By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    All You Need to Know About APTs
    8 months ago
    Avoid infection by dangerous Onion ransomware aka CTB-Locker
    8 months ago
    How Kaspersky Internet Security protects from ransomware
    8 months ago
    Latest News
    Safeguards against firmware signed with stolen MSI keys
    16 hours ago
    WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
    16 hours ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
    6 days ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    7 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    What’s included in the ‘Battle of Shadow and Light’ update for Halo 5: Guardians
    8 months ago
    How to fix printer spooler problems on Windows 10
    8 months ago
    How to fix error 0x80004005 starting VirtualBox VM on Windows 10
    8 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    3 months ago
    Now you can speed up any video in your browser
    3 months ago
    How to restore access to a file after EFS or view it on another computer?
    4 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    4 months ago
  • How To
    How ToShow More
    What is two-factor authentication | Kaspersky official blog
    2 days ago
    Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
    4 days ago
    NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
    4 days ago
    How Oxy uses hooks for maximum extensibility
    How Oxy uses hooks for maximum extensibility
    5 days ago
    The personal threat landscape: securing yourself smartly
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to remove the background from a photo?
    7 months ago
    How to disable cookies in Firefox?
    7 months ago
    Is it worth installing a launcher on your smartphone?
    7 months ago
    Latest News
    How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
    2 days ago
    How to enable Taskbar End Task option to close apps on Windows 11
    2 days ago
    How to check USB4 devices specs from Settings on Windows 11
    2 days ago
    How to enable new header UI for File Explorer on Windows 11
    7 days ago
  • Glossary
  • My Bookmarks
Reading: Wordfence Intelligence Weekly WordPress Vulnerability Report (Apr 17, 2023 to Apr 23, 2023)
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Wordpress Threats

Wordfence Intelligence Weekly WordPress Vulnerability Report (Apr 17, 2023 to Apr 23, 2023)

10alert
Last updated: 28 April
10alert 1 month ago
Share
11 Min Read

Wordfence Intelligence Weekly WordPress Vulnerability Report (Apr 17, 2023 to Apr 23, 2023)

Last week, there were 152 vulnerabilities disclosed in 134 WordPress Plugins and 0 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 41 Vulnerability Researchers that contributed to WordPress Security last week. There were more unpatched vulnerabilities than patched last week, so it’s more important than ever to review those vulnerabilities in this report now to ensure your site is not affected and make the appropriate adjustments if your site is.

Contents
Wordfence Intelligence Weekly WordPress Vulnerability Report (Apr 17, 2023 to Apr 23, 2023)Total Unpatched & Patched Vulnerabilities Last WeekTotal Vulnerabilities by CVSS Severity Last WeekTotal Vulnerabilities by CWE Type Last WeekResearchers That Contributed to WordPress Security Last WeekWordPress Plugins with Reported Vulnerabilities Last WeekVulnerability DetailsEmail posts to subscribers Source: wordfence.com

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface and vulnerability API are completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Unpatched81
Patched71

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity0
Medium Severity134
High Severity16
Critical Severity2

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)93
Cross-Site Request Forgery (CSRF)30
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)11
Missing Authorization10
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)2
Deserialization of Untrusted Data2
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)1
Information Exposure1
Improper Access Control1
URL Redirection to Untrusted Site (‘Open Redirect’)1

Researchers That Contributed to WordPress Security Last Week

Researcher NameNumber of Vulnerabilities
Lana Codes30
Marco Wotschka11
Yuki Haruma9
yuyudhn7
Muhammad Daffa6
LEE SE HYOUNG6
Rio Darmawan6
Sajjad Shariati6
Shreya Pohekar5
minhtuanact5
Justiice4
Ramuel Gall4
TEAM WEBoB of BoB 11th3
Mika3
Ivan Kuzymchak3
Le Ngoc Anh3
Erwan LR3
Cat3
WPScanTeam2
Lokesh Dachepalli2
Nguyen Xuan Chien2
Joshua Martinelle1
Rafie Muhammad1
Rafshanzani Suhada1
Nguyen Huu Do1
Ryo Sato1
Skalucy1
Shezad Master1
zhangyunpei1
Yeting Li [email protected]1
Ameen Alkurdy1
Nithissh S1
Chien Vuong1
thiennv1
Alexander Schmid1
cydave1
easyBug1
Daniel Ruf1
Alex Thomas1
deokhunKim1
Lucio Sá1

 

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and obtain a CVE ID through this form. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
AI ChatBotchatbot
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signuparmember-membership
Accessibility Suite by Online ADAonline-accessibility
Accordion & FAQ – Helpie WordPress Frequently Asked Questions pluginhelpie-faq
Active Directory Integration / LDAP Integrationldap-login-for-intranet-sites
ActiveCampaign – Forms, Site Tracking, Live Chatactivecampaign-subscription-forms
Ad Inserter – Ad Manager & AdSense Adsad-inserter
Album Gallery – WordPress Gallerynew-album-gallery
ApexChatapexchat
Avirato hotels online booking engineavirato-calendar
BBSpoilerbbspoiler
BadgeOSbadgeos
Best Travel Booking WordPress Plugin, Tour Booking System, Trip Booking WordPress Plugin – Yatrayatra
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shopwoo-altcoin-payment-gateway
BizLibrarybizlibrary
Booking calendar, Appointment Booking Systembooking-calendar
Button Builder – Buttons Xbuttons-x
CMP – Coming Soon & Maintenance Plugin by NiteoThemescmp-coming-soon-maintenance
CMS Tree Page Viewcms-tree-page-view
Cab Gridcab-grid
Captcha Them Allcaptcha-them-all
Category Specific RSS feed Subscriptioncategory-specific-rss-feed-menu
Church Adminchurch-admin
Clock In Portal- Staff & Attendance Managementclock-in-portal
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPresscontact-form-to-db
Continuous announcement scrollercontinuous-announcement-scroller
Custom Post Type List Shortcodecustom-post-type-list-shortcode
Customer Support Software, Live Chat, & Marketing Automationformilla-chat-and-marketing
Dave’s WordPress Live Searchdaves-wordpress-live-search
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPresscharitable
EZP Maintenance Modeeasy-pie-maintenance-mode
Easy Ad Managereasy-ad-manager
Easy Slider Revolutioneasy-slider-revolution
Ebook Storeebook-store
Email posts to subscribersemail-posts-to-subscribers
Enable/Disable Auto Login when Registerauto-login-when-resister
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templatesessential-blocks
File Galleryfile-gallery
Flyzoo Chatflyzoo
Form Blockform-block
FormCraft – Contact Form Builder for WordPressformcraft-form-builder
Formilla Edge Targeted Messaging Platform for Sales and Marketingformilla-edge
Freshdesk (official)freshdesk-support
GDPR Compliance & Cookie Consentgdpr-compliance-cookie-consent
Gallery Metaboxgallery-metabox
Google Analytics Top Content Widgetgoogle-analytics-top-posts-widget
Gps Plottergps-plotter
Help Desk WPhelpdeskwp
Image Optimizer by 10web – Image Optimizer and Compression pluginimage-optimizer-wd
Japanized For WooCommercewoocommerce-for-japan
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automationzero-bs-crm
Kaya QR Code Generatorkaya-qr-code-generator
Kiwiz – Certification de facturation – Woocommercewoocommerce-gateway-certification-de-facture-et-gestion-de-pdf-kiwiz
Kodex Posts likeskodex-posts-likes
LIQUID SPEECH BALLOONliquid-speech-balloon
Layer Sliderslider-slideshow
LearnPress Export Import – WordPress extension for LearnPresslearnpress-import-export
Live Chat by Formilla – Real-time Chat & Chatbots Pluginformilla-live-chat
Locatoraid Store Locatorlocatoraid
Login Page Styler | Custom Login | Custom WP Admin Login Page | Admin Security | Admin Protection | Login Page Customizer | Admin Login | Login Security | Login Redirect | Theme Login | Login Menu | Login Form | Admin Dashboard | Change Login Logo | Loginlogin-page-styler
Mail Subscribe Listmail-subscribe-list
Mega Addons For WPBakery Page Buildermega-addons-for-visual-composer
Membership Databasemember-database
Modal Dialogmodal-dialog
Motors – Car Dealer, Classifieds & Listingmotors-car-dealership-classified-listings
NEX-Forms – Ultimate Form Builder – Contact forms and much morenex-forms-express-wp-form-builder
Ninja Tables – Best Data Table Plugin for WordPressninja-tables
OoohBoi Steroids for Elementorooohboi-steroids-for-elementor
Panorama – WordPress Project Management Pluginproject-panorama-lite
Post Shortcodepost-shortcode
PowerPress Podcasting plugin by Blubrrypowerpress
Pretty Urlpretty-url
Product Slider For WooCommerce Liteproduct-slider-for-woocommerce-lite
PropertyHivepropertyhive
Query Wranglerquery-wrangler
RapidExpCartrapidexpcart
Redirect After Loginredirect-after-login
Reservation.Studio widgetreservation-studio-widget
Responsive Filterable Portfolioresponsive-filterable-portfolio
ReviewX – Multi-criteria Rating & Reviews for WooCommercereviewx
Robokassa payment gateway for Woocommercerobokassa
Semalt Blockersemalt
ShopEngine – Elementor WooCommerce Builder Addons, Variation Swatches, Wishlist, Products Compare – All in One Solutionshopengine
Shortcode IMDBshortcode-imdb
Simple Share Buttons Addersimple-share-buttons-adder
Simple Tooltipssimple-tooltips
SiteAlert – Uptime, Speed, and Security Monitoring for WordPressmy-wp-health-check
Sloth Logo Customizersloth-logo-customizer
Smart WooCommerce Searchsmart-woocommerce-search
Social Share Boostsocial-share-boost
SparkPostsparkpost
Stock Exporter for WooCommercestock-exporter-for-woocommerce
Streamstream
Subscribers – Free Web Push Notificationssubscribers-com
Tablesome – Data table & Workflow Automation ( Contact Form Entries, Email Log, OpenAI / ChatGPT )tablesome
TaxoPress is the WordPress Tag, Category, and Taxonomy Managersimple-tags
The School Management – Education & Learning Managementschool-management-system
Themify Portfolio Postthemify-portfolio-post
Thumbnail carousel sliderwp-responsive-thumbnail-slider
Uji Popupuji-popup
Ultimate Carousel For Elementorultimate-carousel-for-elementor
Ultimate Carousel For WPBakery Page Builderultimate-carousel-for-visual-composer
Update Image Tag Alt Attributeupdate-alt-attribute
Verified Reviews (Avis Vérifiés)netreviews
Video Gridvideo-grid
Video List Managervideo-list-manager
Visual CSS Style Editoryellow-pencil-visual-theme-customizer
WCP Contact Formwcp-contact-form
WP Cerber Security, Anti-spam & Malware Scanwp-cerber
WP Custom Author URLwp-custom-author-url
WP Docswp-docs
WP Links Pagewp-links-page
WP Login Boxwp-login-box
WP Original Media Pathwp-original-media-path
WP Popups – WordPress Popup builderwp-popups-lite
WP Responsive Tabs horizontal vertical and accordion Tabsresponsive-horizontal-vertical-and-accordion-tabs
WP-FormAssemblyformassembly-web-forms
WP-dTreewp-dtree-30
WPJAM Basicwpjam-basic
White Label Branding for Elementor Page Builderwhite-label-branding-elementor
WooCommerce Easy Duplicate Productwoo-easy-duplicate-product
WooCommerce Order Status Change Notifierwoocommerce-order-status-change-notifier
Woocommerce Email Reportwooemailreport
Woocommerce Products Designer by ORION – online product customizer for t-shirts, print cards, phone cases Lettering & Decalswoocommerce-products-designer
WordPress Header Builder Plugin – Pearlpearl-header-builder
Wp-D3wp-d3
YARPP – Yet Another Related Posts Pluginyet-another-related-posts-plugin
YML for Yandex Marketyml-for-yandex-market
YourChannel: Everything you want in a YouTube plugin.yourchannel
Zendesk Support for WordPresszendesk
eRocketerocket
f(x) TOCfx-toc
miniOrange’s Google Authenticator – WordPress Two Factor Authentication (2FA , Two Factor, OTP SMS and Email) | Passwordless loginminiorange-2-factor-authentication
vSlider Multi Image Slider for WordPressvslider

Vulnerability Details

Email posts to subscribers

Source: wordfence.com

Translate this article

TAGGED: Authentication, Malware, PoC, Security, Social engineering, Software, Split tunneling, SQL injection, Threats, Vulnerabilities, WordPress, WordPress plugins, Worpdress
10alert April 28, 2023 April 28, 2023
Share this Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Safeguards against firmware signed with stolen MSI keys
Threats 19 hours ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats 19 hours ago
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
News 2 days ago
How to enable Taskbar End Task option to close apps on Windows 11
News 2 days ago
How to check USB4 devices specs from Settings on Windows 11
News 2 days ago

Recent Posts

  • Safeguards against firmware signed with stolen MSI keys
  • WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
  • How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
  • How to enable Taskbar End Task option to close apps on Windows 11
  • How to check USB4 devices specs from Settings on Windows 11

You Might Also Like

Threats

Safeguards against firmware signed with stolen MSI keys

19 hours ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats

WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin

19 hours ago
News

How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11

2 days ago
News

How to check USB4 devices specs from Settings on Windows 11

2 days ago
Show More

Related stories

How to Use Cloudflare to Secure Your WordPress Site
How To Starting Chrome from the command line
How to fix error 0x80070057 in Chrome?
Windows 10 How To Disable Slide to Shutdown
Windows search not working (FIX)
How to watch movies and TV series for free on Kinopoisk?
Previous Next

10 New Stories

What is two-factor authentication | Kaspersky official blog
Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
How Oxy uses hooks for maximum extensibility
The personal threat landscape: securing yourself smartly
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Previous Next
Hot News
Safeguards against firmware signed with stolen MSI keys
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
How to enable Taskbar End Task option to close apps on Windows 11
How to check USB4 devices specs from Settings on Windows 11
10alert.com10alert.com
Follow US

© 10 Alert Network. All Rights Reserved.

  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?