Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to...
- CVSS:
- 4.4
- Affected:
- up to 7.6.0
- Fixed in:
- 7.6.1
- Disclosed:
- Sep 6, 2022
CVE-2022-3144 on NVD →
Wordfence Security – Firewall & Malware Scan <= 7.1.13 - Reflected Cross-Site Scripting and Information Disclosure
medium
Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as full path disclosure and author name disclosure.
- CVSS:
- 4.7
- Affected:
- up to 7.1.14
- Fixed in:
- 7.1.14
- Disclosed:
- Oct 2, 2018
Wordfence Security – Firewall & Malware Scan 6.1.1 - 6.1.6 - Reflected Cross-Site Scripting
medium
The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘adminURL’ parameter in versions 6.1.1 through 6.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...
- CVSS:
- 6.1
- Affected:
- 6.1.1 – 6.1.6
- Fixed in:
- 6.1.7
- Disclosed:
- May 10, 2016
Wordfence <= 5.1.4 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
- CVSS:
- 6.1
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.5
- Disclosed:
- Dec 8, 2014
CVE-2014-4932 on NVD →
Wordfence Security <= 5.2.3 - Stored Cross-Site Scripting via HTTP_HOST
high
The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['HTTP_HOST']' in PHP in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts in pages...
- CVSS:
- 7.2
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Sep 27, 2014
Wordfence <= 5.2.3 - Stored Cross-Site Scripting via REQUEST_URI
high
The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- CVSS:
- 7.2
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Sep 14, 2014
Wordfence <= 5.2.3 - Multiple Protection Mechanism Bypasses
medium
The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. These allow unauthenticated attackers to bypass exploit protection and throttling restrictions.
- CVSS:
- 6.5
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.4
- Disclosed:
- Sep 14, 2014
Wordfence <= 5.2.2 - Stored Cross-Site Scripting
high
The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.3
- Disclosed:
- Sep 8, 2014
Wordfence Security <= 3.8.1 - Stored Cross-Site Scripting
high
The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wfwhois’ parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 7.2
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.3
- Disclosed:
- Aug 1, 2014
Wordfence Security – Firewall & Malware Scan <= 5.1.3 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin/admin.php.
- CVSS:
- 7.2
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Jul 30, 2014
CVE-2014-4664 on NVD →
Wordfence Security - Firewall & Malware Scan <= 3.3.6 - Stored Cross-Site Scripting
medium
WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail functionality.
- CVSS:
- 6.5
- Affected:
- up to 3.3.6
- Fixed in:
- 3.3.7
- Disclosed:
- Oct 19, 2012
Wordfence < 3.3.7 - Reflected Cross-Site Scripting
medium
The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘email’ parameter in versions before 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 3.3.7
- Fixed in:
- 3.3.7
- Disclosed:
- Oct 19, 2012
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database