WordPress Vulnerability Report

WordPress Vulnerability Report — October 9, 2024

Since last week, 182 new vulnerabilities emerged in the WordPress ecosystem including 177 plugins and 5 themes. 45 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 182 vulnerabilities have been publicly disclosed. Security patches for 137 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 45 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Don’t install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 2 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 135 Patched / 42 Unpatched

Soumettre.fr

Plugin Slug:
soumettre-fr
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Loggedin – Limit Active Logins

Plugin Slug:
loggedin
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Docs

Plugin Slug:
buddypress-docs
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DK PDF

Plugin:
DK PDF
Plugin Slug:
dk-pdf
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Copyscape Premium

Plugin Slug:
copyscape-premium
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Keap Official Opt-in Forms

Plugin Slug:
infusionsoft-official-opt-in-forms
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Include Fussball.de Widgets

Plugin Slug:
include-fussball-de-widgets
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LH Copy Media File

Plugin Slug:
lh-copy-media-file
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Payflex Payment Gateway

Plugin Slug:
payflex-payment-gateway
Installations
1,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RumbleTalk Live Group Chat – HTML5

Plugin Slug:
rumbletalk-chat-a-chat-with-themes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VdoCipher: Secure Video Player and Hosting

Plugin Slug:
vdocipher
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hello World

Plugin Slug:
hello-world
Installations
900+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

123.chat

Plugin:
123.chat
Plugin Slug:
123-chat-videochat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Aggregator Advanced Settings

Plugin:
Aggregator Advanced Settings
Plugin Slug:
aggregator-advanced-settings
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Auto Featured Image from Title
Plugin Slug:
auto-featured-image-from-title
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Captcha Bank

Plugin:
Captcha Bank
Plugin Slug:
captcha-bank
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Confetti Fall Animation

Plugin:
Confetti Fall Animation
Plugin Slug:
confetti-fall-animation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Banners

Plugin:
Custom Banners
Plugin Slug:
custom-banners
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Display Medium Posts

Plugin:
Display Medium Posts
Plugin Slug:
display-medium-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Load More

Plugin:
Easy Load More
Plugin Slug:
easy-load-more
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elastik Page Builder

Plugin:
Elastik Page Builder
Plugin Slug:
elastik-page-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gravity Forms Toolbar

Plugin:
Gravity Forms Toolbar
Plugin Slug:
gravity-forms-toolbar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Guten Post Layout

Plugin:
Guten Post Layout
Plugin Slug:
guten-post-layout
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Iconize

Plugin:
Iconize
Plugin Slug:
iconize
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:
KB Support
Plugin Slug:
kb-support
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:
KB Support
Plugin Slug:
kb-support
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LocateAndFilter

Plugin:
LocateAndFilter
Plugin Slug:
locateandfilter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Shortcode

Plugin:
Login Logout Shortcode
Plugin Slug:
login-logout-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Optin Hound

Plugin:
Optin Hound
Plugin Slug:
opt-in-hound
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PDF Image Generator

Plugin:
PDF Image Generator
Plugin Slug:
pdf-image-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

R Animated Icon

Plugin:
R Animated Icon
Plugin Slug:
r-animated-icon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Relogo
Plugin Slug:
relogo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spice Starter Sites

Plugin:
Spice Starter Sites
Plugin Slug:
spice-starter-sites
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVG Complete

Plugin:
SVG Complete
Plugin Slug:
svg-complete
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wechat Social login

Plugin:
Wechat Social login
Plugin Slug:
wechat-social-login
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Wechat Social login

Plugin:
Wechat Social login
Plugin Slug:
wechat-social-login
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce – Store Exporter

Plugin:
WooCommerce – Store Exporter
Plugin Slug:
woocommerce-exporter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Blocks Hub

Plugin:
WP Blocks Hub
Plugin Slug:
wp-blocks-hub
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Cleanup and Basic Functions

Plugin:
WP Cleanup and Basic Functions
Plugin Slug:
wp-cleanup-and-basic-functions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Easy Gallery
Plugin Slug:
wp-easy-gallery
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XO Slider

Plugin:
XO Slider
Plugin Slug:
xo-liteslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
6,000,000+
Vulnerability:
Path Traversal
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
6,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
6,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
3,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.229
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.229.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
3,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.229
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.229.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
6.3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.6.1.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.
Plugin Slug:
broken-link-checker
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.987
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.987.

Checkout Field Editor (Checkout Manager) for WooCommerce

Plugin Slug:
woo-checkout-field-editor-pro
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

SEOPress – On-site SEO

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

TinyPNG – JPEG, PNG & WebP image compression

Plugin Slug:
tiny-compress-images
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.

Smart Custom 404 Error Page

Plugin Slug:
404page
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.4.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.4.

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.17.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.8.

WP Bulk Delete

Plugin Slug:
wp-bulk-delete
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.2.

WordPress Infinite Scroll – Ajax Load More

Plugin Slug:
ajax-load-more
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.3.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.1.

WP Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.6.1.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.22.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

Visual CSS Style Editor

Plugin Slug:
yellow-pencil-visual-theme-customizer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.5.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Page-list

Plugin:
Page-list
Plugin Slug:
page-list
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.

Starbox – the Author Box for Humans

Plugin Slug:
starbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.
Plugin Slug:
yith-woocommerce-ajax-search
Installations
40,000+
Vulnerability:
SQL Injection
Patched in Version:
2.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.1.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.29.

Ibtana – WordPress Website Builder

Plugin Slug:
ibtana-visual-editor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.5.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Code Embed

Plugin:
Code Embed
Plugin Slug:
simple-embed-code
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.

Simple Membership After Login Redirection

Plugin Slug:
simple-membership-after-login-redirection
Installations
20,000+
Vulnerability:
Open Redirection
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Slider by 10Web – Responsive Image Slider

Plugin Slug:
slider-wd
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.59.

Advanced Woo Labels – Product Labels for WooCommerce

Plugin Slug:
advanced-woo-labels
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.02
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.02.
Plugin Slug:
amazon-auto-links
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.3.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.21.

Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed

Plugin Slug:
blockspare
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

Demo Importer Plus

Plugin Slug:
demo-importer-plus
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.
Plugin Slug:
gallery-lightbox-slider
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.0.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.41.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.7.

MC4WP: Mailchimp Top Bar

Plugin Slug:
mailchimp-top-bar
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Popularis Extra

Plugin Slug:
popularis-extra
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

CartBounty – Save and recover abandoned carts for WooCommerce

Plugin Slug:
woo-save-abandoned-carts
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.1.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.13.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.13.1.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.3.

Form plugin for WordPress – Zoho Forms

Plugin Slug:
zoho-forms
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

MaxSlider

Plugin:
MaxSlider
Plugin Slug:
maxslider
Installations
9,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.4.

Affiliate Program Suite — SliceWP Affiliates

Plugin Slug:
slicewp
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.19.
Plugin Slug:
slideshow-gallery
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.4.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking
Installations
8,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.3.

Themify Builder

Plugin Slug:
themify-builder
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.3.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.21.01
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.21.01.

Author Avatars List/Block

Plugin Slug:
author-avatars
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.22.

Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.12.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.6.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite
Installations
5,000+
Vulnerability:
Open Redirection
Patched in Version:
6.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.3.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Easy Mega Menu Plugin for WordPress – ThemeHunk

Plugin Slug:
themehunk-megamenu-plus
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.51.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
4,000+
Vulnerability:
Open Redirection
Patched in Version:
4.0.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.6.

Geo Mashup

Plugin:
Geo Mashup
Plugin Slug:
geo-mashup
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.14.

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress

Plugin Slug:
quillforms
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

AVIF Uploader

Plugin Slug:
avif-support
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Move Addons for Elementor

Plugin Slug:
move-addons
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Robokassa payment gateway for Woocommerce

Plugin Slug:
robokassa
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.5.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.

Hash Form – Drag & Drop Form Builder

Plugin Slug:
hash-form
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

PWA — easy way to Progressive Web App

Plugin Slug:
iworks-pwa
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

Premium Blocks – Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.34.

Search Analytics for WP

Plugin Slug:
search-analytics
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.11.

WP-WebAuthn

Plugin Slug:
wp-webauthn
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.1.

Zotpress

Plugin:
Zotpress
Plugin Slug:
zotpress
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.11.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

Memberful – Membership Plugin

Plugin Slug:
memberful-wp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.73.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.73.8.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Product Delivery Date for WooCommerce – Lite

Plugin Slug:
product-delivery-date-for-woocommerce-lite
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.
Plugin Slug:
responsive-client-logo-carousel-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.0.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

Quantity Dynamic Pricing & Bulk Discounts for WooCommerce

Plugin Slug:
wholesale-pricing-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.
Plugin:
WP MyLinks
Plugin Slug:
wp-mylinks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.9.

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.67
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.67.

QS Dark Mode Plugin

Plugin Slug:
qs-dark-mode
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

Limit Login Attempts (Spam Protection)

Plugin Slug:
wp-limit-failed-login-attempts
Installations
200+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.

Top Bar – PopUps – by WPOptin

Plugin Slug:
wpoptin
Installations
90+
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.2.

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Broken Access Control
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Broken Authentication
Patched in Version:
5.0.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.13.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
SQL Injection
Patched in Version:
5.0.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.12.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.19.

Re:WP

Plugin:
Re:WP
Plugin Slug:
rewp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Echo RSS Feed Post Generator Plugin for WordPress

Plugin:
Echo RSS Feed Post Generator Plugin for WordPress
Plugin Slug:
rss-feed-post-generator-echo
Vulnerability:
Privilege Escalation
Patched in Version:
5.4.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.7.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.16.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.1.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

Affiliate Pro – Affiliate Program for WooCommerce & WordPress

Plugin:
Affiliate Pro – Affiliate Program for WooCommerce & WordPress
Plugin Slug:
wp-wc-affiliate-program
Vulnerability:
Privilege Escalation
Patched in Version:
8.5.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.5.0.

WordPress Themes — 2 Patched / 3 Unpatched

Empowerment

Theme Slug:
empowerment
Downloads
3,400
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

UltraPress

Theme Slug:
ultrapress
Downloads
15,922
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Unseen Blog

Theme Slug:
unseen-blog
Downloads
2,338
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Create

Theme:
Create
Theme Slug:
create
Downloads
64,027
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.2.

Full Frame

Theme Slug:
full-frame
Downloads
199,864
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security