Wordfence Intelligence Weekly WordPress Vulnerability Report (December 16, 2024 to January 5, 2025)


📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.


Special Note: This weeks Wordfence Intelligence Weekly WordPress Vulnerability Report is an extended edition to cover the last few weeks in December over the holidays and the first week in January.

Over the past three weeks, there were 348 vulnerabilities disclosed in 291 WordPress Plugins and 11 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 84 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 21,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch Status Number of Vulnerabilities
Patched 225
Unpatched 123


Total Vulnerabilities by CVSS Severity Last Week

Severity Rating Number of Vulnerabilities
Low Severity 1
Medium Severity 267
High Severity 53
Critical Severity 27


Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE Number of Vulnerabilities
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 153
Missing Authorization 44
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 32
Cross-Site Request Forgery (CSRF) 31
Exposure of Sensitive Information to an Unauthorized Actor 14
Deserialization of Untrusted Data 11
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') 11
Unrestricted Upload of File with Dangerous Type 11
Incorrect Privilege Assignment 7
Improper Control of Generation of Code ('Code Injection') 6
Authorization Bypass Through User-Controlled Key 5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 5
Server-Side Request Forgery (SSRF) 5
External Control of File Name or Path 2
Authentication Bypass Using an Alternate Path or Channel 1
Generation of Predictable Numbers or Identifiers 1
Improper Access Control 1
Improper Authentication 1
Improper Authorization 1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) 1
Improper Neutralization of Special Elements Used in a Template Engine 1
Incorrect Authorization 1
Uncontrolled Resource Consumption 1
Use of Insufficiently Random Values 1
Weak Password Recovery Mechanism for Forgotten Password 1


Researchers That Contributed to WordPress Security Last Week

Researcher Name Number of Vulnerabilities
33
27
24
21
20
17
12
9
9
7
7
7
6
6
6
6
5
5
5
5
Gab
5
4
4
4
4
3
3
3
3
3
3
3
3
3
3
2
2
2
2
2
2
2
2
2
2
2
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software Name Software Slug
10CentMail 10centmail-subscription-management-and-analytics
5centsCDN – WordPress CDN Plugin 5centscdn
Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7
Accessibility by AllAccessible allaccessible
ACF City Selector acf-city-selector
ACH Invoicing Plugin ach-invoice-app
Advanced Floating Content advanced-floating-content
Advanced Google reCAPTCHA advanced-google-recaptcha
AdWork Media EZ Content Locker adwork-media-ez-content-locker
Affiliate Program Suite — SliceWP Affiliates slicewp
AFI – The Easiest Integration Plugin advanced-form-integration
Agency Toolkit agency-toolkit
AI Magic – SEO Content Generator & Article Writer newsletter-page-redirects
Allada T-shirt Designer for Woocommerce – Custom Product Designer for T-shirt personalization and design allada-tshirt-designer-for-woocommerce
AMP for WP – Accelerated Mobile Pages accelerated-mobile-pages
Animated Counters animated-counters
Animation Addons for Elementor animation-addons-for-elementor
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress bookingpress-appointment-booking
Arconix Shortcodes arconix-shortcodes
ARPrice - WordPress Pricing Table Plugin arprice
Ashe Extra ashe-extra
Astra Widgets astra-widgets
Autocompleter autocompleter
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress automatorwp
Avada (Fusion) Builder fusion-builder
AyeCode Connect ayecode-connect
Backup Migration backup-backup
Biagiotti Membership biagiotti-membership
Bitcoin Lightning Publisher for WordPress bitcoin-lightning-publisher
Booking calendar, Appointment Booking System booking-calendar
Broken Link Checker | Finder broken-link-finder
BSK Forms Blacklist bsk-gravityforms-blacklist
BU Section Editing bu-section-editing
Button Block – Get fully customizable & multi-functional buttons button-block
BVD Easy Gallery Manager bvd-easy-gallery-manager
Calculated Fields Form calculated-fields-form
Category Post Shortcode category-post-shortcode
Category Post Slider category-post-slider
Classic Addons – WPBakery Page Builder classic-addons-wpbakery-page-builder-addons
CodeBard Help Desk codebard-help-desk
Coins MarketCap coins-marketcap
Collapsing Categories collapsing-categories
Compact WP Audio Player compact-wp-audio-player
Contact Form 7 Database – CFDB7 advanced-cf7-database
Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder bit-form
Contact Form Master – by Edmon contact-form-master
Content No Cache | Serve uncached partial content even when you add it to a page that is fully cached. content-no-cache
Contests by Rewards Fuel contests-from-rewards-fuel
ConvertCalculator for WordPress convertcalculator
Coupon Plugin coupon-lite
CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout support-x
CRM WordPress Plugin – RepairBuddy computer-repair-shop
Custom Dashboard Widget create-custom-dashboard-widget
Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login Url login-page-styler
Custom Product tabs for WooCommerce wb-custom-product-tabs-for-woocommerce
Data Tables Generator by Supsystic data-tables-generator-by-supsystic
Database Backup and check Tables Automated With Scheduler 2024 database-backup
DirectoryPress – Business Directory And Classified Ad Listing directorypress
Download Manager download-manager
Dynamic Product Category Grid, Slider for WooCommerce dynamic-product-categories-design
Dynamics 365 Integration integration-dynamics
DynamicTags dynamictags
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy easy-digital-downloads
Easy Language Switcher easy-language-switcher
Easy Waveform Player easy-waveform-player
Ebook Store ebook-store
eCommerce Product Catalog Plugin for WordPress ecommerce-product-catalog
EditionGuard for WooCommerce – eBook Sales with DRM editionguard-for-woocommerce-ebook-sales-with-drm
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) bdthemes-element-pack-lite
Elementor Website Builder – More Than Just a Page Builder elementor
ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) css-for-elementor
ElementsReady Addons for Elementor element-ready-lite
Elevio elevio
ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
ELEX WooCommerce Dynamic Pricing and Discounts elex-woocommerce-dynamic-pricing-and-discounts
Email Reminders email-reminders
Embed PDF Viewer embed-pdf-viewer
Embed Twine embed-twine
EMC2 Alert Boxes emc2-alert-boxes
Enter Addons – Ultimate Template Builder for Elementor enteraddons
Envato Elements – Photos & Elementor Templates envato-elements
EO4WP: EmailOctopus for WordPress fw-integration-for-emailoctopus
Essential Addons for Elementor – Popular Elementor Addon With Ready Templates, Advanced Widgets, Kits & WooCommerce Builders essential-addons-for-elementor-lite
Event Espresso – Event Registration & Ticketing Sales event-espresso-decaf
Event Manager, Events Calendar, Tickets, Registrations – Eventin wp-event-solution
EventPrime – Events Calendar, Bookings and Tickets eventprime-event-calendar-management
Events Addon for Elementor events-addon-for-elementor
Export All Posts, Products, Orders, Refunds & Users wp-ultimate-exporter
Export Customers Data export-customers-data
Fancy Product Designer fancy-product-designer
FAQs faqs
Feedify – Web Push Notifications push-notification-by-feedify
File Manager Pro – Filester filester
Financial Calculator finance-calculator-with-application-form
Floating Action Buttons floating-action-buttons
Frontend Admin by DynamiApps acf-frontend-form-element
Full Screen Menu for Elementor full-screen-menu-for-elementor
FV Descriptions fv-descriptions
G Web Pro Store Locator gwebpro-store-locator
gap-hub-user-role. gap-hub-user-role
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory geodirectory
Goodlayers Core goodlayers-core
GS Coaches gs-coach
GS Shots for Dribbble gs-dribbble-portfolio
Gulri Slider gulri-slider
Hero Mega Menu - Responsive WordPress Menu Plugin hmenu
Hestia Nginx Cache hestia-nginx-cache
Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce
Highlight Sitewide Notice, Text, Button Menu highlight
HTML Forms – Simple WordPress Forms Plugin html-forms
Image Hover Effects for Elementor image-hover-effects-elementor-addon
Image Mapper image-mapper
Inline Footnotes inline-footnotes
Interactive UK Map interactive-uk-map
JobBoard Job listing plugin job-board-light
JSP Store Locator jsp-store-locator
Just Writing Statistics just-writing-statistics
Kikx Simple Post Author Filter sa-post-author-filter
Kintpv Wooconnect kintpv-connect
kk Star Ratings – Rate Post & Collect User Feedbacks kk-star-ratings
LaTeX2HTML latex2html
Leads CRM for WordPress WooCommerce leads-crm
Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS sikshya
Ledenbeheer ledenbeheer-external-connection
Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes lifterlms
Loan Comparison loan-comparison
Locatoraid Store Locator locatoraid
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid magazine-blocks
MagicPost – WordPress文章管理功能增强插件 magicpost
Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation
Mang Board WP mangboard
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution marketking-multivendor-marketplace-for-woocommerce
MashShare – Social Media Share Buttons, Social Share Icons mashsharer
Media Library Assistant media-library-assistant
Member Directory and Contact Form pta-member-directory
Memberful – Membership Plugin memberful-wp
Migration, Backup, Staging – WPvivid Backup & Migration wpvivid-backuprestore
Move Addons for Elementor move-addons
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar mp3-music-player-by-sonaar
Multi-column Tag Map multi-column-tag-map
Multiple Shipping And Billing Address For Woocommerce different-shipping-and-billing-address-for-woocommerce
NACC WordPress Plugin nacc-wordpress-plugin
NAVER Analytics naver-analytics
NEX-Forms – Ultimate Form Builder – Contact forms and much more nex-forms-express-wp-form-builder
Nexter Blocks – WordPress Gutenberg Blocks & 1000+ Starter Templates the-plus-addons-for-block-editor
Ninja Forms – The Contact Form Builder That Grows With You ninja-forms
NinjaTeam Chat for Telegram ninjateam-telegram
Notify Odoo notify-odoo
odPhotogalleryPlugin od-photogallery-plugin
One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Upsell & Cross Sell Offers that Boost Sales & Increase Profits with Sales Funnel Builder woo-one-click-upsell-funnel
One to one user Chat by WPGuppy wpguppy-lite
Optio Dentistry optio-dentistry
Outdooractive Embed outdooractive-embed
Page and Post Restriction page-and-post-restriction
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction paid-member-subscriptions
Particle Background particle-background
Partners partners
PCRecruiter Extensions pcrecruiter-extensions
Peter’s Custom Anti-Spam peters-custom-anti-spam-image
Philantro – Donations and Donor Management philantro
Photo Gallery Slideshow & Masonry Tiled Gallery wp-responsive-photo-gallery
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons contest-gallery
Pingmeter Uptime Monitoring pingmeter-uptime-monitoring
Piotnet Addons For Elementor piotnet-addons-for-elementor
PKT1 Centro de envios pkt1-centro-de-envios
PlainInventory – Inventory Management Plugin z-inventory-manager
PlugVersions – Easily rollback to previous versions of your plugins plugversions
Portfolio – Filterable Masonry Portfolio Gallery for Professionals portfolio-pro
Post Grid Elementor Addon post-grid-elementor-addon
Post/Page Copying Tool to Export and Import post/page for Cross site Migration postpage-import-export-with-custom-fields-taxonomies
PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder
PPWP – Password Protect Pages password-protect-page
Preloader by WordPress Monsters preloader-sws
Premium Addons for Elementor premium-addons-for-elementor
Premium Blocks – Gutenberg Blocks for WordPress premium-blocks-for-gutenberg
Pretty Simple Popup Builder pretty-simple-popup-builder
Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages wplegalpages
ProductDyno productdyno
Project Showcase – A WordPress Plugin to Display Projects in Various Layouts gs-projects
Pronamic Google Maps pronamic-google-maps
Reactflow Visitor Recording and Heatmaps reactflow-session-replay-heatmap
real.Kit real-kit
Responsive Blocks – WordPress Gutenberg Blocks responsive-block-editor-addons
Royal Elementor Addons and Templates royal-elementor-addons
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions s2member
SaasPricing – Pricing Table, Price list, Comparison Table for Elementor saaspricing
Saoshyant Element saoshyant-element
ScanCircle scancircle
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more scratch-win-giveaways-for-website-facebook
SearchIQ – The Search Solution searchiq
SendSMS sendsms
Seraphinite Accelerator seraphinite-accelerator
Seraphinite Accelerator (Full, premium) seraphinite-accelerator-ext
Services updates for customers service-updates-for-customers
ShMapper by Teplitsa shmapper-by-teplitsa
ShopElement shopelement
Shortcodes and extra features for Phlox theme auxin-elements
Simple Dashboard simple-dashboard
Simple Page Access Restriction simple-page-access-restriction
Simple Proxy simple-proxy
Sinking Dropdowns WordPress sinking-dropdowns
Slope Widgets slope-widgets
Smart Shopify Product smart-shopify-product
SMS for WooCommerce wc-sms
SMSA Shipping (official) smsa-shipping-official
Spoki – Chat Buttons and WooCommerce Notifications spoki
Spotlightr spotlightr
SSL Wireless SMS Notification ssl-wireless-sms-notification
Standard Box Sizes – for WooCommerce standard-box-sizes
Stop Registration Spam stop-registration-spam
Store Locator for WordPress with Google Maps – LotsOfLocales store-locator
Super Backup & Clone - Migrate for WordPress indeed-wp-superbackup
SvegliaT Buttons svegliat-buttons
SyncFields syncfields
Tabs Shortcode tabs-shortcode
Taeggie Feed taeggie-feed
Target Notifications target-notifications
Taskbuilder – WordPress Project & Task Management plugin taskbuilder
Text Prompter – Unlimited chatgpt text prompts for openai tasks ai-content
Themify Audio Dock themify-audio-dock
Themify Builder themify-builder
TicketSource Ticket Shop ticketsource-events
Tidy Up tidy-up
Top Comments top-comments
Tour Master - Tour Booking, Travel, Hotel tourmaster
Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking tourfic
TPG Get Posts tpg-get-posts
Tracking Code Manager tracking-code-manager
Turnkey bbPress by WeaverTheme weaver-for-bbpress
Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) header-footer-elementor
Ultimate Learning Pro indeed-learning-pro
UpdraftPlus: WP Backup & Migration Plugin updraftplus
Upload Scanner upload-scanner
User Referral ( Free ) – Points, Rewards, Loyalty, Leader Board & Referrals Plugin user-referral-free
User Role Editor user-role-editor
UserPro - Community and User Profile WordPress Plugin userpro
userpro-messaging userpro-messaging
VibeBP vibebp
Video Share VOD – Turnkey Video Site Builder Script video-share-vod
VRPConnector vrpconnector
Wayne Audio Player wayne-audio-player
WC Price History wc-price-history
Widget Options – The #1 WordPress Widget & Block Control Plugin widget-options
Wishlist for WooCommerce: Multi Wishlists Per Customer wish-list-for-woocommerce
Wizhi Multi Filters by Wenprise wizhi-multi-filters
WooCommerce - PDF Vouchers woocommerce-pdf-vouchers
WooCommerce Additional Fees On Checkout (Free) woo-additional-fees-on-checkout-wordpress
WooCommerce Point of Sale woo-point-of-sale
WordPress Auction Plugin wp-auctions
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg groundhogg
WordPress Popular Posts wordpress-popular-posts
WordPress Simple Shopping Cart wordpress-simple-paypal-shopping-cart
Wp advertising management advertising-management
WP All Import Pro wp-all-import-pro
WP BASE Booking of Appointments, Services and Events wp-base-booking-of-appointments-services-and-events
WP Compress – Instant Performance & Speed Optimization wp-compress-image-optimizer
WP Data Access – App, Table, Form and Chart Builder plugin wp-data-access
WP Datepicker wp-datepicker
WP Docs wp-docs
WP eCommerce Quickpay wp-ecommerce-quickpay
WP Job Portal – A Complete Recruitment System for Company or Job Board website wp-job-portal
WP jQuery DataTable wp-jquery-datatable
WP Menu Image wp-menu-image
WP Multi Store Locator wp-multi-store-locator
WP Nice Loader wp-nice-loader
WP on AWS wp-migrate-2-aws
WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder wp-post-author
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts wedevs-project-manager
WP SecureSubmit securesubmit
WP SHAPES wp-shapes
WP Simple Sitemap wp-simple-sitemap
WP Smart Import : Import any XML File to WordPress wp-smart-import
WP Social AutoConnect wp-fb-autoconnect
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor wte-elementor-widgets
WP-Appbox wp-appbox
WPAchievements Free wpachievements-free
WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor
WPC Shop as a Customer for WooCommerce wpc-shop-as-customer
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More wpforms-lite
WPKoi Templates for Elementor wpkoi-templates-for-elementor
wplms-plugin wplms-plugin
WPMasterToolKit (WPMTK) – All in one plugin wpmastertoolkit
WPMozo Addons Lite for Elementor wpmozo-addons-lite-for-elementor
wpSOL wpsol
WPSSO Core – Complete and Optimized Structured Data SEO wpsso
Wtyczka SeoPilot dla WP wtyczka-seopilot-dla-wp
استخراج محصولات ووکامرس برای آیسی isee-products-extractor
워드프레스 결제 심플페이 – 우커머스 결제 플러그인 pgall-for-woocommerce


WordPress Themes with Reported Vulnerabilities Last Week

Software Name Software Slug
AdForest adforest
Barter barter
Digi Store digi-store
Education LMS education-lms
KLEO - Community Focused & Multi-Purpose BuddyPress WordPress Theme kleo
NewsDaily newsdaily
Olivia olivia
Store Commerce store-commerce
Travel Booking WordPress Theme traveler
VW Automobile Lite vw-automobile-lite
WPLMS Learning Management System for WordPress, WordPress LMS wplms


Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-22364
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
ACH Invoicing Plugin
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-11349
Patch Status
Patched
Published
Dec 20, 2024
Affected Software
AdForest
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-11350
Patch Status
Patched
Published
Dec 20, 2024
Affected Software
AdForest
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
Unknown
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Agency Toolkit
Researcher(s): Unknown
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56205
Patch Status
Unpatched
Published
Dec 18, 2024
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-49688
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-12287
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Biagiotti Membership
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56061
Patch Status
Patched
Published
Dec 18, 2024
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-51919
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Fancy Product Designer
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-43243
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
JobBoard Job listing plugin
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56283
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Locatoraid Store Locator
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56059
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Partners
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56291
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2025-22311
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
userpro-messaging
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56071
Patch Status
Unpatched
Published
Dec 18, 2024
Affected Software
Simple Dashboard
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56220
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
SSL Wireless SMS Notification
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-12571
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56214
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56040
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
VibeBP
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56058
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
VRPConnector
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-11281
Patch Status
Patched
Published
Dec 24, 2024
Affected Software
WooCommerce Point of Sale
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56064
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-49222
Patch Status
Patched
Published
Jan 3, 2025
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56046
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-56043
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-49644
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Accessibility by AllAccessible
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-49699
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-10932
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Backup Migration
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-12259
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-12771
Patch Status
Patched
Published
Dec 20, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56213
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56204
Patch Status
Unpatched
Published
Dec 18, 2024
Affected Software
Sinking Dropdowns WordPress
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-12066
Patch Status
Unpatched
Published
Dec 20, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56216
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Themify Builder
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-10957
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-12293
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
User Role Editor
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56203
Patch Status
Unpatched
Published
Dec 18, 2024
Affected Software
Wayne Audio Player
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56068
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56280
Patch Status
Patched
Published
Jan 3, 2025
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56051
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56057
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56054
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56052
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56050
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56048
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-56282
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
High (8.2)
CVE-ID
CVE-2024-56267
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Interactive UK Map
Researcher
CVSS Rating
High (8.2)
CVE-ID
CVE-2024-56045
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (8.1)
CVE-ID
CVE-2024-12432
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (7.6)
CVE-ID
CVE-2024-9624
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
WP All Import Pro
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-49655
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-12025
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Collapsing Categories
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-51818
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Fancy Product Designer
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-56290
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-56284
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
SSL Wireless SMS Notification
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-11912
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Travel Booking WordPress Theme
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-56039
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
VibeBP
Researcher
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-12428
Patch Status
Patched
Published
Dec 24, 2024
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-56067
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
High (7.5)
CVE-ID
CVE-2024-56042
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
wplms-plugin
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2024-11740
Patch Status
Patched
Published
Dec 18, 2024
Affected Software
Download Manager
Researcher
CVSS Rating
High (7.3)
CVE-ID
CVE-2024-11977
Patch Status
Patched
Published
Dec 20, 2024
CVSS Rating
High (7.3)
CVE-ID
CVE-2024-11733
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
WordPress Popular Posts
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-56264
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
ACF City Selector
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-56286
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-12721
Patch Status
Patched
Published
Dec 20, 2024
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-56233
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Kintpv Wooconnect
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-11356
Patch Status
Patched
Published
Dec 16, 2024
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-56249
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
High (7.1)
CVE-ID
CVE-2024-56055
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
High (7.1)
CVE-ID
CVE-2024-56049
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-12031
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Advanced Floating Content
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-49666
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-10856
Patch Status
Patched
Published
Dec 23, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2025-22348
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
DynamicTags
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-12266
Patch Status
Patched
Published
Dec 23, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-49303
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-49333
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-11267
Patch Status
Unpatched
Published
Dec 27, 2024
Affected Software
JSP Store Locator
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-11926
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Travel Booking WordPress Theme
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-56212
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-56041
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
VibeBP
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-12635
Patch Status
Patched
Published
Dec 20, 2024
Affected Software
WP Docs
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-56053
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-56047
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11905
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
Animated Counters
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56242
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Arconix Shortcodes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56274
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Astra Widgets
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-54346
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Barter
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56021
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Category Post Shortcode
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11878
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Category Post Slider
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56257
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56279
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Compact WP Audio Player
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12513
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Contests by Rewards Fuel
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56302
Patch Status
Patched
Published
Dec 30, 2024
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56235
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Coupon Plugin
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22354
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Digi Store
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11881
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Easy Waveform Player
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22334
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Education LMS
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22321
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12509
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Embed Twine
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22365
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
EMC2 Alert Boxes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56252
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56275
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22327
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11783
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Financial Calculator
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11357
Patch Status
Patched
Published
Jan 2, 2025
Affected Software
Goodlayers Core
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56262
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
GS Coaches
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56263
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
GS Shots for Dribbble
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22323
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56019
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Inline Footnotes
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56224
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Ledenbeheer
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12814
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Loan Comparison
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12591
Patch Status
Patched
Published
Dec 20, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56254
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11196
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
Multi-column Tag Map
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12506
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
NACC WordPress Plugin
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56208
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
NewsDaily
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11885
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
NinjaTeam Chat for Telegram
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12507
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Optio Dentistry
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11774
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Outdooractive Embed
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11775
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Particle Background
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11776
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
PCRecruiter Extensions
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12500
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22333
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Piotnet Addons For Elementor
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56268
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Post Grid Elementor Addon
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56261
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56240
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Pronamic Google Maps
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12697
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
real.Kit
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12268
Patch Status
Patched
Published
Dec 23, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56062
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56231
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11439
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
ScanCircle
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11784
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
TicketSource Ticket Shop
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12518
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
ShMapper by Teplitsa
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56260
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
ShopElement
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11902
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
Slope Widgets
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11411
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Spotlightr
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22339
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Store Commerce
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56020
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
SvegliaT Buttons
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11606
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Tabs Shortcode
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11748
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Taeggie Feed
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56239
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Themify Audio Dock
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-11906
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
TPG Get Posts
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-8721
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Tracking Code Manager
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12449
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12622
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
WordPress Simple Shopping Cart
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56287
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
WP jQuery DataTable
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-12475
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
WP Multi Store Locator
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-9619
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
WP SHAPES
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2025-22362
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
WPAchievements Free
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56285
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56241
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-56221
Patch Status
Patched
Published
Dec 19, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56030
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
10CentMail
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22326
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56025
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12454
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11254
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22325
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Autocompleter
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12100
Patch Status
Patched
Published
Dec 23, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56018
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22353
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
BVD Easy Gallery Manager
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12587
Patch Status
Unpatched
Published
Dec 20, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56024
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Custom Dashboard Widget
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56029
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11287
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
Ebook Store
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12262
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
Ebook Store
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12405
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Export Customers Data
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56033
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
FAQs
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11811
Patch Status
Patched
Published
Dec 20, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56032
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
FV Descriptions
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11682
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
G Web Pro Store Locator
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56289
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56223
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Gulri Slider
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56060
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56016
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
Image Mapper
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11331
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22355
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56209
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11688
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
LaTeX2HTML
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56027
Patch Status
Unpatched
Published
Dec 17, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56028
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56296
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Mang Board WP
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11974
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Media Library Assistant
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-51700
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
NAVER Analytics
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56299
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Notify Odoo
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56036
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56014
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
Olivia
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11808
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
Pingmeter Uptime Monitoring
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11806
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
PKT1 Centro de envios
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12239
Patch Status
Patched
Published
Dec 16, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56022
Patch Status
Unpatched
Published
Dec 17, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22320
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
ProductDyno
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11975
Patch Status
Unpatched
Published
Dec 20, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56226
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-51646
Patch Status
Unpatched
Published
Dec 16, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56038
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
SendSMS
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56034
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56026
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Simple Proxy
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12220
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
SMS for WooCommerce
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12219
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
Stop Registration Spam
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22359
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
SyncFields
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22357
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12221
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Turnkey bbPress by WeaverTheme
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56035
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Upload Scanner
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56037
Patch Status
Unpatched
Published
Dec 17, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56210
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56228
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22336
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12395
Patch Status
Patched
Published
Dec 16, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56265
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
WooCommerce - PDF Vouchers
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22358
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Wp advertising management
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12469
Patch Status
Patched
Published
Dec 16, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12468
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
WP Datepicker
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56023
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
WP eCommerce Quickpay
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12408
Patch Status
Patched
Published
Dec 20, 2024
Affected Software
WP on AWS
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22342
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
WP Simple Sitemap
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12701
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12279
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
WP Social AutoConnect
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-56069
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-12710
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
WP-Appbox
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2025-22343
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
wpSOL
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-11812
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
Wtyczka SeoPilot dla WP
Researcher
CVSS Rating
Medium (5.9)
CVE-ID
CVE-2024-11722
Patch Status
Patched
Published
Dec 20, 2024
Affected Software
Frontend Admin by DynamiApps
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-12121
Patch Status
Patched
Published
Dec 18, 2024
Affected Software
Broken Link Checker | Finder
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-10584
Patch Status
Patched
Published
Dec 23, 2024
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-12554
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Peter’s Custom Anti-Spam
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-12617
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
WC Price History
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-56232
Patch Status
Unpatched
Published
Dec 19, 2024
Affected Software
WP Nice Loader
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-12250
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-12034
Patch Status
Patched
Published
Dec 23, 2024
Affected Software
Advanced Google reCAPTCHA
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-22363
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-12601
Patch Status
Patched
Published
Dec 16, 2024
Affected Software
Calculated Fields Form
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11768
Patch Status
Patched
Published
Dec 18, 2024
Affected Software
Download Manager
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56238
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Floating Action Buttons
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56236
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Hestia Nginx Cache
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-12413
Patch Status
Patched
Published
Dec 24, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11294
Patch Status
Patched
Published
Dec 16, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56300
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11280
Patch Status
Patched
Published
Dec 16, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-11295
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Simple Page Access Restriction
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2025-22318
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-52485
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
WP Menu Image
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56270
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
WP SecureSubmit
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56044
Patch Status
Patched
Published
Dec 17, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-56273
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-22351
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-56250
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Just Writing Statistics
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-10862
Patch Status
Unpatched
Published
Dec 24, 2024
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-22350
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Ultimate Learning Pro
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2025-22349
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
WordPress Auction Plugin
Researcher
CVSS Rating
Medium (4.9)
CVE-ID
CVE-2024-56248
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56293
Patch Status
Patched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56292
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Email Reminders
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56256
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Embed PDF Viewer
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56297
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56298
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
Pretty Simple Popup Builder
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-12874
Patch Status
Unpatched
Published
Jan 2, 2025
Affected Software
Top Comments
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-56288
Patch Status
Patched
Published
Jan 3, 2025
Affected Software
WP Docs
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56244
Patch Status
Patched
Published
Dec 30, 2024
Affected Software
Ashe Extra
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12335
Patch Status
Patched
Published
Dec 24, 2024
Affected Software
Avada (Fusion) Builder
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56255
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-22347
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
BSK Forms Blacklist
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56222
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
CodeBard Help Desk
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56218
Patch Status
Patched
Published
Dec 19, 2024
Researcher(s): Unknown
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56276
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56253
Patch Status
Patched
Published
Dec 30, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56217
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Download Manager
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56207
Patch Status
Unpatched
Published
Dec 18, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-10356
Patch Status
Patched
Published
Dec 16, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-22328
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
Elevio
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56251
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12061
Patch Status
Patched
Published
Dec 17, 2024
Affected Software
Events Addon for Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-10797
Patch Status
Unpatched
Published
Dec 20, 2024
Affected Software
Full Screen Menu for Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56206
Patch Status
Unpatched
Published
Dec 18, 2024
Affected Software
gap-hub-user-role.
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56272
Patch Status
Unpatched
Published
Jan 3, 2025
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-12301
Patch Status
Unpatched
Published
Dec 27, 2024
Affected Software
JSP Store Locator
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-9503
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56215
Patch Status
Patched
Published
Dec 19, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56294
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56225
Patch Status
Patched
Published
Dec 19, 2024
Affected Software
Premium Addons for Elementor
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56227
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56229
Patch Status
Patched
Published
Dec 19, 2024
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-54222
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56031
Patch Status
Unpatched
Published
Dec 17, 2024
Affected Software
Smart Shopify Product
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2025-22319
Patch Status
Unpatched
Published
Jan 3, 2025
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56015
Patch Status
Unpatched
Published
Dec 16, 2024
Affected Software
Tidy Up
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56211
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56234
Patch Status
Unpatched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56219
Patch Status
Patched
Published
Dec 19, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56271
Patch Status
Unpatched
Published
Jan 3, 2025
Affected Software
WP SecureSubmit
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56070
Patch Status
Patched
Published
Dec 18, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-56243
Patch Status
Patched
Published
Dec 30, 2024
CVSS Rating
Medium (4.1)
CVE-ID
CVE-2024-56278
Patch Status
Patched
Published
Jan 3, 2025
CVSS Rating
Low (3.7)
CVE-ID
CVE-2024-9654
Patch Status
Patched
Published
Dec 16, 2024


As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

Did you enjoy this post? Share it!

Comments

No Comments

All comments are moderated before being published. Inappropriate or off-topic comments may not be approved.