By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    What is a rootkit and how to remove it
    12 months ago
    The Mask – Unveiling the World’s Most Sophisticated APT Campaign
    12 months ago
    Regin APT Attacks Among the Most Sophisticated Ever Analyzed
    12 months ago
    Latest News
    Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
    8 hours ago
    Beware of scammers! Dangerous apps in the App Store
    3 days ago
    How To Limit Login Attempts on WordPress (+ Should You?)
    4 days ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (September 18, 2023 to September 24, 2023)
    4 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    For 0-day vulnerabilities in Windows, temporary patches
    12 months ago
    Windows 11 22H2 (build 22621.317) outs in the Release Preview Channel
    12 months ago
    How to avoid problems installing Windows 11 22H2
    12 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    8 months ago
    Now you can speed up any video in your browser
    8 months ago
    How to restore access to a file after EFS or view it on another computer?
    8 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    9 months ago
  • How To
    How ToShow More
    Xbox celebrates gaming and disability community
    7 hours ago
    A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
    A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
    7 hours ago
    Running Serverless Puppeteer with Workers and Durable Objects
    Running Serverless Puppeteer with Workers and Durable Objects
    7 hours ago
    everything we announced — plus an AI-powered opportunity for startups
    everything we announced — plus an AI-powered opportunity for startups
    7 hours ago
    Easily manage AI crawlers with our new bot categories
    Easily manage AI crawlers with our new bot categories
    1 day ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to install Windows 11 23H2 (early)
    2 months ago
    How to uninstall Windows 11 23H2
    1 month ago
    How to remove the quiet mode icon in the corner of the iPhone 15 screen ProiPhone 15 Pro and iPhone
    How to remove the quiet mode icon in the corner of the iPhone 15 screen ProiPhone 15 Pro and iPhone
    6 days ago
    Latest News
    How to create Copilot desktop shortcut on Windows 11
    16 hours ago
    How to enable extensions for Google Bard AI
    3 days ago
    Window 11 Copilot: 10 Best tips and tricks
    4 days ago
    How to create AI images with Cocreator on Paint for Windows 11
    5 days ago
  • Glossary
  • My Bookmarks
Reading: Wordfence Intelligence Weekly WordPress Vulnerability Report (August 7, 2023 to August 13, 2023)
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Wordpress Threats

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 7, 2023 to August 13, 2023)

10alert
Last updated: 17 August
10alert 2 months ago
Share
8 Min Read

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 7, 2023 to August 13, 2023)

Last week, there were 86 vulnerabilities disclosed in 68 WordPress Plugins and 3 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 36 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Contents
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 7, 2023 to August 13, 2023)New Firewall Rules Deployed Last WeekTotal Unpatched & Patched Vulnerabilities Last WeekTotal Vulnerabilities by CVSS Severity Last WeekTotal Vulnerabilities by CWE Type Last WeekResearchers That Contributed to WordPress Security Last WeekWordPress Plugins with Reported Vulnerabilities Last WeekWordPress Themes with Reported Vulnerabilities Last WeekVulnerability DetailsKadence Blocks Source: wordfence.com

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API, and webhook integration are completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

  • WAF-RULE-622, data redacted while we work with the developer to ensure this vulnerability gets patched.
  • WAF-RULE-623, data redacted while we work with the developer to ensure this vulnerability gets patched.

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Unpatched25
Patched61

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity0
Medium Severity63
High Severity19
Critical Severity4

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)25
Missing Authorization21
Cross-Site Request Forgery (CSRF)20
Unrestricted Upload of File with Dangerous Type4
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)4
Improper Privilege Management3
Authorization Bypass Through User-Controlled Key2
Improper Control of Filename for Include/Require Statement in PHP Program (‘PHP Remote File Inclusion’)2
Server-Side Request Forgery (SSRF)1
Improper Authorization1
Improper Authentication1
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
Deserialization of Untrusted Data1

Researchers That Contributed to WordPress Security Last Week

Researcher NameNumber of Vulnerabilities
Rafie Muhammad13
Lana Codes
(Wordfence Vulnerability Researcher)
11
Mika5
Marco Wotschka
(Wordfence Vulnerability Researcher)
4
Abdi Pranata4
Cat3
Rio Darmawan2
Aman Rawat2
thiennv2
Skalucy2
Jonas Höbenreich2
Erwan LR2
OZ1NG (TOOR, LISA)2
Ramuel Gall
(Wordfence Vulnerability Researcher)
2
Phd2
minhtuanact2
LEE SE HYOUNG2
Ivy1
Bob Matyas1
Rafshanzani Suhada1
deokhunKim1
Nguyen Hoang Nam1
Dmitrii Ignatyev1
Taihei Shimamine1
Satoo Nakano1
Ryotaro Imamura1
Mesh3l_9111
Dmitrii1
Nguyen Xuan Chien1
Alexander Concha1
Daniel Ruf1
Robert DeVore1
Sayandeep Dutta1
Truoc Phan1
Robert Rowley1
tnt241

 

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and obtain a CVE ID through this form. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
AI ChatBotchatbot
ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signuparmember
Absolute Privacyabsolute-privacy
Accordion and Accordion Slideraccordion-and-accordion-slider
Advanced Custom Fields Proadvanced-custom-fields-pro
All Users Messengerall-users-messenger
BigBlueButtonbigbluebutton
Biometric Login For WooCommercebiometric-login-for-woocommerce
Booking Packagebooking-package
Cantocanto
Donations Made Easy – Smart Donationssmart-donations
Easy Cookie Laweasy-cookie-law
Easy!Appointmentseasyappointments
Email Template Designer – WP HTML Mailwp-html-mail
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementorembedpress
FULL – Customerfull-customer
Fusion Builderfusion-builder
Futurio Extrafuturio-extra
GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent)gdpr-cookie-compliance
Gutenberg Blocks by Kadence Blocks – Page Builder Featureskadence-blocks
Highcompress Image Compressorhigh-compress
ImageRecycle pdf & image compressionimagerecycle-pdf-image-compression
JCH Optimizejch-optimize
Jupiter X Corejupiterx-core
Justified Galleryjustified-gallery
Kangu para WooCommercekangu
Leykaleyka
MailChimp Forms by MailMunchmailchimp-forms-by-mailmunch
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPressninja-forms
Online Booking & Scheduling Calendar for WordPress by vcitameeting-scheduler-by-vcita
POEditorpoeditor
Photo Gallery by Ays – Responsive Image Gallerygallery-photo-gallery
PixTypespixtypes
Popup by Supsysticpopup-by-supsystic
Portfolio and Projectsportfolio-and-projects
Post Grid Combo – 36+ Blocks for Gutenbergpost-grid
Post Timelinepost-timeline
Premium Courses & eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS & TutorLMSpmpro-courses
Premium Packages – Sell Digital Products Securelywpdm-premium-packages
Printful Integration for WooCommerceprintful-shipping-for-woocommerce
Product Attachment for WooCommercewoo-product-attachment
Profile Builder – User Profile & User Registration Formsprofile-builder
Rate my Post – WP Rating Systemrate-my-post
Real Estate Manager – Property Listing and Agent Managementreal-estate-manager
Realiarealia
Responsive WordPress Slider – Avartan Slider Liteavartan-slider-lite
SB Child Listsb-child-list
SendPress Newsletterssendpress
Sign-up Sheetssign-up-sheets
Stock Tickerstock-ticker
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Gridthe-post-grid
Theme Demo Importtheme-demo-import
Themesflat Addons For Elementorthemesflat-addons-for-elementor
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Pluginultimate-member
User Activity Loguser-activity-log
User Activity Tracking and Loguser-activity-tracking-and-log
Visual Website Collaboration, Feedback & Project Management – Atarimatarim-visual-collaboration
WP 404 Auto Redirect to Similar Postwp-404-auto-redirect-to-similar-post
WP Categories Widgetwp-categories-widget
WP Like Buttonwp-like-button
WP Pipeswp-pipes
WooCommerce PDF Invoice Builder, Create invoices, packing slips and morewoo-pdf-invoice-builder
WxSync-标准云微信公众号文章免费采集-任意公众 style=”height: 40px; background-color: rgba(45, 45, 45, 0.05); width: 23.8959%; text-align: center;”>wxsync
YITH WooCommerce Waitlistyith-woocommerce-waiting-list
demon image annotationdemon-image-annotation
flowpaperflowpaper-lite-pdf-flipbook
wSecure Litewsecure
woocommerce-one-page-checkoutwoocommerce-one-page-checkout

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Avada | Website Builder For WordPress & WooCommerceAvada
Bethemebetheme
Business Probusiness-pro

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities.

Kadence Blocks

Source: wordfence.com

Translate this article

TAGGED: Authentication, PoC, Security, Server side request forgery, Software, SQL injection, Threat, Threats, Vulnerabilities, WordPress, WordPress plugins, Worpdress
10alert August 17, 2023 August 17, 2023
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Xbox celebrates gaming and disability community
Windows 7 hours ago
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
Apps 7 hours ago
Running Serverless Puppeteer with Workers and Durable Objects
Running Serverless Puppeteer with Workers and Durable Objects
Apps 7 hours ago
everything we announced — plus an AI-powered opportunity for startups
everything we announced — plus an AI-powered opportunity for startups
Apps 7 hours ago
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Wordpress Threats 11 hours ago

You Might Also Like

Windows

Xbox celebrates gaming and disability community

7 hours ago
everything we announced — plus an AI-powered opportunity for startups
Apps

everything we announced — plus an AI-powered opportunity for startups

7 hours ago
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
Wordpress Threats

Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware

11 hours ago
Easily manage AI crawlers with our new bot categories
Apps

Easily manage AI crawlers with our new bot categories

1 day ago
Show More

Related stories

How to install September 2023 update with 23H2 features for Windows 11
How to upgrade to Windows 11 23H2 with Installation Assistant
How to get the latest Windows 11 innovations
How to blur image background in Photos for Windows 11
How to download official Windows 11 23H2 ISO file
PHP Object Injection Vulnerability in Flatsome Theme

10 New Stories

How to create Copilot desktop shortcut on Windows 11
Easily manage AI crawlers with our new bot categories
Cloudflare is free of CAPTCHAs; Turnstile is free for everyone
Post-quantum cryptography goes GA
Detecting zero-days before zero-day
See what threats are lurking in your Office 365 with Cloudflare Email Retro Scan
Previous Next
Hot News
Xbox celebrates gaming and disability community
A Socket API that works across JavaScript runtimes — announcing a WinterCG spec and Node.js implementation of connect()
Running Serverless Puppeteer with Workers and Durable Objects
everything we announced — plus an AI-powered opportunity for startups
Know your Malware – A Beginner’s Guide to Encoding Techniques Used to Obfuscate Malware
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?