Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024)

Did you know Wordfence runs a Bug Bounty Program for all WordPress plugin and themes at no cost to vendors? Through October 7th, 2024, XSS vulnerabilities in all plugins and themes with >=1,000 Active Installs are in scope for all researchers. In addition, through October 14th, 2024, researchers can earn up to $31,200, for all in-scope vulnerabilities submitted to our Bug Bounty Program! Find a vulnerability, submit the details directly to us, and we handle all the rest.

Last week, there were 145 vulnerabilities disclosed in 100 WordPress Plugins and 23 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, webhook integration, and Wordfence CLI Vulnerability Scanner are all completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Enterprises, Hosting Providers, and even Individuals can use the Wordfence CLI Vulnerability Scanner to run regular vulnerability scans across the sites they protect. Or alternatively, utilize the vulnerability Database API to receive a complete dump of our database of over 18,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our PremiumCare, and Response customers last week:

MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 – Missing Authorization to Arbitrary Vendor Creation/Update/Deletion
WAF-RULE-729 – Data redacted while we work with the vendor on a patch.
WAF-RULE-730 – Data redacted while we work with the vendor on a patch.
WAF-RULE-731 – Data redacted while we work with the vendor on a patch.
WAF-RULE-733 – Data redacted while we work with the vendor on a patch.

Wordfence PremiumCare, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.

Total Unpatched & Patched Vulnerabilities Last Week

Patch Status
Number of Vulnerabilities

Patched
91

Unpatched
54

Total Vulnerabilities by CVSS Severity Last Week

Severity Rating
Number of Vulnerabilities

Medium Severity
118

High Severity
14

Critical Severity
13

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWE
Number of Vulnerabilities

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
70

Missing Authorization
27

Cross-Site Request Forgery (CSRF)
13

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
10

Deserialization of Untrusted Data
6

Information Exposure
6

Use of Less Trusted Source
3

Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)
2

Argument Injection or Modification
1

Authorization Bypass Through User-Controlled Key
1

Improper Authorization
1

Improper Control of Generation of Code (‘Code Injection’)
1

Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
1

Protection Mechanism Failure
1

Server-Side Request Forgery (SSRF)
1

Unrestricted Upload of File with Dangerous Type
1

Researchers That Contributed to WordPress Security Last Week

Researcher Name
Number of Vulnerabilities

19

9

9

8

7

6

6

6

5

5

4

4

3

3

Seb

3

3

3

3

3

2

2

2

2

2

2

2

2

2

1

1

1

1

1

1

1

1

1

1

1

1

1

1

1

1

1

1

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and earn a bounty on in-scope vulnerabilities through our Bug Bounty Program. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.

WordPress Plugins with Reported Vulnerabilities Last Week

Software Name
Software Slug

140+ Widgets | Xpro Addons For Elementor – FREE

xpro-elementor-addons

Animated Number Counters

animated-number-counters

azurecurve Toggle Show/Hide

azurecurve-toggle-showhide

Beaver Builder – WordPress Page Builder

beaver-builder-lite-version

Brickscore

brickscore

Bus Ticket Booking with Seat Reservation – WpBusTicketly | WordPress plugin

bus-ticket-booking-with-seat-reservation

Classic Addons – WPBakery Page Builder

classic-addons-wpbakery-page-builder-addons

Clean Login

clean-login

Collapsing Archives

collapsing-archives

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

fluentform

Custom Query Blocks

post-type-archive-mapping

Droip

droip

DSGVO All in one for WP

dsgvo-all-in-one-for-wp

easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg

easyjobs

Elementor Addon Elements

addon-elements-for-elementor-page-builder

Email Address Encoder

email-address-encoder

EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

embedpress

Enhanced Search Box

extended-search-plugin

EU/UK VAT Manager for WooCommerce

eu-vat-for-woocommerce

Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms

happyforms

Front End Users

front-end-only-users

FunnelKit Funnel Builder Pro

funnel-builder-pro

Gallery Plugin for WordPress – Envira Photo Gallery

envira-gallery-lite

Generate Images – Magic Post Thumbnail

magic-post-thumbnail

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory

geodirectory

GHActivity

ghactivity

GiveWP – Donation Plugin and Fundraising Platform

give

Greenshift Query and Meta Addon

greenshiftquery

Gutenverse – Ultimate Block Addons and Page Builder for Site Editor

gutenverse

HelloAsso

helloasso

HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics

leadin

infolinks Ad Wrap

infolinks-ad-wrap

Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free

funnelforms-free

Jeg Elementor Kit

jeg-elementor-kit

JobSearch WP Job Board

wp-jobsearch

Justified Image Grid – Premium WordPress Gallery

justified-image-grid

LatePoint Plugin

LatePoint

Like Button Rating LikeBtn

likebtn-like-button

Login As Users

login-as-users

Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid

logo-showcase-ultimate

Maintenance & Coming Soon Redirect Animation

maintenance-coming-soon-redirect-animation

Media Library Folders

media-library-plus

Memberpress

memberpress

Mollie Payments for WooCommerce

mollie-payments-for-woocommerce

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

mp3-music-player-by-sonaar

Name Directory

name-directory

Ninja Forms – The Contact Form Builder That Grows With You

ninja-forms

Ninja Tables – Easiest Data Table Builder

ninja-tables

NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN

nitropack

Oxygen Builder

oxygenbuilder

Page Builder: Pagelayer – Drag and Drop website builder

pagelayer

Payment forms, Buy now buttons, and Invoicing System | GetPaid

invoicing

Permalink Manager Lite

permalink-manager

Podlove Podcast Publisher

podlove-podcasting-plugin-for-wordpress

Popup Builder – Create highly converting, mobile friendly marketing popups.

popup-builder

Premium Portfolio Features for Phlox theme

auxin-portfolio

Premium SEO Pack – WP SEO Plugin

premium-seo-pack

Propovoice Pro

propovoice-pro

Relevanssi Live Ajax Search

relevanssi-live-ajax-search

Review Ratings

ratings-shorttags

Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More

reviews-feed

Royal Elementor Addons and Templates

royal-elementor-addons

SendGrid for WordPress

wp-sendgrid-mailer

Share This Image

share-this-image

SKT Blocks – Gutenberg based Page Builder

skt-blocks

Special Feed Items

special-feed-items

Sunshine Photo Cart: Free Client Photo Galleries for Photographers

sunshine-photo-cart

Super Store Finder

superstorefinder-wp

Super Testimonials

super-testimonial

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments

surecart

tagDiv Composer

td-composer

Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab

ecab-taxi-booking-manager

The Events Calendar Pro

events-calendar-pro

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce

the-plus-addons-for-elementor-page-builder

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid

the-post-grid

Theme Editor

theme-editor

Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking

tourfic

Tutor LMS Pro

tutor-pro

Two-factor authentication (formerly IP Vault)

ip-vault-wp-firewall

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

ultimate-store-kit

Vikinghammer Tweet

vikinghammer-tweet

Visual CSS Style Editor

yellow-pencil-visual-theme-customizer

Visual Sound (old)

visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams

Web and WooCommerce Addons for WPBakery Builder

vc-addons-by-bit14

Web Application Firewall – website security

web-application-firewall

Woocommerce Addon Greenshift

greenshiftwoo

WP Accessibility Helper (WAH)

wp-accessibility-helper

WP Armour Extended

wp-armour-extended

WP Booking Calendar

booking

WP Cerber Security, Anti-spam & Malware Scan

wp-cerber

WP Crowdfunding

wp-crowdfunding

WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)

delicious-recipes

WP Events Manager

wp-events-manager

WP Testimonial Widget

wp-testimonial-widget

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin

timetics

WP To Do

wp-todo

WPMobile.App — Android and iOS Mobile Application

wpappninja

WPZOOM Portfolio Lite – Filterable Portfolio Plugin

wpzoom-portfolio

YARPP – Yet Another Related Posts Plugin

yet-another-related-posts-plugin

Zynith SEO

zynith-seo

WordPress Themes with Reported Vulnerabilities Last Week

Software Name
Software Slug

Attire

attire

Betheme

betheme

Blockbooster

blockbooster

Blogpoet

blogpoet

Enfold – Responsive Multi-Purpose Theme

enfold

Esotera

esotera

Filmix

filmix

Fluida

fluida

FotaWP

fotawp

Hotel Galaxy

hotel-galaxy

IntoTheDark

intothedark

Kahuna

kahuna

Liquido

liquido

Mantra

mantra

Masterstudy – Education WordPress Theme

ms-lms-starter-theme

Mystique

mystique

Nirvana

nirvana

Opor Ayam

opor-ayam

Parabola

parabola

Posterity

posterity

ReviveNews

revivenews

Sliding Door

sliding-door

Tempera

tempera

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43931
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board
Researcher
CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43941
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Propovoice Pro
Researcher
CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43965
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
SendGrid for WordPress
Researcher
CVSS Rating
Critical (10.0)
CVE-ID
CVE-2024-43978
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder
Researcher
CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43942
Patch Status
Patched
Published
Aug 26, 2024
Researcher
CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43976
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder
Researcher
CVSS Rating
Critical (9.9)
CVE-ID
CVE-2024-43943
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Woocommerce Addon Greenshift
Researcher
CVSS Rating
Critical (9.8)
CVE-ID
CVE-2024-7857
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Media Library Folders
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-8016
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
The Events Calendar Pro
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-43966
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
WP Testimonial Widget
Researcher
CVSS Rating
Critical (9.1)
CVE-ID
CVE-2024-43939
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Zynith SEO
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43957
Patch Status
Unpatched
Published
Aug 26, 2024
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7435
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Attire
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-2694
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Betheme
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-8252
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Clean Login
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7607
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Front End Users
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43982
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Login As Users
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-43984
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Podlove Podcast Publisher
Researcher
CVSS Rating
High (8.8)
CVE-ID
CVE-2024-7717
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
WP Events Manager
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-43950
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Brickscore
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2024-43975
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Super Store Finder
Researcher
CVSS Rating
High (7.2)
CVE-ID
CVE-2022-2440
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Theme Editor
Researcher
CVSS Rating
High (7.1)
CVE-ID
CVE-2024-5784
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Tutor LMS Pro
Researcher
CVSS Rating
Medium (6.5)
CVE-ID
CVE-2024-43989
Patch Status
Unpatched
Published
Aug 29, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43961
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
azurecurve Toggle Show/Hide
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7895
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-3998
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Betheme
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43953
Patch Status
Unpatched
Published
Aug 26, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43934
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Collapsing Archives
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44059
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Custom Query Blocks
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43964
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
DSGVO All in one for WP
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-4401
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Elementor Addon Elements
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7122
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Elementor Addon Elements
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-5061
Patch Status
Unpatched
Published
Aug 29, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43952
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Esotera
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44054
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Fluida
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-7606
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Front End Users
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-1056
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
FunnelKit Funnel Builder Pro
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43949
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
GHActivity
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43991
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Hotel Galaxy
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-6804
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Jeg Elementor Kit
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43994
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Kahuna
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43992
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
LatePoint Plugin
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43993
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Liquido
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44056
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Mantra
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43988
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Mystique
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44057
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Nirvana
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44058
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Parabola
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43983
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
Podlove Podcast Publisher
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43995
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Posterity
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-1384
Patch Status
Unpatched
Published
Aug 28, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-44001
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-8108
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
Share This Image
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43946
Patch Status
Unpatched
Published
Aug 26, 2024
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43987
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Sliding Door
Researcher
CVSS Rating
Medium (6.4)
CVE-ID
CVE-2024-43951
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Tempera
Researcher
CVSS Rating
Medium (6.3)
CVE-ID
CVE-2024-7858
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Media Library Folders
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43926
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43997
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44061
Patch Status
Unpatched
Published
Aug 29, 2024
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44060
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Filmix
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43958
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
IntoTheDark
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44064
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Like Button Rating LikeBtn
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43921
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-5024
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Memberpress
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43938
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Name Directory
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-44053
Patch Status
Unpatched
Published
Aug 29, 2024
Affected Software
Opor Ayam
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8052
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Review Ratings
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8051
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Special Feed Items
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43971
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-5212
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
tagDiv Composer
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-3886
Patch Status
Patched
Published
Aug 30, 2024
Affected Software
tagDiv Composer
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43959
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Super Testimonials
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8043
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Vikinghammer Tweet
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43948
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WP Armour Extended
Researcher
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-8274
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
WP Booking Calendar
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43933
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (6.1)
CVE-ID
CVE-2024-43963
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Visual CSS Style Editor
Researcher
CVSS Rating
Medium (5.4)
CVE-ID
CVE-2024-5987
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
WP Accessibility Helper (WAH)
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43979
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43998
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
Blogpoet
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43980
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
FotaWP
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-6551
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4536
Patch Status
Patched
Published
Aug 30, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43929
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43944
Patch Status
Unpatched
Published
Aug 26, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43990
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43956
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Memberpress
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-6448
Patch Status
Patched
Published
Aug 27, 2024
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-8195
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Permalink Manager Lite
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-2541
Patch Status
Unpatched
Published
Aug 28, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-3679
Patch Status
Unpatched
Published
Aug 28, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-7573
Patch Status
Patched
Published
Aug 27, 2024
Affected Software
Relevanssi Live Ajax Search
Researcher
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43974
Patch Status
Patched
Published
Aug 28, 2024
Affected Software
ReviveNews
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43923
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4539
Patch Status
Patched
Published
Aug 30, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2022-4100
Patch Status
Patched
Published
Aug 30, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43937
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43919
Patch Status
Unpatched
Published
Aug 26, 2024
CVSS Rating
Medium (5.3)
CVE-ID
CVE-2024-43940
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Zynith SEO
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43999
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43972
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-43967
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
WP Testimonial Widget
Researcher
CVSS Rating
Medium (4.4)
CVE-ID
CVE-2024-3944
Patch Status
Unpatched
Published
Aug 28, 2024
Affected Software
WP To Do
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43954
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
Droip
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43927
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Email Address Encoder
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8091
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Enhanced Search Box
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43925
Patch Status
Patched
Published
Aug 26, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43973
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-44052
Patch Status
Patched
Published
Aug 29, 2024
Affected Software
HelloAsso
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8044
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
infolinks Ad Wrap
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43930
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43928
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
JobSearch WP Job Board
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43945
Patch Status
Unpatched
Published
Aug 26, 2024
Affected Software
LatePoint Plugin
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-6688
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
Oxygen Builder
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-7418
Patch Status
Patched
Published
Aug 28, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8319
Patch Status
Patched
Published
Aug 29, 2024
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-8047
Patch Status
Unpatched
Published
Aug 27, 2024
Affected Software
Visual Sound (old)
Researcher
CVSS Rating
Medium (4.3)
CVE-ID
CVE-2024-43947
Patch Status
Patched
Published
Aug 26, 2024
Affected Software
WP Armour Extended
Researcher

As a reminder, Wordfence has curated an industry leading vulnerability database with all known WordPress core, theme, and plugin vulnerabilities known as Wordfence Intelligence.

This database is continuously updated, maintained, and populated by Wordfence’s highly credentialed and experienced vulnerability researchers through in-house vulnerability research, vulnerability researchers submitting directly to us through our Bug Bounty Program, and by monitoring varying sources to capture all publicly available WordPress vulnerability information and adding additional context where we can.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.

The post Wordfence Intelligence Weekly WordPress Vulnerability Report (August 26, 2024 to September 1, 2024) appeared first on Wordfence.

Leave a Comment