WordPress Vulnerability Report — February 28, 2024

WordPress Vulnerability Report — February 28, 2024

In this report, 73 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 25 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 25 Unpatched

Plugin:

Addon Library

Plugin Slug:
addon-library

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Adsmonetizer

Plugin Slug:
adsensei-b30

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

BeePress

Plugin Slug:
beepress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Configure SMTP

Plugin Slug:
configure-smtp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Download Media

Plugin Slug:
download-media

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Duitku Payment Gateway

Plugin Slug:
duitku-social-payment-gateway

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Fontific | Google Fonts

Plugin Slug:
fontific

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Marketo Forms and Tracking

Plugin Slug:
marketo-forms-and-tracking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Media Alt Renamer

Plugin Slug:
media-alt-renamer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin Slug:
myshopkit-popup-smartbar-slidein

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

PayU India

Plugin Slug:
payu-india

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Play.ht

Plugin Slug:
play-ht

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

postMash – custom post order

Plugin Slug:
postmash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Rolo Slider

Plugin Slug:
rolo-slider

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Slivery Extender

Plugin Slug:
slivery-extender

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

SoundCloud Shortcode

Plugin Slug:
soundcloud-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tabs Shortcode and Widget

Plugin Slug:
tabs-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

User Shortcodes Plus

Plugin Slug:
user-shortcodes-plus

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Watermark RELOADED

Plugin Slug:
watermark-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.19

Severity Score:
Medium

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.3

Severity Score:
Low

Plugin Slug:
pagelayer

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium

Plugin Slug:
pagelayer

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.32

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.31

Severity Score:
Medium

Plugin Slug:
ultimate-member

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.3

Severity Score:
Critical

Plugin Slug:
userfeedback-lite

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.14

Severity Score:
High

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.1

Severity Score:
Medium

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.1

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.13

Severity Score:
High

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Directory Traversal

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.41

Severity Score:
Critical

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
event-tickets

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.2

Severity Score:
Medium

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium

Plugin Slug:
enhanced-text-widget

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium

Plugin Slug:
notificationx

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.3

Severity Score:
Critical

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.0.11

Severity Score:
Medium

Plugin Slug:
restrict-user-access

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6

Severity Score:
Medium

Plugin Slug:
wp-event-manager

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.42

Severity Score:
High

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.4

Severity Score:
High

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.87

Severity Score:
Medium

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.9

Severity Score:
Medium

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.0.9

Severity Score:
Medium

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.0

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.9

Severity Score:
Medium

Plugin Slug:
academy

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.20

Severity Score:
High

Plugin Slug:
archivist-custom-archive-templates

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
High

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1

Severity Score:
Medium

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1

Severity Score:
Medium

Plugin Slug:
kodo-qiniu

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium

Plugin:

Backup

Plugin Slug:
backup2

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.9.9

Severity Score:
High

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.19.3

Severity Score:
Medium

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Authentication

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

WP Social Widget

Plugin Slug:
wp-social-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium

WordPress Themes — 2 Patched /0 Unpatched

Theme Slug:
colibri-wp

Downloads
1,232,050

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.101

Severity Score:
Medium

Theme:

Socialdriver

Theme Slug:
socialdriver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024

Severity Score:
High

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-02-29 10:29:51.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — January 24, 2024

WordPress Vulnerability Report — January 24, 2024

In this report, 88 new vulnerabilities have been publicly disclosed. Security patches for 29 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 59 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

Free Online Training Event! TODAY! Register Now!

TODAY! January 24, 2024 @ 1:00 PM – 2:00 PM (CST)

Not all WordPress threats and vulnerabilities are “created equal.” Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.

This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.

Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 28 Patched / 59 Unpatched

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
kali-forms

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
dearpdf-lite

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
browser-theme-color

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
freshmail-integration

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
albo-pretorio-on-line

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
albo-pretorio-on-line

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
cbxgooglemap

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
post-list-designer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
12-step-meeting-list

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
wp-todo

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

BA Plus

Plugin Slug:
ba-plus-before-after-image-slider-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Better Anchor Links

Plugin Slug:
better-anchor-links

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

CformsII

Plugin Slug:
cforms2

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Custom Dashboard Widgets

Plugin Slug:
custom-dashboard-widgets

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Delhivery Logistics Courier

Plugin Slug:
delhivery-logistics-courier

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Frontpage Manager

Plugin Slug:
frontpage-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Image Tag Manager

Plugin Slug:
image-tag-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

lasTunes

Plugin Slug:
lastunes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Post views Stats

Plugin Slug:
post-views-stats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

SimpleMap Store Locator

Plugin Slug:
simplemap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Splashscreen

Plugin Slug:
splashscreen

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Unlimited Addons for WPBakery Page Builder

Plugin Slug:
unlimited-addons-for-wpbakery-page-builder

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP Smart Editor

Plugin Slug:
wp-smart-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.2.5

Severity Score:
Medium

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.5

Severity Score:
Medium

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.5

Severity Score:
Medium

Plugin Slug:
fluentform

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.7

Severity Score:
Medium

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.9.95

Severity Score:
Medium

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.6

Severity Score:
High

Plugin Slug:
photo-gallery

Installations
200,000+

Vulnerability:
Directory Traversal

Patched in Version:
1.8.20

Severity Score:
Critical

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.28

Severity Score:
Medium

Plugin Slug:
burst-statistics

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.4

Severity Score:
High

Plugin Slug:
filebird

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.1

Severity Score:
Medium

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.0

Severity Score:
Medium

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium

Plugin Slug:
product-import-export-for-woo

Installations
90,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.3.8

Severity Score:
High

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.24.7

Severity Score:
Medium

Plugin Slug:
vk-block-patterns

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.31.2.0

Severity Score:
Medium

Plugin Slug:
advanced-woo-search

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.97

Severity Score:
High

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.94

Severity Score:
Medium

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.0.5

Severity Score:
Medium

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.5

Severity Score:
Medium

Plugin Slug:
profile-builder

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.10.9

Severity Score:
High

Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.18

Severity Score:
Medium

Plugin Slug:
simple-membership

Installations
50,000+

Vulnerability:
Open Redirection

Patched in Version:
4.4.2

Severity Score:
Low

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Path Traversal

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
High

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium

Plugin Slug:
wp-simple-firewall

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
18.5.8

Severity Score:
High

Plugin Slug:
ip2location-country-blocker

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.33.4

Severity Score:
Medium

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.8.0

Severity Score:
High

Plugin Slug:
cryptocurrency-price-ticker-widget

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.6

Severity Score:
Critical

Plugin Slug:
molongui-authorship

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.7.5

Severity Score:
Medium

Plugin Slug:
payment-gateway-stripe-and-woocommerce-integration

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.0

Severity Score:
Critical

Plugin Slug:
portfolio-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium

Plugin Slug:
bp-profile-search

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6

Severity Score:
High

Plugin Slug:
hd-quiz

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.12

Severity Score:
Medium

Plugin Slug:
bulk-editor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8.1

Severity Score:
High

Plugin Slug:
chatbot

Installations
5,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.1.1

Severity Score:
High

Plugin Slug:
slider-by-supsystic

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7

Severity Score:
Medium

Plugin Slug:
fastdup

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.0

Severity Score:
Critical

Plugin Slug:
formzu-wp

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
Medium

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.8

Severity Score:
High

Plugin Slug:
wp-spell-check

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.18

Severity Score:
Medium

Plugin Slug:
wpzoom-shortcodes

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
High

Plugin Slug:
instawp-connect

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
0.1.0.9

Severity Score:
High

Plugin Slug:
shortcode-to-display-post-and-user-data

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium

Plugin Slug:
shortcode-to-display-post-and-user-data

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.0

Severity Score:
Medium

Plugin Slug:
shortcode-to-display-post-and-user-data

Installations
1,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.3.0

Severity Score:
High

Plugin Slug:
stock-locations-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.0

Severity Score:
Medium

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.2.5

Severity Score:
Medium

Plugin:

GeneratePress Premium

Plugin Slug:
generatepress-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium

Plugin:

PeepSo Core: Photos

Plugin Slug:
peepso-photos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.3.1.0

Severity Score:
Medium

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.30

Severity Score:
Critical

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Settings Change

Patched in Version:
1.6.30

Severity Score:
Medium

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.30

Severity Score:
High

Plugin:

WooCommerce Subscriptions

Plugin Slug:
woocommerce-subscriptions

Vulnerability:
Broken Access Control

Patched in Version:
5.8.0

Severity Score:
Medium

Plugin:

WPForms Pro

Plugin Slug:
wpforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5.4

Severity Score:
High

WordPress Themes — 1 Patched / 0 Unpatched

Theme Slug:
colormag

Downloads
3,787,317

Vulnerability:
Broken Access Control

Patched in Version:
3.1.3

Severity Score:
Medium

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-01-24 11:16:58.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — May 1, 2024

WordPress Vulnerability Report — May 1, 2024

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 269 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 90 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 248 Patched / 21 Unpatched

Plugin Slug:
auto-post-thumbnail

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
famethemes-demo-importer

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
ag-custom-admin

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
cryout-serious-slider

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
meks-smart-social-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
xserver-migrator

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin Slug:
anual-archive

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
clickcease-click-fraud-protection

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
democracy-poll

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
login-logout-register-menu

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
meks-themeforest-smart-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
print-o-matic

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
smart-recent-posts-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
customify-sites

Installations
6,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin Slug:
ad-widget

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
popupally

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
pretty-google-calendar

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
facebook-fan-page-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
filterable-portfolio

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
share-this-image

Installations
2,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
smart-maintenance-mode

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Advanced Search

Plugin Slug:
advance-search

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Advanced Most Recent Posts Mod

Plugin Slug:
advanced-most-recent-posts-mod

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Advanced Post List

Plugin Slug:
advanced-post-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

AJAX Login and Registration modal popup + inline form

Plugin Slug:
ajax-login-and-registration-modal-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Element Pack Pro

Plugin Slug:
bdthemes-element-pack

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High

Plugin:

CF7 File Download – File Download for CF7

Plugin Slug:
cf7-file-download

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Client Dash

Plugin Slug:
client-dash

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Contact Form 7 Extension For Mailchimp

Plugin Slug:
contact-form-7-mailchimp-extension

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

CPO Companion

Plugin Slug:
cpo-companion

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Crelly Slider

Plugin Slug:
crelly-slider

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Easy Set Favicon

Plugin Slug:
easy-set-favicon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Embed Google Fonts

Plugin Slug:
embed-google-fonts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Giphypress

Plugin Slug:
giphypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

GWP-Histats

Plugin Slug:
gwp-histats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

JW Player for WordPress

Plugin Slug:
jw-player-7-for-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

MF Gig Calendar

Plugin Slug:
mf-gig-calendar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Mini Loops

Plugin Slug:
mini-loops

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Opal Widgets For Elementor

Plugin Slug:
opal-widgets-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

CodeBard’s Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

PB MailCrypt

Plugin Slug:
pb-mailcrypt-antispam-email-encryption

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Progressive WordPress (PWA)

Plugin Slug:
progressive-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Realtyna Organic IDX plugin

Plugin Slug:
real-estate-listing-realtyna-wpl

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Recencio Book Reviews

Plugin Slug:
recencio-book-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Regenerate post permalink

Plugin Slug:
regenerate-post-permalinks

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

School Management Pro

Plugin Slug:
school-management-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Sliding Widgets

Plugin Slug:
sliding-widgets

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Social Share Buttons by Supsystic

Plugin Slug:
social-share-buttons-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Solid Affiliate

Plugin Slug:
solid-affiliate

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Sticky Anything

Plugin Slug:
toast-stick-anything

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WidgetKit

Plugin Slug:
widgetkit-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

WP GDPR Compliance

Plugin Slug:
wp-gdpr-compliance

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Masquerade

Plugin Slug:
wp-masquerade

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP Page Post Widget Clone

Plugin Slug:
wp-page-post-widget-clone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WTI Like Post

Plugin Slug:
wti-like-post

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

XforWooCommerce

Plugin Slug:
xforwoocommerce

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
all-in-one-seo-pack

Installations
3,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.1.1

Severity Score:
Medium

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.9.16

Severity Score:
Medium

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.217

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.1

Severity Score:
High

Plugin Slug:
optinmonster

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.16.0

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.29

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.26

Severity Score:
Medium

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
700,000+

Vulnerability:
Path Traversal

Patched in Version:
2.12.7

Severity Score:
Medium

Plugin Slug:
contact-form-cfdb7

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.7

Severity Score:
Medium

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.0

Severity Score:
Medium

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.7

Severity Score:
Medium

Plugin Slug:
copy-delete-posts

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.5

Severity Score:
Medium

Plugin Slug:
metform

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.4

Severity Score:
Medium

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.972

Severity Score:
Medium

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3.95

Severity Score:
Medium

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.8.1

Severity Score:
High

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High

Plugin Slug:
call-now-button

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.7

Severity Score:
Medium

Plugin Slug:
chaty

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.9

Severity Score:
Medium

Plugin Slug:
instant-images

Installations
200,000+

Vulnerability:
Privilege Escalation

Patched in Version:
6.1.1

Severity Score:
High

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.5

Severity Score:
Medium

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
photo-gallery

Installations
200,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.21

Severity Score:
Medium

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium

Plugin Slug:
yith-woocommerce-compare

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.38.0

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.4

Severity Score:
Medium

Plugin Slug:
backupwordpress

Installations
100,000+

Vulnerability:
Directory Traversal

Patched in Version:
3.14

Severity Score:
Low

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.264

Severity Score:
Medium

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.274

Severity Score:
Medium

Plugin Slug:
content-views-query-and-display-post-page

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.1

Severity Score:
Medium

Plugin Slug:
fileorganizer

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium

Plugin Slug:
flexible-shipping

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.24.16

Severity Score:
Medium

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.8

Severity Score:
Medium

Plugin Slug:
hummingbird-performance

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.4

Severity Score:
Medium

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.61

Severity Score:
Medium

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.30

Severity Score:
Medium

Plugin Slug:
strong-testimonials

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.12

Severity Score:
Medium

Plugin Slug:
ultimate-social-media-icons

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.7

Severity Score:
Medium

Plugin Slug:
wp-whatsapp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.4

Severity Score:
Medium

Plugin Slug:
paid-memberships-pro

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0

Severity Score:
Medium

Plugin Slug:
paid-memberships-pro

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0

Severity Score:
Medium

Plugin Slug:
vk-block-patterns

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.31.1.1

Severity Score:
Medium

Plugin Slug:
wp-staging

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.5.0

Severity Score:
Medium

Plugin Slug:
backup-backup

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.26.3

Severity Score:
Medium

Plugin Slug:
mainwp-child-reports

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2

Severity Score:
Medium

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.0

Severity Score:
Medium

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium

Plugin Slug:
wp-smtp

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
1.2.7

Severity Score:
High

Plugin Slug:
wp-ulike

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.0

Severity Score:
Medium

Plugin Slug:
wp-ulike

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
4.7.0

Severity Score:
High

Plugin Slug:
wp-ulike

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.0

Severity Score:
Medium

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.16

Severity Score:
Medium

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.9

Severity Score:
High

Plugin Slug:
media-cleaner

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.7.3

Severity Score:
Medium

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
70,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
2.5.4

Severity Score:
Medium

Plugin Slug:
blog2social

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.5.0

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9.2

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.4

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.5

Severity Score:
Medium

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.1.9

Severity Score:
Medium

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.4.9.4

Severity Score:
Medium

Plugin Slug:
enhanced-text-widget

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
Medium

Plugin Slug:
form-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.25

Severity Score:
Medium

Plugin Slug:
jquery-collapse-o-matic

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5.6

Severity Score:
Medium

Plugin Slug:
quick-featured-images

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
13.7.1

Severity Score:
Medium

Plugin Slug:
simple-membership

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.4

Severity Score:
Medium

Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.79

Severity Score:
High

Plugin Slug:
simply-static

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.4

Severity Score:
High

Plugin Slug:
woocommerce-delivery-notes

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.0

Severity Score:
Medium

Plugin Slug:
wp-analytify

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.2.4

Severity Score:
Medium

Plugin Slug:
wp-analytify

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.2.4

Severity Score:
Medium

Plugin Slug:
ag-custom-admin

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.2

Severity Score:
Medium

Plugin Slug:
ays-popup-box

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.7

Severity Score:
Medium

Plugin Slug:
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.5.45.7212

Severity Score:
Medium

Plugin Slug:
master-addons

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.5.6

Severity Score:
Medium

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.12

Severity Score:
High

Plugin Slug:
social-warfare

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.6.2

Severity Score:
Medium

Plugin Slug:
vod-infomaniak

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.7

Severity Score:
High

Plugin Slug:
wp-google-places-review-slider

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.6

Severity Score:
Medium

Plugin Slug:
wp-hide-backed-notices

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3

Severity Score:
Medium

Plugin Slug:
appointment-hour-booking

Installations
20,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.4.57

Severity Score:
Medium

Plugin Slug:
checkout-fees-for-woocommerce

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.12.2

Severity Score:
Medium

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.32

Severity Score:
Medium

Plugin Slug:
gt3-photo-video-gallery

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7.22

Severity Score:
Medium

Plugin Slug:
pricing-table-by-supsystic

Installations
20,000+

Vulnerability:
Content Injection

Patched in Version:
1.9.13

Severity Score:
Medium

Plugin Slug:
rafflepress

Installations
20,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.12.11

Severity Score:
Medium

Plugin Slug:
rate-my-post

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.4.5

Severity Score:
Medium

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.1

Severity Score:
Medium

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.2

Severity Score:
Medium

Plugin Slug:
ultimate-social-media-plus

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.2

Severity Score:
Medium

Plugin Slug:
ultimate-social-media-plus

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.3

Severity Score:
Medium

Plugin Slug:
video-conferencing-with-zoom-api

Installations
20,000+

Vulnerability:
Open Redirection

Patched in Version:
4.4.5

Severity Score:
Medium

Plugin Slug:
woocommerce-product-addon

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
32.0.19

Severity Score:
Critical

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription

Installations
20,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
4.0.18

Severity Score:
High

Plugin Slug:
wpzoom-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.36

Severity Score:
Medium

Plugin Slug:
advanced-floating-content-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium

Plugin Slug:
bp-better-messages

Installations
10,000+

Vulnerability:
Broken Authentication

Patched in Version:
2.4.33

Severity Score:
Medium

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.19

Severity Score:
High

Plugin Slug:
classified-listing

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.11

Severity Score:
Medium

Plugin Slug:
directorist

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.9.0

Severity Score:
Medium

Plugin Slug:
elespare

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.3

Severity Score:
Medium

Plugin Slug:
email-customizer-for-woocommerce

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.1

Severity Score:
High

Plugin Slug:
gamipress

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.8.9

Severity Score:
Low

Plugin Slug:
geodirectory

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.49

Severity Score:
Medium

Plugin Slug:
http-https-remover

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium

Plugin Slug:
list-custom-taxonomy-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2

Severity Score:
Medium

Plugin Slug:
live-composer-page-builder

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.39

Severity Score:
Medium

Plugin Slug:
mycred

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
paid-member-subscriptions

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.11.1

Severity Score:
Medium

Plugin Slug:
pop-up-pop-up

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.4

Severity Score:
Medium

Plugin Slug:
restaurant-reservations

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.17

Severity Score:
Medium

Plugin Slug:
reviewx

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.22

Severity Score:
Medium

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium

Plugin Slug:
send-pdf-for-contact-form-7

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2.4

Severity Score:
Medium

Plugin Slug:
socialsnap

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.6

Severity Score:
Medium

Plugin Slug:
ultimate-posts-widget

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.0

Severity Score:
Medium

Plugin Slug:
wordpress-easy-paypal-payment-or-donation-accept-plugin

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0

Severity Score:
High

Plugin Slug:
wp-datepicker

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.1.1

Severity Score:
High

Plugin Slug:
wp-scheduled-posts

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.9

Severity Score:
Medium

Plugin Slug:
wp-travel-engine

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.1

Severity Score:
High

Plugin Slug:
arconix-faq

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.4

Severity Score:
Medium

Plugin Slug:
fg-joomla-to-wordpress

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.21.0

Severity Score:
Medium

Plugin Slug:
romethemeform

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.96

Severity Score:
Medium

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.92

Severity Score:
Medium

Plugin Slug:
wp-linkedin-auto-publish

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.12

Severity Score:
Medium

Plugin Slug:
wp-migration-duplicator

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.9

Severity Score:
Medium

Plugin Slug:
armember-membership

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.29

Severity Score:
Critical

Plugin Slug:
hkdev-maintenance-mode

Installations
8,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.0.2

Severity Score:
Low

Plugin Slug:
wpc-composite-products

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.8

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
5.8.3

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium

Plugin Slug:
the-plus-addons-for-block-editor

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.6

Severity Score:
Medium

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.2

Severity Score:
Medium

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.4

Severity Score:
Medium

Plugin Slug:
image-slider-widget

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.127

Severity Score:
Medium

Plugin Slug:
integrate-google-drive

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
High

Plugin Slug:
integrate-google-drive

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
Medium

Plugin Slug:
print-my-blog

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.26.3

Severity Score:
Medium

Plugin Slug:
radio-player

Installations
6,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.74

Severity Score:
Medium

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.11

Severity Score:
Medium

Plugin Slug:
assistant

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.9.2

Severity Score:
Medium

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.0.12

Severity Score:
Medium

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.15

Severity Score:
High

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.6

Severity Score:
Medium

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.6

Severity Score:
Medium

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.6.6

Severity Score:
Medium

Plugin Slug:
ultimate-410

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium

Plugin Slug:
advanced-local-pickup-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.2

Severity Score:
Medium

Plugin Slug:
embed-google-photos-album-easily

Installations
4,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.1

Severity Score:
Medium

Plugin Slug:
jc-importer

Installations
4,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.13.1

Severity Score:
Medium

Plugin Slug:
tickera-event-ticketing-system

Installations
4,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.5.2.5

Severity Score:
Medium

Plugin Slug:
vikrentcar

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.3

Severity Score:
Medium

Plugin Slug:
wp-ada-compliance-check-basic

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.4

Severity Score:
Medium

Plugin Slug:
wp-fusion-lite

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.43.0

Severity Score:
Medium

Plugin Slug:
coupon-reveal-button

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium

Plugin Slug:
debug-log-manager

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.2

Severity Score:
Medium

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.9.6

Severity Score:
Critical

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.9.6

Severity Score:
High

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.13

Severity Score:
Medium

Plugin Slug:
vision

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.2

Severity Score:
Medium

Plugin Slug:
widget-post-slider

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.6.0

Severity Score:
Critical

Plugin Slug:
wp-recall

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
16.26.6

Severity Score:
High

Plugin Slug:
wp-recall

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
16.26.6

Severity Score:
Critical

Plugin Slug:
accessibility-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
Medium

Plugin Slug:
advanced-testimonial-carousel-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.1

Severity Score:
Medium

Plugin Slug:
all-in-one-facebook-like-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.8

Severity Score:
Medium

Plugin Slug:
basepress

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.16.2.1

Severity Score:
Medium

Plugin Slug:
basepress

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.16.2.1

Severity Score:
Medium

Plugin Slug:
cookiehub

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.1

Severity Score:
Medium

Plugin Slug:
custom-field-finder

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
0.4

Severity Score:
Medium

Plugin Slug:
feedburner-alternative-and-rss-redirect

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0

Severity Score:
Medium

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.0.25

Severity Score:
Medium

Plugin Slug:
ipages-flipbook

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.2

Severity Score:
Medium

Plugin Slug:
the-pack-addon

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.8.4

Severity Score:
High

Plugin Slug:
the-pack-addon

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.8.3

Severity Score:
Medium

Plugin Slug:
user-meta

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1

Severity Score:
Medium

Plugin Slug:
woocommerce-superfaktura

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.40.4

Severity Score:
Medium

Plugin Slug:
academy

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.17

Severity Score:
High

Plugin Slug:
academy

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.17

Severity Score:
Medium

Plugin Slug:
activedemand

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.2.42

Severity Score:
Critical

Plugin Slug:
admin-bar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.23

Severity Score:
Medium

Plugin Slug:
ai-post-generator

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4

Severity Score:
Medium

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.1

Severity Score:
Medium

Plugin Slug:
booking-ultra-pro

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.13

Severity Score:
High

Plugin Slug:
buddyforms

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
2.8.9

Severity Score:
High

Plugin Slug:
contest-gallery

Installations
1,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
21.3.5

Severity Score:
High

Plugin Slug:
conversational-forms

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.2.0

Severity Score:
High

Plugin Slug:
culqi-checkout

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.0.15

Severity Score:
Medium

Plugin Slug:
eprolo-dropshipping

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.2

Severity Score:
Medium

Plugin Slug:
flexible-shipping-usps

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.10.0

Severity Score:
Medium

Plugin Slug:
headline-analyzer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.4

Severity Score:
Medium

Plugin Slug:
kb-support

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.1

Severity Score:
Medium

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.94

Severity Score:
Critical

Plugin Slug:
print-google-cloud-print-gcp-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.5.4

Severity Score:
High

Plugin Slug:
radio-station

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.8

Severity Score:
Medium

Plugin Slug:
reviews-plus

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.5

Severity Score:
Medium

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.1

Severity Score:
Medium

Plugin Slug:
seers-cookie-consent-banner-privacy-policy

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.1.1

Severity Score:
High

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
7.2.3

Severity Score:
High

Plugin Slug:
streamweasels-twitch-integration

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.0

Severity Score:
Medium

Plugin Slug:
totalpoll-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.10.0

Severity Score:
Medium

Plugin Slug:
vitepos-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.2

Severity Score:
Medium

Plugin Slug:
wp-club-manager

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.12

Severity Score:
Medium

Plugin Slug:
wp-gotowebinar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
15.1

Severity Score:
Medium

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3.1

Severity Score:
Medium

Plugin Slug:
wp-time-slots-booking-form

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.07

Severity Score:
High

Plugin Slug:
wpcal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.5.9

Severity Score:
Medium

Plugin Slug:
wppizza

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.18.11

Severity Score:
Medium

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.4

Severity Score:
High

Plugin Slug:
leaky-paywall

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
4.20.9

Severity Score:
High

Plugin Slug:
olive-one-click-demo-import

Installations
900+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.1.2

Severity Score:
High

Plugin Slug:
woo-aliexpress-dropshipping

Installations
900+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
2.1.2

Severity Score:
High

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
800+

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.4

Severity Score:
Critical

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
Critical

Plugin Slug:
slash-admin

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.2

Severity Score:
High

Plugin Slug:
cardealer

Installations
700+

Vulnerability:
Content Injection

Patched in Version:
4.16

Severity Score:
Low

Plugin Slug:
shortpixel-critical-css

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.3

Severity Score:
High

Plugin Slug:
admin-and-client-message-after-order-for-woocommerce

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
12.5

Severity Score:
Critical

Plugin Slug:
wp-s3-smart-upload

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.1

Severity Score:
High

Plugin Slug:
evergreen-content-poster

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.3

Severity Score:
Medium

Plugin Slug:
5-stars-rating-funnel

Installations
40+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.02

Severity Score:
Medium

Plugin Slug:
better-comments

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium

Plugin Slug:
better-comments

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium

Plugin:

Header Footer Code Manager Pro

Plugin Slug:
99robots-header-footer-code-manager-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.17

Severity Score:
High

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
SQL Injection

Patched in Version:
6.4.1

Severity Score:
High

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Arbitrary File Deletion

Patched in Version:
6.4.1

Severity Score:
High

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
High

Plugin:

ARForms Form Builder

Plugin Slug:
arforms-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
High

Plugin:

Digital Publications by Supsystic

Plugin Slug:
digital-publications-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
1.7.8

Severity Score:
Medium

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Local File Inclusion

Patched in Version:
3.6.1

Severity Score:
High

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.8

Severity Score:
High

Plugin:

Interactive World Maps

Plugin Slug:
interactive-world-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
High

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
High

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Settings Change

Patched in Version:
1.6.2

Severity Score:
Medium

Plugin:

WooCommerce Shipping Label

Plugin Slug:
shipping-labels-for-woo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.9

Severity Score:
Medium

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Broken Access Control

Patched in Version:
29.8

Severity Score:
Medium

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
29.8

Severity Score:
High

Plugin:

WP Media Category Management

Plugin Slug:
wp-media-category-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
High

Plugin:

Wp Staging Pro

Plugin Slug:
wp-staging-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.5.0

Severity Score:
Medium

WordPress Themes — 21 Patched / 7 Unpatched

Theme:

UDesign

Theme Slug:
u-design

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Theme Slug:
accountra

Downloads
20,885

Vulnerability:
Broken Access Control

Patched in Version:
1.0.4

Severity Score:
Medium

Theme Slug:
althea-wp

Downloads
52,642

Vulnerability:
Broken Access Control

Patched in Version:
1.0.16

Severity Score:
Medium

Theme Slug:
blocksy

Downloads
3,113,676

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.40

Severity Score:
Medium

Theme Slug:
blocksy

Downloads
3,113,676

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.34

Severity Score:
Medium

Theme Slug:
brite

Downloads
125,207

Vulnerability:
Broken Access Control

Patched in Version:
1.0.15

Severity Score:
Medium

Theme Slug:
colibri-wp

Downloads
1,271,195

Vulnerability:
Broken Access Control

Patched in Version:
1.0.99

Severity Score:
Medium

Theme Slug:
colornews

Downloads
266,626

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium

Theme Slug:
elevate-wp

Downloads
70,130

Vulnerability:
Broken Access Control

Patched in Version:
1.0.17

Severity Score:
Medium

Theme Slug:
financio

Downloads
17,197

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.4

Severity Score:
Medium

Theme Slug:
hugo-wp

Downloads
59,334

Vulnerability:
Broken Access Control

Patched in Version:
1.0.10

Severity Score:
Medium

Theme Slug:
intrace

Downloads
84,888

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
Medium

Theme Slug:
pathway

Downloads
57,050

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.16

Severity Score:
Medium

Theme Slug:
photology

Downloads
17,339

Vulnerability:
Broken Access Control

Patched in Version:
1.1.4

Severity Score:
Medium

Theme Slug:
royal-elementor-kit

Downloads
461,793

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.117

Severity Score:
Medium

Theme Slug:
startupzy

Downloads
66,824

Vulnerability:
Broken Access Control

Patched in Version:
1.1.2

Severity Score:
Medium

Theme Slug:
teluro

Downloads
188,771

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.36

Severity Score:
Medium

Theme Slug:
travey

Downloads
17,666

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.5

Severity Score:
Medium

Theme Slug:
vertice

Downloads
47,531

Vulnerability:
Broken Access Control

Patched in Version:
1.0.11

Severity Score:
Medium

Theme Slug:
virtue

Downloads
2,473,892

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9

Severity Score:
Medium

Theme Slug:
wp-portfolio

Downloads
82,208

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
Medium

Theme Slug:
zeever

Downloads
208,788

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
Medium

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-05-01 11:27:57.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — May 15, 2024

WordPress Vulnerability Report — May 15, 2024

In this report, 192 vulnerabilities have been publicly disclosed. Security patches for 145 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

window[“e516ebc3_cc22_4120_9024_74a02d8803fb”] = {“blockId”:”e516ebc3-cc22-4120-9024-74a02d8803fb”,”type”:”warning”,”content”:”

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.”,”className”:””};

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

window[“255c72cf_b4e3_402c_9998_e11c0e137abc”] = {“blockId”:”255c72cf-b4e3-402c-9998-e11c0e137abc”,”className”:””,”isOpen”:true};

Table of Contents

window[“d4016609_9a27_4a04_8b01_4cf71ac41793”] = {“blockId”:”d4016609-9a27-4a04-8b01-4cf71ac41793″,”type”:”notice”,”content”:”

Our WordPress Vulnerability Reportu00a0covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating ofu00a0Low,u00a0Medium,u00a0High, oru00a0Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress u2014 and the web u2014 more secure.”,”className”:””};

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

window[“3ce27c10_4561_4878_bd60_5562a4dbf81c”] = {“blockId”:”3ce27c10-4561-4878-bd60-5562a4dbf81c”,”text”:”No new core vulnerabilities were disclosed this week.”,”className”:””};

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 129 Patched / 47 Unpatched

Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer

Plugin:

Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer

Plugin Slug:
clearfy

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34806

The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms – Easy Drag & Drop Form Builder

Plugin:

Flo Forms – Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-35174

The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin:

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34389

The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin:

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34387

The vulnerability has not been patched. You should deactivate the plugin.

140+ Widgets | Best Addons For Elementor – FREE

Plugin:

140+ Widgets | Best Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34570

The vulnerability has not been patched. You should deactivate the plugin.

JCH Optimize

Plugin:

JCH Optimize

Plugin Slug:
jch-optimize

Installations
6,000+

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34808

The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin:

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34390

The vulnerability has not been patched. You should deactivate the plugin.

Kognetiks Chatbot for WordPress

Plugin:

Kognetiks Chatbot for WordPress

Plugin Slug:
chatbot-chatgpt

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-32700

The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:

Netgsm

Plugin Slug:
netgsm

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-4746

The vulnerability has not been patched. You should deactivate the plugin.

Propovoice CRM – Best CRM & Invoicing Plugin to Manage Leads, Clients and Billings automation

Plugin:

Propovoice CRM – Best CRM & Invoicing Plugin to Manage Leads, Clients and Billings automation

Plugin Slug:
propovoice

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-4747

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin:

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-4606

The vulnerability has not been patched. You should deactivate the plugin.

WC Serial Numbers – Ultimate License Manager for Selling, Licensing & Securely Delivering Digital Content with WooCommerce

Plugin:

WC Serial Numbers – Ultimate License Manager for Selling, Licensing & Securely Delivering Digital Content with WooCommerce

Plugin Slug:
wc-serial-numbers

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-35173

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin – WebinarPress

Plugin:

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-34818

The vulnerability has not been patched. You should deactivate the plugin.

Plugin:

gee Search Plus, improved WordPress search

Plugin Slug:
gsearch-plus

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34560

The vulnerability has not been patched. You should deactivate the plugin.

Plugin:

Sticky Social Link

Plugin Slug:
sticky-social-link

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34546

The vulnerability has not been patched. You should deactivate the plugin.

DS Site Message

Plugin:

DS Site Message

Plugin Slug:
ds-site-message

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34439

The vulnerability has not been patched. You should deactivate the plugin.

Viet Nam Affiliate

Plugin:

Viet Nam Affiliate

Plugin Slug:
viet-nam-affiliate

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34417

The vulnerability has not been patched. You should deactivate the plugin.

AWSOM News Announcement

Plugin:

AWSOM News Announcement

Plugin Slug:
awsom-news-announcement

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34428

The vulnerability has not been patched. You should deactivate the plugin.

BlogLentor

Plugin:

BlogLentor

Plugin Slug:
bloglentor-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34421

The vulnerability has not been patched. You should deactivate the plugin.

Brozzme Scroll Top

Plugin:

Brozzme Scroll Top

Plugin Slug:
brozzme-scroll-top

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34426

The vulnerability has not been patched. You should deactivate the plugin.

canvasio3D Light

Plugin:

canvasio3D Light

Plugin Slug:
canvasio3d-light

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-34411

The vulnerability has not been patched. You should deactivate the plugin.

Configure Login Timeout

Plugin:

Configure Login Timeout

Plugin Slug:
configure-login-timeout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34419

The vulnerability has not been patched. You should deactivate the plugin.

Corona Virus (COVID-19) Banner & Live Data

Plugin:

Corona Virus (COVID-19) Banner & Live Data

Plugin Slug:
corona-virus-covid-19-banner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34429

The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:

Crelly Slider

Plugin Slug:
crelly-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3752

The vulnerability has not been patched. You should deactivate the plugin.

Debug Info

Plugin:

Debug Info

Plugin Slug:
debug-info

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34565

The vulnerability has not been patched. You should deactivate the plugin.

EasyEvent

Plugin:

EasyEvent

Plugin Slug:
easyevent

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3628

The vulnerability has not been patched. You should deactivate the plugin.

Enter Addons

Plugin:

Enter Addons

Plugin Slug:
enteraddons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3831

The vulnerability has not been patched. You should deactivate the plugin.

Fancy Elementor Flipbox

Plugin:

Fancy Elementor Flipbox

Plugin Slug:
fancy-elementor-flipbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34572

The vulnerability has not been patched. You should deactivate the plugin.

Fast Custom Social Share by CodeBard

Plugin:

Fast Custom Social Share by CodeBard

Plugin Slug:
fast-custom-social-share-by-codebard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34807

The vulnerability has not been patched. You should deactivate the plugin.

Plugin:

Featured Content Gallery

Plugin Slug:
featured-content-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34424

The vulnerability has not been patched. You should deactivate the plugin.

Forty Four – 404 Plugin for WordPress

Plugin:

Forty Four – 404 Plugin for WordPress

Plugin Slug:
forty-four

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34423

The vulnerability has not been patched. You should deactivate the plugin.

GDPR Compliance

Plugin:

GDPR Compliance

Plugin Slug:
gdpr-compliance

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-34388

The vulnerability has not been patched. You should deactivate the plugin.

Comments Evolved for WordPress

Plugin:

Comments Evolved for WordPress

Plugin Slug:
gplus-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34420

The vulnerability has not been patched. You should deactivate the plugin.

LetterPress

Plugin:

LetterPress

Plugin Slug:
letterpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34568

The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:

MF Gig Calendar

Plugin Slug:
mf-gig-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3755

The vulnerability has not been patched. You should deactivate the plugin.

Pk Favicon Manager

Plugin:

Pk Favicon Manager

Plugin Slug:
phpsword-favicon-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-34416

The vulnerability has not been patched. You should deactivate the plugin.

Pootle Pagebuilder – WordPress Page builder

Plugin:

Pootle Pagebuilder – WordPress Page builder

Plugin Slug:
pootle-page-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34573

The vulnerability has not been patched. You should deactivate the plugin.

Pure Chat

Plugin:

Pure Chat

Plugin Slug:
pure-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3595

The vulnerability has not been patched. You should deactivate the plugin.

QuickieBar

Plugin:

QuickieBar

Plugin Slug:
quickiebar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34425

The vulnerability has not been patched. You should deactivate the plugin.

Social Connect

Plugin:

Social Connect

Plugin Slug:
social-connect

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-4393

The vulnerability has not been patched. You should deactivate the plugin.

Swift Performance Lite

Plugin:

Swift Performance Lite

Plugin Slug:
swift-performance-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3722

The vulnerability has not been patched. You should deactivate the plugin.

Table Maker

Plugin:

Table Maker

Plugin Slug:
table-maker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34574

The vulnerability has not been patched. You should deactivate the plugin.

TT Custom Post Type Creator

Plugin:

TT Custom Post Type Creator

Plugin Slug:
tt-custom-post-type-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34430

The vulnerability has not been patched. You should deactivate the plugin.

Plugin:

Viet Affiliate Link

Plugin Slug:
viet-affiliate-link

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34422

The vulnerability has not been patched. You should deactivate the plugin.

WP etracker

Plugin:

WP etracker

Plugin Slug:
wp-etracker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-34431

The vulnerability has not been patched. You should deactivate the plugin.

WP Favorite Posts

Plugin:

WP Favorite Posts

Plugin Slug:
wp-favorite-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34427

The vulnerability has not been patched. You should deactivate the plugin.

Plugin:

WPCS ( WordPress Custom Search )

Plugin Slug:
wpcs-wp-custom-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34418

The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin:

Yoast SEO

Plugin Slug:
wordpress-seo

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
22.6

Severity Score:
High

CVE:

2024-4041

The vulnerability has been patched, so you should update to version 22.6.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin:

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.4

Severity Score:
Medium

CVE:

2024-4392

The vulnerability has been patched, so you should update to version 13.4.

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin:

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.21

Severity Score:
Medium

CVE:

2024-4624

The vulnerability has been patched, so you should update to version 5.9.21.

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin:

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.20

Severity Score:
Medium

CVE:

2024-4275

The vulnerability has been patched, so you should update to version 5.9.20.

Starter Templates — Elementor, WordPress & Beaver Builder Templates

Plugin:

Starter Templates — Elementor, WordPress & Beaver Builder Templates

Plugin Slug:
astra-sites

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.2

Severity Score:
Medium

CVE:

2024-4630

The vulnerability has been patched, so you should update to version 4.2.2.

Starter Templates — Elementor, WordPress & Beaver Builder Templates

Plugin:

Starter Templates — Elementor, WordPress & Beaver Builder Templates

Plugin Slug:
astra-sites

Installations
1,000,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.1.7

Severity Score:
Medium

CVE:

2024-1467

The vulnerability has been patched, so you should update to version 4.1.7.

One Click Demo Import

Plugin:

One Click Demo Import

Plugin Slug:
one-click-demo-import

Installations
1,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.2.1

Severity Score:
Medium

CVE:

2024-34433

The vulnerability has been patched, so you should update to version 3.2.1.

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin:

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.37

Severity Score:
Medium

CVE:

2024-4481

The vulnerability has been patched, so you should update to version 3.2.37.

Translate Multilingual sites – TranslatePress

Plugin:

Translate Multilingual sites – TranslatePress

Plugin Slug:
translatepress-multilingual

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.6

Severity Score:
Medium

CVE:

2024-34827

The vulnerability has been patched, so you should update to version 2.7.6.

Blocksy Companion

Plugin:

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.46

Severity Score:
Medium

CVE:

2024-4487

The vulnerability has been patched, so you should update to version 2.0.46.

FileBird – WordPress Media Library Folders & File Manager

Plugin:

FileBird – WordPress Media Library Folders & File Manager

Plugin Slug:
filebird

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.6.4

Severity Score:
Medium

CVE:

2024-35166

The vulnerability has been patched, so you should update to version 5.6.4.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin:

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.105

Severity Score:
High

CVE:

2024-3055

The vulnerability has been patched, so you should update to version 1.5.105.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin:

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor

Installations
200,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.5.103

Severity Score:
High

CVE:

2024-2662

The vulnerability has been patched, so you should update to version 1.5.103.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin:

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.103

Severity Score:
High

CVE:

2024-3547

The vulnerability has been patched, so you should update to version 1.5.103.

White Label CMS

Plugin:

White Label CMS

Plugin Slug:
white-label-cms

Installations
200,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.4

Severity Score:
Medium

CVE:

2024-4280

The vulnerability has been patched, so you should update to version 2.7.4.

Advanced Ads – Ad Manager & AdSense

Plugin:

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.52.2

Severity Score:
Medium

CVE:

2024-2290

The vulnerability has been patched, so you should update to version 1.52.2.

Advanced Ads – Ad Manager & AdSense

Plugin:

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.52.2

Severity Score:
Medium

CVE:

2024-3952

The vulnerability has been patched, so you should update to version 1.52.2.

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)

Plugin:

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)

Plugin Slug:
bdthemes-prime-slider-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14.4

Severity Score:
Medium

CVE:

2024-4339

The vulnerability has been patched, so you should update to version 3.14.4.

Beaver Builder – WordPress Page Builder

Plugin:

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1.3

Severity Score:
Medium

CVE:

2024-4430

The vulnerability has been patched, so you should update to version 2.8.1.3.

Beaver Builder – WordPress Page Builder

Plugin:

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1.2

Severity Score:
Medium

CVE:

2024-3923

The vulnerability has been patched, so you should update to version 2.8.1.2.

Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode)

Plugin:

Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode)

Plugin Slug:
content-views-query-and-display-post-page

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
Medium

CVE:

2024-4446

The vulnerability has been patched, so you should update to version 3.7.2.

HT Mega – Absolute Addons For Elementor

Plugin:

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium

CVE:

2024-3990

The vulnerability has been patched, so you should update to version 2.5.1.

Pods – Custom Content Types and Fields

Plugin:

Pods – Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.1.1

Severity Score:
Medium

CVE:

2024-3956

The vulnerability has been patched, so you should update to version 3.2.1.1.

WP Job Manager

Plugin:

WP Job Manager

Plugin Slug:
wp-job-manager

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.0

Severity Score:
Medium

CVE:

2024-34549

The vulnerability has been patched, so you should update to version 2.3.0.

XML Sitemap & Google News

Plugin:

XML Sitemap & Google News

Plugin Slug:
xml-sitemap-feed

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
5.4.9

Severity Score:
High

CVE:

2024-4441

The vulnerability has been patched, so you should update to version 5.4.9.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin:

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.17

Severity Score:
Medium

CVE:

2024-4316

The vulnerability has been patched, so you should update to version 3.9.17.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.6.6

Severity Score:
Medium

CVE:

2024-4277

The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.6.6

Severity Score:
Medium

CVE:

2024-4444

The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
4.2.6.6

Severity Score:
Critical

CVE:

2024-4434

The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.2.6.6

Severity Score:
Critical

CVE:

2024-4397

The vulnerability has been patched, so you should update to version 4.2.6.6.

Import and export users and customers

Plugin:

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.26.6

Severity Score:
Medium

CVE:

2024-34815

The vulnerability has been patched, so you should update to version 1.26.6.

Mesmerize Companion

Plugin:

Mesmerize Companion

Plugin Slug:
mesmerize-companion

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.149

Severity Score:
Medium

CVE:

2024-3494

The vulnerability has been patched, so you should update to version 1.6.149.

Sydney Toolbox

Plugin:

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.32

Severity Score:
Medium

CVE:

2024-4473

The vulnerability has been patched, so you should update to version 1.32.

AI Engine

Plugin:

AI Engine

Plugin Slug:
ai-engine

Installations
70,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.2.70

Severity Score:
Critical

CVE:

2024-34440

The vulnerability has been patched, so you should update to version 2.2.70.

Custom Field Suite

Plugin:

Custom Field Suite

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.6

Severity Score:
Medium

CVE:

2024-3068

The vulnerability has been patched, so you should update to version 2.6.6.

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy)

Plugin:

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy)

Plugin Slug:
easy-digital-downloads

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.12

Severity Score:
Medium

CVE:

2024-32100

The vulnerability has been patched, so you should update to version 3.2.12.

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy)

Plugin:

Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy)

Plugin Slug:
easy-digital-downloads

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.12

Severity Score:
Medium

CVE:

2024-31113

The vulnerability has been patched, so you should update to version 3.2.12.

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Plugin:

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Plugin Slug:
form-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.25

Severity Score:
Medium

CVE:

2024-34437

The vulnerability has been patched, so you should update to version 1.15.25.

Image Hover Effects – Elementor Addon

Plugin:

Image Hover Effects – Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium

CVE:

2024-1166

The vulnerability has been patched, so you should update to version 1.4.2.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin:

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
40,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.39

Severity Score:
High

CVE:

2024-3954

The vulnerability has been patched, so you should update to version 3.1.39.

Timber

Plugin:

Timber

Plugin Slug:
timber-library

Installations
40,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
1.23.1

Severity Score:
High

CVE:

2024-29800

The vulnerability has been patched, so you should update to version 1.23.1.

Plugin:

Visual Footer Credit Remover

Plugin Slug:
visual-footer-credit-remover

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
Medium

CVE:

2024-2846

The vulnerability has been patched, so you should update to version 1.3.

Social Sharing Plugin – Social Warfare

Plugin:

Social Sharing Plugin – Social Warfare

Plugin Slug:
social-warfare

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.4.6

Severity Score:
Medium

CVE:

2024-34825

The vulnerability has been patched, so you should update to version 4.4.6.

Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro

Plugin:

Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro

Plugin Slug:
back-in-stock-notifier-for-woocommerce

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.2

Severity Score:
Medium

CVE:

2024-4038

The vulnerability has been patched, so you should update to version 5.3.2.

Content Blocks (Custom Post Widget)

Plugin:

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.1

Severity Score:
Medium

CVE:

2024-34566

The vulnerability has been patched, so you should update to version 3.3.1.

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers

Plugin:

Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers

Plugin Slug:
rafflepress

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.12.5

Severity Score:
Medium

CVE:

2024-4745

The vulnerability has been patched, so you should update to version 1.12.5.

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Plugin:

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Plugin Slug:
shortpixel-adaptive-images

Installations
20,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.8.4

Severity Score:
Medium

CVE:

2024-35172

The vulnerability has been patched, so you should update to version 3.8.4.

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Plugin:

ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization

Plugin Slug:
shortpixel-adaptive-images

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.4

Severity Score:
Medium

CVE:

2024-4689

The vulnerability has been patched, so you should update to version 3.8.4.

ClickCease Click Fraud Protection

Plugin:

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.5

Severity Score:
Medium

CVE:

2023-6810

The vulnerability has been patched, so you should update to version 3.2.5.

Plugin:

Easy Affiliate Links

Plugin Slug:
easy-affiliate-links

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.3

Severity Score:
Medium

CVE:

2024-34441

The vulnerability has been patched, so you should update to version 3.7.3.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin:

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.9

Severity Score:
Medium

CVE:

2024-35167

The vulnerability has been patched, so you should update to version 1.4.9.

Graphina – Elementor Charts and Graphs

Plugin:

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.10

Severity Score:
Medium

CVE:

2024-4574

The vulnerability has been patched, so you should update to version 1.8.10.

HTML5 Audio Player- Best WordPress Audio Player Plugin

Plugin:

HTML5 Audio Player- Best WordPress Audio Player Plugin

Plugin Slug:
html5-audio-player

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.22

Severity Score:
Medium

CVE:

2024-4398

The vulnerability has been patched, so you should update to version 2.2.22.

Plugin:

Link Library

Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.7

Severity Score:
Medium

CVE:

2024-4281

The vulnerability has been patched, so you should update to version 7.7.

Plugin:

Gallery Block (Meow Gallery)

Plugin Slug:
meow-gallery

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.4

Severity Score:
Medium

CVE:

2024-4386

The vulnerability has been patched, so you should update to version 5.1.4.

Hotel Booking Lite

Plugin:

Hotel Booking Lite

Plugin Slug:
motopress-hotel-booking-lite

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.11.2

Severity Score:
Critical

CVE:

2024-4413

The vulnerability has been patched, so you should update to version 4.11.2.

Shared Counts – Social Media Share Buttons

Plugin:

Shared Counts – Social Media Share Buttons

Plugin Slug:
shared-counts

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.5.0.

Simple Basic Contact Form

Plugin:

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
20240511

Severity Score:
Medium

CVE:

2024-4144

The vulnerability has been patched, so you should update to version 20240511.

SportsPress – Sports Club & League Manager

Plugin:

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.21

Severity Score:
Medium

CVE:

2024-34824

The vulnerability has been patched, so you should update to version 2.7.21.

SSL Zen – Free Let’s Encrypt SSL Certificate & HTTPS/SSL Redirect WordPress Plugin

Plugin:

SSL Zen – Free Let’s Encrypt SSL Certificate & HTTPS/SSL Redirect WordPress Plugin

Plugin Slug:
ssl-zen

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.6.0

Severity Score:
Medium

CVE:

2024-1076

The vulnerability has been patched, so you should update to version 4.6.0.

Themify Shortcodes

Plugin:

Themify Shortcodes

Plugin Slug:
themify-shortcodes

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium

CVE:

2024-4567

The vulnerability has been patched, so you should update to version 2.1.0.

Thim Elementor Kit

Plugin:

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9.1

Severity Score:
Medium

CVE:

2024-4329

The vulnerability has been patched, so you should update to version 1.1.9.1.

Thim Elementor Kit

Plugin:

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
Medium

CVE:

2024-34415

The vulnerability has been patched, so you should update to version 1.1.9.

weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin

Plugin:

weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin

Plugin Slug:
wemail

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.14.3

Severity Score:
Medium

CVE:

2024-34822

The vulnerability has been patched, so you should update to version 1.14.3.

All-in-One Addons for Elementor – WidgetKit

Plugin:

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
Medium

CVE:

2024-34548

The vulnerability has been patched, so you should update to version 2.5.0.

Orders Tracking for WooCommerce

Plugin:

Orders Tracking for WooCommerce

Plugin Slug:
woo-orders-tracking

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.11

Severity Score:
Medium

CVE:

2024-4039

The vulnerability has been patched, so you should update to version 1.2.11.

WP Latest Posts

Plugin:

WP Latest Posts

Plugin Slug:
wp-latest-posts

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.8

Severity Score:
Medium

CVE:

2024-4135

The vulnerability has been patched, so you should update to version 5.0.8.

WP Photo Album Plus

Plugin:

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
8.7.01.002

Severity Score:
Critical

CVE:

2024-31377

The vulnerability has been patched, so you should update to version 8.7.01.002.

YITH WooCommerce Gift Cards

Plugin:

YITH WooCommerce Gift Cards

Plugin Slug:
yith-woocommerce-gift-cards

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.13.0

Severity Score:
Medium

CVE:

2024-0870

The vulnerability has been patched, so you should update to version 4.13.0.

WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc

Plugin:

WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc

Plugin Slug:
wp-sms

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.2

Severity Score:
Medium

CVE:

2024-34811

The vulnerability has been patched, so you should update to version 6.5.2.

Gutenify – Visual Site Builder Blocks & Site Templates.

Plugin:

Gutenify – Visual Site Builder Blocks & Site Templates.

Plugin Slug:
gutenify

Installations
8,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.1

Severity Score:
Medium

CVE:

2024-35165

The vulnerability has been patched, so you should update to version 1.4.1.

If-So Dynamic Content Personalization

Plugin:

If-So Dynamic Content Personalization

Plugin Slug:
if-so

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1.1

Severity Score:
Medium

CVE:

2024-34820

The vulnerability has been patched, so you should update to version 1.7.1.1.

WordPress Affiliates Plugin — SliceWP Affiliates

Plugin:

WordPress Affiliates Plugin — SliceWP Affiliates

Plugin Slug:
slicewp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.11

Severity Score:
Medium

CVE:

2024-34413

The vulnerability has been patched, so you should update to version 1.1.11.

Shipment Tracking, Tracking, and Order Tracking for WooCommerce – ParcelPanel (Free to install)

Plugin:

Shipment Tracking, Tracking, and Order Tracking for WooCommerce – ParcelPanel (Free to install)

Plugin Slug:
parcelpanel

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
3.9.0

Severity Score:
High

CVE:

2024-34412

The vulnerability has been patched, so you should update to version 3.9.0.

WP Compress – Image Optimizer [All-In-One]

Plugin:

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.20.02

Severity Score:
Medium

CVE:

2024-4445

The vulnerability has been patched, so you should update to version 6.20.02.

WP Compress – Image Optimizer [All-In-One]

Plugin:

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Open Redirection

Patched in Version:
6.20.02

Severity Score:
Medium

CVE:

2023-6812

The vulnerability has been patched, so you should update to version 6.20.02.

Better Elementor Addons

Plugin:

Better Elementor Addons

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.5

Severity Score:
Medium

CVE:

2024-34432

The vulnerability has been patched, so you should update to version 1.4.5.

The Best WordPress Knowledgebase and Documentation Plugin – weDocs

Plugin:

The Best WordPress Knowledgebase and Documentation Plugin – weDocs

Plugin Slug:
wedocs

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.5

Severity Score:
Medium

CVE:

2024-34442

The vulnerability has been patched, so you should update to version 2.1.5.

WOLF – WordPress Posts Bulk Editor and Manager Professional

Plugin:

WOLF – WordPress Posts Bulk Editor and Manager Professional

Plugin Slug:
bulk-editor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8.3

Severity Score:
Medium

CVE:

2024-34558

The vulnerability has been patched, so you should update to version 1.0.8.3.

Edwiser Bridge – WordPress Moodle LMS Integration

Plugin:

Edwiser Bridge – WordPress Moodle LMS Integration

Plugin Slug:
edwiser-bridge

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.0.6

Severity Score:
Critical

CVE:

2024-4186

The vulnerability has been patched, so you should update to version 3.0.6.

Plugin:

Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )

Plugin Slug:
magical-addons-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.35

Severity Score:
Medium

CVE:

2024-34547

The vulnerability has been patched, so you should update to version 1.1.35.

Shopping Cart & eCommerce Store

Plugin:

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.6.5

Severity Score:
Medium

CVE:

2024-4213

The vulnerability has been patched, so you should update to version 5.6.5.

Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler

Plugin:

Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler

Plugin Slug:
cf7-styler

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
Medium

CVE:

2024-34826

The vulnerability has been patched, so you should update to version 1.6.5.

3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin

Plugin:

3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook WordPress Plugin

Plugin Slug:
real3d-flipbook-lite

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.72

Severity Score:
Medium

CVE:

2024-34561

The vulnerability has been patched, so you should update to version 3.72.

Startklar Elementor Addons

Plugin:

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets

Installations
4,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.7.14

Severity Score:
High

CVE:

2024-4346

The vulnerability has been patched, so you should update to version 1.7.14.

Startklar Elementor Addons

Plugin:

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.7.14

Severity Score:
Critical

CVE:

2024-4345

The vulnerability has been patched, so you should update to version 1.7.14.

Plugin:

Auto Affiliate Links

Plugin Slug:
wp-auto-affiliate-links

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
6.4.4

Severity Score:
High

CVE:

2024-34386

The vulnerability has been patched, so you should update to version 6.4.4.

All Bootstrap Blocks

Plugin:

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.16

Severity Score:
Medium

CVE:

2024-35169

The vulnerability has been patched, so you should update to version 1.3.16.

Mihdan: Yandex Turbo Feed

Plugin:

Mihdan: Yandex Turbo Feed

Plugin Slug:
mihdan-yandex-turbo-feed

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium

CVE:

2024-4411

The vulnerability has been patched, so you should update to version 1.6.6.

Move Addons for Elementor

Plugin:

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium

CVE:

2024-34562

The vulnerability has been patched, so you should update to version 1.3.1.

Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads & Lead Generation

Plugin:

Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads & Lead Generation

Plugin Slug:
shared-files

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.20

Severity Score:
Medium

CVE:

2024-34438

The vulnerability has been patched, so you should update to version 1.7.20.

WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features)

Plugin:

WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features)

Plugin Slug:
smart-wishlist-for-more-convert

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.9

Severity Score:
Medium

CVE:

2024-34813

The vulnerability has been patched, so you should update to version 1.7.9.

WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features)

Plugin:

WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features)

Plugin Slug:
smart-wishlist-for-more-convert

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.3

Severity Score:
Medium

CVE:

2024-34819

The vulnerability has been patched, so you should update to version 1.7.3.

iPages Flipbook For WordPress

Plugin:

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.2

Severity Score:
Medium

CVE:

2024-4744

The vulnerability has been patched, so you should update to version 1.5.2.

ShopBuilder – Elementor WooCommerce Builder Addons

Plugin:

ShopBuilder – Elementor WooCommerce Builder Addons

Plugin Slug:
shopbuilder

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.9

Severity Score:
Medium

CVE:

2024-34812

The vulnerability has been patched, so you should update to version 2.1.9.

Zotpress

Plugin:

Zotpress

Plugin Slug:
zotpress

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.10

Severity Score:
Medium

CVE:

2024-34569

The vulnerability has been patched, so you should update to version 7.3.10.

Academy LMS – eLearning and online course solution for WordPress

Plugin:

Academy LMS – eLearning and online course solution for WordPress

Plugin Slug:
academy

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.9.26

Severity Score:
Medium

CVE:

2024-35171

The vulnerability has been patched, so you should update to version 1.9.26.

Arigato Autoresponder and Newsletter

Plugin:

Arigato Autoresponder and Newsletter

Plugin Slug:
bft-autoresponder

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.2.4

Severity Score:
Medium

CVE:

2024-34823

The vulnerability has been patched, so you should update to version 2.7.2.4.

Church Admin

Plugin:

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.0

Severity Score:
Medium

CVE:

2024-34828

The vulnerability has been patched, so you should update to version 4.2.0.

Contact List – Premium Staff Listing, Business Directory & Address Book

Plugin:

Contact List – Premium Staff Listing, Business Directory & Address Book

Plugin Slug:
contact-list

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.88

Severity Score:
Medium

CVE:

2024-34821

The vulnerability has been patched, so you should update to version 2.9.88.

Falang multilanguage for WordPress

Plugin:

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.50

Severity Score:
Medium

CVE:

2024-4417

The vulnerability has been patched, so you should update to version 1.3.50.

Ghost

Plugin:

Ghost

Plugin Slug:
ghost

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.0

Severity Score:
High

CVE:

2024-34559

The vulnerability has been patched, so you should update to version 1.5.0.

Gold Addons for Elementor

Plugin:

Gold Addons for Elementor

Plugin Slug:
gold-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium

CVE:

2024-34563

The vulnerability has been patched, so you should update to version 1.3.0.

Dynamics 365 Integration

Plugin:

Dynamics 365 Integration

Plugin Slug:
integration-dynamics

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.18

Severity Score:
Medium

CVE:

2024-34550

The vulnerability has been patched, so you should update to version 1.3.18.

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms

Plugin:

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms

Plugin Slug:
integration-for-contact-form-7-and-pipedrive

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.1

Severity Score:
Medium

CVE:

2024-34817

The vulnerability has been patched, so you should update to version 1.2.1.

SKT Addons for Elementor

Plugin:

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
Medium

CVE:

2024-34445

The vulnerability has been patched, so you should update to version 1.9.

SKT Addons for Elementor

Plugin:

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
Medium

CVE:

2024-34436

The vulnerability has been patched, so you should update to version 1.9.

Squelch Tabs and Accordions Shortcodes

Plugin:

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.4.8

Severity Score:
Medium

CVE:

2024-4463

The vulnerability has been patched, so you should update to version 0.4.8.

Counter Up – Animated Number Counter & Milestone Showcase

Plugin:

Counter Up – Animated Number Counter & Milestone Showcase

Plugin Slug:
wp-counter-up

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium

CVE:

2024-34564

The vulnerability has been patched, so you should update to version 2.3.0.

WP Discourse

Plugin:

WP Discourse

Plugin Slug:
wp-discourse

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.2

Severity Score:
Medium

CVE:

2024-35168

The vulnerability has been patched, so you should update to version 2.5.2.

WPCal.io – Easy Meeting Scheduler

Plugin:

WPCal.io – Easy Meeting Scheduler

Plugin Slug:
wpcal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.5.9

Severity Score:
Medium

CVE:

2024-34816

The vulnerability has been patched, so you should update to version 0.9.5.9.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin:

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.5

Severity Score:
Medium

CVE:

2024-34557

The vulnerability has been patched, so you should update to version 1.5.5.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin:

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
800+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5.5

Severity Score:
Medium

CVE:

2024-34556

The vulnerability has been patched, so you should update to version 1.5.5.

Sticky banner

Plugin:

Sticky banner

Plugin Slug:
sticky-banner

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium

CVE:

2024-35170

The vulnerability has been patched, so you should update to version 1.3.0.

Joli FAQ SEO – WordPress FAQ Plugin

Plugin:

Joli FAQ SEO – WordPress FAQ Plugin

Plugin Slug:
joli-faq-seo

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.3

Severity Score:
Medium

CVE:

2024-4082

The vulnerability has been patched, so you should update to version 1.3.3.

Soccer Engine – Soccer Plugin for WordPress

Plugin:

Soccer Engine – Soccer Plugin for WordPress

Plugin Slug:
soccer-engine-lite

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.13

Severity Score:
Medium

CVE:

2024-4312

The vulnerability has been patched, so you should update to version 1.13.

Hostel

Plugin:

Hostel

Plugin Slug:
hostel

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.5.4

Severity Score:
Medium

CVE:

2024-4314

The vulnerability has been patched, so you should update to version 1.1.5.4.

ADFO – Custom data in admin dashboard

Plugin:

ADFO – Custom data in admin dashboard

Plugin Slug:
admin-form

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.1

Severity Score:
Medium

CVE:

2024-4103

The vulnerability has been patched, so you should update to version 1.9.1.

ADFO – Custom data in admin dashboard

Plugin:

ADFO – Custom data in admin dashboard

Plugin Slug:
admin-form

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
High

CVE:

2024-4104

The vulnerability has been patched, so you should update to version 1.9.1.

Z-Downloads

Plugin:

Z-Downloads

Plugin Slug:
z-downloads

Installations
60+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.11.4

Severity Score:
Critical

CVE:

2024-34555

The vulnerability has been patched, so you should update to version 1.11.4.

Aiomatic

Plugin:

Aiomatic

Plugin Slug:
aiomatic-automatic-ai-content-writer

Vulnerability:
Broken Access Control

Patched in Version:
1.9.4

Severity Score:
Medium

CVE:

2024-34435

The vulnerability has been patched, so you should update to version 1.9.4.

Breakdance

Plugin:

Breakdance

Plugin Slug:
breakdance

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.7.2

Severity Score:
High

CVE:

2024-4605

The vulnerability has been patched, so you should update to version 1.7.2.

Divi Builder

Plugin:

Divi Builder

Plugin Slug:
divi-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.25.1

Severity Score:
Medium

CVE:

2024-4490

The vulnerability has been patched, so you should update to version 4.25.1.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.81

Severity Score:
Medium

CVE:

2024-0904

The vulnerability has been patched, so you should update to version 6.1.81.

Porto Theme – Functionality

Plugin:

Porto Theme – Functionality

Plugin Slug:
porto-functionality

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.1

Severity Score:
Medium

CVE:

2024-3808

The vulnerability has been patched, so you should update to version 3.1.1.

Spectra Pro

Plugin:

Spectra Pro

Plugin Slug:
spectra-pro

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.6

Severity Score:
High

CVE:

2024-3828

The vulnerability has been patched, so you should update to version 1.1.6.

Stockholm Core

Plugin:

Stockholm Core

Plugin Slug:
stockholm-core

Vulnerability:
Local File Inclusion

Patched in Version:
2.4.2

Severity Score:
High

CVE:

2024-34554

The vulnerability has been patched, so you should update to version 2.4.2.

Stockholm Core

Plugin:

Stockholm Core

Plugin Slug:
stockholm-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
High

CVE:

2024-34553

The vulnerability has been patched, so you should update to version 2.4.2.

Unyson

Plugin:

Unyson

Plugin Slug:
unyson

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.31

Severity Score:
Medium

CVE:

2024-34814

The vulnerability has been patched, so you should update to version 2.7.31.

WordPress Themes — 16 Patched

Consus

Theme:

Consus

Theme Slug:
consus

Downloads
16,364

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.7.

EmpowerWP

Theme:

EmpowerWP

Theme Slug:
empowerwp

Downloads
219,376

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.22

Severity Score:
Medium

CVE:

2024-34809

The vulnerability has been patched, so you should update to version 1.0.22.

Himalayas

Theme:

Himalayas

Theme Slug:
himalayas

Downloads
332,940

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium

CVE:

2024-34571

The vulnerability has been patched, so you should update to version 1.3.1.

Ketos

Theme:

Ketos

Theme Slug:
ketos

Downloads
28,703

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.6.

Mindscape

Theme:

Mindscape

Theme Slug:
mindscape

Downloads
41,737

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.23

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.23.

Niveau

Theme:

Niveau

Theme Slug:
niveau

Downloads
16,831

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.9

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.9.

Oasis

Theme:

Oasis

Theme Slug:
oasis

Downloads
69,511

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.13

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.13.

raindrops

Theme:

raindrops

Theme Slug:
raindrops

Downloads
716,615

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.700

Severity Score:
Medium

CVE:

2024-34414

The vulnerability has been patched, so you should update to version 1.700.

Skyline WP

Theme:

Skyline WP

Theme Slug:
skyline-wp

Downloads
169,635

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.11

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.11.

Zeka

Theme:

Zeka

Theme Slug:
zeka

Downloads
20,249

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.10

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.10.

Divi

Theme:

Divi

Theme Slug:
divi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.25.1

Severity Score:
Medium

CVE:

2024-4490

The vulnerability has been patched, so you should update to version 4.25.1.

Extra

Theme:

Extra

Theme Slug:
extra

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.25.1

Severity Score:
Medium

CVE:

2024-4490

The vulnerability has been patched, so you should update to version 4.25.1.

Porto

Theme:

Porto

Theme Slug:
porto

Vulnerability:
Local File Inclusion

Patched in Version:
7.1.1

Severity Score:
High

CVE:

2024-3806

The vulnerability has been patched, so you should update to version 7.1.1.

Porto

Theme:

Porto

Theme Slug:
porto

Vulnerability:
Local File Inclusion

Patched in Version:
7.1.1

Severity Score:
Medium

CVE:

2024-3807

The vulnerability has been patched, so you should update to version 7.1.1.

Stockholm

Theme:

Stockholm

Theme Slug:
stockholm

Vulnerability:
Local File Inclusion

Patched in Version:
9.7

Severity Score:
High

CVE:

2024-34552

The vulnerability has been patched, so you should update to version 9.7.

Stockholm

Theme:

Stockholm

Theme Slug:
stockholm

Vulnerability:
Local File Inclusion

Patched in Version:
9.7

Severity Score:
Critical

CVE:

2024-34551

The vulnerability has been patched, so you should update to version 9.7.

window[“27011011_8965_4393_8beb_65720bd4bc69”] = {“blockId”:”27011011-8965-4393-8beb-65720bd4bc69″,”className”:””,”heading”:”Solid Security is part of Solid Suite u2014 The best foundation for WordPress websites.”,”text”:”Every WordPress site needs security, backups, and management tools. Thatu2019s Solid Suite u2014 an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academyu2019s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!”,”buttonText”:”Get Solid Security”,”buttonLink”:”/pricing”,”buttonTarget”:”_self”,”buttonRel”:””};

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — May 15, 2024 appeared first on SolidWP.

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-05-15 12:21:12.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — April 3, 2024

WordPress Vulnerability Report — April 3, 2024

In this report, 255 vulnerabilities have been publicly disclosed. Security patches for 178 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 77 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5 “Regina” was released on April 2, 2024, as the first major release of 2024. With the new release, you can add and manage fonts across your site, get more from your revisions, play with enhanced background and shadow tools, discover new Data Views, and so much more.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 175 Patched / 77 Unpatched

Plugin Slug:
auxin-elements

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
easy-facebook-likebox

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
pdf-viewer-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
getresponse-integration

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Yoo Slider

Plugin Slug:
yoo-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Responsive flipbook

Plugin Slug:
wppdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Twitter Mega Fan Box Widget

Plugin Slug:
wp-twitter-mega-fan-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Sponsors

Plugin Slug:
wp-sponsors

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP-Eggdrop

Plugin Slug:
wp-eggdrop

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP-Eggdrop

Plugin Slug:
wp-eggdrop

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Broken Images

Plugin Slug:
wp-broken-images

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Popup Cart Lite for WooCommerce

Plugin Slug:
woocommerce-woocart-popup-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Woocommerce Social Media Share Buttons

Plugin Slug:
woocommerce-social-media-share-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WooCommerce Bookings Calendar

Plugin Slug:
woo-bookings-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Whizzy

Plugin Slug:
whizzy

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Whizzy

Plugin Slug:
whizzy

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Weekly Class Schedule

Plugin Slug:
weekly-class-schedule

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

10Web Map Builder for Google Maps

Plugin Slug:
wd-google-maps

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

User Rights Access Manager

Plugin Slug:
user-rights-access-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Ultimate Social Comments – Email Notification & Lazy Load

Plugin Slug:
ultimate-facebook-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Sticky Anything

Plugin Slug:
toast-stick-anything

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Thumbs Rating

Plugin Slug:
thumbs-rating

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tax Rate Upload

Plugin Slug:
tax-rate-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Spin 360 deg and 3D Model Viewer

Plugin Slug:
spin360

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

SpiderFAQ

Plugin Slug:
spider-faq

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Special Box for Content

Plugin Slug:
special-box-for-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Social Author Bio

Plugin Slug:
social-autho-bio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Lightbox slider – Responsive Lightbox Gallery

Plugin Slug:
simple-lightbox-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

SEO Title Tag

Plugin Slug:
seo-title-tag

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Prenotazioni

Plugin Slug:
prenotazioni

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Post-Plugin Library

Plugin Slug:
post-plugin-library

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Pocket News Generator

Plugin Slug:
pocket-news-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Pocket News Generator

Plugin Slug:
pocket-news-generator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Platinum SEO

Plugin Slug:
platinum-seo-pack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

pageMash > Page Management

Plugin Slug:
pagemash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Oxygen Builder

Plugin Slug:
oxygen

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

OpenID

Plugin Slug:
openid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

News Wall

Plugin Slug:
news-wall

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

New Order Notification for Woocommerce

Plugin Slug:
new-order-notification-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Lordicon Animated Icons

Plugin Slug:
lordicon-interactive-icons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Kanban Boards for WordPress

Plugin Slug:
kanban

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Mighty Classic Pros And Cons

Plugin Slug:
joomdev-wp-pros-cons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

IP Blocker Lite

Plugin Slug:
ip-address-blocker

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

iFlyChat – WordPress Chat

Plugin Slug:
iflychat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

HeartThis

Plugin Slug:
heart-this

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Header Image Slider

Plugin Slug:
header-image-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Responsive Image Gallery, Gallery Album

Plugin Slug:
gallery-album

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Responsive Image Gallery, Gallery Album

Plugin Slug:
gallery-album

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Filter Custom Fields & Taxonomies Light

Plugin Slug:
filter-custom-fields-taxonomies-light

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

EnvíaloSimple

Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

DX-Watermark

Plugin Slug:
dx-watermark

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Hacklog Down As PDF

Plugin Slug:
down-as-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

DD Rating

Plugin Slug:
dd-rating

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Custom Field Bulk Editor

Plugin Slug:
custom-field-bulk-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Convert Post Types

Plugin Slug:
convert-post-types

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Contact Forms by Cimatti

Plugin Slug:
contact-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Contact Form 7 Newsletter

Plugin Slug:
contact-form-7-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Comic Easel

Plugin Slug:
comic-easel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Christmas Greetings

Plugin Slug:
christmas-greetings

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Chauffeur Taxi Booking System for WordPress

Plugin Slug:
chauffeur-booking-system

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Change default login logo,url and title

Plugin Slug:
change-default-login-logo-url-and-title

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

CGC Maintenance Mode

Plugin Slug:
cgc-maintenance-mode

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Low

Plugin:

Carousel Anything For WPBakery Page Builder

Plugin Slug:
carousel-anything

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Button

Plugin Slug:
button

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Breakdance

Plugin Slug:
breakdance

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Appointment Calendar

Plugin Slug:
appointment-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

All In One Redirection

Plugin Slug:
all-in-one-redirection-404-pages-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

AI Twitter Feeds (Twitter widget & shortcode)

Plugin Slug:
ai-twitter-feeds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Aesop Story Engine

Plugin Slug:
aesop-story-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

AdsPlace’r – Ad Manager, Inserter, AdSense Ads

Plugin Slug:
adsplacer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Add Shortcodes Actions And Filters

Plugin Slug:
add-actions-and-filters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.9.14

Severity Score:
High

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.9.14

Severity Score:
Medium

Plugin Slug:
all-in-one-wp-security-and-firewall

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.2.7

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.0.7

Severity Score:
High

Plugin Slug:
ninja-forms

Installations
800,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.1

Severity Score:
Medium

Plugin Slug:
ninja-forms

Installations
800,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
Medium

Plugin Slug:
forminator

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29.1

Severity Score:
High

Plugin Slug:
coblocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.18

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.2.26

Severity Score:
Medium

Plugin Slug:
metform

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.6

Severity Score:
Medium

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
8.2.1

Severity Score:
Medium

Plugin Slug:
otter-blocks

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.6

Severity Score:
Medium

Plugin Slug:
cmp-coming-soon-maintenance

Installations
200,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.1.11

Severity Score:
Medium

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
unlimited-elements-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.97

Severity Score:
Medium

Plugin Slug:
woo-cart-abandonment-recovery

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.27

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.2

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.3

Severity Score:
Medium

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
5.5.4

Severity Score:
High

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0.7

Severity Score:
Medium

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4.5

Severity Score:
Medium

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.270

Severity Score:
Medium

Plugin Slug:
download-monitor

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.9.5

Severity Score:
High

Plugin Slug:
essential-blocks

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.10

Severity Score:
Medium

Plugin Slug:
genesis-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium

Plugin Slug:
list-category-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.89.7

Severity Score:
Medium

Plugin Slug:
meta-tag-manager

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1

Severity Score:
High

Plugin Slug:
pagelayer

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.2

Severity Score:
Medium

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.10.2

Severity Score:
Medium

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.0.10.2

Severity Score:
High

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.0.10.2

Severity Score:
Critical

Plugin Slug:
powerpack-lite-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.18

Severity Score:
Medium

Plugin Slug:
powerpack-lite-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.19

Severity Score:
Medium

Plugin Slug:
social-icons-widget-by-wpzoom

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.16

Severity Score:
Medium

Plugin Slug:
stackable-ultimate-gutenberg-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.12

Severity Score:
Medium

Plugin Slug:
template-kit-import

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.15

Severity Score:
Medium

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.5

Severity Score:
Medium

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.5.3

Severity Score:
Medium

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.5.2

Severity Score:
Medium

Plugin Slug:
wp-whatsapp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.3

Severity Score:
Medium

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.4.7

Severity Score:
Medium

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.7.2

Severity Score:
Medium

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.7.2

Severity Score:
Medium

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.7.2

Severity Score:
Medium

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.27

Severity Score:
Medium

Plugin Slug:
boldgrid-easy-seo

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.14

Severity Score:
Medium

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14

Severity Score:
Medium

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
70,000+

Vulnerability:
Path Traversal

Patched in Version:
2.5.3

Severity Score:
Medium

Plugin Slug:
underconstruction

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.22

Severity Score:
Medium

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.1.8

Severity Score:
Medium

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9.3

Severity Score:
High

Plugin Slug:
ajax-load-more

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.2

Severity Score:
Medium

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium

Plugin Slug:
social-pug

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.33.1

Severity Score:
Medium

Plugin Slug:
social-pug

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.33.2

Severity Score:
High

Plugin Slug:
wpfront-user-role-editor

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.1.0

Severity Score:
Medium

Plugin Slug:
fluent-crm

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.45

Severity Score:
Medium

Plugin Slug:
klarna-payments-for-woocommerce

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.0

Severity Score:
Medium

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.76

Severity Score:
High

Plugin Slug:
secupress

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.5.2

Severity Score:
Medium

Plugin Slug:
pz-linkcard

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.5.3

Severity Score:
Medium

Plugin Slug:
pz-linkcard

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
High

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.4

Severity Score:
Medium

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium

Plugin Slug:
woo-bulk-editor

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.4.4

Severity Score:
Medium

Plugin Slug:
brave-popup-builder

Installations
20,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
0.6.6

Severity Score:
Medium

Plugin Slug:
easy-appointments

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.19

Severity Score:
Medium

Plugin Slug:
easy-appointments

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.11.19

Severity Score:
Medium

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.12.11

Severity Score:
Medium

Plugin Slug:
mp3-music-player-by-sonaar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.1

Severity Score:
Medium

Plugin Slug:
mp3-music-player-by-sonaar

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.1

Severity Score:
High

Plugin Slug:
my-calendar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.24

Severity Score:
Medium

Plugin Slug:
shortpixel-adaptive-images

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.3

Severity Score:
Medium

Plugin Slug:
weforms

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.21

Severity Score:
Low

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.6

Severity Score:
Medium

Plugin Slug:
awesome-support

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.1.8

Severity Score:
Medium

Plugin Slug:
booking-package

Installations
10,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.6.29

Severity Score:
High

Plugin Slug:
favorites

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium

Plugin Slug:
gamipress

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.8.6

Severity Score:
Medium

Plugin Slug:
gamipress

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.9.1

Severity Score:
Medium

Plugin Slug:
lws-optimize

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0

Severity Score:
Medium

Plugin Slug:
mailster

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.7

Severity Score:
High

Plugin Slug:
mangboard

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
High

Plugin Slug:
masterstudy-lms-learning-management-system

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.2

Severity Score:
Critical

Plugin Slug:
masterstudy-lms-learning-management-system

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.3.1

Severity Score:
Critical

Plugin Slug:
molongui-authorship

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.7.8

Severity Score:
Low

Plugin Slug:
page-builder-add

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1.8

Severity Score:
Medium

Plugin Slug:
sellkit

Installations
10,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.8.3

Severity Score:
Medium

Plugin Slug:
simple-revisions-delete

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.4

Severity Score:
Medium

Plugin Slug:
very-simple-contact-form

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
14.8

Severity Score:
Medium

Plugin Slug:
wp-travel-engine

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
5.8.0

Severity Score:
High

Plugin Slug:
wp-travel-engine

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
5.8.0

Severity Score:
Critical

Plugin Slug:
xpro-elementor-addons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3

Severity Score:
Medium

Plugin Slug:
media-library-plus

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
8.1.8

Severity Score:
High

Plugin Slug:
wp-hotel-booking

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9.3

Severity Score:
Medium

Plugin Slug:
wp-sms

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.6.3

Severity Score:
Medium

Plugin Slug:
collectchat

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
Medium

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
7,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.18.1

Severity Score:
High

Plugin Slug:
hash-elements

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.7.3

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.7.9

Severity Score:
High

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
SQL Injection

Patched in Version:
5.7.9

Severity Score:
Critical

Plugin Slug:
the-plus-addons-for-block-editor

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.6

Severity Score:
High

Plugin Slug:
wp-forecast

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.3

Severity Score:
Medium

Plugin Slug:
announce-from-the-dashboard

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium

Plugin Slug:
dc-woocommerce-multi-vendor

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.4

Severity Score:
Medium

Plugin Slug:
jch-optimize

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.1

Severity Score:
Medium

Plugin Slug:
nelio-content

Installations
6,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.2.1

Severity Score:
Medium

Plugin Slug:
salon-booking-system

Installations
6,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
9.5.1

Severity Score:
Critical

Plugin Slug:
sliced-invoices

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.3

Severity Score:
Medium

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium

Plugin Slug:
booking-activities

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.20

Severity Score:
High

Plugin Slug:
pmpro-mailchimp

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.5

Severity Score:
Medium

Plugin Slug:
b-slider

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.13

Severity Score:
Medium

Plugin Slug:
remove-old-slugspermalinks

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.0

Severity Score:
Medium

Plugin Slug:
add-fields-to-checkout-page-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.1

Severity Score:
Medium

Plugin Slug:
builderall-cheetah-for-wp

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.2

Severity Score:
Medium

Plugin Slug:
cubewp-framework

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.13

Severity Score:
Critical

Plugin Slug:
landingi-landing-pages

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.2

Severity Score:
Medium

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.0

Severity Score:
Medium

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.11

Severity Score:
Medium

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.10

Severity Score:
Medium

Plugin Slug:
themify-event-post

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.8

Severity Score:
Medium

Plugin Slug:
woocommerce-product-sort-and-display

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.2

Severity Score:
Medium

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
High

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
Critical

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium

Plugin Slug:
layouts-for-elementor

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8

Severity Score:
High

Plugin Slug:
responsive-horizontal-vertical-and-accordion-tabs

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.18

Severity Score:
High

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1

Severity Score:
Medium

Plugin Slug:
wp-express-checkout

Installations
2,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
2.3.8

Severity Score:
High

Plugin Slug:
wpc-badge-management

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.1

Severity Score:
Medium

Plugin Slug:
zionbuilder

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.10

Severity Score:
Medium

Plugin Slug:
zotpress

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
7.3.8

Severity Score:
High

Plugin Slug:
ai-wp-writer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.5.6

Severity Score:
Medium

Plugin Slug:
bulletin-announcements

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
3.9.0

Severity Score:
High

Plugin Slug:
cf-geoplugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6.5

Severity Score:
Medium

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.19

Severity Score:
Medium

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.8

Severity Score:
Medium

Plugin Slug:
contest-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
21.3.6

Severity Score:
High

Plugin Slug:
creative-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium

Plugin Slug:
currency-switcher

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0.2

Severity Score:
Medium

Plugin Slug:
easy-form-builder

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.5

Severity Score:
High

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.48

Severity Score:
High

Plugin Slug:
fg-prestashop-to-woocommerce

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.47.0

Severity Score:
Medium

Plugin Slug:
gs-testimonial

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.5

Severity Score:
Medium

Plugin Slug:
icon

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.0.11

Severity Score:
Medium

Plugin Slug:
oss-aliyun

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.11

Severity Score:
High

Plugin Slug:
pmpro-payfast

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.2

Severity Score:
Medium

Plugin Slug:
print-page

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.9

Severity Score:
Medium

Plugin Slug:
stepbyteservice-openstreetmap

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.20.8

Severity Score:
Medium

Plugin Slug:
tumult-hype-animations

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.12

Severity Score:
High

Plugin Slug:
tumult-hype-animations

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.12

Severity Score:
Medium

Plugin Slug:
webinar-and-video-conference-with-jitsi-meet

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
wholesalex

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.3

Severity Score:
Critical

Plugin Slug:
wooshark-aliexpress-importer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.5

Severity Score:
Medium

Plugin Slug:
wp-crm-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.9.1

Severity Score:
Medium

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.3.2

Severity Score:
Medium

Plugin Slug:
delucks-seo

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.5

Severity Score:
Medium

Plugin Slug:
creative-image-slider

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
High

Plugin:

YITH WooCommerce Account Funds Premium

Plugin Slug:
yith-woocommerce-account-funds-premium

Vulnerability:
Broken Access Control

Patched in Version:
1.34.0

Severity Score:
Medium

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
SQL Injection

Patched in Version:
10.1.76

Severity Score:
High

Plugin:

Wholesale For WooCommerce

Plugin Slug:
woocommerce-wholesale-pricing

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.1

Severity Score:
Medium

Plugin:

Slider by Supsystic

Plugin Slug:
slider-by-supsystic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.11

Severity Score:
Medium

Plugin:

REHub Framework

Plugin Slug:
rehub-framework

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High

Plugin:

Limit Attempts by BestWebSoft

Plugin Slug:
limit-attempts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
High

Plugin:

LayerSlider

Plugin Slug:
layerslider

Vulnerability:
SQL Injection

Patched in Version:
7.10.1

Severity Score:
Critical

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
1.30.0

Severity Score:
High

Plugin:

Calendarista Basic Edition

Plugin Slug:
calendarista-basic-edition

Vulnerability:
Broken Access Control

Patched in Version:
3.0.6

Severity Score:
Medium

WordPress Themes — 3 Patched / 0 Unpatched

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
High

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
Critical

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-04-03 11:59:26.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — April 10, 2024

WordPress Vulnerability Report — April 10, 2024

In this report, 200 vulnerabilities have been publicly disclosed. Security patches for 182 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 18 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.5

Severity Score:
Medium

WordPress Plugins — 177 Patched / 18 Unpatched

Plugin Slug:
user-activity-log

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
slideshow-gallery

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
slideshow-gallery

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
slideshow-gallery

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
bannerlid

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Auto Poster

Plugin Slug:
auto-poster

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Breakdance

Plugin Slug:
breakdance

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

CGC Maintenance Mode

Plugin Slug:
cgc-maintenance-mode

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Passster – Password Protection

Plugin Slug:
content-protector

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Easy Login Styler – White Label Admin Login Page for WordPress

Plugin Slug:
easy-login-styler

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

EnvíaloSimple

Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Font Farsi

Plugin Slug:
font-farsi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Global Elementor Buttons

Plugin Slug:
global-elementor-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Gradient Text Widget for Elementor

Plugin Slug:
gradient-text-widget-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Oxygen Builder

Plugin Slug:
oxygen

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

WordPress Gallery Exporter

Plugin Slug:
wp-gallery-exporter

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
woocommerce

Installations
5,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.6.0

Severity Score:
Medium

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.9.14

Severity Score:
High

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.9.14

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.0

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium

Plugin Slug:
wp-file-manager

Installations
1,000,000+

Vulnerability:
Path Traversal

Patched in Version:
7.2.6

Severity Score:
Medium

Plugin Slug:
ocean-extra

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.10.23

Severity Score:
Medium

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.4

Severity Score:
Medium

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.4

Severity Score:
Medium

Plugin Slug:
forminator

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29.3

Severity Score:
Medium

Plugin Slug:
forminator

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29.1

Severity Score:
High

Plugin Slug:
nextgen-gallery

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.59.1

Severity Score:
Medium

Plugin Slug:
coblocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.26

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.32

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.18

Severity Score:
Medium

Plugin Slug:
cmb2

Installations
300,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.11.0

Severity Score:
High

Plugin Slug:
metform

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.6

Severity Score:
Medium

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.95

Severity Score:
Medium

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
photo-gallery

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.22

Severity Score:
Medium

Plugin Slug:
post-views-counter

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.5

Severity Score:
Medium

Plugin Slug:
responsive-lightbox

Installations
200,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.7

Severity Score:
Medium

Plugin Slug:
woo-cart-abandonment-recovery

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.27

Severity Score:
Medium

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.3

Severity Score:
Medium

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0.7

Severity Score:
Medium

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.270

Severity Score:
Medium

Plugin Slug:
essential-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.4

Severity Score:
Medium

Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium

Plugin Slug:
genesis-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium

Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium

Plugin Slug:
powerpack-lite-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.18

Severity Score:
Medium

Plugin Slug:
powerpack-lite-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.19

Severity Score:
Medium

Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.22.2

Severity Score:
Medium

Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
CSV Injection

Patched in Version:
4.22.2

Severity Score:
Medium

Plugin Slug:
template-kit-import

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.15

Severity Score:
Medium

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.0

Severity Score:
Medium

Plugin Slug:
woo-order-export-lite

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.4.5

Severity Score:
Critical

Plugin Slug:
woolentor-addons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.5

Severity Score:
Medium

Plugin Slug:
woolentor-addons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4

Severity Score:
Medium

Plugin Slug:
email-subscribers

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.16

Severity Score:
Medium

Plugin Slug:
email-subscribers

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.14

Severity Score:
Medium

Plugin Slug:
embedpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.15

Severity Score:
Medium

Plugin Slug:
embedpress

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.9

Severity Score:
Medium

Plugin Slug:
embedpress

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.12

Severity Score:
Medium

Plugin Slug:
flexible-checkout-fields

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.3

Severity Score:
Medium

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.1

Severity Score:
High

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.6.4

Severity Score:
Medium

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.2.6.4

Severity Score:
Medium

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29

Severity Score:
Medium

Plugin Slug:
boldgrid-easy-seo

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.15

Severity Score:
Medium

Plugin Slug:
simple-tags

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.20.0

Severity Score:
Medium

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9.3

Severity Score:
High

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
easy-digital-downloads

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.7

Severity Score:
Medium

Plugin Slug:
easy-digital-downloads

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.10

Severity Score:
Medium

Plugin Slug:
fancybox-for-wordpress

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.4

Severity Score:
Medium

Plugin Slug:
feedzy-rss-feeds

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.4

Severity Score:
Medium

Plugin Slug:
image-watermark

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.4

Severity Score:
Medium

Plugin Slug:
print-invoices-packing-slip-labels-for-woocommerce

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.3

Severity Score:
Medium

Plugin Slug:
profile-builder

Installations
50,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.11.3

Severity Score:
Medium

Plugin Slug:
social-pug

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.33.1

Severity Score:
Medium

Plugin Slug:
wpfront-user-role-editor

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.1.0

Severity Score:
Medium

Plugin Slug:
convertkit

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.6

Severity Score:
Medium

Plugin Slug:
secupress

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.5.2

Severity Score:
Medium

Plugin Slug:
ultimate-post

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.4

Severity Score:
Medium

Plugin Slug:
wp-import-export-lite

Installations
40,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.9.27

Severity Score:
Medium

Plugin Slug:
google-maps-easy

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.11.12

Severity Score:
Medium

Plugin Slug:
sumome

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.35

Severity Score:
Low

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
High

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.4

Severity Score:
Medium

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium

Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.12.11

Severity Score:
Medium

Plugin Slug:
mp3-music-player-by-sonaar

Installations
20,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
5.0

Severity Score:
High

Plugin Slug:
my-calendar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.24

Severity Score:
Medium

Plugin Slug:
powerkit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
Medium

Plugin Slug:
shortpixel-adaptive-images

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.3

Severity Score:
Medium

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.6

Severity Score:
Medium

Plugin Slug:
bookingpress-appointment-booking

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.0.82

Severity Score:
Medium

Plugin Slug:
bookingpress-appointment-booking

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.0.88

Severity Score:
Medium

Plugin Slug:
bunnycdn

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium

Plugin Slug:
captcha-bws

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
5.2.1

Severity Score:
Medium

Plugin Slug:
classified-listing

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.5

Severity Score:
High

Plugin Slug:
classified-listing

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.5

Severity Score:
Medium

Plugin Slug:
contact-form-to-email

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.45

Severity Score:
Medium

Plugin Slug:
favorites

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium

Plugin Slug:
lifterlms

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.5.1

Severity Score:
Medium

Plugin Slug:
mailmunch

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium

Plugin Slug:
masterstudy-lms-learning-management-system

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.3.4

Severity Score:
Critical

Plugin Slug:
s2member

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
240325

Severity Score:
High

Plugin Slug:
subscribe-to-comments-reloaded

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
240119

Severity Score:
Medium

Plugin Slug:
ultimate-maps-by-supsystic

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.17

Severity Score:
Medium

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
8.6.03.005

Severity Score:
Critical

Plugin Slug:
wp-server-stats

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.4

Severity Score:
Medium

Plugin Slug:
media-library-plus

Installations
9,000+

Vulnerability:
Directory Traversal

Patched in Version:
8.1.9

Severity Score:
Medium

Plugin Slug:
wp-migration-duplicator

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.8

Severity Score:
Low

Plugin Slug:
announcer

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.0.1

Severity Score:
Medium

Plugin Slug:
generate-child-theme

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.1

Severity Score:
Medium

Plugin Slug:
learnpress-import-export

Installations
8,000+

Vulnerability:
SQL Injection

Patched in Version:
4.0.4

Severity Score:
High

Plugin Slug:
wpvivid-backup-mainwp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.34

Severity Score:
Medium

Plugin Slug:
armember-membership

Installations
7,000+

Vulnerability:
Directory Traversal

Patched in Version:
4.0.28

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.7.9

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.7.7

Severity Score:
Medium

Plugin Slug:
announce-from-the-dashboard

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium

Plugin Slug:
dc-woocommerce-multi-vendor

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.4

Severity Score:
High

Plugin Slug:
wordpress-tooltips

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.5.9

Severity Score:
High

Plugin Slug:
wp-sort-order

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium

Plugin Slug:
edwiser-bridge

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
3.0.4

Severity Score:
High

Plugin Slug:
js-support-ticket

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.4

Severity Score:
Medium

Plugin Slug:
wp-stateless

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.1

Severity Score:
High

Plugin Slug:
advanced-local-pickup-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.3

Severity Score:
High

Plugin Slug:
custom-post-types

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.5

Severity Score:
Medium

Plugin Slug:
peepso-core

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.1.2

Severity Score:
Medium

Plugin Slug:
watu

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.1.1

Severity Score:
Medium

Plugin Slug:
watu

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.4.1.1

Severity Score:
Medium

Plugin Slug:
comments-import-export-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.6

Severity Score:
Medium

Plugin Slug:
eventprime-event-calendar-management

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.5

Severity Score:
High

Plugin Slug:
export-woocommerce

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9

Severity Score:
Medium

Plugin Slug:
import-xml-feed

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.1.6

Severity Score:
High

Plugin Slug:
modal-popup-box

Installations
3,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.5.3

Severity Score:
High

Plugin Slug:
multiple-pages-generator-by-porthas

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.1

Severity Score:
Medium

Plugin Slug:
oauth2-provider

Installations
3,000+

Vulnerability:
Open Redirection

Patched in Version:
4.4.0

Severity Score:
Medium

Plugin Slug:
premmerce-woocommerce-product-filter

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.3

Severity Score:
Medium

Plugin Slug:
super-testimonial

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
Medium

Plugin Slug:
woocommerce-product-sort-and-display

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.2

Severity Score:
Medium

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.1

Severity Score:
High

Plugin Slug:
arforms-form-builder

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.2

Severity Score:
Medium

Plugin Slug:
arforms-form-builder

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.2

Severity Score:
High

Plugin Slug:
clover-online-orders

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.6

Severity Score:
Medium

Plugin Slug:
form-to-chat

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium

Plugin Slug:
learning-management-system

Installations
2,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.3

Severity Score:
Critical

Plugin Slug:
quick-interest-slider

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.5

Severity Score:
Medium

Plugin Slug:
searchiq

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.6

Severity Score:
High

Plugin Slug:
user-spam-remover

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1

Severity Score:
Medium

Plugin Slug:
woo-checkout-regsiter-field-editor

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.9

Severity Score:
Medium

Plugin Slug:
app-builder

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
3.8.8

Severity Score:
Medium

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.3.1

Severity Score:
Medium

Plugin Slug:
benchmark-email-lite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.7

Severity Score:
Medium

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.1.6

Severity Score:
Critical

Plugin Slug:
creative-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
High

Plugin Slug:
epoll-wp-voting

Installations
1,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.4

Severity Score:
High

Plugin Slug:
fg-drupal-to-wp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.71.0

Severity Score:
Medium

Plugin Slug:
formsite

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium

Plugin Slug:
nudgify

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.4

Severity Score:
Medium

Plugin Slug:
product-designer

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.0.33

Severity Score:
High

Plugin Slug:
redi-restaurant-reservation

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
24.0303

Severity Score:
High

Plugin Slug:
sign-up-sheets

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.12

Severity Score:
Medium

Plugin Slug:
transcoder

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.6

Severity Score:
Medium

Plugin Slug:
ultimate-store-kit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium

Plugin Slug:
unusedcss

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.12

Severity Score:
High

Plugin Slug:
wooshark-aliexpress-importer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.5

Severity Score:
Medium

Plugin Slug:
wp-webinarsystem

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.33.10

Severity Score:
High

Plugin Slug:
wp2leads

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.8

Severity Score:
Medium

Plugin Slug:
5-stars-rating-funnel

Installations
30+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
1.3.02

Severity Score:
High

Plugin:

AWP Classifieds

Plugin Slug:
another-wordpress-classifieds-plugin

Vulnerability:
Broken Access Control

Patched in Version:
4.3.2

Severity Score:
Medium

Plugin:

Beaver Themer

Plugin Slug:
beaver-themer

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.9.1

Severity Score:
Medium

Plugin:

Bricksforge

Plugin Slug:
bricksforge

Vulnerability:
Settings Change

Patched in Version:
2.1.1

Severity Score:
Critical

Plugin:

Bricksforge

Plugin Slug:
bricksforge

Vulnerability:
Settings Change

Patched in Version:
2.1.1

Severity Score:
High

Plugin:

Bricksforge

Plugin Slug:
bricksforge

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium

Plugin:

Demo My WordPress

Plugin Slug:
demo-my-wordpress

Vulnerability:
Privilege Escalation

Patched in Version:
1.1.0

Severity Score:
Critical

Plugin:

Easy Social Share Buttons

Plugin Slug:
easy-social-share-buttons3

Vulnerability:
Broken Access Control

Patched in Version:
9.5

Severity Score:
Medium

Plugin:

Easy Social Share Buttons

Plugin Slug:
easy-social-share-buttons3

Vulnerability:
Local File Inclusion

Patched in Version:
9.5

Severity Score:
High

Plugin:

LayerSlider

Plugin Slug:
layerslider

Vulnerability:
SQL Injection

Patched in Version:
7.10.1

Severity Score:
Critical

Plugin:

REHub Framework

Plugin Slug:
rehub-framework

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
Broken Access Control

Patched in Version:
2.25.2

Severity Score:
Medium

Plugin:

Relevanssi Premium

Plugin Slug:
relevanssi-premium

Vulnerability:
CSV Injection

Patched in Version:
2.25.2

Severity Score:
Medium

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.0

Severity Score:
Medium

Plugin:

Wholesale For WooCommerce

Plugin Slug:
woocommerce-wholesale-pricing

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
2.3.1

Severity Score:
High

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7

Severity Score:
High

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6

Severity Score:
High

WordPress Themes — 4 Patched / 0 Unpatched

Theme Slug:
hello-elementor

Downloads
6,963,021

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.1

Severity Score:
Medium

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
High

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
Critical

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-04-10 10:02:18.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — April 17, 2024

WordPress Vulnerability Report — April 17, 2024

In this report, 342 vulnerabilities have been publicly disclosed. Security patches for 254 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 88 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.2

Severity Score:
Medium

WordPress Plugins — 234 Patched / 81 Unpatched

Plugin Slug:
woo-product-feed-pro

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
whats-new-genarator

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
zero-spam

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
embed-form

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
subscribe2

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
leadinfo

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
pepro-ultimate-invoice

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
sync-post-with-other-site

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
easy-textillate

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
epoll-wp-voting

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin Slug:
momoyoga-integration

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
bannerlid

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Access Category Password

Plugin Slug:
access-category-password

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Ads.txt Admin

Plugin Slug:
ads-txt-admin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Advanced Search

Plugin Slug:
advance-search

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Advanced Page Visit Counter

Plugin Slug:
advanced-page-visit-counter

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Advanced Post Block – Post Grid for WordPress block editor

Plugin Slug:
advanced-post-block

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

AIKit

Plugin Slug:
aikit-wordpress-ai-writing-assistant-using-gpt3

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Aspose.Words Exporter

Plugin Slug:
aspose-doc-exporter

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Before And After

Plugin Slug:
before-and-after

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

bizcalendar-web

Plugin Slug:
bizcalendar-web

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Bulk Block Converter

Plugin Slug:
bulk-block-converter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Canva – Design beautiful blog graphics

Plugin Slug:
canva

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Citadela Listing

Plugin Slug:
citadela-directory

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Citadela Listing

Plugin Slug:
citadela-directory

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Convert Post Types

Plugin Slug:
convert-post-types

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Crony Cronjob Manager

Plugin Slug:
crony

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Custom Order Statuses for WooCommerce

Plugin Slug:
custom-order-statuses-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Customily Product Personalizer

Plugin Slug:
customily-v2

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Delete Custom Fields

Plugin Slug:
delete-custom-fields

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Disable Comments | WPZest

Plugin Slug:
disable-comments-wpz

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Easy CountDowner

Plugin Slug:
easy-countdowner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Easy Logo

Plugin Slug:
easylogo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

EZ Form Calculator

Plugin Slug:
ez-form-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Filter Custom Fields & Taxonomies Light

Plugin Slug:
filter-custom-fields-taxonomies-light

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Find Duplicates

Plugin Slug:
find-duplicates

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Fixed HTML Toolbar

Plugin Slug:
fixed-html-toolbar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Flash Video Player

Plugin Slug:
flash-video-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Font Farsi

Plugin Slug:
font-farsi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook

Plugin Slug:
forms-to-zapier

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Freshdesk (official)

Plugin Slug:
freshdesk-support

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Kimili Flash Embed

Plugin Slug:
kimili-flash-embed

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Contact Form & Lead Form Elementor Builder

Plugin Slug:
lead-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Contact Form & Lead Form Elementor Builder

Plugin Slug:
lead-form-builder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Related Posts for WordPress

Plugin Slug:
microkids-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

MJ Update History

Plugin Slug:
mj-update-history

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Ovic Addon Toolkit

Plugin Slug:
ovic-addon-toolkit

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Product Feed on WooCommerce for Google

Plugin Slug:
purple-xmls-google-product-feed-for-woocommerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Code Insert Manager (Q2W3 Inc Manager)

Plugin Slug:
q2w3-inc-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Realtyna Organic IDX plugin

Plugin Slug:
real-estate-listing-realtyna-wpl

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Sangar Slider

Plugin Slug:
sangar-slider-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Shopkeeper Extender

Plugin Slug:
shopkeeper-extender

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Short URL

Plugin Slug:
shorten-url

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Simple Testimonials Showcase

Plugin Slug:
simple-testimonials-showcase

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tax Rate Upload

Plugin Slug:
tax-rate-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Post Type Builder (PTB)

Plugin Slug:
themify-ptb

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Post Type Builder (PTB)

Plugin Slug:
themify-ptb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Mega Addons For Elementor

Plugin Slug:
ultimate-addons-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

User Activity Log Pro

Plugin Slug:
user-activity-log-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Appointment Bookings for Zoom GoogleMeet and more – Wappointment

Plugin Slug:
wappointment

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WidgetKit

Plugin Slug:
widgetkit-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

2Checkout Payment Gateway for WooCommerce

Plugin Slug:
woocommerce-2checkout-payment

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Simple Registration for WooCommerce

Plugin Slug:
woocommerce-simple-registration

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

WP-Cufon

Plugin Slug:
wp-cufon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WP File Download Light

Plugin Slug:
wp-file-download-light

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Radio – Worldwide Online Radio Stations Directory for WordPress

Plugin Slug:
wp-radio

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Radio – Worldwide Online Radio Stations Directory for WordPress

Plugin Slug:
wp-radio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Search Keyword Redirect

Plugin Slug:
wp-search-keyword-redirect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP TradingView

Plugin Slug:
wp-tradingview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
woocommerce

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.6

Severity Score:
Medium

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium

Plugin Slug:
ewww-image-optimizer

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.3.0

Severity Score:
Medium

Plugin Slug:
sg-cachepress

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.5.0

Severity Score:
Medium

Plugin Slug:
coming-soon

Installations
900,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.15.21

Severity Score:
Medium

Plugin Slug:
smart-slider-3

Installations
900,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.1.23

Severity Score:
Medium

Plugin Slug:
meta-box

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.4

Severity Score:
Medium

Plugin Slug:
ocean-extra

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.28

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.25

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.25

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.17

Severity Score:
Medium

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.1

Severity Score:
Medium

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.4

Severity Score:
Medium

Plugin Slug:
ml-slider

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.70.1

Severity Score:
Medium

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.5

Severity Score:
Medium

Plugin Slug:
forminator

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29.3

Severity Score:
Medium

Plugin Slug:
nextgen-gallery

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.59.1

Severity Score:
Medium

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.2.12

Severity Score:
High

Plugin Slug:
wp-google-maps

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.0.35

Severity Score:
Medium

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
PHP Object Injection

Patched in Version:
0.9.100

Severity Score:
Medium

Plugin Slug:
favicon-by-realfavicongenerator

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.30

Severity Score:
Medium

Plugin Slug:
gutenberg

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
18.1.0

Severity Score:
Medium

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.0.7

Severity Score:
Medium

Plugin Slug:
otter-blocks

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium

Plugin Slug:
otter-blocks

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium

Plugin Slug:
blocksy-companion

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.29

Severity Score:
Medium

Plugin Slug:
custom-facebook-feed

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.2

Severity Score:
Medium

Plugin Slug:
photo-gallery

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.22

Severity Score:
Medium

Plugin Slug:
ultimate-member

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.5

Severity Score:
Medium

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.5

Severity Score:
Medium

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.6

Severity Score:
Medium

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.5.6

Severity Score:
Medium

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.6.0

Severity Score:
Medium

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.4

Severity Score:
Medium

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.3

Severity Score:
Medium

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.2.83

Severity Score:
Medium

Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0

Severity Score:
Medium

Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium

Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.0

Severity Score:
Medium

Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.4

Severity Score:
Medium

Plugin Slug:
email-subscribers

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
5.7.15

Severity Score:
Critical

Plugin Slug:
enhanced-media-library

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.10

Severity Score:
Medium

Plugin Slug:
paid-memberships-pro

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.2

Severity Score:
Medium

Plugin Slug:
paid-memberships-pro

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0

Severity Score:
Medium

Plugin Slug:
paid-memberships-pro

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0

Severity Score:
Medium

Plugin Slug:
remove-footer-credit

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.14

Severity Score:
Medium

Plugin Slug:
instagram-widget-by-wpzoom

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.14

Severity Score:
Medium

Plugin Slug:
real-media-library-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.22.12

Severity Score:
Medium

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29

Severity Score:
Medium

Plugin Slug:
theme-my-login

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.1.7

Severity Score:
Medium

Plugin Slug:
wp-clone-by-wp-academy

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.4

Severity Score:
Medium

Plugin Slug:
boldgrid-easy-seo

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.15

Severity Score:
Medium

Plugin Slug:
user-registration

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.0

Severity Score:
Medium

Plugin Slug:
activecampaign-subscription-forms

Installations
60,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.1.15

Severity Score:
Medium

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.7

Severity Score:
Medium

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.7

Severity Score:
Medium

Plugin Slug:
advanced-iframe

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024.3

Severity Score:
Medium

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.96

Severity Score:
Medium

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.47.0

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9.1

Severity Score:
Medium

Plugin Slug:
form-maker

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.24

Severity Score:
Medium

Plugin Slug:
redirect-redirection

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.0

Severity Score:
Medium

Plugin Slug:
spotlight-social-photo-feeds

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.11

Severity Score:
Medium

Plugin Slug:
woo-smart-quick-view

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.3

Severity Score:
Medium

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.4

Severity Score:
High

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium

Plugin Slug:
wp-letsencrypt-ssl

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.1.0

Severity Score:
High

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium

Plugin Slug:
fancybox-for-wordpress

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.4

Severity Score:
Medium

Plugin Slug:
feedzy-rss-feeds

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.4

Severity Score:
Medium

Plugin Slug:
print-invoices-packing-slip-labels-for-woocommerce

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.3

Severity Score:
Medium

Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium

Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.10

Severity Score:
Medium

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.76

Severity Score:
Medium

Plugin Slug:
advanced-cron-manager

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium

Plugin Slug:
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
7.5.45.7212

Severity Score:
Medium

Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.7.0

Severity Score:
Medium

Plugin Slug:
login-with-ajax

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium

Plugin Slug:
super-socializer

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.13.64

Severity Score:
Medium

Plugin Slug:
testimonial-slider-and-showcase

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
Medium

Plugin Slug:
woo-bulk-editor

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.4.2

Severity Score:
Medium

Plugin Slug:
wp-customer-reviews

Installations
30,000+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
3.7.1

Severity Score:
Medium

Plugin Slug:
beaf-before-and-after-gallery

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.5

Severity Score:
Medium

Plugin Slug:
dashboard-welcome-for-elementor

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.8

Severity Score:
Medium

Plugin Slug:
envo-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.12

Severity Score:
Medium

Plugin Slug:
import-users-from-csv

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
Medium

Plugin Slug:
ip2location-country-blocker

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.34.3

Severity Score:
Medium

Plugin Slug:
mailchimp-forms-by-mailmunch

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.2

Severity Score:
Medium

Plugin Slug:
omnisend-connect

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.14.4

Severity Score:
Medium

Plugin Slug:
powerkit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
Medium

Plugin Slug:
top-bar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
Medium

Plugin Slug:
top-bar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
Medium

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.10.0

Severity Score:
Medium

Plugin Slug:
weforms

Installations
20,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.6.21

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.18.2

Severity Score:
Medium

Plugin Slug:
wp-accessibility-helper

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.6.2.6

Severity Score:
Medium

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.0

Severity Score:
Medium

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.6.5

Severity Score:
High

Plugin Slug:
bunnycdn

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
224

Severity Score:
High

Plugin Slug:
e2pdf

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.23.00

Severity Score:
Medium

Plugin Slug:
ecommerce-product-catalog

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.3.29

Severity Score:
Medium

Plugin Slug:
eroom-zoom-meetings-webinar

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.19

Severity Score:
Medium

Plugin Slug:
job-postings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
High

Plugin Slug:
legal-pages

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.3

Severity Score:
Medium

Plugin Slug:
lifterlms

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.5.1

Severity Score:
Medium

Plugin Slug:
live-composer-page-builder

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.36

Severity Score:
Medium

Plugin Slug:
mailster

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.0.7

Severity Score:
High

Plugin Slug:
order-delivery-date-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.21.0

Severity Score:
Medium

Plugin Slug:
popup-by-supsystic

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.28

Severity Score:
Medium

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.9

Severity Score:
Medium

Plugin Slug:
simple-post-notes

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.7

Severity Score:
Medium

Plugin Slug:
userswp

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.6

Severity Score:
Medium

Plugin Slug:
wp-google-analytics-events

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1

Severity Score:
High

Plugin Slug:
wp-mail-catcher

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.7

Severity Score:
Medium

Plugin Slug:
wp-product-feed-manager

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.0

Severity Score:
High

Plugin Slug:
elements-plus

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16.4

Severity Score:
Medium

Plugin Slug:
flexible-shipping-ups

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.5

Severity Score:
Medium

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.94

Severity Score:
Medium

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.94

Severity Score:
Medium

Plugin Slug:
fatal-error-notify

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.3

Severity Score:
Medium

Plugin Slug:
mage-eventpress

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.3

Severity Score:
Medium

Plugin Slug:
unlimited-elementor-inner-sections-by-boomdevs

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.5

Severity Score:
Medium

Plugin Slug:
wpvivid-backup-mainwp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.34

Severity Score:
Medium

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.18.1

Severity Score:
Medium

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.7.9

Severity Score:
Medium

Plugin Slug:
ultimate-product-catalogue

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.2.16

Severity Score:
Medium

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.11.01

Severity Score:
Medium

Plugin Slug:
ajax-load-more-anything

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.6

Severity Score:
Medium

Plugin Slug:
boostify-header-footer-builder

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium

Plugin Slug:
country-state-city-auto-dropdown

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.2

Severity Score:
Medium

Plugin Slug:
product-input-fields-for-woocommerce

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.0

Severity Score:
Medium

Plugin Slug:
radio-player

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.74

Severity Score:
Medium

Plugin Slug:
responsive-gallery-grid

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.11

Severity Score:
Medium

Plugin Slug:
responsive-tabs

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.7

Severity Score:
Medium

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium

Plugin Slug:
wp-login-and-logout-redirect

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium

Plugin Slug:
bulk-editor

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.8.2

Severity Score:
Medium

Plugin Slug:
church-theme-content

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.1

Severity Score:
Medium

Plugin Slug:
geo-my-wp

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium

Plugin Slug:
instagrate-to-wordpress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.1

Severity Score:
Medium

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
4.0.14

Severity Score:
High

Plugin Slug:
wp-client-reports

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.23

Severity Score:
Medium

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
5.6.4

Severity Score:
High

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.6.0

Severity Score:
Medium

Plugin Slug:
audio-and-video-player

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0

Severity Score:
Medium

Plugin Slug:
contact-form-lite

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.25

Severity Score:
Medium

Plugin Slug:
everest-backup

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.2.5

Severity Score:
Critical

Plugin Slug:
marker-io

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.9

Severity Score:
Medium

Plugin Slug:
multiparcels-shipping-for-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.16.9

Severity Score:
Medium

Plugin Slug:
pardot

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium

Plugin Slug:
wpbenchmark

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.7

Severity Score:
Medium

Plugin Slug:
wpc-grouped-product

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.3

Severity Score:
Medium

Plugin Slug:
wpsynchro

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.11.3

Severity Score:
Medium

Plugin Slug:
zoho-campaigns

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.8

Severity Score:
Medium

Plugin Slug:
zoho-campaigns

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.8

Severity Score:
Medium

Plugin Slug:
premmerce-woocommerce-product-filter

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.3

Severity Score:
Medium

Plugin Slug:
seo-booster

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.10

Severity Score:
Medium

Plugin Slug:
top-table-of-contents

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.16

Severity Score:
Medium

Plugin Slug:
wallet-system-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.10

Severity Score:
Medium

Plugin Slug:
additional-product-fields-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.105

Severity Score:
Medium

Plugin Slug:
bc-woo-custom-thank-you-pages

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.14

Severity Score:
Medium

Plugin Slug:
currency-per-product-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.0

Severity Score:
Medium

Plugin Slug:
gallery-box

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.34

Severity Score:
Medium

Plugin Slug:
gg-woo-feed

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.7

Severity Score:
Medium

Plugin Slug:
gift-voucher

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.4.1

Severity Score:
Medium

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.1.0.23

Severity Score:
Critical

Plugin Slug:
lh-add-media-from-url

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.23

Severity Score:
High

Plugin Slug:
sheets-to-wp-table-live-sync

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.5.1

Severity Score:
Medium

Plugin Slug:
woc-open-close

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.2

Severity Score:
Medium

Plugin Slug:
wp-event-aggregator

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.7

Severity Score:
Medium

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.3.1

Severity Score:
Medium

Plugin Slug:
benchmark-email-lite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.28

Severity Score:
Medium

Plugin Slug:
current-template-name

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.13

Severity Score:
Medium

Plugin Slug:
dashboard-to-do-list

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.2

Severity Score:
Medium

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium

Plugin Slug:
faq-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium

Plugin Slug:
feather-login-page

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.6

Severity Score:
Medium

Plugin Slug:
flexible-shipping-usps

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.3

Severity Score:
Medium

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.17

Severity Score:
High

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.94

Severity Score:
High

Plugin Slug:
mihanpanel-lite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
12.7

Severity Score:
Medium

Plugin Slug:
netgsm

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9

Severity Score:
High

Plugin Slug:
no-bot-registration

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0

Severity Score:
Medium

Plugin Slug:
novelist

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium

Plugin Slug:
poeditor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.9

Severity Score:
Medium

Plugin Slug:
redi-restaurant-reservation

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
24.0303

Severity Score:
Medium

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium

Plugin Slug:
tour-booking-manager

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.1

Severity Score:
Medium

Plugin Slug:
ultimate-store-kit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium

Plugin Slug:
visitor-analytics-io

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium

Plugin Slug:
wc-multi-currency

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6

Severity Score:
Medium

Plugin Slug:
wp-dynamic-keywords-injector

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High

Plugin Slug:
mww-disclaimer-buttons

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2

Severity Score:
Medium

Plugin Slug:
siteimprove

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.7

Severity Score:
Medium

Plugin Slug:
bmi-adultkid-calculator

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
High

Plugin Slug:
chat-help

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.0

Severity Score:
Medium

Plugin Slug:
ays-facebook-popup-likebox

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.3

Severity Score:
Medium

Plugin Slug:
webinar-ignition

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.06.0

Severity Score:
Medium

Plugin Slug:
f4-improvements

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium

Plugin Slug:
wp2leads

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.8

Severity Score:
Medium

Plugin Slug:
nps-computy

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.6

Severity Score:
Medium

Plugin Slug:
nps-computy

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
Medium

Plugin Slug:
save-as-image-by-pdfcrowd

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium

Plugin Slug:
5-stars-rating-funnel

Installations
40+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
1.3.02

Severity Score:
High

Plugin Slug:
affieasy

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.6

Severity Score:
Medium

Plugin:

AWP Classifieds

Plugin Slug:
another-wordpress-classifieds-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.3.2

Severity Score:
Medium

Plugin:

BWL Advanced FAQ Manager

Plugin Slug:
bwl-advanced-faq-manager

Vulnerability:
SQL Injection

Patched in Version:
2.0.4

Severity Score:
High

Plugin:

Calendarista Basic Edition

Plugin Slug:
calendarista-basic-edition

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.3

Severity Score:
Medium

Plugin:

Digital Publications by Supsystic

Plugin Slug:
digital-publications-by-supsystic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.8

Severity Score:
Medium

Plugin:

Essential Grid

Plugin Slug:
essential-grid

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
Medium

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.81

Severity Score:
Medium

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium

Plugin:

RestroPress

Plugin Slug:
restropress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.2.1

Severity Score:
Medium

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.0

Severity Score:
Medium

Plugin:

Table & Contact Form 7 Database – Tablesome

Plugin Slug:
tablesome

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.26

Severity Score:
Medium

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
SQL Injection

Patched in Version:
29.7

Severity Score:
High

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.1.76

Severity Score:
High

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Broken Access Control

Patched in Version:
10.1.77

Severity Score:
Medium

Plugin:

WP Activity Log Premium

Plugin Slug:
wp-security-audit-log-premium

Vulnerability:
SQL Injection

Patched in Version:
4.6.4.1

Severity Score:
High

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7

Severity Score:
High

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6

Severity Score:
High

WordPress Themes — 19 Patched / 7 Unpatched

Theme Slug:
decode

Downloads
269,521

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
gridsby

Downloads
288,716

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
gucherry-blog

Downloads
136,966

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Theme Slug:
happenstance

Downloads
134,390

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
i-excel

Downloads
262,257

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
i-max

Downloads
270,530

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
sensible-wp

Downloads
277,690

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
blocksy

Downloads
3,056,299

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.23

Severity Score:
Medium

Theme Slug:
citylogic

Downloads
292,720

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.30

Severity Score:
Medium

Theme Slug:
default-mag

Downloads
93,066

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.6

Severity Score:
Medium

Theme Slug:
emmet-lite

Downloads
104,881

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.8

Severity Score:
Medium

Theme Slug:
lightning

Downloads
2,240,450

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
15.19.0

Severity Score:
Medium

Theme Slug:
namaha

Downloads
63,477

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.41

Severity Score:
Medium

Theme Slug:
newsxpress

Downloads
11,096

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.8

Severity Score:
Medium

Theme Slug:
panoramic

Downloads
614,830

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.57

Severity Score:
Medium

Theme Slug:
popularfx

Downloads
773,374

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.5

Severity Score:
Medium

Theme Slug:
sarada-lite

Downloads
86,466

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.3

Severity Score:
Medium

Theme Slug:
shopstar

Downloads
286,946

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.34

Severity Score:
Medium

Theme Slug:
sliding-door

Downloads
537,017

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4

Severity Score:
Medium

Theme Slug:
spa-and-salon

Downloads
155,971

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.8

Severity Score:
Medium

Theme Slug:
tainacan-interface

Downloads
16,543

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.2

Severity Score:
High

Theme Slug:
the-conference

Downloads
52,521

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.1

Severity Score:
Medium

Theme Slug:
x-t9

Downloads
30,187

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.19.1

Severity Score:
Medium

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.4.6

Severity Score:
Medium

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Broken Access Control

Patched in Version:
8.4.6

Severity Score:
Medium

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Broken Access Control

Patched in Version:
8.4.6

Severity Score:
High

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-04-17 09:16:24.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report — March 6, 2024

WordPress Vulnerability Report — March 6, 2024

In this report, 126 vulnerabilities have been publicly disclosed. Security patches for 77 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 73 Patched / 48 Unpatched

Plugin Slug:
slivery-extender

Installations
2,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
idonate

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Adsmonetizer

Plugin Slug:
adsensei-b30

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

ArtiBot

Plugin Slug:
artibot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Auto Refresh Single Page

Plugin Slug:
auto-refresh-single-page

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

BeePress

Plugin Slug:
beepress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Blue Triad EZAnalytics

Plugin Slug:
blue-triad-ezanalytics

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Change Memory Limit

Plugin Slug:
change-memory-limit

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Under Construction / Maintenance Mode from Acurax

Plugin Slug:
coming-soon-maintenance-mode-from-acurax

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Under Construction / Maintenance Mode from Acurax

Plugin Slug:
coming-soon-maintenance-mode-from-acurax

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Configure SMTP

Plugin Slug:
configure-smtp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Build & Control Block Patterns

Plugin Slug:
control-block-patterns

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Custom fields shortcode

Plugin Slug:
custom-fields-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Download Media

Plugin Slug:
download-media

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Duitku Payment Gateway

Plugin Slug:
duitku-social-payment-gateway

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Easy!Appointments

Plugin Slug:
easyappointments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Ebook Store

Plugin Slug:
ebook-store

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Conversios.io

Plugin Slug:
enhanced-e-commerce-for-woocommerce-store

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

FeedWordPress

Plugin Slug:
feedwordpress

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Fontific | Google Fonts

Plugin Slug:
fontific

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Maintenance Mode by helderk

Plugin Slug:
hkdev-maintenance-mode

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

JM Twitter Cards

Plugin Slug:
jm-twitter-cards

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Marketing Optimizer

Plugin Slug:
marketing-optimizer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Media Alt Renamer

Plugin Slug:
media-alt-renamer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin Slug:
myshopkit-popup-smartbar-slidein

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Page Builder Sandwich – Front-End Page Builder

Plugin Slug:
page-builder-sandwich

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Page Builder Sandwich – Front-End Page Builder

Plugin Slug:
page-builder-sandwich

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Page Restrict

Plugin Slug:
pagerestrict

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Password Protected Store for WooCommerce

Plugin Slug:
password-protected-woo-store

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

PayU India

Plugin Slug:
payu-india

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

postMash – custom post order

Plugin Slug:
postmash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
restaurant-solutions-checklist

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Rolo Slider

Plugin Slug:
rolo-slider

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Simple Tweet

Plugin Slug:
simple-tweet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

User Shortcodes Plus

Plugin Slug:
user-shortcodes-plus

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Vimeography: Vimeo Video Gallery WordPress Plugin

Plugin Slug:
vimeography

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Watermark RELOADED

Plugin Slug:
watermark-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

WordPress Access Control

Plugin Slug:
wordpress-access-control

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

CodeMirror Blocks

Plugin Slug:
wp-codemirror-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP eCommerce

Plugin Slug:
wp-e-commerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP eCommerce

Plugin Slug:
wp-e-commerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Page Duplicator

Plugin Slug:
wp-page-duplicator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WP Private Content Plus

Plugin Slug:
wp-private-content-plus

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
complianz-gdpr

Installations
900,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.0.0

Severity Score:
Medium

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.22

Severity Score:
Medium

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.4

Severity Score:
Medium

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.58.8

Severity Score:
Medium

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.2

Severity Score:
Medium

Plugin Slug:
nextend-facebook-connect

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.13

Severity Score:
High

Plugin Slug:
generateblocks

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.3

Severity Score:
Medium

Plugin Slug:
pagelayer

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.32

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.31

Severity Score:
Medium

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4.3

Severity Score:
Medium

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.86

Severity Score:
Medium

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.85

Severity Score:
Medium

Plugin Slug:
essential-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.2

Severity Score:
Medium

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.7

Severity Score:
Medium

Plugin Slug:
wp-show-posts

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.5

Severity Score:
Medium

Plugin Slug:
advanced-iframe

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024.2

Severity Score:
Medium

Plugin Slug:
ai-engine

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
High

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.99

Severity Score:
High

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.1

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.1

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.1

Severity Score:
Medium

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.1

Severity Score:
Medium

Plugin Slug:
visualcomposer

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
45.7.0

Severity Score:
Medium

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.57

Severity Score:
High

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.5

Severity Score:
Medium

Plugin Slug:
notificationx

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.3

Severity Score:
Critical

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.0.11

Severity Score:
Medium

Plugin Slug:
mainwp

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.0

Severity Score:
Medium

Plugin Slug:
rafflepress

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.12.7

Severity Score:
High

Plugin Slug:
restrict-user-access

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6

Severity Score:
Medium

Plugin Slug:
seraphinite-accelerator

Installations
20,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.21

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.18.1

Severity Score:
Medium

Plugin Slug:
wp-ecommerce-paypal

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9

Severity Score:
Medium

Plugin Slug:
wp-ecommerce-paypal

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9

Severity Score:
Medium

Plugin Slug:
wp-event-manager

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.42

Severity Score:
High

Plugin Slug:
wp-social

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.1

Severity Score:
Medium

Plugin Slug:
aweber-web-form-widget

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
7.3.15

Severity Score:
High

Plugin Slug:
contact-form-7-paypal-add-on

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2

Severity Score:
Medium

Plugin Slug:
contact-form-7-paypal-add-on

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2

Severity Score:
Medium

Plugin Slug:
envo-elementor-for-woocommerce

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.5

Severity Score:
Medium

Plugin Slug:
envo-elementor-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.5

Severity Score:
Medium

Plugin Slug:
envo-elementor-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.5

Severity Score:
Medium

Plugin Slug:
lifterlms

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.5.2

Severity Score:
Medium

Plugin Slug:
sportspress

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.18

Severity Score:
Medium

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.87

Severity Score:
Medium

Plugin Slug:
wpvivid-backup-mainwp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.33

Severity Score:
High

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.18.0

Severity Score:
Medium

Plugin Slug:
soundcloud-shortcode

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.2

Severity Score:
Medium

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.0

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
responsive-coming-soon

Installations
4,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.2.2

Severity Score:
Medium

Plugin Slug:
chat-bubble

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4

Severity Score:
Medium

Plugin Slug:
slider-responsive-slideshow

Installations
3,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.0

Severity Score:
High

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.9

Severity Score:
Medium

Plugin Slug:
antihacker

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.52

Severity Score:
Medium

Plugin Slug:
antihacker

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.53

Severity Score:
Medium

Plugin Slug:
friends

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.8.6

Severity Score:
Medium

Plugin Slug:
oliver-pos

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.1.9

Severity Score:
Medium

Plugin Slug:
page-and-post-restriction

Installations
1,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3.5

Severity Score:
Medium

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.2.1

Severity Score:
Medium

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.2.1

Severity Score:
Medium

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
0.20.7

Severity Score:
Medium

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1

Severity Score:
Medium

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1

Severity Score:
Medium

Plugin:

Backup

Plugin Slug:
backup2

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.9.9

Severity Score:
High

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.19.3

Severity Score:
Medium

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Authentication

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

WP Social Widget

Plugin Slug:
wp-social-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium

WordPress Themes — 4 Patched / 1 Unpatched

Theme Slug:
atahualpa

Downloads
1,333,690

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Theme Slug:
yuki

Downloads
133,433

Vulnerability:
Broken Access Control

Patched in Version:
1.3.14

Severity Score:
Medium

Theme Slug:
yuki

Downloads
133,433

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.15

Severity Score:
Medium

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.11.6

Severity Score:
Medium

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.11.5

Severity Score:
Critical

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Keep reading the article at Blog – SolidWP. The article was originally written by Sarah Ulmer on 2024-03-06 14:16:57.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

Show Your ❤️ Love! Like Us
Scroll to Top