Calling all superheroes and hunters! Introducing the End of Year Holiday Extravaganza and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through December 9th, 2024:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- All plugins and themes with 50-999 active installs hosted in the WordPress.org repository and updated within the last 2 years are in-scope for all researchers!
- Minimum bounty of $5 for all valid in-scope submissions.
- All researchers earn automatic bonuses of between 5% to 180% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 286 vulnerabilities disclosed in 273 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 43 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 20,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- Advanced Order Export For WooCommerce <= 3.5.5 – Unauthenticated PHP Object Injection via Order Details
- WAF-RULE-760 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-761 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-762 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-764 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 75 |
Unpatched | 211 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 252 |
High Severity | 14 |
Critical Severity | 20 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 225 |
Unrestricted Upload of File with Dangerous Type | 11 |
Missing Authorization | 10 |
Authorization Bypass Through User-Controlled Key | 7 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 7 |
Exposure of Sensitive Information to an Unauthorized Actor | 6 |
Improper Authentication | 4 |
Improper Control of Generation of Code (‘Code Injection’) | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 3 |
Server-Side Request Forgery (SSRF) | 2 |
Authentication Bypass Using an Alternate Path or Channel | 1 |
Cross-Site Request Forgery (CSRF) | 1 |
Improper Access Control | 1 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 1 |
Improper Handling of Missing Values | 1 |
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | 1 |
Insecure Storage of Sensitive Information | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
123 | |
32 | |
21 | |
17 | |
8 | |
6 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
140+ Widgets | Xpro Addons For Elementor – FREE | xpro-elementor-addons |
AA Audio Player | aa-audio-player |
AchillesTheme-shortcodes | achilles-shortcodes |
Active Products Tables for WooCommerce. Use constructor to create tables | profit-products-tables-for-woocommerce |
Add Ribbon Shortcode | add-ribbon |
Admin Amplify | wpr-admin-amplify |
Advanced Video Player with Analytics | advanced-video-player-with-analytics |
Adventure Bucket List | adventure-bucket-list |
AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress | agendapress |
Ajax Content Filter | ajax-content-filter |
Alert Me! | alert-me |
Algori PDF Viewer | algori-pdf-viewer |
Anant Addons for Elementor | anant-addons-for-elementor |
Assist24 Help Desk | assist24it |
Attesa Extra | attesa-extra |
audioCase | audiocase |
Awesome Fitness Testimonials | awesome-fitness-testimonials |
Awesome Tool Tip | awesome-tool-tip |
AzonBox | azonbox |
Bamboo Enquiries | bamboo-enquiries |
Banner System | banner-system |
Basticom Framework | basticom-framework |
Be Shortcodes | be-shortcodes |
Beacon For Help Scout | beacon-for-helpscout |
BeBetter Social Icons | bebetter-social-icons |
best bootstrap widgets for elementor | best-bootstrap-widgets-for-elementor |
Bg Patriarchia BU | bg-patriarchia-bu |
Bing Search API Integration | abbs-bing-search |
Bitcoin Payments | bitcoin-payments |
Blocks Post Grid | blocks-post-grid |
Boombox Shortcode Plugin | boombox-shortcode |
Brand my Footer | brand-my-footer |
Browsing History | browsing-history |
BU Slideshow | bu-slideshow |
Buooy Sticky Header | buooy-sticky-header |
Category Ajax Filter | category-ajax-filter |
CE21 Suite | ce21-suite |
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More | charitable |
Charity Addon for Elementor | charity-addon-for-elementor |
Christian Science Bible Lesson Subjects | christian-science-bible-lesson-subjects |
Code Embed | simple-embed-code |
codeSnips | codesnips |
Combo WP Rewrite Slugs | combo-wp-rewrite-slugs |
Community Yard Sale | community-yard-sale |
Contact Form 7 – Dynamic Text Extension | contact-form-7-dynamic-text-extension |
Contact Form 7 – PayPal & Stripe Add-on | contact-form-7-paypal-add-on |
Content Slider Block | content-slider-block |
Content Syndication Toolkit Reader | content-syndication-toolkit-reader |
Conversion Helper | conversion-helper |
Cookie Nonsense for YT | yt-cookie-nonsense |
Countdown Timer block – Display the event’s date into a timer. | countdown-time |
Cowidgets – Elementor Addons | cowidgets-elementor-addons |
Creative Blocks – Ultimate Blocks for Gutenberg | creative-blocks |
CRM 2go – Formulario de contacto | crm2go |
CRM WordPress Plugin – RepairBuddy | computer-repair-shop |
Custom Dashboard Widget | create-custom-dashboard-widget |
Custom URL Shortener | custom-url-shorter |
Daily Image | daily-image |
Dashing Memberships | dashing-memberships |
Debug Tool | debug-tool |
Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler | cf7-styler |
Don’t Break The Code | dont-break-the-code |
Doofinder | doofinder |
drop in image slideshow gallery | drop-in-image-slideshow-gallery |
DuoGeek – Gutenberg Blocks | duogeek-blocks |
Dynamic Post Grid Elementor Addon | dynamic-post-grid-elementor-addon |
Easy Social Sharebar | easy-social-sharebar |
Easy SVG Support | easy-svg |
eewee admin custom | eewee-admincustom |
Ekiline Block Collection | ekiline-block-collection |
EleForms – All In One Form Integration including DB for Elementor | all-contact-form-integration-for-elementor |
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | bdthemes-element-pack-lite |
Elementor Header & Footer Builder | header-footer-elementor |
ElementsReady Addons for Elementor | element-ready-lite |
Embed documents shortcode | embed-documents-shortcode |
Envo Extra | envo-extra |
ESB Testimonials | esb-testimonials |
Event post | event-post |
EventPress | wp-eventpress |
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin | everest-backup |
Fabrica Synced Pattern Instances | fabrica-reusable-block-instances |
Faltu Testimonial Rotator | faltu-testimonial-rotator |
Fancy User List | fancy-user-listing |
Fast Video and Image Display | fast-video-and-image-display |
Featured product by category name | featured-product-by-category-name |
File Select Control For Elementor | file-select-control-for-elementor |
Firework Shoppable Live Video | firework-videos |
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | form-maker |
Forms | forms-by-made-it |
Forms: 3rd-Party Post Again | forms-3rdparty-post-again |
FOX – Currency Switcher Professional for WooCommerce | woocommerce-currency-switcher |
FriendStore for WooCommerce | friendstore-for-woocommerce |
Gboy Custom Google Map | gboy-custom-google-map |
Geoportail Shortcode | geoportail-shortcode |
Geotagged Media | geotagged-media |
Google Visualization Charts | google-visualization-charts |
GreenCon – Table, Listing, Marketing builder for Gutenberg | greencon |
Gutenium Blocks | gutenium |
HB AUDIO GALLERY | hb-audio-gallery |
Heateor Social Login WordPress | heateor-social-login |
Hola Free Video Player | hola-free-video-player |
Horsemanager | fruitcake-horsemanager |
HQ60 Fidelity Card | hq60-fidelity-card |
I Plant A Tree | i-plant-a-tree |
IA Map Analytics Basic | ia-map-analytics-basic |
Icon Widget | icon-widget-with-links |
Image Carousel Shortcode | image-carousel-shortcode |
Image Classify | image-classify |
imPress | wp-js-impress |
Inline Click To Tweet | inline-click-to-tweet |
IntelliWidget Elements | intelliwidget-elements |
Jigoshop – Store Toolkit | jigoshop-store-toolkit |
JobSearch WP Job Board | wp-jobsearch |
Keymaster Chord Notation Free | keymaster-chord-notation-free |
Kings Tab Slider | kings-tab-slider |
L Squared Hub WP – Virtual Device Plugin | l-squared-hub-wp-virtual-device |
Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages | landing-page-cat |
Lead capture, gated content & newsletter opt-ins | bread-butter |
Lenxel Core for Lenxel(LNX) LMS | lenxel-core |
Leopard – WordPress Offload Media | leopard-wordpress-offload-media |
Lewe Bootstrap Visuals | shortcode-bootstrap-visuals |
LIQUID BLOCKS – Slider, Carousel, Accordion | liquid-blocks |
Location Click Map | location-click-map |
Loginizer | loginizer |
Loginizer Security | loginizer-security |
Loginplus | loginplus |
Luzuk Slider | luzuk-slider |
Luzuk Team | luzuk-team |
Luzuk Testimonials | luzuk-testimonials |
Mage Front End Forms | mage-forms |
Magic Slider | magic-slider |
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) | magical-addons-for-elementor |
Map Store Locator | map-store-location |
Mapme | mapme |
MapPress Maps for WordPress | mappress-google-maps-for-wordpress |
Master Bar | master-bar |
MDC YouTube Downloader | mdc-youtube-downloader |
mFolio Lite | mfolio-lite |
MG Post Contributors | mg-post-contributors |
Minical Hotel Booking Plugin | minical |
Mobile Kiosk | mobile-kiosk |
Moka Get Posts Shortcode | moka-get-posts |
Moose Elementor Kit | moose-elementor-kit |
Multi-day Booking Calendar | multi-day-booking-calendar |
Multifox Plus | multifox-plus |
Multiple Votes in one page | multiple-votes-in-one-page |
My Restaurant Menu | my-restaurant-menu |
myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification | mycred |
Narnoo Commerce Manager | narnoo-commerce-manager |
News Articles | news-articles |
News Ticker | newsticker |
NV Slider | nv-slider |
Official SalesWizard CRM Plugin | official-saleswizard-crm |
Olympus Shortcodes | olympus-shortcodes |
OpenCart Product Display | opencart-product-display |
OS BXSlider | os-bxslider |
OS Our Team | os-our-team |
OS Pricing Tables | os-pricing-tables |
OSM – OpenStreetMap | osm |
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | paid-member-subscriptions |
Parallaxer – Parallax Effect on Content | parallaxer-lite-parallax-effects-on-images |
ParOne Feeds | parone |
Pay With Stripe – Your WordPress Payments Stripe Gateway | payments-stripe-gateway |
Pdf Embedder Fay | pdf-embedder-fay |
Persian Nested Show/Hide Text | persian-nested-showhide-text |
PF Timer | pf-timer |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery | photo-gallery |
Photographer Connections | photographer-connections |
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons | contest-gallery |
Plenigo | plenigo |
Poll Maker – Versus Polls, Anonymous Polls, Image Polls | poll-maker |
Popup Image | popup-image |
Postcasa Shortcode | postcasa |
Postify: Post Layout For Elementor | postify-for-elementor |
Posts Filter | posts-filter |
Posts Search | posts-search |
Pricing Tables WordPress Plugin – Easy Pricing Tables | easy-pricing-tables |
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) | bdthemes-prime-slider-lite |
Pro Addons For Elementor | pro-addons-for-elementor |
PropertyShift | propertyshift |
Provide Forex Signals | provide-forex-signals |
Pull This | pull-this |
Quform – WordPress Form Builder | quform |
ra_qrcode | ra-qrcode |
Realty by BestWebSoft | realty |
Redirecter | shortcode-for-redirection |
RegistrationMagic – User Registration Plugin with Custom Registration Forms | custom-registration-form-builder-with-submission-manager |
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates | responsive-addons-for-elementor |
Responsive Data Table | responsive-data-table |
Responsive Filterable Portfolio | responsive-filterable-portfolio |
Rig Elements For Elementor | rig-elements |
RSV 360 View | rsv-360-view |
RSV PDF Preview | rsv-pdf-preview |
Saragna – Social Stream WordPress | saragna-social-stream |
Satisfaction Reports from Help Scout | happiness-reports-for-help-scout |
scrollup | scrollup |
Search order by product SKU for WooCommerce | search-order-by-product-sku-for-woocommerce |
Sell Media File with Stripe | sell-media-file |
Semantic Shortcode | semantic-shortcode |
Seriously Simple Podcasting | seriously-simple-podcasting |
Share Buttons – Social Media | rich-web-share-button |
Shortcode Collection | shortcode-collection |
Shortcodes Blocks Creator Ultimate | ultimate-shortcodes-creator |
Simple Modal | simplemodal |
Simple Shortcode for Google Maps | simple-google-maps-short-code |
Simple Social Share Block | simple-social-share-block |
SimpleGMaps | simplegmaps |
Simplistic SEO | simplistic-seo |
Simpul Events by Esotech | simpul-events-by-esotech |
SKT Addons for Elementor | skt-addons-for-elementor |
Smooth Maps | colour-smooth-maps |
Social button | social-button |
Social Locker – Increase Traffic | social-locker-content |
Social Share, Social Login and Social Comments Plugin – Super Socializer | super-socializer |
SrcSet Responsive Images for WordPress | truenorth-srcset |
Stylish Internal Links | stylish-internal-links |
Surbma | Font Awesome | surbma-font-awesome |
SV Forms | sv-forms |
SVT Simple | svt-simple |
SysBasics Customize My Account for WooCommerce | customize-my-account-for-woocommerce |
Team Showcase and Slider – Team Members Builder | team-showcase-ultimate |
TeleAdmin | teleadmin |
Testimonial Slider Shortcode | testimonial-slider-shortcode |
Text Advertisements | text-advertisements |
The Novel Design Store Directory | noveldesign-store-directory |
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library) | the-pack-addon |
Tickera – WordPress Event Ticketing | tickera-event-ticketing-system |
Tigris Flexplatform | tigris-flexplatform |
TinyCode | tinycode |
Topbar ID for Elementor | topbar-id-for-elementor |
Trendy Restaurant Menu – Best Restaurant Plugin for WordPress | trendy-restaurant-menu |
Tumult Hype Animations | tumult-hype-animations |
Twitter real time search scrolling | twitter-real-time-search-scrolling |
Ultimate Accordion | ultimate-accordion |
Ultimate Bootstrap Elements for Elementor | ultimate-bootstrap-elements-for-elementor |
Ultimate Flipbox Addon for Elementor | ultimate-flipbox-addon-for-elementor |
User Meta – User Profile Builder and User management plugin | user-meta |
User Password Reset | user-password-reset |
Utech Spinning Earth | utech-spinning-earth |
UW Freelancer | uw-freelancer |
Video Gallery for WooCommerce | video-wc-gallery |
VP Sitemap | vp-sitemap |
Wd-image-magnifier-xoss | wd-image-magnifier-xoss |
WE – Client Logo Carousel | we-client-logo-carousel |
Web Stories Widgets For Elementor | shortcodes-for-amp-web-stories-and-elementor-widget |
Websand Subscription Form | websand-subscription-form |
Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera | wp-website-creator |
Wezido – Elementor Addon Based on Easy Digital Downloads | wezido-elementor-addon-based-on-easy-digital-downloads |
WooCommerce – Social Login | woo-social-login |
WooCommerce Report | ithemelandco-woo-report |
WooCommerce Support Ticket System | woocommerce-support-ticket-system |
WordPress User Extra Fields | wp-user-extra-fields |
WoW Guild Armory Roster | guild-armory-roster |
WP Agenda | wp-agenda |
WP Contest | wp-contest |
WP Listings Pro | wp-listings-pro |
WP Membership | wp-membership |
WP MMenu Lite | wp-mmenu-lite |
WP PagSeguro Payments | wp-pagseguro-payments |
WP Photo Album Plus | wp-photo-album-plus |
WP Responsive Video | my-wp-responsive-video |
Wp Slide Categorywise | wp-slide-categorywise |
WP Virtual Room Configurator | configure-conference-room |
WP Visual Adverts | wp-visual-adverts |
WP-Basics | wp-basics |
wp_automatic_widget | wp-automatic-widget |
WPHelpful | wphelpful |
WS Form LITE – Drag & Drop Contact Form Builder for WordPress | ws-form |
XT Floating Cart for WooCommerce | woo-floating-cart-lite |
YaDisk Files | wp-yadisk-files |
yPHPlista | yphplista |
Zotpress | zotpress |
活动链接推广插件 | yr-activity-link |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Anih – Creative Agency WordPress Theme | anih |
Storely | storely |
Th Shop Mania | th-shop-mania |
Top Store | top-store |
WPLMS Learning Management System for WordPress, WordPress LMS | wplms |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (10.0)
CVE-2024-8615
Patched
Nov 5, 2024
JobSearch WP Job Board
Critical (9.9)
CVE-2024-9307
Unpatched
Nov 5, 2024
mFolio Lite
Critical (9.9)
CVE-2024-8614
Patched
Nov 5, 2024
JobSearch WP Job Board
Critical (9.8)
CVE-2024-10871
Patched
Nov 8, 2024
Category Ajax Filter
Critical (9.8)
CVE-2024-10284
Unpatched
Nov 8, 2024
CE21 Suite
Critical (9.8)
CVE-2024-10285
Unpatched
Nov 8, 2024
CE21 Suite
Critical (9.8)
CVE-2024-51793
Unpatched
Nov 8, 2024
CRM WordPress Plugin – RepairBuddy
Critical (9.8)
CVE-2024-10586
Unpatched
Nov 8, 2024
Debug Tool
Critical (9.8)
CVE-2024-51791
Patched
Nov 8, 2024
Forms
Critical (9.8)
CVE-2024-51790
Unpatched
Nov 8, 2024
HB AUDIO GALLERY
Critical (9.8)
CVE-2024-51789
Unpatched
Nov 8, 2024
Image Classify
Leopard <= 3.1.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
Critical (9.8)
CVE-2024-10589
Patched
Nov 8, 2024
Leopard – WordPress Offload Media
Critical (9.8)
CVE-2024-10687
Patched
Nov 4, 2024
Critical (9.8)
CVE-2024-10508
Patched
Nov 8, 2024
Critical (9.8)
CVE-2024-51788
Unpatched
Nov 8, 2024
The Novel Design Store Directory
Critical (9.8)
CVE-2024-10625
Patched
Nov 8, 2024
WooCommerce Support Ticket System
Critical (9.8)
CVE-2024-10627
Patched
Nov 8, 2024
WooCommerce Support Ticket System
Critical (9.8)
CVE-2024-10801
Patched
Nov 8, 2024
WordPress User Extra Fields
Critical (9.8)
CVE-2024-10547
Patched
Nov 8, 2024
WP Membership
Critical (9.8)
CVE-2024-10470
Patched
Nov 8, 2024
WPLMS Learning Management System for WordPress, WordPress LMS
High (8.8)
CVE-2024-10674
Patched
Nov 8, 2024
Th Shop Mania
High (8.8)
CVE-2024-10673
Patched
Nov 8, 2024
Top Store
High (8.8)
CVE-2024-10711
Patched
Nov 4, 2024
WooCommerce Report
High (8.8)
CVE-2024-10626
Patched
Nov 8, 2024
WooCommerce Support Ticket System
High (8.1)
CVE-2024-10020
Patched
Nov 5, 2024
Heateor Social Login WordPress
High (8.1)
CVE-2024-10097
Patched
Nov 4, 2024
High (8.1)
CVE-2024-10114
Patched
Nov 4, 2024
WooCommerce – Social Login
High (8.1)
CVE-2024-9946
Patched
Nov 5, 2024
Social Share, Social Login and Social Comments Plugin – Super Socializer
High (7.5)
CVE-2024-10028
Patched
Nov 5, 2024
High (7.4)
CVE-2024-10709
Unpatched
Nov 4, 2024
YaDisk Files
High (7.3)
CVE-2024-10261
Patched
Nov 8, 2024
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
High (7.3)
CVE-2024-10640
Patched
Nov 8, 2024
FOX – Currency Switcher Professional for WooCommerce
High (7.3)
CVE-2024-10263
Patched
Nov 4, 2024
Tickera – WordPress Event Ticketing
High (7.3)
CVE-2024-10958
Patched
Nov 10, 2024
WP Photo Album Plus
Medium (6.5)
CVE-2024-10294
Unpatched
Nov 8, 2024
CE21 Suite
Medium (6.5)
CVE-2024-9657
Patched
Nov 4, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (6.5)
CVE-2024-51882
Unpatched
Nov 8, 2024
Gboy Custom Google Map
Medium (6.5)
CVE-2024-51843
Unpatched
Nov 8, 2024
Horsemanager
Medium (6.5)
CVE-2024-51820
Unpatched
Nov 8, 2024
L Squared Hub WP – Virtual Device Plugin
Medium (6.5)
CVE-2024-51845
Unpatched
Nov 8, 2024
Share Buttons – Social Media
Medium (6.5)
CVE-2024-9262
Unpatched
Nov 8, 2024
User Meta – User Profile Builder and User management plugin
Medium (6.5)
CVE-2024-51837
Unpatched
Nov 8, 2024
WP Contest
Medium (6.4)
CVE-2024-52348
Unpatched
Nov 8, 2024
AA Audio Player
Medium (6.4)
CVE-2024-51878
Unpatched
Nov 8, 2024
AchillesTheme-shortcodes
Medium (6.4)
CVE-2024-10168
Patched
Nov 5, 2024
Active Products Tables for WooCommerce. Use constructor to create tables
Medium (6.4)
CVE-2024-51823
Unpatched
Nov 8, 2024
Add Ribbon Shortcode
Advanced Video Player with Analytics <= 1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51824
Unpatched
Nov 8, 2024
Advanced Video Player with Analytics
Medium (6.4)
CVE-2024-51908
Unpatched
Nov 8, 2024
Adventure Bucket List
Medium (6.4)
CVE-2024-51807
Unpatched
Nov 8, 2024
AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress
Medium (6.4)
CVE-2024-51825
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51813
Patched
Nov 8, 2024
Anant Addons for Elementor
Medium (6.4)
CVE-2024-51910
Unpatched
Nov 8, 2024
Assist24 Help Desk
Medium (6.4)
CVE-2024-51909
Unpatched
Nov 8, 2024
Awesome Fitness Testimonials <= 1.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51806
Unpatched
Nov 8, 2024
Awesome Fitness Testimonials
Medium (6.4)
CVE-2024-52349
Unpatched
Nov 8, 2024
Awesome Tool Tip
Medium (6.4)
CVE-2024-51931
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51859
Unpatched
Nov 8, 2024
Bamboo Enquiries
Medium (6.4)
CVE-2024-51816
Unpatched
Nov 8, 2024
Banner System
Medium (6.4)
CVE-2024-9443
Patched
Nov 4, 2024
Basticom Framework
Medium (6.4)
CVE-2024-51881
Unpatched
Nov 8, 2024
Be Shortcodes
Medium (6.4)
CVE-2024-51828
Unpatched
Nov 8, 2024
Beacon For Help Scout
Medium (6.4)
CVE-2024-51880
Unpatched
Nov 8, 2024
BeBetter Social Icons
Medium (6.4)
CVE-2024-51851
Unpatched
Nov 8, 2024
best bootstrap widgets for elementor
Medium (6.4)
CVE-2024-51799
Unpatched
Nov 8, 2024
Bg Patriarchia BU
Medium (6.4)
CVE-2024-51826
Unpatched
Nov 8, 2024
Bitcoin Payments
Medium (6.4)
CVE-2024-51928
Unpatched
Nov 8, 2024
Blocks Post Grid
Medium (6.4)
CVE-2024-51827
Unpatched
Nov 8, 2024
Boombox Shortcode Plugin
Medium (6.4)
CVE-2024-51801
Unpatched
Nov 8, 2024
Brand my Footer
Medium (6.4)
CVE-2024-51802
Unpatched
Nov 8, 2024
Lead capture, gated content & newsletter opt-ins
Medium (6.4)
CVE-2024-51885
Unpatched
Nov 8, 2024
Browsing History
Medium (6.4)
CVE-2024-52351
Unpatched
Nov 8, 2024
BU Slideshow
Medium (6.4)
CVE-2024-51938
Unpatched
Nov 8, 2024
Charity Addon for Elementor
Medium (6.4)
CVE-2024-52353
Patched
Nov 8, 2024
Christian Science Bible Lesson Subjects
Medium (6.4)
CVE-2024-10814
Patched
Nov 8, 2024
Code Embed
Medium (6.4)
CVE-2024-51808
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51846
Unpatched
Nov 8, 2024
Community Yard Sale
Medium (6.4)
CVE-2024-51933
Unpatched
Nov 8, 2024
Cookie Nonsense for YT
Medium (6.4)
CVE-2024-8960
Unpatched
Nov 8, 2024
Cowidgets – Elementor Addons
Medium (6.4)
CVE-2024-51822
Unpatched
Nov 8, 2024
Creative Blocks – Ultimate Blocks for Gutenberg
Medium (6.4)
CVE-2024-52350
Unpatched
Nov 8, 2024
CRM 2go – Formulario de contacto
Medium (6.4)
CVE-2024-51860
Unpatched
Nov 8, 2024
Custom Dashboard Widget
Medium (6.4)
CVE-2024-51930
Unpatched
Nov 8, 2024
Custom URL Shortener
drop in image slideshow gallery <= 12.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51914
Unpatched
Nov 8, 2024
drop in image slideshow gallery
Medium (6.4)
CVE-2024-51868
Unpatched
Nov 8, 2024
DuoGeek – Gutenberg Blocks
Medium (6.4)
CVE-2024-51852
Patched
Nov 8, 2024
Dynamic Post Grid Elementor Addon
Medium (6.4)
CVE-2024-51833
Unpatched
Nov 8, 2024
Easy Social Sharebar
Easy SVG Support <= 3.7 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-10269
Patched
Nov 7, 2024
Easy SVG Support
Medium (6.4)
CVE-2024-51934
Unpatched
Nov 8, 2024
Ekiline Block Collection
Medium (6.4)
CVE-2024-10325
Patched
Nov 7, 2024
Elementor Header & Footer Builder
Medium (6.4)
CVE-2024-51787
Patched
Nov 4, 2024
ElementsReady Addons for Elementor
Medium (6.4)
CVE-2024-51904
Unpatched
Nov 8, 2024
Embed documents shortcode
Medium (6.4)
CVE-2024-51936
Unpatched
Nov 8, 2024
ESB Testimonials
Medium (6.4)
CVE-2024-10186
Patched
Nov 5, 2024
Event post
Medium (6.4)
CVE-2024-51861
Unpatched
Nov 8, 2024
EventPress
Medium (6.4)
CVE-2024-51853
Unpatched
Nov 8, 2024
Faltu Testimonial Rotator
Medium (6.4)
CVE-2024-51889
Unpatched
Nov 8, 2024
Fancy User List
Fast Video and Image Display <= 2.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51935
Unpatched
Nov 8, 2024
Fast Video and Image Display
Featured product by category name <= 1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51911
Unpatched
Nov 8, 2024
Featured product by category name
File Select Control For Elementor <= 1.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51841
Unpatched
Nov 8, 2024
File Select Control For Elementor
Medium (6.4)
CVE-2024-51890
Unpatched
Nov 8, 2024
Geoportail Shortcode
Medium (6.4)
CVE-2024-51862
Unpatched
Nov 8, 2024
Google Visualization Charts
Medium (6.4)
CVE-2024-51926
Unpatched
Nov 8, 2024
GreenCon – Table, Listing, Marketing builder for Gutenberg
Medium (6.4)
CVE-2024-51869
Unpatched
Nov 8, 2024
Gutenium Blocks
Medium (6.4)
CVE-2024-51854
Unpatched
Nov 8, 2024
Hola Free Video Player
Medium (6.4)
CVE-2024-51883
Unpatched
Nov 8, 2024
I Plant A Tree
Medium (6.4)
CVE-2024-51937
Unpatched
Nov 8, 2024
IA Map Analytics Basic
Medium (6.4)
CVE-2024-51929
Unpatched
Nov 8, 2024
Icon Widget
Medium (6.4)
CVE-2024-51842
Unpatched
Nov 8, 2024
Image Carousel Shortcode
Medium (6.4)
CVE-2024-51803
Unpatched
Nov 8, 2024
Inline Click To Tweet
Medium (6.4)
CVE-2024-51912
Unpatched
Nov 8, 2024
IntelliWidget Elements
Keymaster Chord Notation Free <= 1.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51809
Unpatched
Nov 8, 2024
Keymaster Chord Notation Free
Medium (6.4)
CVE-2024-51932
Unpatched
Nov 8, 2024
Kings Tab Slider
Medium (6.4)
CVE-2024-9270
Unpatched
Nov 8, 2024
Lenxel Core for Lenxel(LNX) LMS
Medium (6.4)
CVE-2024-51810
Unpatched
Nov 8, 2024
Lewe Bootstrap Visuals
Medium (6.4)
CVE-2024-52357
Patched
Nov 8, 2024
LIQUID BLOCKS – Slider, Carousel, Accordion
Medium (6.4)
CVE-2024-51844
Unpatched
Nov 8, 2024
Location Click Map
Medium (6.4)
CVE-2024-51834
Unpatched
Nov 8, 2024
Luzuk Slider
Medium (6.4)
CVE-2024-51871
Unpatched
Nov 8, 2024
Luzuk Team
Medium (6.4)
CVE-2024-51872
Unpatched
Nov 8, 2024
Luzuk Testimonials
Medium (6.4)
CVE-2024-52339
Unpatched
Nov 8, 2024
Mage Front End Forms
Medium (6.4)
CVE-2024-51896
Unpatched
Nov 8, 2024
Magic Slider
Medium (6.4)
CVE-2024-51920
Unpatched
Nov 8, 2024
Map Store Locator
Medium (6.4)
CVE-2024-51913
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-10715
Patched
Nov 5, 2024
MapPress Maps for WordPress
Medium (6.4)
CVE-2024-51875
Unpatched
Nov 8, 2024
MDC YouTube Downloader
Minical Hotel Booking Plugin <= 1.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51895
Unpatched
Nov 8, 2024
Minical Hotel Booking Plugin
Medium (6.4)
CVE-2024-51829
Unpatched
Nov 8, 2024
Mobile Kiosk
Medium (6.4)
CVE-2024-51804
Unpatched
Nov 8, 2024
Moka Get Posts Shortcode
Medium (6.4)
CVE-2024-51856
Unpatched
Nov 8, 2024
Moose Elementor Kit
Medium (6.4)
CVE-2024-51873
Unpatched
Nov 8, 2024
Multi-day Booking Calendar
Medium (6.4)
CVE-2024-51916
Unpatched
Nov 8, 2024
Multifox Plus
Medium (6.4)
CVE-2024-51917
Unpatched
Nov 8, 2024
Multiple Votes in one page
Medium (6.4)
CVE-2024-51849
Unpatched
Nov 8, 2024
My Restaurant Menu
myCred <= 2.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode
Medium (6.4)
CVE-2024-10187
Patched
Nov 7, 2024
Medium (6.4)
CVE-2024-51897
Unpatched
Nov 8, 2024
News Articles
Medium (6.4)
CVE-2024-51830
Unpatched
Nov 8, 2024
News Ticker
Medium (6.4)
CVE-2024-51887
Unpatched
Nov 8, 2024
Official SalesWizard CRM Plugin <= 1.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51891
Unpatched
Nov 8, 2024
Official SalesWizard CRM Plugin
Medium (6.4)
CVE-2024-51857
Unpatched
Nov 8, 2024
Olympus Shortcodes
Medium (6.4)
CVE-2024-51835
Unpatched
Nov 8, 2024
OpenCart Product Display
Medium (6.4)
CVE-2024-52342
Unpatched
Nov 8, 2024
OS BXSlider
Medium (6.4)
CVE-2024-52341
Unpatched
Nov 8, 2024
OS Our Team
Medium (6.4)
CVE-2024-52343
Unpatched
Nov 8, 2024
OS Pricing Tables
Medium (6.4)
CVE-2024-52355
Patched
Nov 8, 2024
OSM – OpenStreetMap
Medium (6.4)
CVE-2024-51848
Unpatched
Nov 8, 2024
Parallaxer – Parallax Effect on Content
Medium (6.4)
CVE-2024-51874
Unpatched
Nov 8, 2024
ParOne Feeds
Medium (6.4)
CVE-2024-51918
Unpatched
Nov 8, 2024
Pay With Stripe – Your WordPress Payments Stripe Gateway
Medium (6.4)
CVE-2024-51795
Unpatched
Nov 8, 2024
Pdf Embedder Fay
Medium (6.4)
CVE-2018-5158
Patched
Nov 8, 2024
Algori PDF Viewer
Medium (6.4)
CVE-2024-51831
Unpatched
Nov 8, 2024
Persian Nested Show/Hide Text
Medium (6.4)
CVE-2024-51863
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-52340
Unpatched
Nov 8, 2024
Photographer Connections
Medium (6.4)
CVE-2024-51832
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51811
Unpatched
Nov 8, 2024
Popup Image
Medium (6.4)
CVE-2024-52352
Unpatched
Nov 8, 2024
Postcasa Shortcode
Medium (6.4)
CVE-2024-51893
Unpatched
Nov 8, 2024
Postify: Post Layout For Elementor
Medium (6.4)
CVE-2024-51886
Unpatched
Nov 8, 2024
Posts Filter
Medium (6.4)
CVE-2024-51884
Unpatched
Nov 8, 2024
Posts Search
Medium (6.4)
CVE-2024-8323
Patched
Nov 5, 2024
Pricing Tables WordPress Plugin – Easy Pricing Tables
Medium (6.4)
CVE-2024-8442
Patched
Nov 6, 2024
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)
Medium (6.4)
CVE-2024-51812
Patched
Nov 8, 2024
Pro Addons For Elementor
Medium (6.4)
CVE-2024-52344
Unpatched
Nov 8, 2024
Provide Forex Signals
Medium (6.4)
CVE-2024-51838
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-52345
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51786
Patched
Nov 4, 2024
Realty by BestWebSoft
Medium (6.4)
CVE-2024-51855
Unpatched
Nov 8, 2024
Redirecter
Responsive Addons for Elementor <= 1.5.4 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-52358
Patched
Nov 8, 2024
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates
Medium (6.4)
CVE-2024-51927
Unpatched
Nov 8, 2024
Rig Elements For Elementor
Medium (6.4)
CVE-2024-51906
Unpatched
Nov 8, 2024
RSV 360 View
Medium (6.4)
CVE-2024-51905
Unpatched
Nov 8, 2024
RSV PDF Preview
Medium (6.4)
CVE-2024-51921
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51892
Unpatched
Nov 8, 2024
Sell Media File with Stripe
Medium (6.4)
CVE-2024-51898
Unpatched
Nov 8, 2024
Semantic Shortcode
Medium (6.4)
CVE-2024-51864
Unpatched
Nov 8, 2024
Shortcode Collection
Medium (6.4)
CVE-2024-10340
Patched
Nov 4, 2024
Shortcodes Blocks Creator Ultimate
Medium (6.4)
CVE-2024-10621
Patched
Nov 7, 2024
Simple Shortcode for Google Maps
Medium (6.4)
CVE-2024-51865
Unpatched
Nov 8, 2024
Simple Social Share Block
Medium (6.4)
CVE-2024-52346
Unpatched
Nov 8, 2024
SimpleGMaps
Medium (6.4)
CVE-2024-51867
Unpatched
Nov 8, 2024
Simpul Events by Esotech
Medium (6.4)
CVE-2024-51901
Unpatched
Nov 8, 2024
Smooth Maps
Medium (6.4)
CVE-2024-51866
Unpatched
Nov 8, 2024
Social button
Medium (6.4)
CVE-2024-51858
Unpatched
Nov 8, 2024
Social Locker – Increase Traffic
Medium (6.4)
CVE-2024-51794
Unpatched
Nov 8, 2024
Storely
Medium (6.4)
CVE-2024-51939
Unpatched
Nov 8, 2024
Stylish Internal Links
Medium (6.4)
CVE-2024-51798
Unpatched
Nov 8, 2024
Surbma | Font Awesome
Medium (6.4)
CVE-2024-51877
Unpatched
Nov 8, 2024
SV Forms
Testimonial Slider Shortcode <= 1.1.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51925
Unpatched
Nov 8, 2024
Testimonial Slider Shortcode
Medium (6.4)
CVE-2024-51879
Unpatched
Nov 8, 2024
Text Advertisements
Medium (6.4)
CVE-2024-52356
Patched
Nov 8, 2024
Medium (6.4)
CVE-2024-51819
Unpatched
Nov 8, 2024
Tigris Flexplatform
Medium (6.4)
CVE-2024-51902
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51894
Unpatched
Nov 8, 2024
Topbar ID for Elementor
Medium (6.4)
CVE-2024-51796
Unpatched
Nov 8, 2024
Trendy Restaurant Menu – Best Restaurant Plugin for WordPress
Medium (6.4)
CVE-2024-51797
Unpatched
Nov 8, 2024
Ultimate Accordion
Medium (6.4)
CVE-2024-51870
Unpatched
Nov 8, 2024
Ultimate Flipbox Addon for Elementor
Medium (6.4)
CVE-2024-51839
Unpatched
Nov 8, 2024
Utech Spinning Earth
Medium (6.4)
CVE-2024-51922
Unpatched
Nov 8, 2024
VP Sitemap
Medium (6.4)
CVE-2024-51840
Unpatched
Nov 8, 2024
Wd-image-magnifier-xoss
Medium (6.4)
CVE-2024-51821
Unpatched
Nov 8, 2024
WE – Client Logo Carousel
Web Stories Widgets For Elementor <= 1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-52354
Patched
Nov 8, 2024
Web Stories Widgets For Elementor
Medium (6.4)
CVE-2024-51923
Unpatched
Nov 8, 2024
Websand Subscription Form
Medium (6.4)
CVE-2024-52347
Unpatched
Nov 8, 2024
Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera
Medium (6.4)
CVE-2024-51836
Unpatched
Nov 8, 2024
Wezido – Elementor Addon Based on Easy Digital Downloads
Medium (6.4)
CVE-2024-51850
Unpatched
Nov 8, 2024
WoW Guild Armory Roster
Medium (6.4)
CVE-2024-51924
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51903
Unpatched
Nov 8, 2024
WP Listings Pro
Medium (6.4)
CVE-2024-51847
Unpatched
Nov 8, 2024
WP PagSeguro Payments
Medium (6.4)
CVE-2024-51940
Unpatched
Nov 8, 2024
WP Responsive Video
WP Virtual Room Configurator <= 1.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-51907
Unpatched
Nov 8, 2024
WP Virtual Room Configurator
Medium (6.4)
CVE-2024-51876
Unpatched
Nov 8, 2024
wp_automatic_widget
Medium (6.4)
CVE-2024-9178
Patched
Nov 4, 2024
XT Floating Cart for WooCommerce
Medium (6.4)
CVE-2024-51805
Unpatched
Nov 8, 2024
Medium (6.4)
CVE-2024-51814
Unpatched
Nov 8, 2024
Medium (6.1)
CVE-2024-51691
Unpatched
Nov 4, 2024
Admin Amplify
Medium (6.1)
CVE-2024-51717
Unpatched
Nov 4, 2024
Ajax Content Filter
Medium (6.1)
CVE-2024-51692
Unpatched
Nov 4, 2024
Bing Search API Integration
Medium (6.1)
CVE-2024-51699
Unpatched
Nov 4, 2024
Buooy Sticky Header
Medium (6.1)
CVE-2024-51689
Unpatched
Nov 4, 2024
Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler
Medium (6.1)
CVE-2024-10876
Patched
Nov 8, 2024
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
Medium (6.1)
CVE-2024-10683
Patched
Nov 8, 2024
Contact Form 7 – PayPal & Stripe Add-on
Medium (6.1)
CVE-2024-51696
Unpatched
Nov 4, 2024
Content Syndication Toolkit Reader
Medium (6.1)
CVE-2024-10676
Unpatched
Nov 4, 2024
Conversion Helper
Medium (6.1)
CVE-2024-51776
Unpatched
Nov 4, 2024
Daily Image
Medium (6.1)
CVE-2024-51760
Unpatched
Nov 4, 2024
Dashing Memberships
Medium (6.1)
CVE-2024-51779
Unpatched
Nov 4, 2024
Don’t Break The Code
Medium (6.1)
CVE-2024-51697
Unpatched
Nov 4, 2024
Doofinder
Medium (6.1)
CVE-2024-51780
Unpatched
Nov 4, 2024
eewee admin custom
Medium (6.1)
CVE-2024-51695
Unpatched
Nov 4, 2024
Fabrica Synced Pattern Instances
Medium (6.1)
CVE-2024-51781
Unpatched
Nov 4, 2024
Firework Shoppable Live Video
Medium (6.1)
CVE-2024-10265
Patched
Nov 10, 2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Medium (6.1)
CVE-2024-51783
Unpatched
Nov 4, 2024
Forms: 3rd-Party Post Again
Medium (6.1)
CVE-2024-51784
Unpatched
Nov 4, 2024
FriendStore for WooCommerce
Medium (6.1)
CVE-2024-51694
Unpatched
Nov 4, 2024
Geotagged Media
Medium (6.1)
CVE-2024-51713
Unpatched
Nov 4, 2024
HQ60 Fidelity Card
Medium (6.1)
CVE-2024-51704
Unpatched
Nov 4, 2024
imPress
Medium (6.1)
CVE-2024-51712
Unpatched
Nov 4, 2024
Jigoshop – Store Toolkit
Medium (6.1)
CVE-2024-9226
Patched
Nov 8, 2024
Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages
Medium (6.1)
CVE-2024-51782
Unpatched
Nov 4, 2024
Medium (6.1)
CVE-2024-51698
Unpatched
Nov 4, 2024
Master Bar
Medium (6.1)
CVE-2024-51701
Unpatched
Nov 4, 2024
MG Post Contributors
Medium (6.1)
CVE-2024-51708
Unpatched
Nov 4, 2024
Narnoo Commerce Manager
Medium (6.1)
CVE-2024-51762
Unpatched
Nov 4, 2024
PropertyShift
Medium (6.1)
CVE-2024-51710
Unpatched
Nov 4, 2024
Responsive Data Table
Medium (6.1)
CVE-2024-51711
Unpatched
Nov 4, 2024
Saragna – Social Stream WordPress
Medium (6.1)
CVE-2024-51778
Unpatched
Nov 4, 2024
Satisfaction Reports from Help Scout
Medium (6.1)
CVE-2024-51693
Unpatched
Nov 4, 2024
Search order by product SKU for WooCommerce
Seriously Simple Podcasting <= 3.5.0 – Reflected Cross-Site Scripting via add_query_arg Parameter
Medium (6.1)
CVE-2024-9667
Patched
Nov 4, 2024
Seriously Simple Podcasting
Medium (6.1)
CVE-2024-51718
Unpatched
Nov 4, 2024
Simple Modal
Medium (6.1)
CVE-2024-51719
Unpatched
Nov 4, 2024
Simplistic SEO
Medium (6.1)
CVE-2024-51702
Unpatched
Nov 4, 2024
SrcSet Responsive Images for WordPress
Medium (6.1)
CVE-2024-51759
Unpatched
Nov 4, 2024
SVT Simple
Medium (6.1)
CVE-2024-10837
Patched
Nov 9, 2024
SysBasics Customize My Account for WooCommerce
Medium (6.1)
CVE-2024-51763
Unpatched
Nov 4, 2024
Team Showcase and Slider – Team Members Builder
Medium (6.1)
CVE-2024-51709
Unpatched
Nov 4, 2024
Medium (6.1)
CVE-2024-51716
Unpatched
Nov 4, 2024
Twitter real time search scrolling
Medium (6.1)
CVE-2024-51714
Unpatched
Nov 4, 2024
User Password Reset
Medium (6.1)
CVE-2024-51706
Unpatched
Nov 4, 2024
UW Freelancer
Medium (6.1)
CVE-2024-51705
Unpatched
Nov 4, 2024
WP MMenu Lite
Medium (6.1)
CVE-2024-51690
Unpatched
Nov 4, 2024
Wp Slide Categorywise
Medium (6.1)
CVE-2024-51707
Unpatched
Nov 4, 2024
WP Visual Adverts
Medium (6.1)
CVE-2024-51703
Unpatched
Nov 4, 2024
WP-Basics
Medium (6.1)
CVE-2024-51761
Unpatched
Nov 4, 2024
Medium (6.1)
CVE-2024-10647
Patched
Nov 5, 2024
WS Form LITE – Drag & Drop Contact Form Builder for WordPress
Medium (5.5)
CVE-2024-9775
Unpatched
Nov 8, 2024
Anih – Creative Agency WordPress Theme
Medium (5.4)
CVE-2024-9867
Patched
Nov 4, 2024
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
Medium (5.3)
CVE-2024-10779
Unpatched
Nov 8, 2024
Cowidgets – Elementor Addons
EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 – Missing Authorization
Medium (5.3)
CVE-2024-6626
Unpatched
Nov 5, 2024
EleForms – All In One Form Integration including DB for Elementor
Medium (5.3)
CVE-2024-8756
Patched
Nov 8, 2024
Quform – WordPress Form Builder
Medium (5.3)
CVE-2024-10535
Patched
Nov 5, 2024
Video Gallery for WooCommerce
Medium (4.9)
CVE-2024-9874
Patched
Nov 8, 2024
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
Medium (4.7)
CVE-2024-51785
Patched
Nov 4, 2024
Responsive Filterable Portfolio
Medium (4.4)
CVE-2024-9878
Patched
Nov 4, 2024
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Medium (4.4)
CVE-2024-10710
Unpatched
Nov 4, 2024
YaDisk Files
Medium (4.3)
CVE-2024-10319
Patched
Nov 4, 2024
140+ Widgets | Xpro Addons For Elementor – FREE
Medium (4.3)
CVE-2024-10688
Patched
Nov 8, 2024
Attesa Extra
Combo WP Rewrite Slugs <= 1.0 – Missing Authorization to Authenticated (Subscriber+) Settings Change
Medium (4.3)
CVE-2024-51817
Unpatched
Nov 8, 2024
Combo WP Rewrite Slugs
Medium (4.3)
CVE-2024-10084
Patched
Nov 5, 2024
Contact Form 7 – Dynamic Text Extension
Medium (4.3)
CVE-2024-10667
Patched
Nov 8, 2024
Content Slider Block
Medium (4.3)
CVE-2024-10669
Patched
Nov 8, 2024
Countdown Timer block – Display the event’s date into a timer.
Medium (4.3)
CVE-2024-10588
Unpatched
Nov 8, 2024
Debug Tool
Medium (4.3)
CVE-2024-10770
Patched
Nov 8, 2024
Envo Extra
Medium (4.3)
CVE-2024-10352
Patched
Nov 8, 2024
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
Medium (4.3)
CVE-2024-10693
Patched
Nov 8, 2024
SKT Addons for Elementor
Medium (4.3)
CVE-2024-10543
Patched
Nov 5, 2024
Tumult Hype Animations
Medium (4.3)
CVE-2024-10329
Patched
Nov 4, 2024
Ultimate Bootstrap Elements for Elementor
Medium (4.3)
CVE-2024-7429
Patched
Nov 4, 2024
Zotpress
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (November 4, 2024 to November 10, 2024) appeared first on Wordfence.