop website builder
Medium (4.3)
CVE-2024-0588
Patched
Mar 25, 2024
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Medium (4.3)
CVE-2023-6965
Patched
Mar 28, 2024
Pods – Custom Content Types and Fields
Medium (4.3)
CVE-2024-31100
Unpatched
Mar 29, 2024
Popup Cart Lite for WooCommerce
Medium (4.3)
CVE-2024-30513
Patched
Mar 28, 2024
ProfileGrid – User Profiles, Memberships, Groups and Communities
Medium (4.3)
CVE-2024-2951
Patched
Mar 26, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Medium (4.3)
CVE-2024-31099
Unpatched
Mar 29, 2024
Shortcodes and extra features for Phlox theme
Medium (4.3)
CVE-2024-30482
Patched
Mar 28, 2024
Simple Revisions Delete
Medium (4.3)
CVE-2024-30517
Patched
Mar 28, 2024
Sliced Invoices – WordPress Invoice Plugin
Medium (4.3)
CVE-2024-30536
Patched
Mar 29, 2024
Slugs Manager: Delete Old Permalinks from WordPress Database
Medium (4.3)
CVE-2024-30464
Patched
Mar 28, 2024
Social Icons Widget & Block by WPZOOM
Medium (4.3)
CVE-2024-30528
Patched
Mar 29, 2024
Spiffy Calendar
WholesaleX <= 1.3.1 – Authenticated(Subscriber+) Missing Authorization via multiple AJAX actions
Medium (4.3)
CVE-2024-30234
Patched
Mar 26, 2024
WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing)
Medium (4.3)
CVE-2024-30233
Patched
Mar 26, 2024
WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing)
Medium (4.3)
CVE-2024-30466
Patched
Mar 28, 2024
WooCommerce Multilingual & Multicurrency with WPML
Medium (4.3)
CVE-2024-30458
Patched
Mar 28, 2024
FOX – Currency Switcher Professional for WooCommerce
Medium (4.3)
CVE-2024-30457
Patched
Mar 28, 2024
MDTF – Meta Data and Taxonomies Filter
Medium (4.3)
CVE-2024-30454
Patched
Mar 28, 2024
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc
Medium (4.3)
CVE-2024-30537
Patched
Mar 29, 2024
WPC Badge Management for WooCommerce
Medium (4.3)
CVE-2024-30456
Patched
Mar 28, 2024
WPCS – WordPress Currency Switcher Professional
Medium (4.3)
CVE-2024-30470
Patched
Mar 28, 2024
YITH WooCommerce Account Funds Premium
Low (2.7)
CVE-2024-30492
Patched
Mar 28, 2024
Export and Import Users and Customers
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (March 25, 2024 to March 31, 2024) appeared first on Wordfence.