Wordfence 3.8.6 - lib/IPTraf.php User-Agent Header Stored XSS
Wordfence Security – Firewall, Malware Scan, and Login Security
Minimum safe version
7.6.1
Update to 7.6.1 or later to address 32 fixable vulnerabilities
Wordfence 3.8.1 - Password Creation Restriction Bypass
Wordfence 3.8.1 - wp-admin/admin.php whois Parameter Stored XSS
Wordfence 3.3.5 - XSS & IAA
Wordfence 5.2.4 - Unspecified Issue
Wordfence 5.2.4 - IPTraf.php URI Request Stored XSS
Wordfence 5.2.3 - Banned IP Functionality Bypass
Wordfence 5.2.3 - Multiple Vulnerabilities
Wordfence 5.2.2 - XSS in Referer Header
Wordfence <= 7.1.12 - Username Enumeration Prevention Bypass
Wordfence Security - Firewall & Malware Scan <= 3.3.6 - Stored Cross-Site Scripting
Wordfence < 3.3.7 - Reflected Cross-Site Scripting
Wordfence Security <= 3.8.1 - Stored Cross-Site Scripting
Wordfence <= 5.2.2 - Stored Cross-Site Scripting
Wordfence <= 5.2.3 - Stored Cross-Site Scripting via REQUEST_URI
Wordfence <= 5.2.3 - Multiple Protection Mechanism Bypasses
Wordfence Security <= 5.2.3 - Stored Cross-Site Scripting via HTTP_HOST
Wordfence Security – Firewall & Malware Scan 6.1.1 - 6.1.6 - Reflected Cross-Site Scripting
Wordfence Security – Firewall & Malware Scan <= 7.1.13 - Reflected Cross-Site Scripting and Information Disclosure
CVE-2022-3144
WordPress Wordfence Plugin <= 5.2.4 - Unspecified Vulnerability
WordPress Wordfence Plugin <= 3.3.5 - Multiple Vulnerabilities
WordPress Wordfence Plugin <= 3.8.1 - Stored XSS
WordPress Wordfence Plugin <= 5.2.2 - Cross Site Scripting
WordPress Wordfence Plugin <= 5.2.4 - Stored XSS
WordPress Wordfence Plugin <= 3.8.1 - Bypass
WordPress Wordfence Plugin <= 5.2.3 - Multiple Vulnerabilities
WordPress Wordfence Plugin <= 3.8.6 - Stored XSS
WordPress Wordfence Security Plugin - Multiple Vulnerabilities
WordPress Wordfence Security Plugin - Cross Site Scripting
WordPress Wordfence Plugin <= 5.2.3 - Bypass
CVE-2014-4664
CVE-2014-4932
CVE-2019-9669