plugin

Wordfence Vulnerabilities

12 known security issues reported for the Wordfence WordPress plugin. Most recent disclosed Sep 6, 2022.

5 high 7 medium

Running Wordfence on your site? Check whether your installed version is affected.

Scan your site free

Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to...

CVSS:
4.4
Affected:
up to 7.6.0
Fixed in:
7.6.1
Disclosed:
Sep 6, 2022

CVE-2022-3144 on NVD →

Wordfence Security – Firewall & Malware Scan <= 7.1.13 - Reflected Cross-Site Scripting and Information Disclosure

medium

Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as full path disclosure and author name disclosure.

CVSS:
4.7
Affected:
up to 7.1.14
Fixed in:
7.1.14
Disclosed:
Oct 2, 2018

Wordfence Security – Firewall & Malware Scan 6.1.1 - 6.1.6 - Reflected Cross-Site Scripting

medium

The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adminURL’ parameter in versions 6.1.1 through 6.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
6.1.1 – 6.1.6
Fixed in:
6.1.7
Disclosed:
May 10, 2016

Wordfence <= 5.1.4 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.

CVSS:
6.1
Affected:
up to 5.1.5
Fixed in:
5.1.5
Disclosed:
Dec 8, 2014

CVE-2014-4932 on NVD →

Wordfence Security <= 5.2.3 - Stored Cross-Site Scripting via HTTP_HOST

high

The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['HTTP_HOST']' in PHP in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts in pages...

CVSS:
7.2
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Sep 27, 2014

Wordfence <= 5.2.3 - Stored Cross-Site Scripting via REQUEST_URI

high

The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
7.2
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Sep 14, 2014

Wordfence <= 5.2.3 - Multiple Protection Mechanism Bypasses

medium

The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. These allow unauthenticated attackers to bypass exploit protection and throttling restrictions.

CVSS:
6.5
Affected:
up to 5.2.4
Fixed in:
5.2.4
Disclosed:
Sep 14, 2014

Wordfence <= 5.2.2 - Stored Cross-Site Scripting

high

The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 5.2.3
Fixed in:
5.2.3
Disclosed:
Sep 8, 2014

Wordfence Security <= 3.8.1 - Stored Cross-Site Scripting

high

The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wfwhois’ parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
7.2
Affected:
up to 3.8.1
Fixed in:
3.8.3
Disclosed:
Aug 1, 2014

Wordfence Security – Firewall & Malware Scan <= 5.1.3 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php.

CVSS:
7.2
Affected:
up to 5.1.3
Fixed in:
5.1.4
Disclosed:
Jul 30, 2014

CVE-2014-4664 on NVD →

Wordfence Security - Firewall & Malware Scan <= 3.3.6 - Stored Cross-Site Scripting

medium

WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail functionality.

CVSS:
6.5
Affected:
up to 3.3.6
Fixed in:
3.3.7
Disclosed:
Oct 19, 2012

Wordfence < 3.3.7 - Reflected Cross-Site Scripting

medium

The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ parameter in versions before 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 3.3.7
Fixed in:
3.3.7
Disclosed:
Oct 19, 2012

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database