Wordfence Intelligence Weekly WordPress Vulnerability Report (December 2, 2024 to December 8, 2024)

💥 Time to wrap up this year and kick-off the new year with a bang! We’re wrapping up the year with our End of Year Holiday ExtravaganzaHigh-Risk Bonus Blitz Challenge, and Superhero Challenge for the Wordfence Bug Bounty Program. Through January 6th, 2025:

  • All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
  • All plugins and themes with 50-999 active installs hosted in the WordPress.org repository and updated within the last 2 years are in-scope for all researchers!
  • All plugins and themes hosted in the WordPress.org repository with any install count are in scope for our preset list of high threat vulnerabilities.
  • $150 bonus awarded when a researcher submits at least 15 valid high threat vulnerabilities, and then a $50 bonus awarded for every 5 submitted thereafter.
  • Minimum bounty of $5 for all valid in-scope submissions.
  • All researchers earn automatic bonuses of between 5% to 180% for valid submissions
  • Pending report limits are increased for all
  • It’s possible to earn up to $31,200 for high impact vulnerabilities!

Last week, there were 198 vulnerabilities disclosed in 183 WordPress Plugins and 7 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 62 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 20,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

  • WAF-RULE-774 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-775 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-776 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-777 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-778 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-779 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-780 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-781 – Data redacted while we work with the vendor on a patch.
  • WAF-RULE-782 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 124
Unpatched 74


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Medium Severity 161
High Severity 31
Critical Severity 6


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 101
Missing Authorization 32
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 17
Cross-Site Request Forgery (CSRF) 13
Authorization Bypass Through User-Controlled Key 8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
Improper Control of Generation of Code ('Code Injection') 4
Unrestricted Upload of File with Dangerous Type 4
Deserialization of Untrusted Data 2
Exposure of Sensitive Information to an Unauthorized Actor 2
Authentication Bypass Using an Alternate Path or Channel 1
Improper Access Control 1
Improper Authentication 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
URL Redirection to Untrusted Site ('Open Redirect') 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
23
19
11
9
8
8
7
7
Gab
5
5
5
4
4
4
4
4
3
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
luc
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
140+ Widgets | Xpro Addons For Elementor – FREE xpro-elementor-addons
ABCBiz Addons for Elementor abcbiz-addons
Accessibility by AllAccessible allaccessible
Accordion Slider accordion-slider
Accounting for WooCommerce accounting-for-woocommerce
Additional Custom Order Status for WooCommerce order-status-for-woocommerce
Advanced Element Bucket Addons for Elementor cs-element-bucket
Advanced File Manager file-manager-advanced
AI Quiz | Quiz Maker ai-quiz
AIO Contact aio-contact
All Bootstrap Blocks all-bootstrap-blocks
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) wp-analytify
AnyWhere Elementor anywhere-elementor
ARforms arforms
Arkhe Blocks arkhe-blocks
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup armember-membership
Authors List authors-list
AWeber Forms by Optin Cat aweber-wp
Awesome Shortcodes awesome-shortcodes
B Testimonial – Testimonial plugin for WP b-testimonial
Beautiful taxonomy filters beautiful-taxonomy-filters
Beaver Builder – WordPress Page Builder beaver-builder-lite-version
Block Controller block-controller
BMLT Tabbed Map bmlt-tabbed-map
Bold Page Builder bold-page-builder
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg borderless
BP Profile Shortcodes Extra bp-profile-shortcodes-extra
Broadcast threewp-broadcast
Campaign Monitor Forms by Optin Cat campaign-monitor-wp
Captivate Sync captivatesync-trade
CardGate Payments for WooCommerce cardgate
Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid wp-carousel-free
Charity Addon for Elementor charity-addon-for-elementor
Church Admin church-admin
Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons
Clickbank WordPress Plugin (Storefront) clickbank-storefront
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress sprout-invoices
CLUEVO LMS, E-Learning Platform cluevo-lms
CMSMasters Elementor Addon cmsmasters-elementor-addon
Colibri Page Builder colibri-page-builder
Comfino Payment Gateway comfino-payment-gateway
Connexion Logs logs-de-connexion
Contact Form Builder by vcita contact-form-with-a-meeting-scheduler-by-vcita
Contact Form, Survey & Form Builder – MightyForms mightyforms
Contact Form, Survey, Quiz & Popup Form Builder – ARForms arforms-form-builder
Cookielay cookielay
Country Blocker country-blocker
Designer – Addons for Elementor designer
DN Shipping by Weight for WooCommerce dn-shipping-by-weight
Dollie Hub – Build Your Own WordPress Cloud Platform dollie
Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! pie-forms-for-wp
Easy Code Snippets easy-code-snippets
Easy Social Feed Premium easy-facebook-likebox-premium
Eleblog – Elementor Blog And Magazine Addons ele-blog
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) bdthemes-element-pack-lite
ElementsReady Addons for Elementor element-ready-lite
Email Address Obfuscation email-address-obfuscation
Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner
FancyBox for WordPress fancybox-for-wordpress
FAT Services Booking fat-services-booking
Feedpress Generator – External RSS Frontend Customizer feedpress-generator
FileBird – WordPress Media Library Folders & File Manager filebird
FileOrganizer – Manage WordPress and Website Files fileorganizer
Firelight Lightbox easy-fancybox
float block float-block
FloristPress – Customize your Woo store for your Florist bakkbone-florist-companion
Flower Delivery by Florist One flower-delivery-by-florist-one
Folder Gallery folder-gallery
Form Data Collector form-data-collector
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder form-maker
ForumWP – Forum & Discussion Board forumwp
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials stars-testimonials-with-slider-and-masonry-grid
Friends friends
Futurio Extra futurio-extra
FV Flowplayer Video Player fv-wordpress-flowplayer
Gallery multi-gallery
Gallery Plugin for WordPress – Envira Photo Gallery envira-gallery-lite
Getwid – Gutenberg Blocks getwid
Gold Addons for Elementor gold-addons-for-elementor
Goodlayers Core goodlayers-core
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor gutentor
IdeaPush ideapush
If Menu – Visibility control for Menus if-menu
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free funnelforms-free
Intro Tour Tutorial DeepPresentation dp-intro-tours
jAlbum Bridge jalbum-bridge
KiviCare – Clinic & Patient Management System (EHR) kivicare-clinic-management-system
Knowledge Base documentation & wiki plugin – BasePress Docs basepress
LA-Studio Element Kit for Elementor lastudio-element-kit
Library Management System – Manage e-Digital Books Library library-management-system
Listdom – Business Directory and Classified Ads Listings WordPress Plugin listdom
Login Widget With Shortcode login-sidebar-widget
Login With OTP otp-login
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) magical-addons-for-elementor
Maspik – Advanced Spam Protection contact-forms-anti-spam
Message Filter for Contact Form 7 cf7-message-filter
Mini Program API wp-mini-program
Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-woocommerce
Mollie for Contact Form 7 cf7-mollie
My auctions allegro my-auctions-allegro-free-edition
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. mycred
Namaste! LMS namaste-lms
News Kit Elementor Addons news-kit-elementor-addons
NEX-Forms – Ultimate Form Builder – Contact forms and much more nex-forms-express-wp-form-builder
Next-Cart Store to WooCommerce Migration nextcart-woocommerce-migration
Ni WooCommerce Order Export ni-woocommerce-order-export
NPS computy nps-computy
Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita
ONLYOFFICE Docs onlyoffice
Paloma Widget postman-widget
PDF Builder for WooCommerce. Create invoices,packing slips and more woo-pdf-invoice-builder
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery nextgen-gallery
Pie Register - Social Sites Login (Add on) pie-register-social-site
Pie Register Premium pie-register-premium
Pinpoint Booking System – #1 WordPress Booking Plugin booking-system
Pojo Forms pojo-forms
Poll Maker – Versus Polls, Anonymous Polls, Image Polls poll-maker
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX ultimate-post
Posti Shipping posti-shipping
PowerPack Elementor Addons (Free Widgets, Extensions and Templates) powerpack-lite-for-elementor
Prodigy Commerce prodigy-commerce
Product Labels For Woocommerce (Sale Badges) aco-product-labels-for-woocommerce
Pulsating Chat Button amin-chat-button
Quick License Manager – WooCommerce Plugin quick-license-manager
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins related-post
Responsive Lightbox & Gallery responsive-lightbox
Responsive Videos responsive-youtube-videos
Revy revy
RRAddons for Elementor rrdevs-for-elementor
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions s2member
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more scratch-win-giveaways-for-website-facebook
SearchIQ – The Search Solution searchiq
SG Helper sg-helper
Shortcodes Blocks Creator Ultimate ultimate-shortcodes-creator
Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal simple-e-commerce-shopping-cart
Simple Redirection eelv-redirection
Simple User Registration wp-registration
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel depicter
Smart PopUp Blaster smart-popup-blaster
Smoove connector for Elementor forms smoove-elementor
SMS for Lead Capture Forms clicksend-lead-capture-form
Spectra – WordPress Gutenberg Blocks ultimate-addons-for-gutenberg
Splash Sync splash-connector
SV100 Companion sv100-companion
Swift Performance Lite swift-performance-lite
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce the-plus-addons-for-elementor-page-builder
Themesflat Addons For Elementor themesflat-addons-for-elementor
TI WooCommerce Wishlist ti-woocommerce-wishlist
Tutor LMS Elementor Addons tutor-lms-elementor-addons
TWChat – Send or receive messages from users twchat
TwentyTwenty twentytwenty
Ultimate Coming Soon & Maintenance ultimate-coming-soon
Unlock Addons for Elementor unlock-addons-for-elementor
Verowa Connect verowa-connect
Video Gallery – YouTube Gallery and Vimeo Gallery gallery-videos
Visual Portfolio, Photo Gallery & Post Grid visual-portfolio
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder wdesignkit
WIP WooCarousel Lite wip-woocarousel-lite
WordPress Auction Plugin wp-auctions
WordPress Page Builder – Zion Builder zionbuilder
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout gs-pinterest-portfolio
Wot Elementor Widgets wot-elementor-widgets
WP eCards wp-ecards-invites
WP GeoNames wp-geonames
WP Hide & Security Enhancer wp-hide-security-enhancer
WP Job Manager – Company Profiles wp-job-manager-companies
WP Mailster wp-mailster
WP Media Optimizer (.webp) wp-media-optimizer-webp
WP Private Content Plus wp-private-content-plus
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts wedevs-project-manager
WP System wp-system
WP Travel – Ultimate Travel Booking System, Tour Management Engine wp-travel
WP Umbrella: Update Backup Restore & Monitoring wp-health
WP-SVG wp-svg
WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor
WPC Smart Quick View for WooCommerce woo-smart-quick-view
WPCasa wpcasa
XLTab – Accordions and Tabs for Elementor Page Builder xl-tab
Z-Downloads z-downloads
Zooom zooom
افزونه پیامک ووکامرس Persian WooCommerce SMS persian-woocommerce-sms
워드프레스 결제 심플페이 – 우커머스 결제 플러그인 pgall-for-woocommerce
코드엠샵 소셜톡 mshop-naver-talktalk


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
Blocksy blocksy
Flixita flixita
NewsMash newsmash
NewsMunch newsmunch
Pubnews pubnews
Soledad soledad
Sweet Date sweetdate


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-54214
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Revy
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-53822
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Pie Register Premium
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-12155
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
SV100 Companion
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-43222
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
Sweet Date
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-12209
Patch Status
Patched
Published
Dec 7, 2024
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-53810
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Simple User Registration
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-11643
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
Accessibility by AllAccessible
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-11323
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
AI Quiz | Quiz Maker
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-53824
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
All Bootstrap Blocks
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-54225
Patch Status
Unpatched
Published
Dec 5, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-11501
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Gallery
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-10578
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Pubnews
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-53807
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP Mailster
Researcher
CVSS Rating
High (8.6)
CVE-ID
CVE-2024-54221
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
FAT Services Booking
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2024-11178
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Login With OTP
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2024-11289
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Soledad
Researcher
CVSS Rating
High (8.1)
CVE-ID
CVE-2024-10516
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Swift Performance Lite
Researcher
CVSS Rating
High (7.7)
CVE-ID
CVE-2024-54216
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
ARforms
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11391
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Advanced File Manager
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-12270
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Beautiful taxonomy filters
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11952
Patch Status
Patched
Published
Dec 3, 2024
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11728
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-54215
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Revy
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-10567
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
TI WooCommerce Wishlist
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11460
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Verowa Connect
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-51615
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
WordPress Auction Plugin
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11585
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
WP Hide & Security Enhancer
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-53805
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP Mailster
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2024-10952
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
Authors List
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-54219
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
AIO Contact
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-11010
Patch Status
Patched
Published
Dec 6, 2024
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-10247
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.8)
CVE-ID
CVE-2024-8679
Patch Status
Unpatched
Published
Dec 6, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-54218
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
AIO Contact
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-54223
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-11732
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
BP Profile Shortcodes Extra
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-11730
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-11729
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-53815
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-53803
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP Mailster
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-53813
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54247
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
ABCBiz Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54210
Patch Status
Unpatched
Published
Dec 2, 2024
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53794
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Arkhe Blocks
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11880
Patch Status
Patched
Published
Dec 3, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53797
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11420
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
Blocksy
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11866
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
BMLT Tabbed Map
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53801
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Bold Page Builder
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53820
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Captivate Sync
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-9694
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
CMSMasters Elementor Addon
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10056
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
Contact Form Builder by vcita
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11897
Patch Status
Unpatched
Published
Dec 3, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10320
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Cookielay
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54224
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11935
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
Email Address Obfuscation
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54220
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
FAT Services Booking
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11769
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
Flower Delivery by Florist One
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53802
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Futurio Extra
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11853
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
jAlbum Bridge
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11380
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Mini Program API
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54260
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
News Kit Elementor Addons
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10849
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
NewsMash
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10848
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
NewsMunch
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11450
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
ONLYOFFICE Docs
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53818
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11747
Patch Status
Unpatched
Published
Dec 3, 2024
Affected Software
Responsive Videos
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54232
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
RRAddons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10885
Patch Status
Patched
Published
Dec 3, 2024
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11339
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Smart PopUp Blaster
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-10484
Patch Status
Patched
Published
Dec 2, 2024
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-53796
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11352
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
TwentyTwenty
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54230
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Unlock Addons for Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11779
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
WIP WooCarousel Lite
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54213
Patch Status
Unpatched
Published
Dec 2, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54228
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Wot Elementor Widgets
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11903
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
WP eCards
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11782
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP Mailster
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11644
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
WP-SVG
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11451
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Zooom
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11904
Patch Status
Patched
Published
Dec 6, 2024
Affected Software
코드엠샵 소셜톡
Researcher
CVSS Rating
Medium (6.3)
CVE-ID
CVE-2024-10909
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Pojo Forms
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11324
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
Accounting for WooCommerce
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11814
Patch Status
Patched
Published
Dec 3, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54209
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Awesome Shortcodes
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54208
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Block Controller
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11379
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Broadcast
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11326
Patch Status
Patched
Published
Dec 2, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12257
Patch Status
Patched
Published
Dec 6, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11336
Patch Status
Unpatched
Published
Dec 5, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11329
Patch Status
Patched
Published
Dec 6, 2024
Affected Software
Comfino Payment Gateway
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54226
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Country Blocker
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11464
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Easy Code Snippets
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11457
Patch Status
Unpatched
Published
Dec 6, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-10836
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Flixita
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11823
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Folder Gallery
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11461
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Form Data Collector
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-10879
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11204
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11200
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Goodlayers Core
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11466
Patch Status
Patched
Published
Dec 3, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54255
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Login Widget With Shortcode
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12165
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
Mollie for Contact Form 7
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11707
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
My auctions allegro
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11687
Patch Status
Patched
Published
Dec 5, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54231
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Ni WooCommerce Order Export
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11807
Patch Status
Patched
Published
Dec 3, 2024
Affected Software
NPS computy
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-54205
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Paloma Widget
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-53821
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Pie Register Premium
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-10832
Patch Status
Unpatched
Published
Dec 3, 2024
Affected Software
Posti Shipping
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11813
Patch Status
Unpatched
Published
Dec 3, 2024
Affected Software
Pulsating Chat Button
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11805
Patch Status
Patched
Published
Dec 2, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12167
Patch Status
Unpatched
Published
Dec 6, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12166
Patch Status
Unpatched
Published
Dec 6, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11367
Patch Status
Unpatched
Published
Dec 6, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11368
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Splash Sync
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11374
Patch Status
Unpatched
Published
Dec 6, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-53812
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP GeoNames
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2023-6978
Patch Status
Patched
Published
Dec 3, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12060
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
WP Media Optimizer (.webp)
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12003
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
WP System
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-10046
Patch Status
Patched
Published
Dec 6, 2024
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2024-11093
Patch Status
Unpatched
Published
Dec 3, 2024
Affected Software
SG Helper
Researcher
CVSS Rating
Medium (5.5)
CVE-ID
CVE-2024-54207
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
WordPress Auction Plugin
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-54217
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
ARforms
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-9866
Patch Status
Patched
Published
Dec 5, 2024
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-53798
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-53795
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Church Admin
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11373
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Connexion Logs
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-12028
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Friends
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-7894
Patch Status
Patched
Published
Dec 6, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-54227
Patch Status
Unpatched
Published
Dec 5, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-9706
Patch Status
Unpatched
Published
Dec 5, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-53804
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WP Mailster
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11292
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
WP Private Content Plus
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-53826
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
WPCasa
Researcher
CVSS Rating
Medium (5.2)
CVE-ID
CVE-2024-11325
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
AWeber Forms by Optin Cat
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-11372
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Connexion Logs
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-53808
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-53817
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-11645
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
float block
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-9769
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-54206
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Z-Downloads
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53814
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-10777
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
AnyWhere Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12062
Patch Status
Unpatched
Published
Dec 2, 2024
Affected Software
Charity Addon for Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-11444
Patch Status
Unpatched
Published
Dec 5, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-11842
Patch Status
Patched
Published
Dec 6, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53825
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53799
Patch Status
Patched
Published
Dec 2, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12110
Patch Status
Unpatched
Published
Dec 5, 2024
Affected Software
Gold Addons for Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-11844
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
IdeaPush
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-10787
Patch Status
Patched
Published
Dec 3, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53806
Patch Status
Patched
Published
Dec 2, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12027
Patch Status
Patched
Published
Dec 5, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12026
Patch Status
Patched
Published
Dec 6, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53809
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Namaste! LMS
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12115
Patch Status
Patched
Published
Dec 6, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-54250
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Prodigy Commerce
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-54251
Patch Status
Patched
Published
Dec 5, 2024
Affected Software
Prodigy Commerce
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-11341
Patch Status
Patched
Published
Dec 4, 2024
Affected Software
Simple Redirection
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-11353
Patch Status
Unpatched
Published
Dec 6, 2024
Affected Software
SMS for Lead Capture Forms
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-53816
Patch Status
Patched
Published
Dec 2, 2024
Affected Software
Tutor LMS Elementor Addons
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-9705
Patch Status
Unpatched
Published
Dec 5, 2024


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments

All comments are moderated before being published. Inappropriate or off-topic comments may not be approved.