Open Nav
Sign Up

How I found a CVE in a 4 milion (!) active users of WordFence

Ori Gabriel

September 27, 2022

I just registered my first CVE. Here is the background story.

One of our goals at OP Innovate is to protect our clients and partners at all times. During a recent penetration testing engagement, the testing scope included a WordPress website. So I decided to channel some effort into WordPress plugins where a vulnerability could potentially affect millions of users. One of the plugins I found was Wordfence.

Wordfence is a firewall and security scanner, and it is considered to be a leader in WordPress security. It has over 4 million active installations.

After reviewing the different functionalities of the plugin, I was drawn to a certain field in the management page of the firewall.

This field acts to immediately block the IPs of users who try to sign in with their usernames. I decided to see if I could inject raw HTML code into the field to test whether it would be saved in an un-sanitized form. As I expected, the payload was successfully injected and rendered by the browser. After that I decided to give it a try to craft a new payload, this time containing JavaScript code, in order to launch a cross-site-scripting attack.

Guess what? It works!

I quickly informed the Wordfence team about my finding and they responded immediately, releasing an update within 24 hours. Their quick remediation ensured that this vulnerability no longer affects millions of their users.

Wordfence reached out to NVD who issued a new CVE – My first CVE

Resources highlights

VMware vCenter CVE-2026-59310 Actively Exploited for RCE and Persistent Access

Threat actors are actively exploiting CVE-2026-59310, a critical unauthenticated remote code execution vulnerability affecting VMware vCenter Server, with incident responders identifying compromises across dozens of…

Read more >

cve-2026-59310

ShieldBreak: Microsoft Defender 0-Day Leads to SYSTEM Privileges

A security researcher has released ShieldBreak, a new proof-of-concept exploit targeting Microsoft Defender that can elevate a low-privileged Windows user to NT AUTHORITY\SYSTEM on fully…

Read more >

shieldbreak

Microsoft SharePoint CVE-2026-55040 PoC Weaponized in Active Attacks

Attackers have begun using publicly available exploit code for CVE-2026-55040, a critical Microsoft SharePoint authentication bypass vulnerability that allows an unauthenticated remote attacker to impersonate…

Read more >

cve_2026_55040

WordPress CVE-2026-64638 Pre-Auth XSS Can Be Chained to RCE (XSS2Shell)

WordPress has released security updates to address a high-severity vulnerability that allows unauthenticated attackers to execute JavaScript in the context of a WordPress website and,…

Read more >

cve_2026_64638_xss2shell

ChainDrop npm Supply Chain Attack Compromises Hundreds of Packages and Steals Developer Credentials

A rapidly spreading software supply chain attack known as ChainDrop has compromised hundreds of packages in the npm ecosystem, including widely used caching libraries with…

Read more >

chaindrop_npm

N-able N-central Authentication Bypass Exploitation (CVE-2026-18577)

A high-severity authentication bypass vulnerability in N-able N-central is being actively exploited to compromise remote monitoring and management servers and gain access to downstream customer…

Read more >

cve-2026-18577_op
Under Cyber Attack?

Fill out the form and we will contact you immediately.