Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- Top-tier researchers earn automatic bonuses of between 10% to 120% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 221 vulnerabilities disclosed in 205 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 52 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 19,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-756 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 93 |
Unpatched | 128 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Medium Severity | 149 |
High Severity | 40 |
Critical Severity | 32 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 99 |
Cross-Site Request Forgery (CSRF) | 32 |
Unrestricted Upload of File with Dangerous Type | 17 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 14 |
Missing Authorization | 12 |
Deserialization of Untrusted Data | 10 |
Exposure of Sensitive Information to an Unauthorized Actor | 7 |
Improper Control of Generation of Code (‘Code Injection’) | 5 |
Authentication Bypass Using an Alternate Path or Channel | 4 |
Authorization Bypass Through User-Controlled Key | 4 |
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) | 4 |
Incorrect Privilege Assignment | 4 |
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’) | 3 |
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) | 1 |
Improper Check or Handling of Exceptional Conditions | 1 |
Improper Privilege Management | 1 |
Reliance on Cookies without Validation and Integrity Checking in a Security Decision | 1 |
Server-Side Request Forgery (SSRF) | 1 |
Weak Password Recovery Mechanism for Forgotten Password | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
24 | |
22 | |
18 | |
16 | |
13 | |
12 | |
8 | |
6 | |
6 | |
6 | |
6 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
AADMY – Add Auto Date Month Year Into Posts | auto-date-year-month |
AB Categories Search Widget | ab-categories-search-widget |
Accordion Slider | accordion-slider |
Ad Inserter – Ad Manager & AdSense Ads | ad-inserter |
Add Categories Post Footer | add-categories-post-footer |
Add Widget After Content | add-widget-after-content |
Adding drop down roles in registration | user-drop-down-roles-in-registration |
ADIF Log Search Widget | adif-log-search-widget |
Admin Management Xtended | admin-management-xtended |
Advanced Advertising System | advanced-advertising-system |
Advanced Category and Custom Taxonomy Image | advanced-category-and-custom-taxonomy-image |
Advanced Custom Fields | advanced-custom-fields |
Advanced Custom Fields Pro | advanced-custom-fields-pro |
Affiliator | affiliator-lite |
Ahime Image Printer | ahime-image-printer |
Ahmeti Wp Timeline | ahmeti-wp-timeline |
Ajax Custom CSS/JS | ajax-awesome-css |
Ajax Rating with Custom Login | ajax-rating-with-custom-login |
ajax-extend | ajax-extend |
Akismet htaccess writer | akismet-htaccess-writer |
Analyse Uploads | analyse-uploads |
Animator – Scroll Triggered Animations | scroll-triggered-animations |
Apa Banner Slider | apa-banner-slider |
APA Register Newsletter Form | apa-register-newsletter-form |
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin | simply-schedule-appointments |
AppPresser – Mobile App Framework | apppresser |
Arconix Shortcodes | arconix-shortcodes |
Arkhe Blocks | arkhe-blocks |
Author Discussion | author-discussion |
Awesome Contact Form7 for Elementor | awesome-contact-form7-for-elementor |
Azz Anonim Posting | azz-anonim-posting |
Back Link Tracker | back-link-tracker |
Better Author Bio | better-author-bio |
Booking.com Banner Creator | bookingcom-banner-creator |
Branding | branding |
BuddyPress Better Registration | better-bp-registration |
Bulk images optimizer: Resize, optimize, convert to webp, rename … | bulk-image-resizer |
bVerse Convert | bverse-convert |
Calculated Fields Form | calculated-fields-form |
CJ Change Howdy | cj-change-howdy |
Click to Chat – WP Support All-in-One Floating Widget | support-chat |
Clio Grow Form | clio-grow-form |
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors | publishpress-authors |
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App | peepso-core |
Community Lite Video Chat | avchat-3 |
Contact Form by Supsystic | contact-form-by-supsystic |
Contact Forms, Live Support, CRM, Video Messages | live-support-tickets |
Cooked Pro | cooked-pro |
Cookie Scanner – automated cookie list | cookie-scanner |
Country Flags for Elementor | country-flags-for-elementor |
Crazy Call To Action Box | crazy-call-to-action-box |
cSlider | cslider |
CSV Product Import Export for WooCommerce | csv-wc-product-import-export |
CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 8.x | woo-multi-currency |
Custom Add to Cart Button Label and Link | woo-custom-cart-button |
Customer Email Verification for WooCommerce | emails-verification-for-woocommerce |
Da Reactions | da-reactions |
Debrandify · Remove or Replace WordPress Branding | debrandify |
Digital Lottery | digital-lottery |
Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons | woo-discount-rules |
DPD Baltic Shipping | woo-shipping-dpd-baltic |
Duplicate Title Validate | duplicate-title-validate |
Dynamic Elementor Addons | dynamic-elementor-addons |
Easy Menu Manager | WPZest | easy-menu-manager-wpzest |
Edit WooCommerce Templates | woo-edit-templates |
Edwiser Bridge – WordPress Moodle LMS Integration | edwiser-bridge |
El mejor Cluster | mejorcluster |
Elemenda | elemenda |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
Elementor Website Builder – More than Just a Page Builder | elementor |
ElementsReady Addons for Elementor | element-ready-lite |
Email Template Customizer for WooCommerce | email-template-customizer-for-woo |
Encyclopedia / Glossary / Wiki | encyclopedia-lexicon-glossary-wiki-dictionary |
Endless Posts Navigation | endless-posts-navigation |
EventON Pro | eventon |
Events Addon for Elementor | events-addon-for-elementor |
Exclusive Addons for Elementor | exclusive-addons-for-elementor |
Feed Comments Number | feed-comments-number |
FERMA.ru.net | ferma-ru-net-checkout |
File Manager Pro | wp-file-manager-pro |
Flat UI Button | flat-ui-button |
Flexmls® IDX Plugin | flexmls-idx |
Fonto – Custom Web Fonts Manager | fonto |
Forminator Forms – Contact Form, Payment Form & Custom Form Builder | forminator |
FREE DOWNLOAD MANAGER | free-download-manager |
Free Stock Photos Foter | free-stock-photos-foter |
G Meta Keywords | g-meta-keywords |
Gantry 4 Framework | gantry |
GERRYWORKS Post by Mail | gerryworks-post-by-mail |
GetResponse Forms by Optin Cat | getresponse |
Giveaway Boost | giveaway-boost |
GiveWP – Donation Plugin and Fundraising Platform | give |
Google Map Locations | google-map-locations |
GoogleDrive folder list | googledrive-folder-list |
Htaccess File Editor – Easily Edit, Backup, Restore .htaccess file | htaccess-file-editor |
Hyperlink Group Block | hyperlink-group-block |
IdeaPush | ideapush |
Infinite-Scroll | infinite-scroll |
Jetpack – WP Security, Backup, Speed, & Growth | jetpack |
JiangQie Free Mini Program | jiangqie-free-mini-program |
Job Board Manager for WordPress | jemployee |
Kama SpamBlock | kama-spamblock |
Leyka | leyka |
Lightbox slider – Responsive Lightbox Gallery | simple-lightbox-gallery |
Limb Gallery | Create Beautiful Image & Video Galleries | limb-gallery |
Linked Variation for WooCommerce | linked-variation-for-woocommerce |
Locatoraid Store Locator | locatoraid |
Maan Addons For Elementor | maan-elementor-addons |
MAS Companies For WP Job Manager | mas-wp-job-manager-company |
MAS Elementor | mas-addons-for-elementor |
Mighty Builder – Drag & Drop WordPress Page Builder | mighty-builder |
Miniorange OTP Verification with Firebase | miniorange-firebase-sms-otp-verification |
Mitm Bug Tracker | mitm-bug-tracker |
Most And Least Read Posts Widget | most-and-least-read-posts-widget |
Multiline files upload for contact form 7 | multiline-files-for-contact-form-7 |
My Favorites | my-favorites |
My Reading Library | my-reading-library |
MyTweetLinks | mytweetlinks |
Nextend Social Login Pro | nextend-social-login-pro |
Nice Backgrounds | nicebackgrounds |
Omnipress | omnipress |
Parallax Image | parallax-image |
Parcel Pro | woo-parcel-pro |
PeproDev Ultimate Invoice | pepro-ultimate-invoice |
Photo Gallery Builder | photo-gallery-builder |
Photo Gallery Slideshow & Masonry Tiled Gallery | wp-responsive-photo-gallery |
photokit | photokit |
Pinpoint Booking System – #1 WordPress Booking Plugin | booking-system |
Plexx Elementor Extension | plexx-elementor-extension |
Plugin Name: Sovratec Case Management | sovratec-case-management |
Point Maker | point-maker |
Post From Frontend | post-from-frontend |
Primary Addon for Elementor | primary-addon-for-elementor |
Product Customizer Light | product-customizer-light |
Product Website Showcase | product-websites-showcase |
ProfileGrid – User Profiles, Groups and Communities | profilegrid-user-profiles-groups-and-communities |
Property Lot Management System | plms |
Rate Own Post | rate-own-post |
Recently – Viewed, Most Viewed and Sold Products for WooCommerce | recently-viewed-most-viewed-and-sold-products-for-woocommerce |
ReDi Restaurant Reservation | redi-restaurant-reservation |
Responsive Lightbox & Gallery | responsive-lightbox |
Responsive Pricing Table Builder – wpPricing Builder | wppricing-builder-lite-responsive-pricing-table-builder |
Royal Elementor Addons and Templates | royal-elementor-addons |
RS-Members | rs-members |
RSS Feed Widget | rss-feed-widget |
SafetyForms – Create forms with Real-time Email Validation | safetymails-forms |
Secure Custom Fields | advanced-custom-fields |
SendGrid for WordPress | wp-sendgrid-mailer |
SendPulse Free Web Push | sendpulse-web-push |
SEO Manager | seo-manager |
SermonAudio Widgets | sermonaudio-widgets |
Shipyaari Shipping Management | shipyaari-shipping-managment |
Simple Code Insert Shortcode | simple-code-insert-shortcode |
Simple Custom Post Order | simple-custom-post-order |
Simple Testimonials Showcase | simple-testimonials-showcase |
Simple User Registration | wp-registration |
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) | sina-extension-for-elementor |
SiteBuilder Dynamic Components | sitebuilder-dynamic-components |
SlimStat Analytics | wp-slimstat |
Smart Blocks | smart-blocks |
Smart Online Order for Clover | clover-online-orders |
Social Auto Poster | social-auto-poster |
Social Link Groups | social-link-groups |
Social Share With Floating Bar | social-share-with-floating-bar |
StreamWeasels Twitch Integration | streamweasels-twitch-integration |
Suki Sites Import | suki-sites-import |
Surfer – WordPress Plugin | surferseo |
SW Contact Form | sw-contact-form |
Table of Contents Plus | table-of-contents-plus |
TAKETIN To WP Membership | taketin-to-wp-membership |
The Ultimate WordPress Toolkit – WP Extended | wpextended |
Themesflat Addons For Elementor | themesflat-addons-for-elementor |
Time Clock Pro | time-clock-pro |
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin | time-clock |
Tito | tito |
Ultimate AI | Ultimate_AI |
UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) | ultraaddons-elementor-lite |
Unlimited Addon For Elementor | unlimited-addon-for-elementor |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | unlimited-elements-for-elementor |
VKontakte Wall Post | vkontakte-wall-post |
VOD Infomaniak | vod-infomaniak |
Woo Manage Fraud Orders | woo-manage-fraud-orders |
WooCommerce | woocommerce |
Woostagram Connect | woostagram-connect |
WordPress Image SEO | wp-image-seo |
WordPress Portfolio Builder – Portfolio Gallery | uber-grid |
WordPress Social Share Buttons | share-button |
WordPress Video | wordpress-video |
WP 2FA with Telegram | two-factor-login-telegram |
WP Content Copy Protection & No Right Click | wp-content-copy-protector |
WP Dropbox Dropins | wp-dropbox-dropins |
WP Easy Post Types | easy-post-types |
WP Education – Education WordPress Plugin for Elementor | wp-education |
WP Photo Album Plus | wp-photo-album-plus |
WP Popup Builder – Popup Forms and Marketing Lead Generation | wp-popup-builder |
WP REST API FNS Plugin | rest-api-fns |
WP SendFox | wp-sendfox |
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin | timetics |
WP ULike – All-in-One Engagement Toolkit | wp-ulike |
WP VR – 360 Panorama and Virtual Tour Builder For WordPress | wpvr |
WP-Spreadplugin | wp-spreadplugin |
WPIDE – File Manager & Code Editor | wpide |
Wsify widget | wsify-widget |
Zita Elementor Site Library | zita-site-library |
افزونه پیامک ووکامرس Persian WooCommerce SMS | persian-woocommerce-sms |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Digitally | digitally |
Disconnected | disconnected |
my flatonica | my-flatonica |
my wooden under construction | my-wooden-under-construction |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
Critical (9.8)
CVE-2024-49217
Unpatched
Oct 14, 2024
Adding drop down roles in registration
Critical (9.8)
CVE-2024-49624
Unpatched
Oct 18, 2024
Advanced Advertising System
Critical (9.8)
CVE-2024-49326
Unpatched
Oct 17, 2024
Affiliator
Critical (9.8)
CVE-2024-49245
Unpatched
Oct 14, 2024
Ahime Image Printer
Critical (9.8)
CVE-2024-49254
Unpatched
Oct 14, 2024
ajax-extend
Critical (9.8)
CVE-2024-49253
Unpatched
Oct 14, 2024
Analyse Uploads
Critical (9.8)
CVE-2024-49257
Unpatched
Oct 14, 2024
Azz Anonim Posting
Critical (9.8)
CVE-2024-49247
Unpatched
Oct 14, 2024
BuddyPress Better Registration
Critical (9.8)
CVE-2024-49291
Patched
Oct 15, 2024
Cooked Pro
Critical (9.8)
CVE-2024-49242
Unpatched
Oct 14, 2024
Digital Lottery
Critical (9.8)
CVE-2024-49216
Unpatched
Oct 14, 2024
Feed Comments Number
Critical (9.8)
CVE-2024-49332
Unpatched
Oct 17, 2024
Giveaway Boost
Critical (9.8)
CVE-2024-9634
Patched
Oct 15, 2024
GiveWP – Donation Plugin and Fundraising Platform
Critical (9.8)
CVE-2024-49314
Unpatched
Oct 15, 2024
JiangQie Free Mini Program
Critical (9.8)
CVE-2024-49322
Unpatched
Oct 15, 2024
Job Board Manager for WordPress
Critical (9.8)
CVE-2024-9863
Patched
Oct 16, 2024
Miniorange OTP Verification with Firebase
Miniorange OTP Verification with Firebase <= 3.6.0 – Unauthenticated Arbitrary User Password Change
Critical (9.8)
CVE-2024-9862
Patched
Oct 16, 2024
Miniorange OTP Verification with Firebase
Critical (9.8)
CVE-2024-49318
Unpatched
Oct 15, 2024
My Reading Library
Critical (9.8)
CVE-2024-9893
Patched
Oct 15, 2024
Nextend Social Login Pro
Critical (9.8)
CVE-2024-49610
Unpatched
Oct 17, 2024
photokit
Critical (9.8)
CVE-2024-49611
Unpatched
Oct 17, 2024
Product Website Showcase
Critical (9.8)
CVE-2024-49218
Unpatched
Oct 14, 2024
Recently – Viewed, Most Viewed and Sold Products for WooCommerce
Critical (9.8)
CVE-2024-49626
Unpatched
Oct 18, 2024
Shipyaari Shipping Management
Critical (9.8)
CVE-2024-49604
Unpatched
Oct 17, 2024
Simple User Registration
Critical (9.8)
CVE-2024-49625
Unpatched
Oct 18, 2024
SiteBuilder Dynamic Components
Critical (9.8)
CVE-2024-49324
Unpatched
Oct 17, 2024
Plugin Name: Sovratec Case Management
Critical (9.8)
CVE-2024-9105
Unpatched
Oct 15, 2024
Ultimate AI
Critical (9.8)
CVE-2024-49327
Unpatched
Oct 17, 2024
Woostagram Connect
Critical (9.8)
CVE-2024-49607
Unpatched
Oct 17, 2024
WP Dropbox Dropins
Critical (9.8)
CVE-2024-49328
Unpatched
Oct 17, 2024
WP REST API FNS Plugin
Critical (9.8)
CVE-2024-49329
Unpatched
Oct 17, 2024
WP REST API FNS Plugin
Critical (9.8)
CVE-2024-9263
Patched
Oct 16, 2024
High (8.8)
CVE-2024-49622
Unpatched
Oct 17, 2024
Apa Banner Slider
High (8.8)
CVE-2024-49621
Unpatched
Oct 18, 2024
APA Register Newsletter Form
High (8.8)
CVE-2024-49617
Unpatched
Oct 18, 2024
Back Link Tracker
High (8.8)
CVE-2024-9215
Patched
Oct 16, 2024
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
High (8.8)
CVE-2024-49623
Unpatched
Oct 18, 2024
Duplicate Title Validate
High (8.8)
CVE-2024-49243
Unpatched
Oct 14, 2024
Dynamic Elementor Addons
High (8.8)
CVE-2024-49620
Unpatched
Oct 18, 2024
FERMA.ru.net
High (8.8)
CVE-2024-8507
Patched
Oct 15, 2024
File Manager Pro
High (8.8)
CVE-2024-49227
Unpatched
Oct 14, 2024
Free Stock Photos Foter
High (8.8)
CVE-2024-49608
Unpatched
Oct 18, 2024
GERRYWORKS Post by Mail
High (8.8)
CVE-2024-49251
Unpatched
Oct 14, 2024
Maan Addons For Elementor
High (8.8)
CVE-2024-49618
Unpatched
Oct 18, 2024
MyTweetLinks
High (8.8)
CVE-2024-49330
Unpatched
Oct 17, 2024
Nice Backgrounds
High (8.8)
CVE-2024-49317
Patched
Oct 15, 2024
Point Maker
High (8.8)
CVE-2024-49616
Unpatched
Oct 18, 2024
Rate Own Post
High (8.8)
CVE-2024-49219
Unpatched
Oct 14, 2024
RS-Members
High (8.8)
CVE-2024-49615
Unpatched
Oct 18, 2024
SafetyForms – Create forms with Real-time Email Validation
High (8.8)
CVE-2024-49614
Unpatched
Oct 18, 2024
SermonAudio Widgets
High (8.8)
CVE-2024-49613
Unpatched
Oct 18, 2024
Simple Code Insert Shortcode
High (8.8)
CVE-2024-49619
Unpatched
Oct 18, 2024
Social Link Groups
High (8.8)
CVE-2024-49612
Unpatched
Oct 18, 2024
SW Contact Form
High (8.8)
CVE-2024-49226
Unpatched
Oct 14, 2024
TAKETIN To WP Membership
High (8.8)
CVE-2024-49260
Unpatched
Oct 14, 2024
Limb Gallery | Create Beautiful Image & Video Galleries
High (8.8)
CVE-2024-9687
Patched
Oct 14, 2024
WP 2FA with Telegram
High (8.8)
CVE-2024-10079
Unpatched
Oct 17, 2024
WP Easy Post Types
High (8.3)
CVE-2024-9593
Patched
Oct 18, 2024
AppPresser – Mobile App Framework <= 4.4.4 – Privilege Escalation and Account Takeover via Weak OTP
High (8.1)
CVE-2024-9305
Patched
Oct 15, 2024
AppPresser – Mobile App Framework
High (8.1)
CVE-2024-9861
Patched
Oct 16, 2024
Miniorange OTP Verification with Firebase
High (7.5)
CVE-2024-49246
Unpatched
Oct 14, 2024
Ajax Rating with Custom Login
High (7.5)
CVE-2024-49305
Unpatched
Oct 15, 2024
Customer Email Verification for WooCommerce
High (7.5)
CVE-2024-8746
Patched
Oct 15, 2024
File Manager Pro
High (7.5)
CVE-2024-49315
Unpatched
Oct 15, 2024
FREE DOWNLOAD MANAGER
High (7.4)
CVE-2024-8918
Patched
Oct 15, 2024
File Manager Pro
AADMY – Add Auto Date Month Year Into Posts <= 2.0.1 – Unauthenticated Arbitrary Shortcode Execution
High (7.3)
CVE-2024-9837
Patched
Oct 14, 2024
AADMY – Add Auto Date Month Year Into Posts
High (7.3)
CVE-2024-10078
Unpatched
Oct 17, 2024
WP Easy Post Types
High (7.3)
CVE-2024-9061
Patched
Oct 15, 2024
WP Popup Builder – Popup Forms and Marketing Lead Generation
High (7.2)
CVE-2024-49331
Unpatched
Oct 17, 2024
Property Lot Management System
High (7.2)
CVE-2024-9184
Patched
Oct 16, 2024
SendPulse Free Web Push
High (7.2)
CVE-2024-9548
Patched
Oct 14, 2024
SlimStat Analytics
High (7.2)
CVE-2024-49271
Patched
Oct 14, 2024
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Medium (6.5)
CVE-2024-49609
Unpatched
Oct 18, 2024
Author Discussion
Medium (6.5)
CVE-2024-49244
Unpatched
Oct 14, 2024
CSV Product Import Export for WooCommerce
Medium (6.5)
CVE-2024-49258
Unpatched
Oct 14, 2024
Limb Gallery | Create Beautiful Image & Video Galleries
Medium (6.5)
CVE-2024-9820
Patched
Oct 14, 2024
WP 2FA with Telegram
Medium (6.4)
CVE-2024-9582
Patched
Oct 15, 2024
Accordion Slider
Medium (6.4)
CVE-2024-49307
Patched
Oct 15, 2024
Admin Management Xtended
Medium (6.4)
CVE-2024-9425
Patched
Oct 17, 2024
Advanced Category and Custom Taxonomy Image
Medium (6.4)
CVE-2024-9703
Patched
Oct 17, 2024
Arconix Shortcodes
Medium (6.4)
CVE-2024-49261
Unpatched
Oct 14, 2024
Arkhe Blocks
Medium (6.4)
CVE-2024-49319
Patched
Oct 15, 2024
Awesome Contact Form7 for Elementor
Medium (6.4)
CVE-2024-49265
Unpatched
Oct 14, 2024
Booking.com Banner Creator
Medium (6.4)
CVE-2024-9452
Unpatched
Oct 17, 2024
Branding
Medium (6.4)
CVE-2024-49228
Unpatched
Oct 14, 2024
bVerse Convert
Medium (6.4)
CVE-2024-10055
Patched
Oct 17, 2024
Click to Chat – WP Support All-in-One Floating Widget
Medium (6.4)
CVE-2024-49289
Patched
Oct 15, 2024
Cooked Pro
Medium (6.4)
CVE-2024-49262
Unpatched
Oct 14, 2024
Country Flags for Elementor
Medium (6.4)
CVE-2024-49236
Unpatched
Oct 14, 2024
Crazy Call To Action Box
Medium (6.4)
CVE-2024-49296
Unpatched
Oct 15, 2024
Custom Add to Cart Button Label and Link
Medium (6.4)
CVE-2024-49255
Patched
Oct 14, 2024
Da Reactions
Medium (6.4)
CVE-2024-9674
Patched
Oct 17, 2024
Debrandify · Remove or Replace WordPress Branding
Medium (6.4)
CVE-2024-9366
Unpatched
Oct 17, 2024
Easy Menu Manager | WPZest
Medium (6.4)
CVE-2024-49312
Unpatched
Oct 15, 2024
Edwiser Bridge – WordPress Moodle LMS Integration
Medium (6.4)
CVE-2024-49232
Unpatched
Oct 14, 2024
El mejor Cluster
Medium (6.4)
CVE-2024-9373
Unpatched
Oct 17, 2024
Elemenda
Medium (6.4)
CVE-2024-9444
Patched
Oct 15, 2024
ElementsReady Addons for Elementor
Medium (6.4)
CVE-2024-49264
Patched
Oct 14, 2024
Events Addon for Elementor
Medium (6.4)
CVE-2024-49292
Patched
Oct 15, 2024
Exclusive Addons for Elementor
Medium (6.4)
CVE-2024-10014
Unpatched
Oct 17, 2024
Flat UI Button
Medium (6.4)
CVE-2024-8920
Patched
Oct 16, 2024
Fonto – Custom Web Fonts Manager
Medium (6.4)
CVE-2024-49301
Unpatched
Oct 15, 2024
G Meta Keywords
Medium (6.4)
CVE-2024-49279
Unpatched
Oct 15, 2024
Hyperlink Group Block
Medium (6.4)
CVE-2024-49280
Unpatched
Oct 15, 2024
Lightbox slider – Responsive Lightbox Gallery
Medium (6.4)
CVE-2024-49233
Patched
Oct 14, 2024
MAS Elementor
Medium (6.4)
CVE-2024-48049
Unpatched
Oct 14, 2024
Mighty Builder – Drag & Drop WordPress Page Builder
Medium (6.4)
CVE-2024-49263
Patched
Oct 14, 2024
My Favorites
Medium (6.4)
CVE-2024-49278
Unpatched
Oct 15, 2024
Omnipress
Medium (6.4)
CVE-2024-9898
Patched
Oct 16, 2024
Parallax Image
Medium (6.4)
CVE-2024-49298
Patched
Oct 15, 2024
PeproDev Ultimate Invoice
Medium (6.4)
CVE-2024-49234
Patched
Oct 14, 2024
Plexx Elementor Extension
Medium (6.4)
CVE-2024-49259
Patched
Oct 14, 2024
Primary Addon for Elementor
Medium (6.4)
CVE-2024-9848
Unpatched
Oct 17, 2024
Product Customizer Light
Medium (6.4)
CVE-2024-49282
Unpatched
Oct 15, 2024
Responsive Lightbox & Gallery
Medium (6.4)
CVE-2024-10057
Patched
Oct 17, 2024
RSS Feed Widget
Medium (6.4)
CVE-2024-9521
Unpatched
Oct 15, 2024
SEO Manager
Medium (6.4)
CVE-2024-49270
Patched
Oct 14, 2024
Smart Blocks
Medium (6.4)
CVE-2024-9895
Patched
Oct 14, 2024
Smart Online Order for Clover
Medium (6.4)
CVE-2024-9897
Patched
Oct 18, 2024
StreamWeasels Twitch Integration
Suki Sites Import <= 1.2.1 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
Medium (6.4)
CVE-2024-8916
Unpatched
Oct 17, 2024
Suki Sites Import
Themesflat Addons For Elementor <= 2.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-49310
Patched
Oct 15, 2024
Themesflat Addons For Elementor
Medium (6.4)
CVE-2024-49241
Unpatched
Oct 14, 2024
Tito
Medium (6.4)
CVE-2024-49277
Unpatched
Oct 15, 2024
Unlimited Addon For Elementor <= 2.0.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
Medium (6.4)
CVE-2024-49267
Unpatched
Oct 14, 2024
Unlimited Addon For Elementor
Medium (6.4)
CVE-2024-49302
Unpatched
Oct 15, 2024
WordPress Portfolio Builder – Portfolio Gallery
Medium (6.4)
CVE-2024-49231
Unpatched
Oct 14, 2024
WordPress Video
WP Easy Post Types <= 1.4.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta
Medium (6.4)
CVE-2024-10080
Unpatched
Oct 17, 2024
WP Easy Post Types
WP Education <= 1.2.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via text_html_tag
Medium (6.4)
CVE-2024-49630
Unpatched
Oct 18, 2024
WP Education – Education WordPress Plugin for Elementor
Medium (6.4)
CVE-2024-49225
Unpatched
Oct 14, 2024
Responsive Pricing Table Builder – wpPricing Builder
Medium (6.4)
CVE-2024-8921
Patched
Oct 15, 2024
Zita Elementor Site Library
Medium (6.1)
CVE-2024-49240
Unpatched
Oct 14, 2024
AB Categories Search Widget
Medium (6.1)
CVE-2024-49248
Patched
Oct 14, 2024
Ad Inserter – Ad Manager & AdSense Ads
Medium (6.1)
CVE-2024-49239
Unpatched
Oct 14, 2024
Add Categories Post Footer
Medium (6.1)
CVE-2024-49238
Unpatched
Oct 14, 2024
ADIF Log Search Widget
Medium (6.1)
CVE-2024-49237
Unpatched
Oct 14, 2024
Ahmeti Wp Timeline
Medium (6.1)
CVE-2024-49230
Unpatched
Oct 14, 2024
Ajax Custom CSS/JS
Medium (6.1)
CVE-2024-49316
Unpatched
Oct 15, 2024
Akismet htaccess writer
Medium (6.1)
CVE-2024-49308
Unpatched
Oct 15, 2024
Animator – Scroll Triggered Animations
Medium (6.1)
CVE-2024-49605
Unpatched
Oct 18, 2024
Community Lite Video Chat
Medium (6.1)
CVE-2024-49223
Unpatched
Oct 14, 2024
CJ Change Howdy
Medium (6.1)
CVE-2024-49276
Unpatched
Oct 15, 2024
Clio Grow Form
Medium (6.1)
CVE-2024-49220
Unpatched
Oct 14, 2024
Cookie Scanner – automated cookie list
Medium (6.1)
CVE-2024-49221
Unpatched
Oct 14, 2024
Medium (6.1)
CVE-2024-49283
Unpatched
Oct 15, 2024
Medium (6.1)
CVE-2024-49309
Unpatched
Oct 15, 2024
Digitally
Medium (6.1)
CVE-2024-49268
Unpatched
Oct 14, 2024
Disconnected
Medium (6.1)
CVE-2024-9350
Patched
Oct 17, 2024
DPD Baltic Shipping
Medium (6.1)
CVE-2024-10049
Unpatched
Oct 17, 2024
Edit WooCommerce Templates
Medium (6.1)
CVE-2024-49320
Patched
Oct 15, 2024
Encyclopedia / Glossary / Wiki
Medium (6.1)
CVE-2024-8719
Patched
Oct 16, 2024
Flexmls® IDX Plugin
Medium (6.1)
CVE-2024-9382
Unpatched
Oct 17, 2024
Gantry 4 Framework
Medium (6.1)
CVE-2024-8740
Unpatched
Oct 17, 2024
GetResponse Forms by Optin Cat
Medium (6.1)
CVE-2024-49606
Unpatched
Oct 18, 2024
Google Map Locations
Medium (6.1)
CVE-2024-49335
Unpatched
Oct 18, 2024
GoogleDrive folder list
Medium (6.1)
CVE-2024-9647
Patched
Oct 15, 2024
Kama SpamBlock
Medium (6.1)
CVE-2024-9652
Patched
Oct 15, 2024
Locatoraid Store Locator
Medium (6.1)
CVE-2024-9206
Patched
Oct 17, 2024
MAS Companies For WP Job Manager
Medium (6.1)
CVE-2024-49224
Unpatched
Oct 14, 2024
Mitm Bug Tracker
Medium (6.1)
CVE-2024-49269
Unpatched
Oct 14, 2024
Medium (6.1)
CVE-2024-9383
Unpatched
Oct 17, 2024
Parcel Pro
Medium (6.1)
CVE-2024-9213
Patched
Oct 16, 2024
افزونه پیامک ووکامرس Persian WooCommerce SMS
Pinpoint Booking System <= 2.9.9.5.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting
Medium (6.1)
CVE-2024-49304
Unpatched
Oct 15, 2024
Pinpoint Booking System – #1 WordPress Booking Plugin
Medium (6.1)
CVE-2024-9240
Patched
Oct 16, 2024
ReDi Restaurant Reservation
Medium (6.1)
CVE-2024-8787
Patched
Oct 15, 2024
Smart Online Order for Clover
Medium (6.1)
CVE-2024-8790
Unpatched
Oct 17, 2024
Social Share With Floating Bar
Medium (6.1)
CVE-2024-9347
Patched
Oct 16, 2024
The Ultimate WordPress Toolkit – WP Extended
Medium (6.1)
CVE-2024-49313
Unpatched
Oct 15, 2024
VKontakte Wall Post
Medium (6.1)
CVE-2024-9937
Unpatched
Oct 15, 2024
Woo Manage Fraud Orders
Medium (6.1)
CVE-2024-9951
Patched
Oct 16, 2024
WP Photo Album Plus
Medium (6.1)
CVE-2024-9219
Patched
Oct 18, 2024
WordPress Social Share Buttons
Medium (6.1)
CVE-2024-48048
Unpatched
Oct 14, 2024
Wsify widget
Medium (5.6)
CVE-2024-9104
Unpatched
Oct 15, 2024
Ultimate AI
Medium (5.5)
CVE-2024-49266
Unpatched
Oct 14, 2024
WP-Spreadplugin
Medium (5.4)
CVE-2024-49229
Unpatched
Oct 14, 2024
Better Author Bio
Medium (5.4)
CVE-2024-9873
Patched
Oct 15, 2024
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App
Medium (5.4)
CVE-2024-9888
Patched
Oct 15, 2024
ElementInvader Addons for Elementor
Medium (5.3)
CVE-2024-9940
Patched
Oct 16, 2024
Calculated Fields Form
Contact Forms, Live Support, CRM, Video Messages <= 1.10.2 – Unauthenticated Information Disclosure
Medium (5.3)
CVE-2024-49235
Unpatched
Oct 14, 2024
Contact Forms, Live Support, CRM, Video Messages
Medium (5.3)
CVE-2024-10040
Unpatched
Oct 17, 2024
Infinite-Scroll
Medium (5.3)
CVE-2024-9689
Unpatched
Oct 15, 2024
Post From Frontend
Medium (5.3)
CVE-2024-9944
Patched
Oct 14, 2024
WooCommerce
Medium (5.3)
CVE-2024-49284
Unpatched
Oct 15, 2024
WP SendFox
Medium (5.3)
CVE-2024-9546
Patched
Oct 14, 2024
WPIDE – File Manager & Code Editor
Medium (4.9)
CVE-2019-25218
Patched
Oct 18, 2024
Photo Gallery Slideshow & Masonry Tiled Gallery
Medium (4.9)
CVE-2024-49299
Unpatched
Oct 15, 2024
Surfer – WordPress Plugin
Medium (4.7)
CVE-2024-8541
Patched
Oct 15, 2024
Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons
Medium (4.4)
CVE-2024-9892
Patched
Oct 17, 2024
Add Widget After Content
Medium (4.4)
CVE-2024-49593
Patched
Oct 15, 2024
Medium (4.4)
CVE-2024-7877
Patched
Oct 15, 2024
Medium (4.4)
CVE-2024-7876
Patched
Oct 15, 2024
Contact Form by Supsystic <= 1.7.28 – Authenticated (Administrator+) Stored Cross-Site Scripting
Medium (4.4)
CVE-2024-48046
Patched
Oct 14, 2024
Contact Form by Supsystic
Medium (4.4)
CVE-2024-49288
Unpatched
Oct 15, 2024
Email Template Customizer for WooCommerce
Medium (4.4)
CVE-2024-49295
Unpatched
Oct 15, 2024
Simple Testimonials Showcase
Medium (4.3)
CVE-2024-9361
Unpatched
Oct 17, 2024
Bulk images optimizer: Resize, optimize, convert to webp, rename …
Medium (4.3)
CVE-2024-49290
Patched
Oct 15, 2024
Cooked Pro
ElementInvader Addons for Elementor <= 1.2.9 – Authenticated (Contributor+) Information Exposure
Medium (4.3)
CVE-2024-9889
Patched
Oct 18, 2024
ElementInvader Addons for Elementor
Medium (4.3)
CVE-2024-6757
Patched
Oct 14, 2024
Elementor Website Builder – More than Just a Page Builder
Medium (4.3)
CVE-2024-49629
Patched
Oct 18, 2024
Endless Posts Navigation
Medium (4.3)
CVE-2023-6243
Patched
Oct 18, 2024
EventON Pro
Medium (4.3)
CVE-2024-9352
Patched
Oct 16, 2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Medium (4.3)
CVE-2024-9351
Patched
Oct 16, 2024
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Medium (4.3)
CVE-2024-49256
Patched
Oct 14, 2024
Htaccess File Editor – Easily Edit, Backup, Restore .htaccess file
Medium (4.3)
CVE-2024-49275
Patched
Oct 14, 2024
IdeaPush
Medium (4.3)
Unknown
Patched
Oct 14, 2024
Jetpack – WP Security, Backup, Speed, & Growth
Medium (4.3)
CVE-2024-49252
Patched
Oct 14, 2024
Leyka
Medium (4.3)
CVE-2024-48047
Unpatched
Oct 14, 2024
Linked Variation for WooCommerce
Medium (4.3)
CVE-2024-49628
Patched
Oct 18, 2024
Most And Least Read Posts Widget
Medium (4.3)
CVE-2024-9891
Patched
Oct 15, 2024
Multiline files upload for contact form 7
Medium (4.3)
CVE-2024-49325
Unpatched
Oct 17, 2024
Photo Gallery Builder
Medium (4.3)
CVE-2024-49273
Patched
Oct 14, 2024
ProfileGrid – User Profiles, Groups and Communities
Medium (4.3)
CVE-2024-7417
Patched
Oct 16, 2024
Royal Elementor Addons and Templates
SendGrid for WordPress <= 1.4 – Missing Authorization to Authenticated (Subscriber+) Log Deletion
Medium (4.3)
CVE-2024-9364
Unpatched
Oct 17, 2024
SendGrid for WordPress
Medium (4.3)
CVE-2024-49321
Patched
Oct 15, 2024
Simple Custom Post Order
Medium (4.3)
CVE-2024-9540
Patched
Oct 15, 2024
Medium (4.3)
CVE-2024-49272
Patched
Oct 14, 2024
Social Auto Poster
Medium (4.3)
CVE-2024-49250
Unpatched
Oct 14, 2024
Table of Contents Plus
Medium (4.3)
CVE-2024-49274
Patched
Oct 14, 2024
VOD Infomaniak
Medium (4.3)
CVE-2024-49627
Unpatched
Oct 18, 2024
WordPress Image SEO
Medium (4.3)
CVE-2024-49306
Patched
Oct 15, 2024
WP Content Copy Protection & No Right Click
Medium (4.3)
CVE-2024-9649
Patched
Oct 15, 2024
WP ULike – All-in-One Engagement Toolkit
Medium (4.3)
CVE-2024-49293
Patched
Oct 15, 2024
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
The post Wordfence Intelligence Weekly WordPress Vulnerability Report (October 14, 2024 to October 20, 2024) appeared first on Wordfence.