WordPress Vulnerability Report

WordPress Vulnerability Report — August 28, 2024

Since last week, 122 new vulnerabilities emerged in the WordPress ecosystem including 118 plugins and 4 themes. 49 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 122 vulnerabilities have been publicly disclosed. Security patches for 73 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 72 Patched / 46 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
yet-another-related-posts-plugin
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Maintenance & Coming Soon Redirect Animation

Plugin Slug:
maintenance-coming-soon-redirect-animation
Installations
5,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Super Testimonials

Plugin Slug:
super-testimonial
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Classic Addons – WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendGrid for WordPress

Plugin Slug:
wp-sendgrid-mailer
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Skitter Slideshow

Plugin Slug:
wp-skitter-slideshow
Installations
500+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AdRotate

Plugin:
AdRotate
Plugin Slug:
adrotate1
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Animated Number Counters

Plugin:
Animated Number Counters
Plugin Slug:
animated-number-counters
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:
App Builder
Plugin Slug:
app-builder
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

azurecurve Toggle Show/Hide

Plugin:
azurecurve Toggle Show/Hide
Plugin Slug:
azurecurve-toggle-showhide
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog Introduction

Plugin:
Blog Introduction
Plugin Slug:
blogintroduction-wordpress-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brickscore

Plugin:
Brickscore
Plugin Slug:
brickscore
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin:
Smart Online Order for Clover
Plugin Slug:
clover-online-orders
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GHActivity

Plugin:
GHActivity
Plugin Slug:
ghactivity
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gixaw Chat

Plugin:
Gixaw Chat
Plugin Slug:
gixaw-chat
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hide My Site

Plugin:
Hide My Site
Plugin Slug:
hide-my-site
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ILC Thickbox

Plugin:
ILC Thickbox
Plugin Slug:
ilc-thickbox
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin:
LWS Affiliation
Plugin Slug:
lws-affiliation
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Memberpress

Plugin:
Memberpress
Plugin Slug:
memberpress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Paypal

Plugin:
Misiek Paypal
Plugin Slug:
misiek-paypal
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:
Misiek Photo Album
Plugin Slug:
misiek-photo-album
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:
Misiek Photo Album
Plugin Slug:
misiek-photo-album
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OTA Sync Booking Engine Widget

Plugin:
OTA Sync Booking Engine Widget
Plugin Slug:
ota-sync-booking-engine-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Propovoice Pro

Plugin:
Propovoice Pro
Plugin Slug:
propovoice-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Video

Plugin:
Responsive Video
Plugin Slug:
responsive-video
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder – Advanced addons for Elementor

Plugin:
RT Easy Builder – Advanced addons for Elementor
Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Headline Rotator

Plugin:
Simple Headline Rotator
Plugin Slug:
simple-headline-rotator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Snapshot Backup

Plugin:
Snapshot Backup
Plugin Slug:
snapshot-backup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Web and WooCommerce Addons for WPBakery Builder

Plugin:
Web and WooCommerce Addons for WPBakery Builder
Plugin Slug:
vc-addons-by-bit14
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woo Inquiry

Plugin:
Woo Inquiry
Plugin Slug:
woo-inquiry
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordSurvey

Plugin:
WordSurvey
Plugin Slug:
wordsurvey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:
WP Testimonial Widget
Plugin Slug:
wp-testimonial-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:
WP Testimonial Widget
Plugin Slug:
wp-testimonial-widget
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:
WP Testimonial Widget
Plugin Slug:
wp-testimonial-widget
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:
Z Y N I T H
Plugin Slug:
zynith-seo
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:
Z Y N I T H
Plugin Slug:
zynith-seo
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Privilege Escalation
Patched in Version:
6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.4.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
responsive-lightbox
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.
Plugin Slug:
responsive-lightbox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.37.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.3.4.
Plugin Slug:
custom-permalinks
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

Email Address Encoder

Plugin Slug:
email-address-encoder
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.24.

EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

Plugin Slug:
embedpress
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.9.
Plugin Slug:
envira-gallery-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.15.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.2.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

WordPress Button Plugin MaxButtons

Plugin Slug:
maxbuttons
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
9.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.0.

String locator

Plugin Slug:
string-locator
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.6.

Ninja Tables – Easiest Data Table Builder

Plugin Slug:
ninja-tables
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.13.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
70,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.1.

Visual CSS Style Editor

Plugin Slug:
yellow-pencil-visual-theme-customizer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.4.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.31.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Last Modified Info

Plugin Slug:
wp-last-modified-info
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

Image Hotspot by DevVN

Plugin Slug:
devvn-image-hotspot
Installations
30,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.

Simple Job Board

Plugin Slug:
simple-job-board
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.12.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.12.4.

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.4.

Generate Images – Magic Post Thumbnail

Plugin Slug:
magic-post-thumbnail
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.10.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.0.
Plugin Slug:
bp-profile-search
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.

Themify Builder

Plugin Slug:
themify-builder
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.2.

GEO my WP

Plugin:
GEO my WP
Plugin Slug:
geo-my-wp
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.5.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.0.2.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
5.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.3.

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.49
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.49.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations
4,000+
Vulnerability:
Settings Change
Patched in Version:
2.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.11.

Collapsing Archives

Plugin Slug:
collapsing-archives
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.29.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.29.1.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.30.

Event Espresso – Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.22.decaf
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.22.decaf.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.15.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.15.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.2.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.2.8.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.3.103
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.103.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.103
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.103.

Favicon Generator (CLOSED)

Plugin Slug:
favicon-generator
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
2.4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.5.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.5.

Greenshift Query and Meta Addon

Plugin:
Greenshift Query and Meta Addon
Plugin Slug:
greenshiftquery
Vulnerability:
SQL Injection
Patched in Version:
3.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.2.

Greenshift Woocommerce Addon

Plugin:
Greenshift Woocommerce Addon
Plugin Slug:
greenshiftwoo
Vulnerability:
SQL Injection
Patched in Version:
1.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.8.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygenbuilder
Vulnerability:
Broken Access Control
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

Multilingual CMS

Plugin:
Multilingual CMS
Plugin Slug:
sitepress-multilingual-cms
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.6.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.13.

WBW Product Table PRO

Plugin:
WBW Product Table PRO
Plugin Slug:
woo-producttables-pro
Vulnerability:
SQL Injection
Patched in Version:
1.9.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.5.

WP Armour Extended

Plugin:
WP Armour Extended
Plugin Slug:
wp-armour-extended
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.32.

WP Armour Extended

Plugin:
WP Armour Extended
Plugin Slug:
wp-armour-extended
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.32.

File Manager Pro

Plugin:
File Manager Pro
Plugin Slug:
wp-file-manager-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.3.8.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
PHP Object Injection
Patched in Version:
2.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

WordPress Themes — 1 Patched / 3 Unpatched

Esotera

Theme:
Esotera
Theme Slug:
esotera
Downloads
59,465
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

IntoTheDark

Theme Slug:
intothedark
Downloads
1,994
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tempera

Theme:
Tempera
Theme Slug:
tempera
Downloads
703,425
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Phlox PRO

Theme:
Phlox PRO
Theme Slug:
phlox-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.16.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.16.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security