Wordfence Intelligence Weekly WordPress Vulnerability Report (July 10, 2023 to July 16, 2023)
Note: We accidentally sent out an email for this report with last weeks subject line. Due to the subject line not being very different week to week for this report, we opted to just leave it as is and not send a follow-up email. We apologize for this error on our part!
Last week, there were 69 vulnerabilities disclosed in 68 WordPress Plugins and 1 WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 29 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.
Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface and vulnerability API are completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.
Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.
New Firewall Rules Deployed Last Week
The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.
The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:
- WAF-RULE-618 – Information redacted while we work with the developer to ensure this gets patched.
Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.
Total Unpatched & Patched Vulnerabilities Last Week
Patch Status | Number of Vulnerabilities |
Unpatched | 16 |
Patched | 53 |
Total Vulnerabilities by CVSS Severity Last Week
Severity Rating | Number of Vulnerabilities |
Low Severity | 0 |
Medium Severity | 52 |
High Severity | 17 |
Critical Severity | 0 |
Total Vulnerabilities by CWE Type Last Week
Vulnerability Type by CWE | Number of Vulnerabilities |
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) | 25 |
Cross-Site Request Forgery (CSRF) | 14 |
Missing Authorization | 14 |
Server-Side Request Forgery (SSRF) | 3 |
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) | 3 |
Information Exposure | 3 |
Authorization Bypass Through User-Controlled Key | 2 |
Unprotected Storage of Credentials | 1 |
Incorrect Authorization | 1 |
Use of Less Trusted Source | 1 |
URL Redirection to Untrusted Site (‘Open Redirect’) | 1 |
Incorrect Privilege Assignment | 1 |
Researchers That Contributed to WordPress Security Last Week
Researcher Name | Number of Vulnerabilities |
Rafie Muhammad | 8 |
Mika | 6 |
Lana Codes (Wordfence Vulnerability Researcher) | 5 |
LEE SE HYOUNG | 3 |
Erwan LR | 3 |
Phd | 3 |
Alex Thomas (Wordfence Vulnerability Researcher) | 3 |
Abdi Pranata | 3 |
Yuki Haruma | 2 |
emad | 2 |
Nguyen Xuan Chien | 2 |
Le Hong Minh | 2 |
Dave Jong | 2 |
Andreas Damen | 1 |
yuyudhn | 1 |
Fariq Fadillah Gusti Insani | 1 |
Nithissh S | 1 |
Ullash Raj | 1 |
Emili Castells | 1 |
Rafshanzani Suhada | 1 |
Bob Matyas | 1 |
Ravi Dharmawan | 1 |
Paul Goodchild | 1 |
Skalucy | 1 |
Cat | 1 |
WPScanTeam | 1 |
Kindaichi Hiro | 1 |
Shreya Pohekar | 1 |
Rio Darmawan | 1 |
Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and obtain a CVE ID through this form. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.
WordPress Plugins with Reported Vulnerabilities Last Week
Software Name | Software Slug |
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | armember-membership |
All-In-One Security (AIOS) – Security and Firewall | all-in-one-wp-security-and-firewall |
Art Direction | art-direction |
Authors List | authors-list |
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin | bookingpress-appointment-booking |
BuddyPress Builder for Elementor – BuddyBuilder | stax-buddy-builder |
Buy Me a Coffee – Button and Widget Plugin | buymeacoffee |
Checkout with Zelle on Woocommerce | wc-zelle |
Coming Soon Chop Chop | cc-coming-soon |
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms | fluentform |
Custom Field For WP Job Manager | custom-field-for-wp-job-manager |
Custom Fields for WooCommerce | addify-custom-fields-for-woocommerce |
Custom Registration Forms Builder for WooCommerce | addify-custom-registration-forms-builder |
DirectoryPress – Business Directory And Classified Ad Listing | directorypress |
Dovetail | dovetail |
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels | wpfunnels |
Export and Import Users and Customers | users-customers-import-export-for-wp-woocommerce |
Falang multilanguage for WordPress | falang |
Forminator – Contact Form, Payment Form & Custom Form Builder | forminator |
Grid Kit Premium | grid-kit-premium |
HTTP Headers | http-headers |
IP2Location Country Blocker | ip2location-country-blocker |
Image Watermark for WooCommerce | addify-image-watermark-for-woocommerce |
Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site | integrate-google-drive |
Integration for Contact Form 7 and Salesforce | cf7-salesforce |
JetFormBuilder — Dynamic Blocks Form Builder | jetformbuilder |
KB Support – WordPress Help Desk | kb-support |
MF Gig Calendar | mf-gig-calendar |
Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking | mail-control |
MailArchiver | mailarchiver |
Media Library Assistant | media-library-assistant |
OptiMonk: Popups, Personalization & A/B Testing | exit-intent-popups-by-optimonk |
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress | post-smtp |
Premium Addons Pro for Elementor | premium-addons-pro |
Price Calculator for WooCommerce | addify-price-calculator-for-woocommerce |
Product Dynamic Pricing and Discounts for WooCommerce | addify-product-dynamic-pricing-and-discounts |
Radio Forge Muses Player with Skins | radio-forge |
Replace Word | replace-word |
School Management System – WPSchoolPress | wpschoolpress |
Short URL | shorten-url |
Shortcode IMDB | shortcode-imdb |
Social Media Icons Widget | spoontalk-social-media-icons-widget |
Social Share, Social Login and Social Comments Plugin – Super Socializer | super-socializer |
Spectra – WordPress Gutenberg Blocks | ultimate-addons-for-gutenberg |
Terms descriptions | terms-descriptions |
Twittee Text Tweet | twittee-text-tweet |
User Activity Log | user-activity-log |
Variation Images Gallery for WooCommerce | woo-product-variation-gallery |
Variation Swatches for WooCommerce | woo-product-variation-swatches |
WP Default Feature Image | wp-default-feature-image |
WP Social AutoConnect | wp-fb-autoconnect |
WP Testimonials | testimonial-widgets |
WPAdmin AWS CDN | aws-cdn-by-wpadmin |
WooCommerce Abandoned Cart Recovery | addify-abandoned-cart-recovery |
WooCommerce Advanced Free Gifts | addify-free-gifts-woocommerce |
WooCommerce Checkout Field Manager | addify-checkout-fields-manager |
WooCommerce Custom Order Number | addify-custom-order-number |
WooCommerce Gift Registry | addify-gift-registry-for-woocommerce |
WooCommerce GoCardless Gateway | woocommerce-gateway-gocardless |
WooCommerce Order Approval | addify-order-approval-woocommerce |
WooCommerce Order Tracking | addify-order-tracking-for-woocommerce |
WooCommerce Pre-Orders | woocommerce-pre-orders |
WooCommerce Product Labels and Stickets | addify-product-labels-and-stickers |
WooCommerce Product Stock Alert | woocommerce-product-stock-alert |
WooCommerce Ship to Multiple Addresses | woocommerce-shipping-multiple-addresses |
WooCommerce Warranty Requests | woocommerce-warranty |
Zippy | zippy |
cartflows-pro | cartflows-pro |
WordPress Themes with Reported Vulnerabilities Last Week
Software Name | Software Slug |
RealHomes | realhomes |
Vulnerability Details
Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities.
JetFormBuilder
Source: wordfence.com