Wordfence Intelligence Weekly WordPress Vulnerability Report (January 13, 2025 to January 19, 2025)
📢 Did you know Wordfence runs a Bug Bounty Program for all WordPress plugins and themes at no cost to vendors? Researchers can earn up to $31,200 per vulnerability, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.
Last week, there were 694 vulnerabilities disclosed in 655 WordPress Plugins and 18 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 80 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 22,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- Adifier System <= 3.1.7 – Unauthenticated Arbitrary Password Reset
- WAF-RULE-794 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-795 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-796 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-798 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-799 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-800 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-801 – Data redacted while we work with the vendor on a patch.
- WAF-RULE-802 – Data redacted while we work with the vendor on a patch.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
---|---|
Patched | 121 |
Unpatched | 573 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
---|---|
Low Severity | 2 |
Medium Severity | 640 |
High Severity | 43 |
Critical Severity | 9 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
---|---|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 455 |
Cross-Site Request Forgery (CSRF) | 121 |
Missing Authorization | 55 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | 20 |
Unrestricted Upload of File with Dangerous Type | 9 |
Exposure of Sensitive Information to an Unauthorized Actor | 7 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | 7 |
Incorrect Privilege Assignment | 4 |
Deserialization of Untrusted Data | 3 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 3 |
Exposure of Private Personal Information to an Unauthorized Actor | 2 |
Authorization Bypass Through User-Controlled Key | 1 |
Dependency on Vulnerable Third-Party Component | 1 |
Files or Directories Accessible to External Parties | 1 |
Improper Access Control | 1 |
Improper Authentication | 1 |
Improper Control of Generation of Code ('Code Injection') | 1 |
Improper Privilege Management | 1 |
Unverified Password Change | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
---|---|
221 | |
157 | |
60 | |
42 | |
38 | |
13 | |
13 | |
13 | |
9 | |
7 | |
7 | |
4 | |
4 | |
4 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
"Visit Site" Link enhanced – WordPress PlugIn | visit-site-link-enhanced |
.TUBE Video Curator | tube-video-curator |
301 SEO REDIRECTION | COUNTRY BASED REDIRECTION [ REDIRECTION PLUS ] | redirection-plus |
a Gateway for Pasargad Bank on WooCommerce | a-gateway-for-pasargad-bank-on-woocommerce |
Accessibility Task Manager | accessibility-task-manager |
Ad Blocking Detector | ad-blocking-detector |
Add custom content after post | add-custom-content-after-post |
add custom google tag manager | add-custom-google-tag-manager |
Add RSS | add-rss |
Adifier System | adifier-system |
Admin and Customer Messages After Order for WooCommerce: OrderConvo | admin-and-client-message-after-order-for-woocommerce |
Admin Cleanup | admin-cleanup |
Admin Menu Organizer | admin-menu-organizer |
Admin Options Pages | admin-options-pages |
AdsMiddle | adsmiddle |
Advanced Angular Contact Form | advanced-angular-contact-form |
Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin | file-manager-advanced |
Affiliate Tools Việt Nam | affiliate-tools-viet-nam |
Age Verification for your checkout page. Verify your customer's identity | agecheckernet |
AI Responsive Gallery Album | ai-responsive-gallery-album |
Ajax Contact Form | fws-ajax-contact-form |
Ajax WP Query Search Filter | ajax-wp-query-search-filter |
all-in-one-box-login | all-in-one-login |
AlT Report | alt-report |
Altima Lookbook Free for WooCommerce | altima-lookbook-free-for-woocommerce |
Amber | amberlink |
amr personalise | amr-personalise |
Annie | annie |
Anonymize Links | anonymize-links |
ApplicantPro | applicantpro |
Apply with LinkedIn buttons | apply-with-linkedin-buttons |
ApplyOnline – Application Form Builder and Manager | apply-online |
Attach Gallery Posts | attach-gallery-posts |
Auphonic Importer | auphonic-importer |
Auto FTP | auto-ftp |
AW WooCommerce Kode Pembayaran | aw-woocommerce-kode-pembayaran |
Awesome Hooks | awesome-hooks |
Awesome Responsive Photo Gallery – Image & Video Lightbox Gallery | awesome-responsive-photo-gallery |
Awesome Twitter Feeds | awesome-twitter-feeds |
Awesome WordPress Timeline Plugin | awesome-timeline |
AZ Content Finder | az-content-finder |
azurecurve Floating Featured Image | azurecurve-floating-featured-image |
Background animation blocks | background-animation-blocks |
Background Control | background-control |
Banner Garden Plugin for WordPress | banner-garden |
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) | barcode-scanner-lite-pos-to-manage-products-inventory-and-orders |
Bauernregeln | bauernregeln |
Better Protected Pages | better-protected-pages |
Better WishList API | better-wlm-api |
Bible Embed | bible-embed |
Bit.ly linker | bitly-linker |
BizLibrary | bizlibrary |
Block Collection for You – WP Block Pack | wp-block-pack |
Blog Summary | blog-summary |
Blogger Image Import | blogger-image-import |
Blrt WP Embed | blrt-wp-embed |
blu Logistics | blu-logistics |
Blue Wrench Video Widget | blue-wrench-videos-widget |
Board Election | board-election |
Bold pagos en linea | bold-pagos-en-linea |
bonjour-bar | bonjour-bar |
Book a Place | book-a-place |
Bookalet | bookalet |
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment | booking-and-rental-manager-for-woocommerce |
Brizy Pro | brizy-pro |
Browser-Update-Notify | browser-update-notify |
Build Private Store For Woocommerce | build-private-store-for-woocommerce |
Bulk Categories Assign | bulk-categories-assign |
Button Block – Get fully customizable & multi-functional buttons | button-block |
Cache Sniper for Nginx | snipe-nginx-cache |
Calendi | calendi |
Call To Action Popup | call-to-action-popup |
CAMOO SMS | camoo-sms |
Canalplan | canalplan-ac |
Captchelfie – Captcha by Selfie | captchelfie-captcha-by-selfie |
Car Demon | car-demon |
Catalog Importer, Scraper & Crawler | intelligent-importer |
Catch Duplicate Switcher | catch-duplicate-switcher |
Category Custom Fields | categorycustomfields |
Category D3 Tree | category-d3-tree |
Causes – Donation Plugin | causes |
CBX Accounting & Bookkeeping | cbxwpsimpleaccounting |
CC Circle Progress Bar | cc-circle-progress-bar |
CGD Arrange Terms | shopp-arrange |
Chamber Dashboard Business Directory | chamber-dashboard-business-directory |
Charity-thermometer | charitydonation-thermometer |
ChatGPT Open AI Images & Content for WooCommerce | glasses-for-woocommerce |
Chatter | chatter |
Checkout for PayPal | checkout-for-paypal |
Chess Tempo Viewer | chesstempoviewer |
CJ Custom Content | cj-custom-content |
ClickBank Storefront WordPress Plugin | mycbgenie-clickbank-storefront |
CMC MIGRATE | cmc-migrate |
CNZZ&51LA for WordPress | cnzz51la-for-wordpress |
Cobwebo URL Plugin | cobwebo-url |
CodeBard Help Desk | codebard-help-desk |
CoDesigner – All in One Elementor WooCommerce Builder | woolementor |
Comment-Emailer | comment-emailer |
Compare Ninja: Create Professional Comparison Tables and Easily Add Them to Your Website | compare-ninja-comparison-tables |
ComparePress | comparepress |
Contact Form 7 Anti Spambot | contact-form-7-anti-spambot |
Contact Form 7 Redirect & Thank You Page | cf7-redirect-thank-you-page |
Contact Form 7 Round Robin Lead Distribution | contact-form-7-round-robin-lead-distribution |
Contact Form 7 – CCAvenue Add-on | cf7-cc-avenue-add-on |
Contact Form 7 – Paystack Add-on | cf7-paystack-add-on |
Contact Form With Shortcode | contact-form-with-shortcode |
Content Mirror | content-mirror |
Content Planner | content-planner |
Content Security Policy Pro | content-security-policy-pro |
ContentOptin Lite – WP Content Upgrade Plugin | contentoptin |
Contexto | contexto |
Cookie Consent & Autoblock for GDPR/CCPA | cookie-consent-autoblock |
Copy Move Posts | copy-move-posts |
Copyright Safeguard Footer Notice | copyright-safeguard-footer-notice |
Coronavirus (COVID-19) Outbreak Data Widgets | coronavirus-data-widgets |
Course Booking System | course-booking-system |
CRUDLab Like Box | crudlab-facebook-like-box |
CtyGrid Hyp3rL0cal Search WordPress Plugin | hyp3rl0cal-city-search |
CubePM | cubepm |
Curated Search | curated-search |
Custom Coming Soon | custom-coming-soon |
Custom CSS Addons | css-addons |
Custom List Table Example | custom-list-table-example |
Custom Page Extensions | custom-page-extensions |
Custom Post | custom-post-type-gui |
Custom Post Type Lockdown WordPress | custom-post-type-lockdown |
Custom Widget Classes | custom-widget-classes |
Custom Widget Creator | custom-widget-creator |
Custom WP Store Locator | custom-store-locator |
Customizable Captcha and Contact us | customizable-captcha-and-contact-us-form |
Cyber Slider | cyber-new-slider |
Daily Proverb | daily-proverb |
Data Dash | data-dash |
Database Sync | database-sync |
DD Roles | dd-roles |
Debt Calculator | debt-calculator |
Debug Tool | debug-tool |
Demo User DZS – Showcase your admin safely | demo-user-dzs-showcase-your-admin-safely |
Dezdy | dezdy-mcommerce |
DF Draggable | df-draggable |
dForms | dforms |
DN Sitemap Control | dn-sitemap-control |
Donate visa | donate-visa |
Download Manager | download-manager |
Download, Downloads – WordPress Download plugin By Edmon | ydn-download |
DsgnWrks Twitter Importer | dsgnwrks-twitter-importer |
DX Sales CRM | dx-sales-crm |
DZS Ajaxer Lite – Ajaxify Your WordPress Site and Comments | dzs-ajaxer-lite-dynamic-page-load |
Easy Automatic Newsletter Lite | easy-automatic-newsletter |
Easy Bet | easy-bet |
Easy Code Placement | easy-code-placement |
Easy Code Snippets | easy-code-snippets |
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | easy-digital-downloads |
Easy EU Cookie law | easy-eu-cookie-law |
Easy FAQs | easy-faqs |
Easy Filter | easy-filter |
Easy Filtering | easy-filtering |
Easy Portfolio | easy-portfolio |
Easy School Registration | easy-school-registration |
Easy Shortcode Buttons | easy-shortcode-buttons |
Easy Tweet Embed | easy-tweet-embed |
Easy Tynt | easy-tynt |
ECT Add to Cart Button | ect-add-to-cart-button |
EditionGuard for WooCommerce – eBook Sales with DRM | editionguard-for-woocommerce-ebook-sales-with-drm |
EELV Newsletter | eelv-newsletter |
ElementInvader Addons for Elementor | elementinvader-addons-for-elementor |
Elementor Addon Elements | addon-elements-for-elementor-page-builder |
Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements | ai-addons-for-elementor |
Email Capture & Lead Generation | email-capture-lead-generation |
Email on Publish | email-on-publish |
Email to Download | email-to-download |
EmailPress | emailpress |
EmailShroud | emailshroud |
EMI Calculator | emi-calculator |
Enhanced YouTube Shortcode | enhanced-youtube-shortcode |
Envato Affiliater | envato-affiliater |
ePermissions | epermissions |
Error Notification | error-notification |
Essay Wizard (wpCRES) | essay-wizard-wpcres |
Essential WP Real Estate | essential-wp-real-estate |
EU DSGVO Helper | dsgvo |
Event Countdown Timer Plugin by TechMix | event-countdown-timer |
Event Monster – Event Management, Tickets Booking, Upcoming Event | event-monster |
Event Registration Calendar By vcita | event-registration-calendar-by-vcita |
Eventer - WordPress Event & Booking Manager Plugin | eventer |
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress | everest-forms |
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media | evergreen-content-poster |
Explara Membership | explara-membership |
Explore pages | explore-pages |
Extra Options – Favicons | extra-options-favicons |
EZPlayer | ezplayer |
Fast Tube | fast-tube |
FAT Event Lite | fat-event-lite |
Feedburner Optin Form | feedburner-optin-form |
Find Content IDs | find-content-ids |
Find Your Reps | find-your-reps |
First Comment Redirect | first-comment-redirect |
Flexible Blogtitle | flexible-blogtitle |
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce | flexible-coupons |
Flexo Slider | flexo-slider |
Floatbox Plus | floatbox-plus |
FLX Dashboard Groups | flx-dashboard-groups |
Flying Twitter Birds | flying-twitter-birds |
FontAwesome.io ShortCodes | fontawesomeio-shortcodes |
FooGallery Captions | foogallery-captions |
Form To JSON | form-to-json |
Form To Online Booking | cf7-calendly-integration |
Formatted post | formatted-post |
Foundation Columns | foundation-columns |
FP RSS Category Excluder | fp-rss-category-excluder |
Free MailClient FMC | mailclient |
FWD Slider | fwd-slider |
G Web Pro Store Locator | gwebpro-store-locator |
Gallerio | gallerio |
Gallery and Lightbox | gallery-and-lightbox |
Gallery: Hybrid – Advanced Visual Gallery | hybrid-gallery |
GDPR Personal Data Reports | gdpr-personal-data-reports |
GDReseller | gdreseller |
Genki Announcement | genki-announcement |
GeoDigs | geodigs |
Geotagged Media | geotagged-media |
Giga Messenger – Express | giga-messenger-bots |
Gigaom Sphinx | go-sphinx |
Giveaways and Contests by PromoSimple | giveaways-contests-by-promosimple |
Glofox Shortcodes | glofox-shortcodes |
Glossy | glossy |
GMap Shortcode | gmap-shortcode |
GMAPS for WPBakery Page Builder Free | gmaps-for-visual-composer-free |
go Social | go-social |
Goldstar | goldstar |
Goo.gl Url Shorter | googl-url-shorter |
Good Old Gallery | good-old-gallery |
Goodlayers Blocks | goodlayers-blocks |
Google Map on Post/Page | google-map-on-postpage |
Google Map With Fancybox | location-piker |
Google Org Chart | google-org-chart |
Google Transliteration | google-transliteration |
GoogleMapper | googlemapper-2 |
GravatarLocalCache | gravatarlocalcache |
Gravity Forms | gravityforms |
Greek Namedays Widget From Eortologio.Net | greek-namedays-widget |
Group category creator | group-category-creator |
GSheetConnector for Forminator Forms | gsheetconnector-forminator |
Guten Free Options | guten-free-options |
Hack me if you can | hack-me-if-you-can |
Heartland Management Terminal | heartland-management-terminal |
HireHive Job Plugin | zartis-job-plugin |
History timeline | history-timeline |
HM Portfolio | hm-portfolio |
Homey Login Register | homey-login-register |
Horizontal Line Shortcode | horizontal-line-shortcode |
Hotspots Analytics | hotspots |
HSS Embed Streaming Video | hss-embed-streaming-video |
Htaccess File Editor – Easily Edit, Backup, Restore .htaccess file | htaccess-file-editor |
HTML5 Video Player – mp4 Video Player Plugin and Block | html5-video-player |
HTTP to HTTPS link changer by Eyga.net | https-links-in-content |
HyperComments | comments-with-hypercommentscom |
iBuildApp | ibuildapp |
Image Gallery Box by CRUDLab | image-gallery-box-by-crudlab |
Image Source Control Lite – Show Image Credits and Captions | image-source-control-isc |
Image Switcher | image-switcher |
ImageMeta | imagemeta |
imaGenius | imagenius |
Import Users to MailChimp | import-users-to-mailchimp |
Improved Sale Badges – Free Version | improved-sale-badges-free-version |
Incredible Font Awesome | incredible-font-awesome |
InFunding – Plugin for Charity & Crowdfunding Website | infunding |
Instant Appointment | instant-appointment |
Interactive Page Hierarchy | interactive-page-hierarchy |
Internal Links Generator | internal-links-generator |
iSpring Embedder | embed-ispring |
JB Horizontal Scroller News Ticker | jb-horizontal-scroller-news-ticker |
Jet Skinner for BuddyPress | jet-skinner-for-buddypress |
JetEngine | jet-engine |
JSM Screenshot Machine Shortcode | screenshot-machine-shortcode |
JustRows free | justrows-free |
Kapost | kapost-byline |
Killer Theme Options | killer-theme-options |
Kopa Nictitate Toolkit | kopa-nictitate-toolkit |
Ksher | ksher-payment |
Kubio AI Page Builder | kubio |
Kumihimo | kumihimo |
Kv Compose Email From Dashboard | kv-send-email-from-admin |
LawPress – Law Firm Website Management | lawpress |
Legal + | legal-plus |
Legull | legull |
Len Slider | len-slider |
LH Email | lh-email |
LH Login Page | lh-login-page |
Library Instruction Recorder | library-instruction-recorder |
Lijit Search | wp-lijit-wijit |
Lime Developer Login | lime-developer-login |
Links/Problem Reporter | report-broken-links |
Live Dashboard | live-dashboard |
LJ Custom Menu Links | lj-custom-menu-links |
Local Shipping Labels for WooCommerce | local-shipping-labels-for-woocommerce |
LocalGrid | localgrid |
Lockets | lockets |
Login Watchdog | login-watchdog |
Loginplus | loginplus |
LSD Google Maps Embedder | lsd-google-maps-embedder |
LTL Freight Quotes – Worldwide Express Edition | ltl-freight-quotes-worldwide-express-edition |
MACME | macme |
Magic Google Maps | magic-google-maps |
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder | mailchimp-subscribe-sm |
Mancx AskMe Widget | mancx-askme-widget |
Maniac SEO | maniac-seo |
Mapbox for WP Advanced | mapbox-for-wp-advanced |
Mark Posts | mark-posts |
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution | marketking-multivendor-marketplace-for-woocommerce |
Marmoset Viewer | marmoset-viewer |
Marquee Style RSS News Ticker | marquee-style-rss-news-ticker |
Mass Custom Fields Manager | mass-custom-fields-manager |
Mass Messaging in BuddyPress | mass-messaging-in-buddypress |
MD Custom content after or before of post | md-custom-content |
MDC YouTube Downloader | mdc-youtube-downloader |
MDJM Event Management | mobile-dj-manager |
MeinTurnierplan.de Widget Viewer | meinturnierplande-widget-viewer |
melascrivi-plugin | melascrivi |
MemeOne | memeone |
Menus Plus+ | menus-plus |
MercadoLibre Integration | mercadolibre-integration |
Metaphor Widgets | mtphr-widgets |
MFPlugin | mfplugin |
MHR-Custom-Anti-Copy | mhr-custom-anti-copy |
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet | paid-membership |
Mind3doM RyeBread Widgets | mind3dom-ryebread-widgets |
Mindmeister Shortcode | mindmeister-shortcode |
Minterpress | minterpress |
MJ Contact us | mj-contact-us |
MLL Audio Player MP3 Ajax | music-let-loose-mp3-audio-player |
Mobigate | mobigatevn |
Mojo Under Construction | mojo-under-construction |
More Link Modifier | more-link-modifier |
Motors – Car Dealership & Classified Listings Plugin | motors-car-dealership-classified-listings |
Moving Users | moving-users |
Multi Step Form | multi-step-form |
Multi Uploader for Gravity Forms | gf-multi-uploader |
Multilang Contact Form | multilang-contact-form |
Musicbox | musicbox |
My auctions allegro | my-auctions-allegro-free-edition |
My Favorite Car | my-favorite-cars |
My Tickets – Accessible Event Ticketing | my-tickets |
my-related-posts | my-related-posts |
MyAnime Widget | myanime-widget |
mybb Last Topics | mybb-last-topics |
MyBookProgress by Stormhill Media | mybookprogress |
Nativery Plugin | nativery |
Nature FlipBook WordPress Plugin | vertical-diamond-flipbook-flash |
Navigation Du Lapin Blanc | navigation-du-lapin-blanc |
Neon Product Designer | neon-product-designer-for-woocommerce |
Network-Favorites | network-favorites |
Ni WooCommerce Sales Report Email | ni-woocommerce-sales-report-email |
Nite Shortcodes | nite-shortcodes |
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN | nitropack |
NoFollow Free | nofollow-free |
Notifications Center | notifications-center |
Notifikácie.sk | notifikacie-sk |
ntp-header-images | header-images-rotator |
NV Slider | nv-slider |
One Backend Language | one-backend-language |
Online Marksheet Creator : eMarksheet | emarksheet |
Online Payments – Get Paid with PayPal, Square & Stripe | paypal-payment-button-by-vcita |
OPSI Israel Domestic Shipments | woo-ups-pickup |
Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords | muzaara-adwords-optimize-dashboard |
OrangeBox | orangebox |
PAFacile | pafacile |
Page Builder by SiteOrigin | siteorigin-panels |
Page Health-O-Meter | page-health-o-meter |
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | paid-member-subscriptions |
PAPERCITE | papercite |
Partners | partners |
Password Protect Plugin for WordPress | password-protect-plugin-for-wordpress |
Passwordless WP – Login with your glance or fingerprint | passwordless-wp |
Passwords Manager | passwords-manager |
Pastebin | pastebin-embed |
Payment Button for PayPal | wp-paypal |
PayPal Marketing Solutions | paypal-promotions-and-insights |
PDF for WPForms + Drag and Drop Template Builder | pdf-for-wpforms |
PDF.js Shortcode | pdfjs-shortcode |
Photo Video Store | photo-video-store |
Picture Gallery – Frontend Image Uploads, AJAX Photo List | picture-gallery |
Pin Locations on Map | pin-locations-on-map |
Piotnet Addons For Elementor | piotnet-addons-for-elementor |
Pit Login Welcome | pit-login-welcome |
Plestar Directory Listing | plestar-directory-listing |
Podamibe Twilio Private Call | podamibe-twilio-private-call |
Podlove Podcast Publisher | podlove-podcasting-plugin-for-wordpress |
Podčlánková inzerce | podclankova-inzerce |
pootle button | pootle-button |
Popliup – WordPress Popup Plugin | popliup |
Post & Page Notes | post-page-notes |
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | post-and-page-builder |
Post Carousel & Slider | post-types-carousel-slider |
Post Grid By PickPlugins | post-grid |
Post Meta | post-meta |
Post-to-Post Links | easy-post-to-post-links |
Posts Footer Manager | intelly-posts-footer-manager |
Powie's pLinks PagePeeker | plinks |
Predict When | predict-when |
Preloader Quotes | preloader-quotes |
Product Carousel For WooCommerce – WoorouSell | woorousell |
Progress Tracker | progress-tracker |
Proofreading | proofreading |
Ps Ads Pro | ps-ads-pro |
Push Envoy Notifications | push-envoy |
Push Notification for Post and BuddyPress | push-notification-for-post-and-buddypress |
QMean – WordPress Did You Mean and Search Suggestion Like Google | qmean |
QR Code Generator | qrcode-wprhe |
Quick Count | quick-count |
Quote me | quote-me |
quote-posttype-plugin | quote-post-type-plugin |
QuoteMedia Tools | quotemedia-tools |
radSLIDE | radslide |
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings | rate-star-review |
ReadMe Creator | readme-creator |
Real Seguro Viagem | seguro-viagem |
REAL WordPress Sidebar | drag-and-drop-custom-sidebar |
Realty Workstation | realty-workstation |
Realtyna Provisioning | realtyna-provisioning |
Rebrand Fluent Forms | rebrand-fluent-forms |
Recip.ly Plugin | reciply |
Redux Converter | redux-converter |
Related Post Shortcode | related-post-shortcode |
Rename Author Slug | rename-author-slug |
ResAds | resads |
Responsive jQuery Slider | responsive-jquery-slider |
Responsivity | responsivity |
Rezdy Reloaded | reloaded-rezdy |
Rio Photo Gallery | rio-photo-gallery |
rng-refresh | rng-refresh |
Rocket Media Library Mime Type | rocket-media-library-mime-type |
Rollover Tab | rollover-tab |
RomanCart On WordPress | romancart-on-wordpress |
RomethemeKit For Elementor | rometheme-for-elementor |
root Cookie | root-cookie |
Royal Elementor Addons and Templates | royal-elementor-addons |
RS Survey | rs-survey |
RSS Icon Widget | rss-icon-widget |
RSS News Scroller | rss-news-scroller |
RSV GMaps | rsv-google-maps |
RSVP ME | rsvp-me |
RSVPMaker Volunteer Roles | rsvpmaker-volunteer-roles |
S-DEV SEO | s-dev-seo |
Sale with Razorpay | sell-with-razorpay |
Salvador – AI Image Generator | salvador-ai-image-generator |
Sandbox | sandbox |
Save & Import Image from URL | save-import-image-from-url |
SC Simple Zazzle | sc-simple-zazzle |
Scroll Top Advanced – Scroll to ID or Class | scroll-top-advanced |
Scroll Top – WordPress Scroll to Top plugin | scroll-to-top-builder |
Secure CAPTCHA | secure-captcha |
Send to a Friend Addon | send-booking-invites-to-friends |
Send to Twitter | send-to-twitter |
SendGrid for WordPress | wp-sendgrid-mailer |
Sensei LMS – Online Courses, Quizzes, & Learning | sensei-lms |
SEOReseller Partner Plugin | sr-partner |
SetMore Theme – Custom Post Types | service-provider-profile-cpt |
Setup Default Featured Image | setup-default-feature-image |
SexBundle | sexbundle |
Shabbos and Yom Tov | shabbos-and-yom-tov |
Shipdeo | shipdeo-woo |
ShipWorks Connector for Woocommerce | shipworks-e-commerce-bridge |
Shockingly Big IE6 Warning | shockingly-big-ie6-warning |
Shortcode in Comment | shortcode-in-comment |
Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com | shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com |
Sidebar-Content from Shortcode | sidebar-content-from-shortcode |
Simple Custom post type custom field | simple-content-construction-kit |
Simple Membership Custom Messages | simple-membership-custom-messages |
Simple Project Manager | simple-project-managment |
Simple shortcode buttons | simple-shortcode-buttons |
Simple Vertical Timeline | simple-vertical-timeline |
Simple:Press Forum | simplepress |
Singsys -Awesome Gallery | awesome-gallery-singsys |
Site Launcher | site-launcher |
Slider for Writers | slider-for-writers |
Slides & Presentations | slide |
Small Package Quotes – Unishippers Edition | small-package-quotes-unishippers-edition |
Small Package Quotes – Worldwide Express Edition | small-package-quotes-wwe-edition |
Smallerik File Browser | smallerik-file-browser |
Smooth Dynamic Slider | smooth-dynamic-slider |
Snippy | snippy |
Social Analytics | social-analytics |
Social Media Engine | social-media-engine |
Social proof testimonials and reviews by Repuso | social-testimonials-and-reviews-widget |
Social Pug: Author Box | social-pug-author-box |
SOCIAL.NINJA | seo-meta |
Social2Blog | social2blog |
Solidres – Hotel booking plugin for WordPress | solidres |
Spiderpowa Embed PDF | spiderpowa-embed-pdf |
Staging CDN | staging-cdn |
Stars SMTP Mailer | stars-smtp-mailer |
StatPressCN | statpresscn |
Sticky Button – Click to Chat | sticky-chat-button |
Stop Comment Spam | stop-comment-spam |
Store Locator for WordPress with Google Maps – LotsOfLocales | store-locator |
Stray Random Quotes | stray-quotes |
Stripe and PayPal Payment Forms for WordPress – PayForm | payform |
Strx Magic Floating Sidebar Maker | strx-magic-floating-sidebar-maker |
Style Admin | style-admin |
Sur.ly | surly |
Swift Calendar Online Appointment Scheduling | online-appointment-scheduling-software |
Tab My Content | tab-my-content |
Tag Groups is the Advanced Way to Display Your Taxonomy Terms | tag-groups |
Tagesteller / Mittagsmenü Plugin | tagesteller |
Taskbuilder – WordPress Project & Task Management plugin | taskbuilder |
Tax Report for WooCommerce | tax-report-for-woocommerce |
Team 118GROUP Agent | team-118group-agent |
Texteller | texteller |
The Loops | the-loops |
The Ultimate WordPress Toolkit – WP Extended | wpextended |
Theme My Ontraport Smartform | theme-my-ontraport-smartform |
Tidy.ro | tidyro |
TinyMCE Extended Config | tinymce-extended-config |
Top Flash Embed | top-flash-embed |
TransFinanz | transfinanz |
Translation.Pro | translation-pro |
turboSMTP | turbosmtp |
Twitter Bootstrap Collapse aka Accordian Shortcode | twitter-bootstrap-collapse-aka-accordian-shortcode |
Twitter News Feed | twitter-news-feed |
Twitter Post | twitterpost |
Twitter Shortcode | twitter-shortcode |
Ui Slider Filter By Price | ui-slider-filter-by-price |
Ultimate Events | ultimate-events |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | ultimate-member |
Ultimate Subscribe | ultimate-subscribe |
Unique UX | unique-ux |
Universal Analytics Injector | universal-analytics-injector |
University quizzes online | university-quizzes-online |
UpDownUpDown | updownupdown-postcomment-voting |
UpdraftPlus: WP Backup & Migration Plugin | updraftplus |
URL Shortener | Conversion Tracking | AB Testing | WooCommerce | easy-broken-link-checker |
user files | user-files |
User Management | user-management |
User Sync ActiveCampaign | registered-user-sync-activecampaign |
Userbase Access Control | userbase-access-control |
Utilities for MTG | utilities-for-mtg |
Vampire Character Manager | vampire-character |
vcOS | vcos |
Verge3D Publishing and E-Commerce | verge3d |
Video Share VOD – Turnkey Video Site Builder Script | video-share-vod |
ViewMedica 9 | viewmedica |
VikAppointments Services Booking Calendar | vikappointments |
VOD Infomaniak | vod-infomaniak |
VSTEMPLATE Creator | vstemplate-creator |
W3 Total Cache | w3-total-cache |
W3SPEEDSTER | w3speedster-wp |
WAH Forms | wah-forms |
WC Wallet | wc-wallet |
WCS QR Code Generator | wcs-qr-code-generator |
Weaver Themes Shortcode Compatibility | weaver-themes-shortcode-compatibility |
Web Push | web-push |
Web Testimonials | web-testimonials |
Webcamconsult | webcamconsult |
WH Cache & Security | wh-cache-and-security |
Wibstats | wibstats-statistics-for-wordpress-mu |
Widget Options – The #1 WordPress Widget & Block Control Plugin | widget-options |
Winning Portfolio | winning-portfolio |
WM Options Import Export | wm-options-import-export |
Woo Store Mode | woo-store-mode |
Woo Tuner | woo-tuner |
Woo Update Variations In Cart | woo-update-variations-in-cart |
WooCommerce Advanced Bulk Edit Products, Orders, Coupons, Any WordPress Post Type – Smart Manager | smart-manager-for-wp-e-commerce |
WooCommerce Order Search | woocommerce-order-searching |
WOOEXIM – WooCommerce Export Import Plugin | wooexim |
Word Freshener | word-freshener |
WordPress Additional Logins | wp-additional-logins |
WordPress Call me Now | call-me-now |
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg | groundhogg |
WordPress Custom Sidebar | wordpress-custom-sidebar |
WordPress Data Guard [Website Security] | wordpress-data-guards |
WordPress File Search | wpfilesearch |
WordPress Gallery Plugin | wordpress-gallery-plugin |
WordPress Google Map Professional (Map In Your Language) | google-map-professional |
WordPress Graphs & Charts – Easy Interactive HTML5 Charts Plugin | graph-lite |
WordPress HelpDesk & Support Ticket System Plugin – Octrace Support | octrace-support |
WordPress Local SEO | dh-local-seo |
WordPress Logging Service | wordpress-logging-service |
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly | tour-booking-manager |
WordPress 淘宝客插件 | taobaoke |
WordPress-to-candidate for Salesforce CRM | salesforce-wordpress-to-candidate |
World Cup Predictor | world-cup-predictor |
WOW Best CSS Compiler | best-css-compiler |
WP Abstracts | wp-abstracts-manuscripts-manager |
WP All Import Pro | wp-all-import-pro |
WP Background Tile | wp-background-tile |
WP Booking Calendar | booking |
WP Bulletin Board | wp-bulletin-board |
WP Cloud | cloud |
WP Contest | wp-contest |
WP Cookies Alert | wp-cookies-alert |
WP Custom Google Search | wp-custom-google-search |
WP Download Codes | wp-download-codes |
WP Dream Carousel | wp-dream-carousel |
WP FixTag | wp-fixtag |
WP FPO | wp-fpo |
WP Front-end login and register | wp-front-end-login-and-register |
WP Headmaster | wp-headmaster |
WP Hotel Booking | wp-hotel-booking |
WP IMAP Auth | wp-imap-authentication |
WP Intro.JS Plugin | wp-intro-js-tours |
WP Inventory Manager | wp-inventory-manager |
WP Journal | wpjournal |
WP krpano | wp-krpano |
WP Load Gallery | wp-load-gallery |
WP Login Attempt Log | wp-login-attempt-log |
WP Lyrics | wplyrics |
WP Meetup | wp-meetup |
WP News Sliders | wp-news-sliders |
WP OpenSearch | wp-opensearch |
WP Options Editor | wp-options-editor |
WP Order By | wp-order-by |
WP Photo Sphere | wp-photo-sphere |
WP Post Category Notifications | wp-post-category-notifications |
WP Post Corrector | wp-post-corrector |
WP Projects Portfolio with Client Testimonials | wp-projects-portfolio |
WP PT-Viewer | wp-ptviewer |
WP Query Creator | wp-query-creator |
WP Responsive Tabs | wp-responsive-tabs |
WP Service Payment Form With Authorize.net | wp-service-payment-form-with-authorizenet |
WP Smart Tooltip | wp-smart-tool-tip |
WP Smart TV | wp-smart-tv |
WP Social Broadcast | wp-social-broadcast |
WP SpaceContent | wp-spacecontent |
WP ULike – All-in-One Engagement Toolkit | wp-ulike |
WP Ultimate Reviews FREE | wp-ultimate-reviews-free |
WP User Profile Avatar | wp-user-profile-avatar |
WP ViewSTL | wp-viewstl |
WP VTiger Synchronization | msstiger |
WP-Announcements | wp-announcements |
WP-BlackCheck | wp-blackcheck |
WP-Clap | wp-clap |
wp-flickr-press | wp-flickr-press |
WP-HR Manager: The Human Resources Plugin for WordPress | wp-hr-manager |
WP-NOTCAPTCHA | wp-notcaptcha |
wp-pano | wp-pano |
WP-Player | wp-player |
WP-Revive Adserver | wp-revive-adserver |
Wp-Scribd-List | wp-scribd-list |
WP2APP | wp2appir |
wp_amaps | wp-amaps |
WPDB to Sql | wpdb-to-sql |
WpDevTool | wpdevtool |
WpF Ultimate Carousel | wpf-ultimate-carousel |
WPLingo – Forum Plugin | wplingo |
WPSyncSheets Lite For Elementor – Elementor Pro Form Google Spreadsheet Addon | wpsyncsheets-elementor |
WR Price List Manager For Woocommerce | wr-price-list-for-woocommerce |
XLSXviewer | xlsx-viewer |
Xola | xola-bookings-for-tours-activities |
XTRA Settings | xtra-settings |
yCyclista | ycyclista |
Yet Another Countdown Plugin | yacp |
Youtube Video Grid | Youmax | youmax-channel-embeds-for-youtube-businesses |
Zarinpal Paid Download | zarinpal-paid-downloads |
新淘客WordPress插件 | wp-xintaoke |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
---|---|
Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme | buzzclub |
CarZine | carzine |
DWT - Directory & Listing WordPress Theme | dwt-listing |
Envo Multipurpose | envo-multipurpose |
flashy | flashy |
Ghostwriter | ghostwriter |
Homey | homey |
Js O3 Lite | js-o3-lite |
moseter | moseter |
Multifox | multifox |
my white | my-white |
Offset Writing | offset-writing |
Polka Dots | polka-dots |
Tantyyellow | tantyyellow |
The Ultralight | the-ultralight |
TIJAJI | tijaji |
Tiki Time | tiki-time |
Tuaug4 | tuaug4 |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.
As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.
This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
Comments
11:41 pm
We are using tools based on wget to monitor plugin vulnerabilities. However, we now receive HTTP 202 using wget or curl for this page which makes our tools useless (no content). Browser works fine. Why?
2:30 pm
Thanks for mentioning this - we will look into it. However, we recommend utilizing our vulnerability API https://www.wordfence.com/help/wordfence-intelligence/v2-accessing-and-consuming-the-vulnerability-data-feed/ or webhooks https://www.wordfence.com/help/wordfence-intelligence/wordfence-intelligence-webhook-notifications/ which are completely free to access to stay on top of the latest vulnerabilities. You will receive access to the same vulnerabilities found in these reports, but more in real-time.