By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    An Android that robbed your bank account -Kaspersky Daily
    1 year ago
    New CryptoLocker-like Malware for Android
    1 year ago
    Apple Watch And The Other Smartwatches
    1 year ago
    Latest News
    How To Disable PHP Execution and Directory Browsing?
    15 hours ago
    Patchstack Becomes Member Of Open Source Security Foundation
    2 days ago
    PDF Phishing: Beyond the Bait
    2 days ago
    Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
    2 days ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    How To Configure Cloudflare To Maximize WordPress Speed + Security
    1 year ago
    Windows 11 build 25179 rolls out in the Dev Channel
    1 year ago
    How to set a static IP address on Windows 11
    1 year ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    10 months ago
    Now you can speed up any video in your browser
    10 months ago
    How to restore access to a file after EFS or view it on another computer?
    10 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    11 months ago
  • How To
    How ToShow More
    Latest copyright decision in Germany rejects blocking through global DNS resolvers
    Latest copyright decision in Germany rejects blocking through global DNS resolvers
    22 hours ago
    Restricted Settings in Android 13 and 14
    22 hours ago
    A year in recap: Windows accessibility
    2 days ago
    How to stop, disable, and remove any Android apps — even system ones
    4 days ago
    Bigger, Better, Cooler in a 2U1N form factor
    Bigger, Better, Cooler in a 2U1N form factor
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    New Easter eggs in the Google search engine
    1 year ago
    How to view all user accounts on Windows 11
    1 year ago
    How to change sleep power settings on Windows 10
    11 months ago
    Latest News
    How to check CPU temp on Windows 11
    1 day ago
    How to disable news feed from Widgets on Windows 11
    2 days ago
    How to fix performance issues after upgrading to Windows 11 23H2
    2 days ago
    How to disable updates on Windows 10 Pro and Home
    3 days ago
  • Glossary
  • My Bookmarks
Reading: Wordfence Intelligence Weekly WordPress Vulnerability Report (October 9, 2023 to October 15, 2023)
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
Wordpress Threats

Wordfence Intelligence Weekly WordPress Vulnerability Report (October 9, 2023 to October 15, 2023)

10alert
Last updated: 19 October
10alert 2 months ago
Share
10 Min Read

Wordfence Intelligence Weekly WordPress Vulnerability Report (October 9, 2023 to October 15, 2023)

Last week, there were 103 vulnerabilities disclosed in 85 WordPress Plugins and no WordPress themes, with 7 of those being in WordPress Core, that have been added to the Wordfence Intelligence Vulnerability Database, and there were 46 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected.

Contents
Wordfence Intelligence Weekly WordPress Vulnerability Report (October 9, 2023 to October 15, 2023)New Firewall Rules Deployed Last WeekTotal Unpatched & Patched Vulnerabilities Last WeekTotal Vulnerabilities by CVSS Severity Last WeekTotal Vulnerabilities by CWE Type Last WeekResearchers That Contributed to WordPress Security Last WeekWordPress Plugins with Reported Vulnerabilities Last WeekVulnerability DetailsAccessibility Suite by Online ADA Source: wordfence.com

Our mission with Wordfence Intelligence is to make valuable vulnerability information easily accessible to everyone, like the WordPress community, so individuals and organizations alike can utilize that data to make the internet more secure. That is why the Wordfence Intelligence user interface, vulnerability API and webhook integration are completely free to access and utilize both personally and commercially, and why we are running this weekly vulnerability report.

Individuals and Enterprises can use the vulnerability Database API to receive a complete dump of our database of over 12,000 vulnerabilities and then utilize the webhook integration to stay on top of the newest vulnerabilities added in real-time, as well as any updates made to the database, all for free.

Click here to sign-up for our mailing list to receive weekly vulnerability reports like this and important WordPress Security reports in your inbox the moment they are published.


New Firewall Rules Deployed Last Week

The Wordfence Threat Intelligence Team reviews each vulnerability to determine impact and severity, along with assessing the likelihood of exploitation, to verify that the Wordfence Firewall provides sufficient protection.

The team rolled out enhanced protection via firewall rules for the following vulnerabilities in real-time to our Premium, Care, and Response customers last week:

  • WordPress Core <6.3.2 – Authenticated (Subscriber+) Arbitrary Shortcode Execution
  • WordPress Core 6.3 – 6.3.1 – Authenticated(Contributor+) Cross-Site Scripting via Footnotes Block

Wordfence Premium, Care, and Response customers received this protection immediately, while users still running the free version of Wordfence will receive this enhanced protection after a 30 day delay.


Total Unpatched & Patched Vulnerabilities Last Week

Patch StatusNumber of Vulnerabilities
Unpatched52
Patched51

Total Vulnerabilities by CVSS Severity Last Week

Severity RatingNumber of Vulnerabilities
Low Severity0
Medium Severity91
High Severity5
Critical Severity7

Total Vulnerabilities by CWE Type Last Week

Vulnerability Type by CWENumber of Vulnerabilities
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)46
Cross-Site Request Forgery (CSRF)26
Missing Authorization9
Information Exposure6
Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)4
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)3
Unrestricted Upload of File with Dangerous Type2
Improper Control of Generation of Code (‘Code Injection’)1
Improper Input Validation1
Guessable CAPTCHA1
URL Redirection to Untrusted Site (‘Open Redirect’)1
Improper Preservation of Consistency Between Independent Representations of Shared State1
External Control of File Name or Path1
Improper Neutralization of Special Elements in Output Used by a Downstream Component (‘Injection’)1

Researchers That Contributed to WordPress Security Last Week

Researcher NameNumber of Vulnerabilities
Mika11
Rio Darmawan8
thiennv8
Marco Wotschka
(Wordfence Vulnerability Researcher)
7
Abdi Pranata6
Rafie Muhammad5
Lana Codes
(Wordfence Vulnerability Researcher)
5
minhtuanact4
LEE SE HYOUNG3
Satoo Nakano2
DoYeon Park2
Skalucy2
yuyudhn2
Phd2
Lokesh Dachepalli2
Prasanna V Balaji2
Le Ngoc Anh2
Elliot2
Ala Arfaoui1
Nguyen Xuan Chien1
James Golovich1
WhiteCyberSec1
Karolis Narvilas1
Marc-Alexandre Montpas1
Francesco Marano1
qilin_991
Nano1
Vladislav Pokrovsky1
Chloe Chamberland
(Wordfence Vulnerability Researcher)
1
Edourard L1
Revan Arifio1
Jb Audras1
Jonas Höbenreich1
SeungYongLee1
Enrico Marcolini1
Claudio Marchesini1
mascara77841
Fioravante Souza1
Jorge Costa1
s5s1
raouf_maklouf1
Bob Matyas1
Rafshanzani Suhada1
Bae Song Hyun1
Nguyen Anh Tien1
Emili Castells1

 

Are you a security researcher who would like to be featured in our weekly vulnerability report? You can responsibly disclose your WordPress vulnerability discoveries to us and obtain a CVE ID through this form. Responsibly disclosing your vulnerability discoveries to us will also get your name added on the Wordfence Intelligence leaderboard along with being mentioned in our weekly vulnerability report.


WordPress Plugins with Reported Vulnerabilities Last Week

Software NameSoftware Slug
AGP Font Awesome Collectionagp-font-awesome-collection
AI ChatBotchatbot
AMP WP – Google AMP For WordPressamp-wp
Accessibility Suite by Online ADAonline-accessibility
Add to Calendar Buttonadd-to-calendar-button
Amministrazione Trasparenteamministrazione-trasparente
ApplyOnline – Application Form Builder and Managerapply-online
BuddyPress Global Searchbuddypress-global-search
CITS Support svg, webp Media and TTF,OTF File Uploadcits-support-svg-webp-media-upload
CPT Shortcode Generatorcpt-shortcode
Campaign Monitor Forms by Optin Catcampaign-monitor-wp
Caret Country Access Limitcaret-country-access-limit
Comments Ratingscomments-ratings
Comments – wpDiscuzwpdiscuz
Constant Contact Forms by MailMunchconstant-contact-forms-by-mailmunch
Contact Form Generator : Creative form builder for WordPresscontact-form-generator
Contact Form With Captchacontact-form-with-captcha
Copy or Move Commentscopy-or-move-comments
Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPresscharitable
Easy Testimonial Slider and Formeasy-testimonial-rotator
Ebook Storeebook-store
Embed Calendlyembed-calendly-scheduling
Etsy Shopetsy-shop
Eupago Gateway For Woocommerceeupago-gateway-for-woocommerce
EventPrime – Events Calendar, Bookings and Ticketseventprime-event-calendar-management
Fast WP Speedfast-wp-speed
Fattura24fattura24
Feed Statisticswordpress-feed-statistics
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builderform-maker
GEO my WordPressgeo-my-wp
Gallery – Image and Video Gallery with Thumbnailsgallery-album
Get Custom Field Valuesget-custom-field-values
Gutenberggutenberg
HTML5 Mapshtml5-maps
History Log by click5history-log-by-click5
IMPress Listingswp-listings
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerceemail-subscribers
Image Regenerate & Select Cropimage-regenerate-select-crop
Lazy Load for Videoslazy-load-for-videos
LeadSquared Suiteleadsquared-suite
Libsyn Publisher Hublibsyn-podcasting
Login Screen Managerlogin-screen-manager
MailChimp Forms by MailMunchmailchimp-forms-by-mailmunch
Master Addons for Elementormaster-addons
Migration, Backup, Staging – WPvividwpvivid-backuprestore
Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPressnewsletter-bulk-email
Next Pagenext-page
Nexter Extensionnexter-extension
PDF Blockpdf-block
Peter’s Custom Anti-Spampeters-custom-anti-spam-image
PixFieldspixfields
Poll Maker – Best WordPress Poll Pluginpoll-maker
Post Gallerysimple-post-gallery
Print, PDF, Email by PrintFriendlyprintfriendly
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPageswplegalpages
Proofreadingproofreading
QR Twitter Widgetqr-twitter-widget
Remote Content Shortcoderemote-content-shortcode
Responsive Column Widgetsresponsive-column-widgets
Responsive Tabsresponsive-tabs
Royal Elementor Addons and Templatesroyal-elementor-addons
RumbleTalk Live Group Chat – HTML5rumbletalk-chat-a-chat-with-themes
Scroll post excerptscroll-post-excerpt
Sendle Shipping Pluginofficial-sendle-shipping-method
Simple File Listsimple-file-list
Simple Tweetsimple-tweet
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Managementsimple-urls
Slick Contact Formsslick-contact-forms
Snap Pixelsnap-pixel
Sort SearchResult By Titlesort-searchresult-by-title
SpiderVPlayerplayer
Taggbox – UGC Galleries, Social Media Widgets, User Reviews & Analyticstaggbox-widget
Thumbnail Slider With Lightboxwp-responsive-slider-with-lightbox
Tweepletweeple
Ultimate Taxonomy Managerultimate-taxonomy-manager
User Submitted Posts – Enable Users to Submit Posts from the Front Enduser-submitted-posts
Video Playlist For YouTubevideo-playlist-for-youtube
WP Attachmentswp-attachments
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accountingerp
WP GoToWebinarwp-gotowebinar
WP Lightbox 2wp-lightbox-2
WP Open Street Mapwp-open-street-map
WP ULike – Most Advanced WordPress Marketing Toolkitwp-ulike
WordPress Backup & Migrationwp-migration-duplicator
which template filewhich-template-file

Vulnerability Details

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities. If you’d like to receive real-time notifications whenever a vulnerability is added to the Wordfence Intelligence Vulnerability Database, check out our Slack and HTTP Webhook Integration, which is completely free to utilize.

Accessibility Suite by Online ADA

Source: wordfence.com

Translate this article

TAGGED: PoC, Security, Social engineering, Software, Split tunneling, SQL injection, Threat, Threats, Vulnerabilities, WordPress, WordPress plugins, Worpdress
10alert October 19, 2023 October 19, 2023
Share This Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

How To Disable PHP Execution and Directory Browsing?
How To Disable PHP Execution and Directory Browsing?
Wordpress Threats 18 hours ago
Latest copyright decision in Germany rejects blocking through global DNS resolvers
Latest copyright decision in Germany rejects blocking through global DNS resolvers
Apps 22 hours ago
Restricted Settings in Android 13 and 14
How To 22 hours ago
How to check CPU temp on Windows 11
News 1 day ago
Patchstack Becomes Member Of Open Source Security Foundation
Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats 2 days ago

You Might Also Like

How To Disable PHP Execution and Directory Browsing?
Wordpress Threats

How To Disable PHP Execution and Directory Browsing?

18 hours ago
Latest copyright decision in Germany rejects blocking through global DNS resolvers
Apps

Latest copyright decision in Germany rejects blocking through global DNS resolvers

22 hours ago
How To

Restricted Settings in Android 13 and 14

22 hours ago
Patchstack Becomes Member Of Open Source Security Foundation
Wordpress Threats

Patchstack Becomes Member Of Open Source Security Foundation

2 days ago
Show More

Related stories

Several Critical Vulnerabilities including Privilege Escalation, Authentication Bypass, and More Patched in UserPro WordPress Plugin
BridesMaid – neuron writes toasts For those very occasions when you need to give out a powerful
The other day Yandex pleased us with the announcement of a new Midi station – an excellent reason to listen
REMIX – remixes of pictures from neural networksCreate, share and correct works
How to download Diablo IV for free and absolutely legallyBlizzard has opened a free
Rostelecom employees were forced to abandon Android and iOS in favor of Aurora.
Previous Next

10 New Stories

PDF Phishing: Beyond the Bait
A year in recap: Windows accessibility
How to disable news feed from Widgets on Windows 11
How to fix performance issues after upgrading to Windows 11 23H2
Update ASAP! Critical Unauthenticated Arbitrary File Upload in MW WP Form Allows Malicious Code Execution
Fake CVE Phishing Campaign Tricks WordPress Users Into Installing Malware
Previous Next
Hot News
How To Disable PHP Execution and Directory Browsing?
Latest copyright decision in Germany rejects blocking through global DNS resolvers
Restricted Settings in Android 13 and 14
How to check CPU temp on Windows 11
Patchstack Becomes Member Of Open Source Security Foundation
10alert.com10alert.com
Follow US
© 10 Alert Network. All Rights Reserved.
  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?