{"error":0,"message":null,"data":{"name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security","plugin":"wordfence","link":"https:\/\/wordpress.org\/plugins\/wordfence\/","latest":"1788882000","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e349136eb4bb902c7d28deeb0b9642b83054378d5313c57bfc1059bd54507f66","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] <= 7.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.2.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-9669","name":"CVE-2019-9669","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-9669","description":"[en] The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as the firewall rules are not maintained as part of the Wordfence software but rather it is a set of rules hosted on vendor servers and pushed to the plugin with no versioning associated. Bypassing a WAF rule doesn't make a WordPress site vulnerable (speaking in terms of software vulnerabilities)","date":"2019-04-25"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"3c9b64a2808e9c56ff6b6c74cf07baf21444e2b11ebcc55816062cf9175191bc","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-4932","name":"CVE-2014-4932","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-4932","description":"[en] Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.","date":"2018-08-28"},{"id":"f76207484d3de8320c42a2ecb8f7d0106d20188a","name":"WordPress Wordfence Plugin <= 5.1.4 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-1-4-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate plugin.","date":"2015-12-09"},{"id":"bcfccd3703dcf4ecb94eca29da2f50e8263f25e5","name":"Wordfence <= 5.1.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-514-reflected-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.","date":"2014-12-08"},{"id":"cc0457e1-0d4a-413a-89a5-330a4a96d1bd","name":"Wordfence &lt;= 5.1.4 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/cc0457e1-0d4a-413a-89a5-330a4a96d1bd","description":"An attacker can inject arbitrary script via the vulnerable query string parameter val of the whois.php file.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"2f159a5306fe6d187fce0c7e19205a5c10b594bfcda016a11255c7acf8804587","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-4664","name":"CVE-2014-4664","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-4664","description":"[en] Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin\/admin.php.","date":"2014-11-06"},{"id":"235a15d2d52bdfc1138a93c19e7a7f4df754688d","name":"WordPress Wordfence Security Plugin <= 5.1.3 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-security-plugin-5-1-3-xss","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML via the \"whoisval\" parameter on the WordfenceWhois page to wp-admin\/admin.php.\nUpdate the plugin.","date":"2014-06-26"},{"id":"ac0b05c21f604627cc456d8a330539fbe3bf53c1","name":"Wordfence Security \u2013 Firewall & Malware Scan <= 5.1.3 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-firewall-malware-scan-513-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the WordfenceWhois page to wp-admin\/admin.php.","date":"2014-07-30"},{"id":"7ab4c0ab-0d45-42b4-8742-61183d7f69a7","name":"Wordfence &lt;= 5.2.4 - Multiple Vulnerabilities (XSS &amp; Bypasses)","link":"https:\/\/wpscan.com\/vulnerability\/7ab4c0ab-0d45-42b4-8742-61183d7f69a7","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a Multiple Vulnerabilities (XSS &amp; Bypasses) security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e769011f073f35d050c127ff6d2b0c8d4608aadf8b2f2a5cf6887766ce46c16f","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8a8518c2a9deece43620f1060eef60d9ffc39b3d","name":"WordPress Wordfence Plugin <= 5.2.3 - Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-2-3-bypass","description":"This plugin is prone to banned IP functionality bypass vulnerability. Unlogged requests won't trigger automatic throttling and banning.\nUpdate plugin.","date":"2015-06-24"}],"impact":[]},{"uuid":"84aabc395e2b4afbf2c636bc41353221d98f0f745616d5d0b784df08b1adcadc","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.3.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"67916c18ee318bd5da19c7290f2f7d7934b14ee4","name":"WordPress Wordfence Security Plugin -  Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-security-plugin-cross-site-scripting","description":"WordPress Wordfence Security plugin is prone to a cross-site scripting vulnerability.  It fails to properly clean up user-supplied input.  An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials.  Other attacks are also possible.\nUpdate the plugin.","date":"2012-10-18"}],"impact":[]},{"uuid":"1582a518b43018bfb630d66adc85e3737aa111d37c52f4f819a04d4ede435384","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] <= 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"b37d06ffd3f117f4c7029a3516db9f0448311740","name":"WordPress Wordfence Security Plugin - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-security-plugin-multiple-vulnerabilities","description":"WordPress Wordfence Security plugin is prone to multiple HTML injection and security bypass vulnerabilities. These issues allow HTML and script code run in the context of the affected browser. In this way an attacker can steal cookie-based authentication credentials or control how the site is rendered to the user.\nUpgrade the plugin.","date":"2014-09-14"}],"impact":[]},{"uuid":"509e0e77b8fed618abb9d54dca5576e98d6ff4e09fdd04396d5a302efb26af6a","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"29c808b2225f38c0a4ffba7685fca9a6480ef8ee","name":"WordPress Wordfence Plugin <= 3.8.6 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-3-8-6-stored-xss","description":"This plugin is prone to lib\/IPTraf.php User-Agent header stored cross site scripting vulnerability.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"9ec8d069904df03176e6dba4e58ad2f5560412e92979aff82d90a1c5bb2c88e4","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"aa1daeda409de798477499d7e3bbc60935cd56b0","name":"WordPress Wordfence Plugin <= 5.2.3 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-2-3-multiple-vulnerabilities","description":"This plugin is prone to stored XSS, insufficient logging, throttle bypass and exploit detection bypass vulnerabilities.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"3d6938b3fa1941e550044cf0f11253dab62d9f84ae477efa9f1ec29f2b7444cf","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7bb3650b3cd75da872db9413ee1dfe7f3af511c0","name":"WordPress Wordfence Plugin <= 3.8.1 - Bypass","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-3-8-1-bypass","description":"This plugin is prone to a password creation restriction bypass vulnerability.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"bb471c36f639591281684ecace6efb8c371b8d68a72ea7e2d26eef4e9a0bb68c","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f0a4d63cf29c5d522c5c9bde1e9d9325ffc1417e","name":"WordPress Wordfence Plugin <= 5.2.4 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-2-4-stored-xss","description":"This plugin is prone to IPTraf.php URI request stored cross site scripting vulnerability.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"ba2b29b2a445ecb3250b60174c14e52daef151f6fefc4b4917e95d0886e94d1c","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b6e5f232ebfadbd8c0ffb355d5890a12526d5437","name":"WordPress Wordfence Plugin <= 5.2.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-2-2-cross-site-scripting","description":"This plugin is prone to cross site scripting in referer header.  Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"7e928e56b2073cbee853cf4d56e37364615ea1db4ec3df9685d4337945d763fe","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"91f7b7c686cb5476b11b60a1eef9fdd19522315d","name":"WordPress Wordfence Plugin <= 3.8.1 - Stored XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-3-8-1-stored-xss","description":"This plugin is prone to wp-admin\/admin.php whois parameter stored cross site scripting vulnerability.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"361ffa3ca1a452c8ee907e1153e18d72c0a2ddb3a3ca600648ae9cdbcf9438e5","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.3.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3e127008295d09f964a6dce8c80f5705dbf6d5e8","name":"WordPress Wordfence Plugin <=  3.3.5 - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-3-3-5-multiple-vulnerabilities","description":"This plugin is prone to \"email\" cross site scripting and insufficient anti-automation vulnerabilities.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"cf8ffe159f9a1a755dc7b9d72c4aa5e63d35ef8c02dd919216d9992a43693dca","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6009a5606267f94fed88ae990c685c90cbe2f472","name":"WordPress Wordfence Plugin <= 5.2.4 - Unspecified Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-plugin-5-2-4-unspecified-vulnerability","description":"This plugin is prone to an unspecified issue.\nUpdate plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"944f1f34d39afd7d6d616900b83a6d35ae60227651ff0012312a2825e828fc01","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 7.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3144","name":"CVE-2022-3144","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3144","description":"[en] The Wordfence Security \u2013 Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.","date":"2022-09-23"},{"id":"a3c5b2202065291ddca4b42dc6a26ec4dcf0eca6","name":"WordPress Wordfence Security \u2013 Firewall & Malware Scan plugin <= 7.6.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wordfence\/vulnerability\/wordpress-wordfence-security-firewall-malware-scan-plugin-7-6-0-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Ori Gabriel in WordPress Wordfence Security \u2013 Firewall & Malware Scan plugin (versions <= 7.6.0).\nUpdate the WordPress Wordfence plugin to the latest available version (at least 7.6.1).","date":"2022-09-07"},{"id":"bce2c080eaecd25a9757e4405886cd3f3da4b094","name":"Wordfence Security \u2013 Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-firewall-malware-scan-760-authenticated-admin-stored-cross-site-scripting","description":"The Wordfence Security \u2013 Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version.","date":"2022-09-06"},{"id":"3f3273f3-bc73-4a3e-8ba7-c5a31c4a1c8c","name":"Wordfence &lt; 7.6.1 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/3f3273f3-bc73-4a3e-8ba7-c5a31c4a1c8c","description":"The plugin does not sanitise and escape a settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b0684bf7a8f8c4e91944579c1d9e4f05dbf79983bb6bd7659ef516fc1b04d886","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 7.1.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2f056e25ad5b18699d5517d2e613a05efd8f0ca6","name":"Wordfence Security \u2013 Firewall & Malware Scan <= 7.1.13 - Reflected Cross-Site Scripting and Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-firewall-malware-scan-7113-reflected-cross-site-scripting-and-information-disclosure","description":"Wordfence before 7.1.14 was vulnerable in certain unusual configurations to Reflected Cross-Site Scripting, as well as full path disclosure and author name disclosure.","date":"2018-10-02"}],"impact":[]},{"uuid":"245ec1db792bc3468b6d6c40874f3067dbcfe7e1745e3416daee261c3e050030","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 6.1.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"00aa547baa4c4b4b05cf8510a103d29aece5b127","name":"Wordfence Security \u2013 Firewall & Malware Scan 6.1.1 - 6.1.6 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-firewall-malware-scan-611-616-reflected-cross-site-scripting","description":"The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018adminURL\u2019 parameter in versions 6.1.1 through 6.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2016-05-10"}],"impact":[]},{"uuid":"a4270803639143bbec3811f67d35e21bd6de402c6669dc4a325e7fd1042b6579","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"18c637b225d0b0074b2f37a9b70fb7ba7067a9cb","name":"Wordfence Security <= 5.2.3 - Stored Cross-Site Scripting via HTTP_HOST","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-523-stored-cross-site-scripting-via-http-host","description":"The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the  '$_SERVER['HTTP_HOST']' in PHP in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-09-27"}],"impact":[]},{"uuid":"17ae3c8f844e93ea794a882be212f246ea44af0b3283c3ae684770d80c9f5b6a","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"015cc9543604353e9c1cfc46fc6b90a54347301e","name":"Wordfence <= 5.2.3 - Multiple Protection Mechanism Bypasses","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-523-multiple-protection-mechanism-bypasses","description":"The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. These allow unauthenticated attackers to bypass exploit protection and throttling restrictions.","date":"2014-09-14"}],"impact":[]},{"uuid":"efc6f73c236e326d9c975fe3da3e109a2638765ba7ae704473901aadc792b97a","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"de7cd82330b9b2b70bbf776455817639c0ec927e","name":"Wordfence <= 5.2.3 - Stored Cross-Site Scripting via REQUEST_URI","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-523-stored-cross-site-scripting-via-request-uri","description":"The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-09-14"}],"impact":[]},{"uuid":"15a602cc6df2c6aaf3400e04eaa61ab326890731bbfdb949e79e89424cb7a065","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6d1be3726685d6d3f1ada6a1cf21c388af9850f9","name":"Wordfence <= 5.2.2 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-522-stored-cross-site-scripting","description":"The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-09-08"}],"impact":[]},{"uuid":"ba50a8a61674fbb7d5e0d076a6f8d789daeb95f02b96a16ef868aa2b2f6e54d2","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ff1670440500e40c312ed955e2945e75d4958012","name":"Wordfence Security <= 3.8.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-381-stored-cross-site-scripting","description":"The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wfwhois\u2019 parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2014-08-01"}],"impact":[]},{"uuid":"770fdeed1770b95a7315b07e8a7aadb6f160f110dc04e1214b2f560ba3c29888","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.3.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cca2d8e2dfed9c7b1d5e0ff49c957bedb659c1d5","name":"Wordfence < 3.3.7 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-337-reflected-cross-site-scripting","description":"The Wordfence plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018email\u2019 parameter in versions before 3.3.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2012-10-19"}],"impact":[]},{"uuid":"e9e05c7525f4390003269e6d12e04c8930fb2a6cb9bb648461cae5490b06f770","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.3.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d5fe5158ce62d2423ee77ed31efe1d73c6bd182c","name":"Wordfence Security - Firewall & Malware Scan <= 3.3.6 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wordfence\/wordfence-security-firewall-malware-scan-336-stored-cross-site-scripting","description":"WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail functionality.","date":"2012-10-19"}],"impact":[]},{"uuid":"2fc5871059fbb4e1d69396d163798eb672cb75d14c3f3ab75058988b41f58d56","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 7.1.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"007d0d95-be0c-4f08-bb9b-2f7ff9953fda","name":"Wordfence &lt;= 7.1.12 - Username Enumeration Prevention Bypass","link":"https:\/\/wpscan.com\/vulnerability\/007d0d95-be0c-4f08-bb9b-2f7ff9953fda","description":"The plugin protection against user enumeration (ie ?author=id) could be bypassed by using an array as author parameter","date":null}],"impact":[]},{"uuid":"4f21af1f7176a2371e07546aa7d06af5dd5fc7fff6066f7ae89168dc46ef71af","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"514cc85e-b184-4673-8b7e-718b3eca0c4d","name":"Wordfence 5.2.2 - XSS in Referer Header","link":"https:\/\/wpscan.com\/vulnerability\/514cc85e-b184-4673-8b7e-718b3eca0c4d","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a XSS in Referer Header security vulnerability.","date":null}],"impact":[]},{"uuid":"8cc785cd79c38881bf8f24042520404b3f534c5f433367899dd17023b88a7655","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b7101912-11de-477e-85e7-dc191ef260f7","name":"Wordfence 5.2.3 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/b7101912-11de-477e-85e7-dc191ef260f7","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.","date":null}],"impact":[]},{"uuid":"e0a54980cf647fcd42ffd9c724ce06ef78e532f4a2e2e03ff6c84c514590b1b4","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1e2e1d07-426f-4f00-b0f6-b1480e4a5893","name":"Wordfence 5.2.3 - Banned IP Functionality Bypass","link":"https:\/\/wpscan.com\/vulnerability\/1e2e1d07-426f-4f00-b0f6-b1480e4a5893","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a Banned IP Functionality Bypass security vulnerability.","date":null}],"impact":[]},{"uuid":"9187afc495a017520df125ee05a6ffcd54b290d51b00f77b4d69e97322e78e6a","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0d15602b-ef3d-4bdc-9789-8156221218cb","name":"Wordfence 5.2.4 - IPTraf.php URI Request Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/0d15602b-ef3d-4bdc-9789-8156221218cb","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by an IPTraf.php URI Request Stored XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"408edbf03b955c6af645d71739a7854fbc84a5f3cbf110a3bae8755f7b0ba6fd","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d161193d-f1e1-4b40-acc5-7a8e8fa221ab","name":"Wordfence 5.2.4 - Unspecified Issue","link":"https:\/\/wpscan.com\/vulnerability\/d161193d-f1e1-4b40-acc5-7a8e8fa221ab","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by an Unspecified Issue security vulnerability.","date":null}],"impact":[]},{"uuid":"dade0fe406bd9c820f4e97326e385547f6cc4144f489bbacc05fddbcedb3f11c","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.3.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.3.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ee00e949-7bad-4e50-92f0-5b860223044d","name":"Wordfence 3.3.5 - XSS &amp; IAA","link":"https:\/\/wpscan.com\/vulnerability\/ee00e949-7bad-4e50-92f0-5b860223044d","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a XSS &amp; IAA security vulnerability.","date":null}],"impact":[]},{"uuid":"4e988389b37350be323c14659ecf01fd28544cb3fcb99a8ca9c6e9b6ceff8d50","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"81ae1e9c-016f-4a0e-a5a4-57d5596ea057","name":"Wordfence 3.8.1 - wp-admin\/admin.php whois Parameter Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/81ae1e9c-016f-4a0e-a5a4-57d5596ea057","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a wp-admin\/admin.php whois Parameter Stored XSS security vulnerability.","date":null}],"impact":[]},{"uuid":"d27d9d61509cd42e8a4c496ece546899dbf90b784300b06780074aa8e552ed75","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e8db92cf-6a4c-4890-88ae-588a8f288a60","name":"Wordfence 3.8.1 - Password Creation Restriction Bypass","link":"https:\/\/wpscan.com\/vulnerability\/e8db92cf-6a4c-4890-88ae-588a8f288a60","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a Password Creation Restriction Bypass security vulnerability.","date":null}],"impact":[]},{"uuid":"3076f787ede8b46ef89b3eb21c365baae9730c8713bf36ac001101130f031c87","name":"Wordfence Security &#8211; Firewall, Malware Scan, and Login Security [wordfence] < 3.8.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ed08c0e6-db27-45d6-8304-8feadf85261e","name":"Wordfence 3.8.6 - lib\/IPTraf.php User-Agent Header Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/ed08c0e6-db27-45d6-8304-8feadf85261e","description":"The Wordfence Security &ndash; Firewall &amp; Malware Scan WordPress plugin was affected by a lib\/IPTraf.php User-Agent Header Stored XSS security vulnerability.","date":null}],"impact":[]}]},"updated":"1776153795"}