By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    GoTrim botnet hacks WordPress sites – Hacker
    GoTrim botnet hacks WordPress sites – Hacker
    10 months ago
    Wordfence Intelligence CE Weekly Vulnerability Report (Feb 6, 2023 to Feb 12, 2023)
    Wordfence Intelligence CE Weekly Vulnerability Report (Feb 6, 2023 to Feb 12, 2023)
    8 months ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    4 months ago
    Latest News
    Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
    8 hours ago
    Beware of scammers! Dangerous apps in the App Store
    3 days ago
    How To Limit Login Attempts on WordPress (+ Should You?)
    4 days ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (September 18, 2023 to September 24, 2023)
    4 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    How To Configure Cloudflare To Maximize WordPress Speed + Security
    12 months ago
    Windows 11 build 25179 rolls out in the Dev Channel
    12 months ago
    How to set a static IP address on Windows 11
    12 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    8 months ago
    Now you can speed up any video in your browser
    8 months ago
    How to restore access to a file after EFS or view it on another computer?
    8 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    9 months ago
  • How To
    How ToShow More
    Xbox celebrates gaming and disability community
    7 hours ago
    A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
    A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
    7 hours ago
    Running Serverless Puppeteer with Workers and Durable Objects
    Running Serverless Puppeteer with Workers and Durable Objects
    7 hours ago
    everything we announced — plus an AI-powered opportunity for startups
    everything we announced — plus an AI-powered opportunity for startups
    7 hours ago
    Easily manage AI crawlers with our new bot categories
    Easily manage AI crawlers with our new bot categories
    1 day ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    Windows Search Hacks
    12 months ago
    How do I buy from the App Store now?
    12 months ago
    How to move a user profile to another drive in Windows?
    12 months ago
    Latest News
    How to create Copilot desktop shortcut on Windows 11
    16 hours ago
    How to enable extensions for Google Bard AI
    3 days ago
    Window 11 Copilot: 10 Best tips and tricks
    4 days ago
    How to create AI images with Cocreator on Paint for Windows 11
    5 days ago
  • Glossary
  • My Bookmarks
Reading: Wordfence Intelligence Weekly WordPress Vulnerability Report (August 28, 2023 to September 3, 2023)
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Wordpress Threats

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 28, 2023 to September 3, 2023)

10alert
Last updated: 7 September
10alert 4 weeks ago
Share
7 Min Read

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 28, 2023 to September 3, 2023)

Last week, there were 64 vulnerabilities disclosed in 61 WordPress Plugins and 2 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 32 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Contents
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 28, 2023 to September 3, 2023)Total Unpatched & Patched Vulnerabilities Last WeekTotal Vulnerabilities by CVSS Severity Last WeekTotal Vulnerabilities by CWE Type Last WeekResearchers That Contributed to WordPress Security Last WeekWordPress Plugins with Reported Vulnerabilities Last WeekWordPress Themes with Reported Vulnerabilities Last WeekVulnerability DetailsForminator Source: wordfence.com

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API and webhook notifications are completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


 

Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Unpatched37
Patched27

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity2
Medium Severity53
High Severity6
Critical Severity3

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)29
Missing Authorization12
Cross-Site Request Forgery (CSRF)11
Unrestricted Upload of File with Dangerous Type5
Server-Side Request Forgery (SSRF)1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Improper Input Validation1
Authorization Bypass Through User-Controlled Key1
Improper Control of Generation of Code (‘Code Injection’)1
Use of Less Trusted Source1
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)1

Researchers That Contributed to WordPress Security Last Week

Researcher NameNumber of Vulnerabilities
Rio Darmawan11
Rafie Muhammad5
Lana Codes
(Wordfence Vulnerability Researcher)
4
thiennv3
LEE SE HYOUNG3
Mika2
Zlrqh2
Dmitrii2
László Radnai2
Elliot2
Marco Wotschka
(Wordfence Vulnerability Researcher)
2
Bartłomiej Marek2
Tomasz Swiadek2
Abdi Pranata2
Phd1
Emili Castells1
Pavitra Tiwari1
Ramuel Gall
(Wordfence Vulnerability Researcher)
1
FearZzZz1
emad1
Prasanna V Balaji1
deokhunKim1
yuyudhn1
Le Ngoc Anh1
Dipak Panchal1
mehmet1
Lokesh Dachepalli1
Jonas Höbenreich1
Enrico Marcolini1
Animesh Gaurav1
Jonatas Souza Villa Flor1
Ravi Dharmawan1

 

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and obtain a CVE ID through this form. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Activity Logaryo-activity-log
AffiliateWPAffiliateWP
All-in-One WP Migration Box Extensionall-in-one-wp-migration-box-extension
All-in-One WP Migration Dropbox Extensionall-in-one-wp-migration-dropbox-extension
All-in-One WP Migration Google Drive Extensionall-in-one-wp-migration-gdrive-extension
All-in-One WP Migration OneDrive Extensionall-in-one-wp-migration-onedrive-extension
Better Elementor Addonsbetter-elementor-addons
Bridge Corebridge-core
Ditty – Responsive News Tickers, Sliders, and Listsditty-news-ticker
DoLogin Securitydologin
Easy Coming Sooneasy-coming-soon
Easy Newsletter Signupseasy-newsletter-signups
Email Encoder – Protect Email Addresses and Phone Numbersemail-encoder-bundle
Fast & Effective Popups & Lead-Generation for WordPress – HollerBoxholler-box
FileOrganizer – Manage WordPress and Website Filesfileorganizer
Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Managerfolders
Font Awesome 4 Menusfont-awesome-4-menus
Forminator – Contact Form, Payment Form & Custom Form Builderforminator
GiveWP – Donation Plugin and Fundraising Platformgive
GuruWalk Affiliatesguruwalk-affiliates
Happy Addons for Elementor Prohappy-elementor-addons-pro
Import XML and RSS Feedsimport-xml-feed
Localize Remote Imageslocalize-remote-images
Login and Logout Redirectlogin-and-logout-redirect
LuckyWP Scripts Controlluckywp-scripts-control
Maintenance Switchmaintenance-switch
MakeStories (for Google Web Stories)makestories-helper
Metform Elementor Contact Form Buildermetform
Multi-column Tag Mapmulti-column-tag-map
Olive One Click Demo Importolive-one-click-demo-import
Order Tracking – WordPress Status Tracking Pluginorder-tracking
Ovic Product Bundleovic-product-bundle
Popup Builder – Create highly converting, mobile friendly marketing popups.popup-builder
Popup boxays-popup-box
PowerPress Podcasting plugin by Blubrrypowerpress
Prevent files / folders accessprevent-file-access
Pricing Deals for WooCommercepricing-deals-for-woocommerce
RSVPMakerrsvpmaker
Remove/hide Author, Date, Category Like Entry-Metaremovehide-author-date-category-like-entry-meta
Responsive Gallery Gridresponsive-gallery-grid
Sermon’e – Sermons Onlinesermone-online-sermons-management
Simple 301 Redirects by BetterLinkssimple-301-redirects
Site Reviewssite-reviews
Sitekitsitekit
Slimstat Analyticswp-slimstat
Smarty for WordPresssmarty-for-wordpress
Snap Pixelsnap-pixel
Social Media Share Buttons & Social Sharing Iconsultimate-social-media-icons
Social Share Boostsocial-share-boost
Surfer – WordPress Pluginsurferseo
URL Shortener by MyThemeShopmts-url-shortener
Ultimate Addons for Contact Form 7ultimate-addons-for-contact-form-7
WP Bannerize Prowp-bannerize-pro
WP GoToWebinarwp-gotowebinar
WP Search Analyticssearch-analytics
WP Super Minifywp-super-minify
WP Synchro – WordPress Migration Plugin for Database & Fileswpsynchro
WP Users Mediawp-users-media
WP-dTreewp-dtree-30
WordPress Ecommerce For Creating Fast Online Stores – By SureCartsurecart
authLdapauthldap

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Arya Multipurpose Proarya-multipurpose-pro
Everest News Proeverest-news-pro

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities.

Forminator

Source: wordfence.com

Translate this article

TAGGED: PoC, Security, Server side request forgery, Software, SQL injection, Threats, Vulnerabilities, WordPress, WordPress plugins, Worpdress
10alert September 7, 2023 September 7, 2023
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Xbox celebrates gaming and disability community
Windows 7 hours ago
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
Apps 7 hours ago
Running Serverless Puppeteer with Workers and Durable Objects
Running Serverless Puppeteer with Workers and Durable Objects
Apps 7 hours ago
everything we announced — plus an AI-powered opportunity for startups
everything we announced — plus an AI-powered opportunity for startups
Apps 7 hours ago
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Wordpress Threats 11 hours ago

You Might Also Like

Windows

Xbox celebrates gaming and disability community

7 hours ago
everything we announced — plus an AI-powered opportunity for startups
Apps

everything we announced — plus an AI-powered opportunity for startups

7 hours ago
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Wordpress Threats

Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware

11 hours ago
Easily manage AI crawlers with our new bot categories
Apps

Easily manage AI crawlers with our new bot categories

1 day ago
Show More

Related stories

How to install September 2023 update with 23H2 features for Windows 11
How to upgrade to Windows 11 23H2 with Installation Assistant
How to get the latest Windows 11 innovations
How to blur image background in Photos for Windows 11
How to download official Windows 11 23H2 ISO file
PHP Object Injection Vulnerability in Flatsome Theme

10 New Stories

How to create Copilot desktop shortcut on Windows 11
Easily manage AI crawlers with our new bot categories
Cloudflare is free of CAPTCHAs; Turnstile is free for everyone
Post-quantum cryptography goes GA
Detecting zero-days before zero-day
See what threats are lurking in your Office 365 with Cloudflare Email Retro Scan
Previous Next
Hot News
Xbox celebrates gaming and disability community
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
Running Serverless Puppeteer with Workers and Durable Objects
everything we announced — plus an AI-powered opportunity for startups
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?