Wordfence Intelligence Weekly WordPress Vulnerability Report (December 9, 2024 to December 15, 2024)
💥 Time to wrap up this year and kick-off the new year with a bang! We’re wrapping up the year with our End of Year Holiday Extravaganza, High-Risk Bonus Blitz Challenge, and Superhero Challenge for the Wordfence Bug Bounty Program. Through January 6th, 2025:
- All in-scope vulnerability types for WordPress plugins/themes with >= 1,000 active installations are in-scope for ALL researchers
- All plugins and themes with 50-999 active installs hosted in the WordPress.org repository and updated within the last 2 years are in-scope for all researchers!
- All plugins and themes hosted in the WordPress.org repository with any install count are in scope for our preset list of high threat vulnerabilities.
- $150 bonus awarded when a researcher submits at least 15 valid high threat vulnerabilities, and then a $50 bonus awarded for every 5 submitted thereafter.
- Minimum bounty of $5 for all valid in-scope submissions.
- All researchers earn automatic bonuses of between 5% to 180% for valid submissions
- Pending report limits are increased for all
- It’s possible to earn up to $31,200 for high impact vulnerabilities!
Last week, there were 369 vulnerabilities disclosed in 343 WordPress Plugins and 8 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 72 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 21,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- s2Member (Pro) <= 241114 – Unauthenticated Remote Code Execution
- WAF-RULE-783 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 181 |
Unpatched | 188 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 292 |
High Severity | 49 |
Critical Severity | 26 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 155 |
Cross-Site Request Forgery (CSRF) | 72 |
Missing Authorization | 55 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 32 |
Exposure of Sensitive Information to an Unauthorized Actor | 8 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | 8 |
Improper Control of Generation of Code ('Code Injection') | 8 |
Authorization Bypass Through User-Controlled Key | 6 |
Unrestricted Upload of File with Dangerous Type | 5 |
Deserialization of Untrusted Data | 4 |
Improper Privilege Management | 4 |
Improper Access Control | 3 |
Improper Authentication | 2 |
Server-Side Request Forgery (SSRF) | 2 |
Authentication Bypass Using an Alternate Path or Channel | 1 |
Exposure of Private Personal Information to an Unauthorized Actor | 1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 1 |
Path Traversal: '/../filedir' | 1 |
Uncontrolled Resource Consumption | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
66 | |
28 | |
25 | |
18 | |
18 | |
15 | |
13 | |
11 | |
10 | |
9 | |
8 | |
7 | |
7 | |
7 | |
7 | |
6 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
360 Javascript Viewer | 360deg-javascript-viewer |
3D Avatar User Profile | 3d-avatar-user-profile |
Accept Stripe Payments Using Contact Form 7 | accept-stripe-payments-using-contact-form-7 |
Active Products Tables for WooCommerce. Use constructor to create tables | profit-products-tables-for-woocommerce |
Add image to Post | add-image-to-post |
Add infos to The Events Calendar | add-infos-to-the-events-calendar |
addWeather | myweather |
Admin Customization | wpp-customization |
Advance Menu Manager | advance-menu-manager |
Advanced Blog Post Block | advanced-blog-post-block |
Advanced Data Table For Elementor | advanced-data-table-for-elementor |
Advanced Fancybox | advanced-fancybox |
Advanced What should we write next about | advanced-what-should-we-write-about-next |
AI Content Writer, RSS Feed to Post, Autoblogging SEO Help | seo-help |
AI Post Generator | AutoWriter | ai-post-generator |
AIcomments – комментарии и отзывы ChatGPT | aicomments |
AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot | ai-seo-translator |
Amazon Product Price | amazon-product-price |
Analytics Cat – Google Analytics Made Easy | analytics-cat |
Aphorismus | aphorismus |
AppMaps | appmaps |
Appsplate | appsplate |
AR for WordPress | ar-for-wordpress |
Arabic Webfonts | arabic-webfonts |
Arena.IM – Live Blogging for real-time events | arena-liveblog-and-chat-tool |
AutoWP – AI Content Writer & Rewriter | autowp-ai-content-writer-rewriter |
Awesome Support – WordPress HelpDesk & Support Plugin | awesome-support |
Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch | axeptio-sdk-integration |
Banner System | banner-system |
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. | barcode-scanner-lite-pos-to-manage-products-inventory-and-orders |
Beaver Builder – WordPress Page Builder | beaver-builder-lite-version |
Bet sport Free | bet-sport-free |
Better WP Login Page | better-wp-login-page |
bodi0`s Easy cache | bodi0s-easy-cache |
Bold Page Builder | bold-page-builder |
Booking System Trafft | booking-system-trafft |
Bootstrap Buttons | bootstrap-buttons |
BP Email Assign Templates | bp-email-assign-templates |
Buk for WordPress | buk-appointments |
Bukza | bukza |
Caldera SMTP Mailer | caldera-smtp-mailer |
Car Dealer (Dealership) and Vehicle sales | cardealer |
CarDealerPress | cardealerpress |
Catch Popup | catch-popup |
Category of Posts | list-one-category-of-posts |
CE21 Suite | ce21-suite |
Check Pincode For Woocommerce | check-pincode-for-woocommerce |
Child Theme Creator by Orbisius | orbisius-child-theme-creator |
CK and SyntaxHighlighter | ck-and-syntaxhighlighter |
CleverNode Related Content | clevernode-related-content |
CM Answers – Powerful WordPress Forum Plugin | cm-answers |
Code Generator Pro | code-generator-pro |
Cognito Forms | cognito-forms |
Comments On Feed | comments-on-feed |
Companion Portfolio – Responsive Portfolio Plugin | companion-portfolio |
Connatix Video Embed | connatix-video-embed |
Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent | gdpr-cookie-consent |
CoSchool LMS – A complete Learning Management System to Create and Sell Your Courses Online | coschool |
Country Blocker | country-blocker |
Coupon Affiliates – Affiliate Plugin for WooCommerce | woo-coupon-usage |
Crafthemes Demo Import | crafthemes-demo-import |
Cricket Live Score | cricket-score |
CRUDLab Google Plus Button | crudlab-google-plus |
Cryptocurrency Price Widget | cryptocurrency-price-widget |
CSV to html | csv-to-html |
Currency Converter Widget ⚡ PRO | currency-converter-widget-pro |
Custom Skins Contact Form 7 | custom-skins-contact-form-7 |
de:branding | debranding |
dejure.org Vernetzungsfunktion | dejureorg-vernetzungsfunktion |
Device Detector | device-detector |
Display Future Posts | display-future-posts |
Dr Affiliate | dr-affiliate |
DTC Documents | dtc-documents |
DX Dark Site | devrix-dark-site |
Easy Site Importer | easy-site-importer |
EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin | eazydocs |
ECT Product Carousel | ect-product-carousel |
ECT Social Share | ect-social-share |
EduAdmin Booking | eduadmin-booking |
EELV Newsletter | eelv-newsletter |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
Email Reminders | email-reminders |
Essential Real Estate | essential-real-estate |
eTemplates | etemplates |
Eveeno | eveeno |
Events Addon for Elementor | events-addon-for-elementor |
Evernote Sync | evernote-sync |
Falcon – WordPress Optimizations & Tweaks | falcon |
Fancy Roller Scroller | fancy-roller-scroller |
FAQ And Answers – Create Frequently Asked Questions Area on WP Sites | faq-and-answers |
Feedpress Generator – External RSS Frontend Customizer | feedpress-generator |
Filestack Official | filestack-upload |
Firebase OTP Authentication | authentication-via-otp-using-firebase |
Flaming Forms | flaming-forms |
Flash News / Post (Responsive) | flashnews-fading-effect-pearlbells |
Floating Video Player | floating-player |
FloristPress – Customize your Woo store for your Florist | bakkbone-florist-companion |
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | fluentform |
FooGallery Premium | foogallery-premium |
FormFacade – WordPress plugin for Google Forms | formfacade |
ForumWP – Forum & Discussion Board | forumwp |
Frontend Admin by DynamiApps | acf-frontend-form-element |
FULL – Cliente | full-customer |
Ganohrs Toggle Shortcode | ganohrs-toggle-shortcode |
Gaxx Keywords | gaxx-keywords |
GEO my WP | geo-my-wp |
GeoDataSource Country Region DropDown | geodatasource-country-region-dropdown |
GeoFlickr | geoflickr |
Geoportail Shortcode | geoportail-shortcode |
Get Post Content Shortcode | get-post-content-shortcode |
GitSync | git-sync |
glomex oEmbed | glomex-oembed |
Go Animate | goanimate |
Gou Manage My Account Menu – User Roles | gou-wc-account-tabs |
Greenshift – animation and page builder blocks | greenshift-animation-and-page-builder-blocks |
Grid Plus – Unlimited grid layout | grid-plus |
Gutenberg Blocks and Page Layouts – Attire Blocks | attire-blocks |
Gutensee | gutensee |
Hack-Info | hack-info |
Hash Form – Drag & Drop Form Builder | hash-form |
Hello Event Widgets For Elementor | hello-event-widgets-for-elementor |
Hello In All Languages | hello-in-all-languages |
Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress | hive-support |
Horizontal scroll image slideshow | horizontal-scroll-image-slideshow |
HostFact bestelformulier integratie | hostfact-bestelformulier-integratie |
HQ Rental Software | hq-rental-software |
Hurrakify | hurrakify |
I Plant A Tree | i-plant-a-tree |
ICDSoft Reseller Store | icdsoft-reseller-store |
iChart – Easy Charts and Graphs | ichart |
IDer Login for WordPress | ider-login |
ImageRecycle pdf & image compression | imagerecycle-pdf-image-compression |
ImmoToolBox Connect | immotoolbox-connect |
Import Eventbrite Events | import-eventbrite-events |
IMS Countdown | ims-countdown |
Increase Sociability | increase-sociability |
Insertify – Ad,HTML,CSS,JS,PHP,PDF,Header & Footer | insertify |
Instant Appointment | instant-appointment |
Integrate Firebase | integrate-firebase |
Invoice Payment for WooCommerce | invoice-payment-for-woocommerce |
J&T Express Malaysia | jt-express |
jCarousel for WordPress | jcarousel-for-wordpress |
Jet Footer Code | jet-footer-code |
Job Board Manager | job-board-manager |
KH Easy User Settings | kh-easy-user-settings |
Koalendar – Events & Appointments Booking Calendar | koalendar-free-booking-widget |
Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site | kredeum-nfts |
Ksher | ksher-payment |
Kundgenerator | kundgenerator |
kvCORE IDX | kvcore-idx |
LabelGrid Tools | label-grid-tools |
Last Viewed Posts by WPBeginner | last-viewed-posts |
LaunchPage.app Importer | launchpage-app-importer |
LDD Directory Lite | ldd-directory-lite |
Leader | leader |
LeaderBoard Plugin | leaderboard-lite |
LearnPress – WordPress LMS Plugin | learnpress |
Library Bookshelves | library-bookshelves |
Library Management System – Manage e-Digital Books Library | library-management-system |
Lifetime free Drag & Drop Contact Form Builder for WordPress VForm | v-form |
Like in Vk.com | like-on-vkontakte |
LionScripts: Site Maintenance & Noindex Nofollow Plugin | maintenance-and-noindex-nofollow |
ListApp Mobile Manager | listapp-mobile-manager |
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites | mainwp-child |
Mandrill WP – Email Form Under Post | email-form-under-post |
Mark New Posts | mark-new-posts |
MDC Comment Toolbar | mdc-comment-toolbar |
Media Downloader | media-downloader |
Members – Membership & User Role Editor Plugin | members |
Metrika | metrika |
Mimoos | devoluciones-packback |
Minify HTML | minify-html-markup |
Minterpress | minterpress |
Mollie for Contact Form 7 | cf7-mollie |
MStore API – Create Native Android & iOS Apps On The Cloud | mstore-api |
Multiple Admin Emails | multiple-admin-emails |
My IDX Home Search | my-idx-home-search |
MyParcel | woocommerce-myparcel |
Nabz Image Gallery | nabz-image-gallery |
Navayan CSV Export | navayan-csv-export |
New User Approve | new-user-approve |
News Ticker for Elementor | news-ticker-for-elementor |
Newsletter Subscriptions | newsletter-subscriptions |
Newsletter, Email Marketing, Email Subscriber – Mail Picker | mail-picker |
NewsmanApp | newsmanapp |
Nias course | دوره ساز نیاس | nias-course |
NiceJob | nicejob |
Ninja Forms – The Contact Form Builder That Grows With You | ninja-forms |
Notibar – Notification Bar for WordPress | notibar |
NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar | notificationx |
OAuth Single Sign On – SSO (OAuth Client) | miniorange-login-with-eve-online-google-facebook |
Online Booking & Scheduling Calendar for WordPress by vcita | meeting-scheduler-by-vcita |
ONLYOFFICE DocSpace | onlyoffice-docspace |
Onlywire Multi Autosubmitter | onlywire-multi-autosubmitter |
Opt-In Downloads | halfdata-optin-downloads |
Order Delivery & Pickup Location Date Time ( Free Version ) | order-delivery-pickup-location-date-time-free-version |
Out of the Block: OpenStreetMap | ootb-openstreetmap |
Password for WP | password-for-wp |
Payment Gateway Per Product for WooCommerce | woocommerce-product-payments |
Perfect Font Awesome Integration | perfect-font-awesome-integration |
phZoom Plugin for WordPress | phzoom |
PixProof – Easy Photo Proofing for Photographers | pixproof |
Planaday API | planaday-api |
Plezi | plezi |
Poll, Poll Forms – WordPress Poll plugin by Poll Builder | poll-builder |
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder | popup-maker |
Post Carousel & Slider | post-types-carousel-slider |
Post to Pdf | post-to-pdf |
Posti Shipping | posti-shipping |
Posts and Products Views for WooCommerce | posts-and-products-views |
Posts Date Ranges | posts-date-ranges |
PowerBI Embed Reports | embed-power-bi-reports |
PowerFormBuilder – Contact Form Database Manager for WordPress | power-forms-builder |
Primary Addon for Elementor | primary-addon-for-elementor |
Primer MyData for Woocommerce | primer-mydata |
Print Science Designer | print-science-designer |
Product Carousel Slider & Grid Ultimate for WooCommerce | woo-product-carousel-slider-and-grid-ultimate |
Projectopia – WordPress Project Management | projectopia-core |
Property Hive Mortgage Calculator | property-hive-mortgage-calculator |
Property Hive Stamp Duty Calculator | property-hive-stamp-duty-calculator |
Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart | push-monkey-desktop-push-notifications |
Quietly Insights | quietly-insights |
Quran multilanguage Text & Audio | quran-text-multilanguage |
Quran Phrases About Most People Shortcodes | quran-phrases-about-most-people-shortcodes |
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress | radio-player |
Radius Blocks – WordPress Gutenberg Blocks | radius-blocks |
RapidLoad – Optimize Web Vitals Automatically | unusedcss |
Rate My Post – Star Rating Plugin by FeedbackWP | rate-my-post |
Responsive Filterable Portfolio | responsive-filterable-portfolio |
Responsive Google Maps | by imbaa | responsive-google-maps |
Restaurant & Cafe Addon for Elementor | restaurant-cafe-addon-for-elementor |
Restrict – membership, site, content and user access restrictions for WordPress | restricted-content |
Revi.io – Customer & Products Reviews | revi-io-customer-and-product-reviews |
Role Includer | role-includer |
Saksh Escrow System | saksh-escrow-system |
Schema App Structured Data | schema-app-structured-data-for-schemaorg |
SeedProd Pro | seedprod-coming-soon-pro-5 |
Seraphinite Bulk Discounts for WooCommerce | seraphinite-discount-for-woocommerce |
Service | service |
Share Buttons – Social Media | rich-web-share-button |
Shortcodes for Elementor | shortcode-elementor |
Sign In With Google | sign-in-with-google |
Simple Booking – Widget | simple-booking-widget |
Simple Link Directory | simple-link-directory |
Simple Locator | simple-locator |
Simple Payment | simple-payment |
Simple Presenter | simple-presenter |
Simple Restrict | simple-restrict |
SIP Calculator | sip-calculator |
SiteOrigin Widgets Bundle | so-widgets-bundle |
Smaily for WP | smaily-for-wp |
Smart Agenda – Prise de rendez-vous en ligne | smart-agenda-prise-de-rendez-vous-en-ligne |
Smart PopUp Blaster | smart-popup-blaster |
SMSify | smsify |
Snippet Shortcodes | shortcode-variables |
Social Media Sharing | social-media-sharing |
Social Media Shortcodes | social-media-shortcodes |
SOPA Blackout | sopa-blackout |
Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate | spreadr-for-woocomerce |
SQL Chart Builder | sql-chart-builder |
Staggs – Product Configurator Toolkit | staggs |
States Map US | ymc-states-map |
Stripe Donation | bin-stripe-donation |
Super Backup & Clone - Migrate for WordPress | indeed-wp-superbackup |
Surbma | SalesAutopilot Shortcode | surbma-salesautopilot-shortcode |
SVG Shortcode | svg-shortcode |
Tabs Maker | tabs-maker |
TagGator | taggator |
TCBD Popover | tcbd-popover |
Termin-Kalender | termin-kalender |
The Permalinker | the-permalinker |
Themify Store Locator | themify-store-locator |
This is a Subversion repository; use the 'svnadmin' tool to examine | critical-site-intel-stats |
Tickera – WordPress Event Ticketing | tickera-event-ticketing-system |
Tithe.ly Giving Button | wp-tithely |
Top and footer bars for announcements, notifications, advertisements, promotions – YooBar | yoo-bar |
TSB Occasion Editor | tsb-occasion-editor |
turboSMTP | turbosmtp |
Ui Slider Filter By Price | ui-slider-filter-by-price |
Ultimate Endpoints With Rest Api | custom-wp-rest-api |
UNIVERSAM | universam-demo |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | unlimited-elements-for-elementor |
Utech World Time | utech-world-time-for-wp |
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce | vayu-blocks |
vBSSO-lite | vbsso-lite |
Video & Photo Gallery for Ultimate Member | gallery-for-ultimate-member |
Vimeography: Vimeo Video Gallery WordPress Plugin | vimeography |
Visual Recent Posts | visual-recent-posts |
Visualmodo Elements | visualmodo-elements |
Waymark | waymark |
Web Stories | web-stories |
Web3 Crypto Payments by DePay for WooCommerce | depay-payments-for-woocommerce |
Website Toolbox Community | website-toolbox-forums |
WooCommerce - PDF Vouchers | woocommerce-pdf-vouchers |
WooCommerce Basic Ordernumbers | woocommerce-basic-ordernumbers |
Woocommerce Blocks – Woolook | woolook |
WooCommerce Cart Count Shortcode | woo-cart-count-shortcode |
WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more | gs-books-showcase |
WordPress Filter | wordpress-filter |
WordPress HelpDesk & Support Ticket System Plugin – Octrace Support | octrace-support |
WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more | gs-portfolio |
WordPress Post Grid Layouts with Pagination – Sogrid | sogrid |
Wovax IDX | wovax-idx |
WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More | wp-ad-guru |
WP Controller | wp-management-controller |
WP Cookies Enabler | wp-cookies-enabler |
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses | wp-courses |
WP Crowdfunding | wp-crowdfunding |
WP Currency Exchange Rates | wp-currency-exchange-rates |
WP Email Log – PostBox | postbox-email-logs |
WP Fiddle | wp-fiddle |
WP Flipkart Importer | wp-flipkart-importer |
WP GeoNames | wp-geonames |
WP Job Portal – A Complete Recruitment System for Company or Job Board website | wp-job-portal |
WP Log Action | wp-log-action |
Wp Login with Ajax | wp-login-with-ajax |
WP Mailster | wp-mailster |
WP Mega Menu | wp-megamenu |
Wp NssUser Register | wp-nssuser-register |
Wp photo text slider 50 | wp-photo-text-slider-50 |
WP Pipes | wp-pipes |
WP Quick Shop | wp-quick-shop |
WP Service Payment Form With Authorize.net | wp-service-payment-form-with-authorizenet |
WP Simple Pay Lite Manager | stripe-manager |
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin | timetics |
WP-Ban-User | wp-ban-user |
WP-HideThat | wp-hide-that |
WP-NERD Toolkit | wp-nerd-toolkit |
WP-Revive Adserver | wp-revive-adserver |
WPBookit | wpbookit |
WPC Order Notes for WooCommerce | woo-order-notes |
WPCargo Track & Trace | wpcargo |
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | wpforms-lite |
WPMobile.App — Android and iOS Mobile Application | wpappninja |
WP微信机器人 | wp-weixin-robot |
Wr Age Verification | wr-age-verification |
XML Multilanguage Sitemap Generator | xml-multilanguage-sitemap-generator |
XPD Reduce Image Filesize | xpd-reduce-image-filesize |
YDS Support Ticket System | yds-support-ticket-system |
Youtube Video Grid | Youmax | youmax-channel-embeds-for-youtube-businesses |
Zita Site Builder – Elementor, WordPress & Gutenberg Website Builder | ai-site-builder |
افزونه پیامک ووکامرس Persian WooCommerce SMS | persian-woocommerce-sms |
畅言评论系统 | changyan |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Avada | Website Builder For WordPress & WooCommerce | Avada |
Bicycleshop | bicycleshop |
Brandy | brandy |
hmd | hmd |
Plain Post | plain-post |
TravelTour | traveltour |
Woffice CRM | woffice |
Woodmart | woodmart |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Comments