WordPress Vulnerability Report

WordPress Vulnerability Report — September 11, 2024

Since last week, 64 new vulnerabilities emerged in the WordPress ecosystem including 64 plugins. 19 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 64 vulnerabilities have been publicly disclosed. Security patches for 45 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 19 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.2 is now available! This minor release includes 15 bug fixes in Core and 11 in the Block Editor, addressing issues like unexpected CSS specificity changes in certain themes.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 45 Patched / 19 Unpatched

Form Vibes – Database Manager for Forms

Plugin Slug:
form-vibes
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pocket Widget

Plugin Slug:
pocket-widget
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Amelia

Plugin:
Amelia
Plugin Slug:
ameliabooking
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:
AZIndex
Plugin Slug:
azindex
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:
AZIndex
Plugin Slug:
azindex
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cab fare calculator

Plugin:
Cab fare calculator
Plugin Slug:
cab-fare-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Geo Controller

Plugin:
Geo Controller
Plugin Slug:
cf-geoplugin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chatbot Support AI

Plugin:
Chatbot Support AI
Plugin Slug:
chatbot-support-ai
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cost Calculator Builder Pro

Plugin:
Cost Calculator Builder Pro
Plugin Slug:
cost-calculator-builder-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DN Popup

Plugin:
DN Popup
Plugin Slug:
dn-popup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Dynamic Featured Image
Plugin Slug:
dynamic-featured-image
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ForumWP

Plugin:
ForumWP
Plugin Slug:
forumwp
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RD Station

Plugin:
RD Station
Plugin Slug:
integracao-rd-station
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Preloader Plus – WordPress Loading Screen Plugin

Plugin:
Preloader Plus – WordPress Loading Screen Plugin
Plugin Slug:
preloader-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

S.A.F

Plugin:
S.A.F
Plugin Slug:
security-antivirus-firewall
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slider comparison image before and after

Plugin:
Slider comparison image before and after
Plugin Slug:
slider-comparison-image-before-and-after
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viral Signup

Plugin:
Viral Signup
Plugin Slug:
viral-signup
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
6,000,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.5.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.5.0.1.

Ninja Forms – The Contact Form Builder That Grows With You

Plugin Slug:
ninja-forms
Installations
800,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.11.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
400,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
9.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.2.

Customizer Export/Import

Plugin Slug:
customizer-export-import
Installations
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.9.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.7.1.

Ivory Search – WordPress Search Plugin

Plugin Slug:
add-search-to-menu
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.7.

Big File Uploads – Increase Maximum File Upload Size

Plugin Slug:
tuxedo-big-file-uploads
Installations
100,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

WP ULike – The Ultimate Engagement Toolkit for Websites

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.2.1.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.7.

Sensei LMS – Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.24.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.2.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.17.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
2.9.9.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.9.5.1.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.4.

Remember Me Controls

Plugin Slug:
remember-me-controls
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.9.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.3.

Affiliate Super Assistent

Plugin Slug:
amazonsimpleadmin
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

Attributes for Blocks

Plugin Slug:
attributes-for-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Share This Image

Plugin Slug:
share-this-image
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.03
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.03.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
16.26.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 16.26.9.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
2,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.3.

Advanced Sermons

Plugin Slug:
advanced-sermons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Revision Manager TMC

Plugin Slug:
revision-manager-tmc
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.20.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.13.

WP AdCenter – Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
900+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

Ninja Forms File Uploads Extension

Plugin:
Ninja Forms File Uploads Extension
Plugin Slug:
ninja-forms-uploads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.18.

PixelYourSite PRO

Plugin:
PixelYourSite PRO
Plugin Slug:
pixelyoursite-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.4.3.

WordPress Themes — 0 Patched / 0 Unpatched

No new theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security