Wordfence Security – Firewall, Malware Scan, and Login Security

Wordfence is a WordPress security plugin that offers a range of features, including an endpoint firewall, malware scanner, login security, live traffic views, and more. The plugin is powered by a team of dedicated analysts who research the latest malware variants and WordPress exploits, turning them into firewall rules and malware signatures that are released to customers in real-time. Wordfence also employs a global 24-hour dedicated incident response team that provides priority customers with a one-hour response time for any security incident. The plugin is considered the most comprehensive WordPress security solution available.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.2.3

    Fixed

    The Wordfence plugin for WordPress is not secure in versions up to 5.2.3. This vulnerability allows an attacker who is not logged in to inject malicious code into web pages that will be executed when...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 7.1.14

    Fixed

    Wordfence is a security plugin for WordPress websites. Before version 7.1.14, there were certain configurations that could have made it vulnerable to malicious attacks, such as Reflected Cross-Site S...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.2.3

    Fixed

    The Wordfence plugin for WordPress is vulnerable to a type of cyber attack known as Stored Cross-Site Scripting. This type of attack happens when a hacker injects malicious code into a website that i...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 3.3.6

    Fixed

    WordPress is a content management system used to create websites. A plugin is an additional feature that can be added to a website. Wordfence is a plugin for WordPress websites that provides a securi...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 3.3.7

    Fixed

    The Wordfence plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack can occur if the plugin is outdated and not up to date with the latest ...

    Read More
  • Weak configuration vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.2.4

    Fixed

    The Wordfence Plugin is an online security tool used to help protect websites from malicious attacks. Unfortunately, a vulnerability was recently discovered in the older version of the plugin (versio...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 7.6.0

    Fixed

    The Wordfence Security - Firewall & Malware Scan plugin for WordPress had a security issue in versions up to 7.6.0. This issue allowed people with administrative privileges to inject malicious web...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.1.5

    Fixed

    A security vulnerability has been found in the Wordfence Security plugin for WordPress that allows people to inject malicious code

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 3.8.1

    Fixed

    The Wordfence Security plugin for WordPress is vulnerable to a type of security attack called Stored Cross-Site Scripting. This vulnerability exists in versions of the plugin up to and including 3.8....

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 6.1.6

    Fixed

    The Wordfence plugin for WordPress is vulnerable to a security issue called Reflected Cross-Site Scripting. It affects versions 6.1.1 to 6.1.6. Attackers can use this security issue to inject web scr...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.2.3

    Fixed

    The Wordfence Security plugin for WordPress is vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This type of attack happens when a user of the plugin, which is up to version 5...

    Read More
  • Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.1.3

    Fixed

    Hackers can use a security weakness in the Wordfence Security plugin for WordPress to insert malicious code into the WordfenceWhois page on the WordPress administrative dashboard. This security flaw e...

    Read More