In this report, 285 vulnerabilities have been publicly disclosed. Security patches for 99 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 186 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.7 Beta 3 is available and ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site.
WordPress Plugins — 99 Patched / 186 Unpatched
Countdown, Coming Soon, Maintenance – Countdown & Clock
- Plugin Slug:
- countdown-builder
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50516
WP Hotel Booking
- Plugin:
- WP Hotel Booking
- Plugin Slug:
- wp-hotel-booking
- Installations
- 8,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51582
Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler
- Plugin Slug:
- cf7-styler
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51689
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
- Plugin Slug:
- gift-voucher
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9165
Administrator Z
- Plugin:
- Administrator Z
- Plugin Slug:
- administrator-z
- Installations
- 400+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50524
Simple Page Specific Sidebars
- Plugin:
- Simple Page Specific Sidebars
- Plugin Slug:
- page-specific-sidebars
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51633
Training – Courses
- Plugin:
- Training – Courses
- Plugin Slug:
- training
- Installations
- 20+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50529
All Post Contact Form
- Plugin:
- All Post Contact Form
- Plugin Slug:
- allpost-contactform
- Installations
- 10+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50523
Easy SVG Upload
- Plugin:
- Easy SVG Upload
- Plugin Slug:
- easy-svg-upload
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9708
3D Presentation
- Plugin:
- 3D Presentation
- Plugin Slug:
- 3d-presentation
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51578
5 Stars Rating Funnel
- Plugin:
- 5 Stars Rating Funnel
- Plugin Slug:
- 5-stars-rating-funnel
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51579
Aajoda Testimonials
- Plugin:
- Aajoda Testimonials
- Plugin Slug:
- aajoda-testimonials
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51614
Bing Search API Integration
- Plugin:
- Bing Search API Integration
- Plugin Slug:
- abbs-bing-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51692
Addressbook
- Plugin:
- Addressbook
- Plugin Slug:
- addressbook
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51644
Admin SMS Alert
- Plugin:
- Admin SMS Alert
- Plugin Slug:
- admin-sms-alert
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51637
Advanced Control Manager for WordPress by ItalyStrap
- Plugin:
- Advanced Control Manager for WordPress by ItalyStrap
- Plugin Slug:
- advanced-control-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50541
Advanced PDF Generator
- Plugin:
- Advanced PDF Generator
- Plugin Slug:
- advanced-pdf-generator
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51641
Ajax Content Filter
- Plugin:
- Ajax Content Filter
- Plugin Slug:
- ajax-content-filter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51717
Alley Elementor Widget
- Plugin:
- Alley Elementor Widget
- Plugin Slug:
- alley-elementor-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50521
AmaDiscount
- Plugin:
- AmaDiscount
- Plugin Slug:
- amadiscount
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51608
amazing neo icon font for elementor
- Plugin:
- amazing neo icon font for elementor
- Plugin Slug:
- amazing-neo-icon-font-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50543
Amazon Associate Filter
- Plugin:
- Amazon Associate Filter
- Plugin Slug:
- amazon-associate-filter
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51643
AMP Img Shortcode
- Plugin:
- AMP Img Shortcode
- Plugin Slug:
- amp-img-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51576
Ancient World Linked Data
- Plugin:
- Ancient World Linked Data
- Plugin Slug:
- ancient-world-linked-data-for-wordpress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50520
APK Downloader
- Plugin:
- APK Downloader
- Plugin Slug:
- apk-downloader
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51654
AR For Woocommerce
- Plugin:
- AR For Woocommerce
- Plugin Slug:
- ar-for-woocommerce
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50510
Custom Author URL
- Plugin:
- Custom Author URL
- Plugin Slug:
- author-slug
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51655
Awesome Progress Bar
- Plugin:
- Awesome Progress Bar
- Plugin Slug:
- awesome-progess-bar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50548
Awesome Shortcodes For Genesis
- Plugin:
- Awesome Shortcodes For Genesis
- Plugin Slug:
- awesome-shortcodes-for-genesis
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51638
AwesomePress
- Plugin:
- AwesomePress
- Plugin Slug:
- awesomepress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51616
Bigmart Elements
- Plugin:
- Bigmart Elements
- Plugin Slug:
- bigmart-elements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51589
Blrt WP Embed
- Plugin:
- Blrt WP Embed
- Plugin Slug:
- blrt-wp-embed
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51606
Bonway Static Block Editor
- Plugin:
- Bonway Static Block Editor
- Plugin Slug:
- bonway-static-block-editor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50549
bpmn.io
- Plugin:
- bpmn.io
- Plugin Slug:
- bpmnio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51577
Bulk Change Role
- Plugin:
- Bulk Change Role
- Plugin Slug:
- bulk-role-change
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50504
Buooy Sticky Header
- Plugin:
- Buooy Sticky Header
- Plugin Slug:
- buooy-sticky-header
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51699
Business
- Plugin:
- Business
- Plugin Slug:
- business
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51596
Clever Addons for Elementor
- Plugin:
- Clever Addons for Elementor
- Plugin Slug:
- cafe-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51580
Classy Addons for Elementor
- Plugin:
- Classy Addons for Elementor
- Plugin Slug:
- classy-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50553
Clyp
- Plugin:
- Clyp
- Plugin Slug:
- clyp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51617
Code Explorer
- Plugin:
- Code Explorer
- Plugin Slug:
- code-explorer
- Vulnerability:
- Directory Traversal
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-5816
Content Syndication Toolkit Reader
- Plugin:
- Content Syndication Toolkit Reader
- Plugin Slug:
- content-syndication-toolkit-reader
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51696
Conversion Helper
- Plugin:
- Conversion Helper
- Plugin Slug:
- conversion-helper
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-10676
Crypto
- Plugin:
- Crypto
- Plugin Slug:
- crypto
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-9989
Crypto
- Plugin:
- Crypto
- Plugin Slug:
- crypto
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-9988
Crypto
- Plugin:
- Crypto
- Plugin Slug:
- crypto
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9990
Custom Admin Menu
- Plugin:
- Custom Admin Menu
- Plugin Slug:
- custom-admin-menu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51618
Daily Image
- Plugin:
- Daily Image
- Plugin Slug:
- daily-image
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51776
Dashing Memberships
- Plugin:
- Dashing Memberships
- Plugin Slug:
- dashing-memberships
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51760
DataMentor
- Plugin:
- DataMentor
- Plugin Slug:
- datamentor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50545
Definitive Addons for Elementor
- Plugin:
- Definitive Addons for Elementor
- Plugin Slug:
- definitive-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51587
Display Terms Shortcode
- Plugin:
- Display Terms Shortcode
- Plugin Slug:
- display-terms-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51610
Domain Sharding
- Plugin:
- Domain Sharding
- Plugin Slug:
- domain-sharding
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50533
Don’t Break The Code
- Plugin:
- Don’t Break The Code
- Plugin Slug:
- dont-break-the-code
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51779
Doofinder
- Plugin:
- Doofinder
- Plugin Slug:
- doofinder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51697
(dp) AddThis
- Plugin:
- (dp) AddThis
- Plugin Slug:
- dp-addthis
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50540
DS.DownloadList
- Plugin:
- DS.DownloadList
- Plugin Slug:
- dsdownloadlist
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50507
e-shops
- Plugin:
- e-shops
- Plugin Slug:
- e-shops-cart2
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51648
eewee admin custom
- Plugin:
- eewee admin custom
- Plugin Slug:
- eewee-admincustom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51780
Elementary Addons
- Plugin:
- Elementary Addons
- Plugin Slug:
- elementary-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51586
Emoji Shortcode
- Plugin:
- Emoji Shortcode
- Plugin Slug:
- emoji-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51609
Enable Shortcodes inside Widgets,Comments and Experts
- Plugin:
- Enable Shortcodes inside Widgets,Comments and Experts
- Plugin Slug:
- enable-shortcodes-inside-widgetscomments-and-experts
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9846
EndomondoWP
- Plugin:
- EndomondoWP
- Plugin Slug:
- endomondowp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50551
Events Manager Pro – extended
- Plugin:
- Events Manager Pro – extended
- Plugin Slug:
- events-manager-pro-extended
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50532
Extender All In One For Elementor
- Plugin:
- Extender All In One For Elementor
- Plugin Slug:
- extender-all-in-one-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51575
EzyOnlineBookings Online Booking System Widget
- Plugin:
- EzyOnlineBookings Online Booking System Widget
- Plugin Slug:
- ezyonlinebookings-online-booking-system
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51628
Fabrica Synced Pattern Instances
- Plugin:
- Fabrica Synced Pattern Instances
- Plugin Slug:
- fabrica-reusable-block-instances
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51695
Featured Posts Scroll
- Plugin:
- Featured Posts Scroll
- Plugin Slug:
- featured-posts-scroll
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
Firework Shoppable Live Video
- Plugin:
- Firework Shoppable Live Video
- Plugin Slug:
- firework-videos
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51781
Flash Show And Hide Box
- Plugin:
- Flash Show And Hide Box
- Plugin Slug:
- flash-show-and-hide-box
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51656
Forms: 3rd-Party Post Again
- Plugin:
- Forms: 3rd-Party Post Again
- Plugin Slug:
- forms-3rdparty-post-again
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51783
FriendStore for WooCommerce
- Plugin:
- FriendStore for WooCommerce
- Plugin Slug:
- friendstore-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51784
GDReseller
- Plugin:
- GDReseller
- Plugin Slug:
- gdreseller
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50536
Genoo
- Plugin:
- Genoo
- Plugin Slug:
- genoo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51605
Geotagged Media
- Plugin:
- Geotagged Media
- Plugin Slug:
- geotagged-media
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51694
Get Quote For Woocommerce
- Plugin:
- Get Quote For Woocommerce
- Plugin Slug:
- get-a-quote-for-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9430
Gmap Point List
- Plugin:
- Gmap Point List
- Plugin Slug:
- gmap-point-list
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51594
GMO Social Connection
- Plugin:
- GMO Social Connection
- Plugin Slug:
- gmo-social-connection
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51636
Golf Tracker
- Plugin:
- Golf Tracker
- Plugin Slug:
- golf-tracker
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51607
Satisfaction Reports from Help Scout
- Plugin:
- Satisfaction Reports from Help Scout
- Plugin Slug:
- happiness-reports-for-help-scout
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51778
Header Footer Composer for Elementor
- Plugin:
- Header Footer Composer for Elementor
- Plugin Slug:
- header-footer-composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51629
Plug your WooCommerce into the largest catalog of customized print products from Helloprint
- Plugin:
- Plug your WooCommerce into the largest catalog of customized print products from Helloprint
- Plugin Slug:
- helloprint
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50525
Hoo Addons for Elementor
- Plugin:
- Hoo Addons for Elementor
- Plugin Slug:
- hoo-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51590
Hover Video Preview
- Plugin:
- Hover Video Preview
- Plugin Slug:
- hover-video-preview
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50552
HQ60 Fidelity Card
- Plugin:
- HQ60 Fidelity Card
- Plugin Slug:
- hq60-fidelity-card
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51713
ID-SK Toolkit
- Plugin:
- ID-SK Toolkit
- Plugin Slug:
- idsk-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50517
Jigoshop – Store Exporter
- Plugin:
- Jigoshop – Store Exporter
- Plugin Slug:
- jigoshop-exporter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50519
Jigoshop – Store Toolkit
- Plugin:
- Jigoshop – Store Toolkit
- Plugin Slug:
- jigoshop-store-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51712
Kento Ads Rotator
- Plugin:
- Kento Ads Rotator
- Plugin Slug:
- kento-ads-rotator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51583
LH QR Codes
- Plugin:
- LH QR Codes
- Plugin Slug:
- lh-qr-codes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51572
Lodgix.com Vacation Rental Website Builder
- Plugin:
- Lodgix.com Vacation Rental Website Builder
- Plugin Slug:
- lodgixcom-vacation-rental-listing-management-booking-plugin
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50539
Loginplus
- Plugin:
- Loginplus
- Plugin Slug:
- loginplus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51782
Market 360 Viewer
- Plugin:
- Market 360 Viewer
- Plugin Slug:
- market-360-viewer
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51619
Marketing Automation by AZEXO
- Plugin:
- Marketing Automation by AZEXO
- Plugin Slug:
- marketing-automation-by-azexo
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50506
Marquee Elementor with Posts
- Plugin:
- Marquee Elementor with Posts
- Plugin Slug:
- marquee-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51584
Master Bar
- Plugin:
- Master Bar
- Plugin Slug:
- master-bar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51698
MasterBip para Elementor
- Plugin:
- MasterBip para Elementor
- Plugin Slug:
- masterbip-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51571
MDR Webmaster Tools
- Plugin:
- MDR Webmaster Tools
- Plugin Slug:
- mdr-webmaster-tools
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51640
Media Modal
- Plugin:
- Media Modal
- Plugin Slug:
- media-modal
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51604
Meta Store Elements
- Plugin:
- Meta Store Elements
- Plugin Slug:
- meta-store-elements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51592
MG Post Contributors
- Plugin:
- MG Post Contributors
- Plugin Slug:
- mg-post-contributors
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51701
ML Responsive Audio player with playlist Shortcode
- Plugin:
- ML Responsive Audio player with playlist Shortcode
- Plugin Slug:
- mlr-audio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51573
Mobilize
- Plugin:
- Mobilize
- Plugin Slug:
- mobilize
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51649
Multi Purpose Mail Form
- Plugin:
- Multi Purpose Mail Form
- Plugin Slug:
- multi-purpose-mail-form
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50526
MyOrderDesk
- Plugin:
- MyOrderDesk
- Plugin Slug:
- myorderdesk
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50546
Narnoo Commerce Manager
- Plugin:
- Narnoo Commerce Manager
- Plugin Slug:
- narnoo-commerce-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51708
Naver Blog
- Plugin:
- Naver Blog
- Plugin Slug:
- naver-blog-api
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51639
NMR Strava activities
- Plugin:
- NMR Strava activities
- Plugin Slug:
- nmr-strava-activities
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51603
Porsline
- Plugin:
- Porsline
- Plugin Slug:
- porsline
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51620
Website price calculator
- Plugin:
- Website price calculator
- Plugin Slug:
- price-calculator-to-your-website
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51601
Pricer Ninja
- Plugin:
- Pricer Ninja
- Plugin Slug:
- pricer-ninja-pricing-tables
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50518
PropertyShift
- Plugin:
- PropertyShift
- Plugin Slug:
- propertyshift
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51762
Quran Shortcode
- Plugin:
- Quran Shortcode
- Plugin Slug:
- quran-shortcode
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51625
Random Featured Post
- Plugin:
- Random Featured Post
- Plugin Slug:
- random-featured-post-plugin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51650
Reftagger Shortcode
- Plugin:
- Reftagger Shortcode
- Plugin Slug:
- reftagger-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51612
Responsive Data Table
- Plugin:
- Responsive Data Table
- Plugin Slug:
- responsive-data-table
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51710
Responsive Flickr Gallery
- Plugin:
- Responsive Flickr Gallery
- Plugin Slug:
- responsive-flickr-gallery
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51630
RSVP ME
- Plugin:
- RSVP ME
- Plugin Slug:
- rsvp-me
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50544
Sales Page Addon – Elementor & Beaver Builder
- Plugin:
- Sales Page Addon – Elementor & Beaver Builder
- Plugin Slug:
- sales-page-addon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51585
Saragna
- Plugin:
- Saragna
- Plugin Slug:
- saragna-social-stream
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51711
Search order by product SKU for WooCommerce
- Plugin:
- Search order by product SKU for WooCommerce
- Plugin Slug:
- search-order-by-product-sku-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51693
Selar.co Widget
- Plugin:
- Selar.co Widget
- Plugin Slug:
- selar-co-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51598
Seo Free
- Plugin:
- Seo Free
- Plugin Slug:
- seo-free
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51642
SH Slideshow
- Plugin:
- SH Slideshow
- Plugin Slug:
- sh-slideshow
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51632
Show Visitor IP Address
- Plugin:
- Show Visitor IP Address
- Plugin Slug:
- show-visitor-ip-address
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50538
Sided
- Plugin:
- Sided
- Plugin Slug:
- sided
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50554
Simple Business Manager
- Plugin:
- Simple Business Manager
- Plugin Slug:
- simple-business-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51599
Easy Gallery
- Plugin:
- Easy Gallery
- Plugin Slug:
- simple-gallery-odihost
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51570
Simple Goods
- Plugin:
- Simple Goods
- Plugin Slug:
- simple-goods
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51574
Simple Job Manager
- Plugin:
- Simple Job Manager
- Plugin Slug:
- simple-job-manager
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51602
Simple Modal
- Plugin:
- Simple Modal
- Plugin Slug:
- simplemodal
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51718
Simplistic SEO
- Plugin:
- Simplistic SEO
- Plugin Slug:
- simplistic-seo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51719
SIP Reviews Shortcode for WooCommerce
- Plugin:
- SIP Reviews Shortcode for WooCommerce
- Plugin Slug:
- sip-reviews-shortcode-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6480
SIP Reviews Shortcode for WooCommerce
- Plugin:
- SIP Reviews Shortcode for WooCommerce
- Plugin Slug:
- sip-reviews-shortcode-woocommerce
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-6479
Skip To
- Plugin:
- Skip To
- Plugin Slug:
- skip-to
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51652
SKSDEV Toolkit
- Plugin:
- SKSDEV Toolkit
- Plugin Slug:
- sksdev-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51595
Slicko
- Plugin:
- Slicko
- Plugin Slug:
- slicko-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51591
Smart Mockups
- Plugin:
- Smart Mockups
- Plugin Slug:
- smart-mockups
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50537
Stacks Mobile App Builder
- Plugin:
- Stacks Mobile App Builder
- Plugin Slug:
- stacks-mobile-app-builder
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50528
Stacks Mobile App Builder
- Plugin:
- Stacks Mobile App Builder
- Plugin Slug:
- stacks-mobile-app-builder
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50527
Stars SMTP Mailer
- Plugin:
- Stars SMTP Mailer
- Plugin Slug:
- stars-smtp-mailer
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50530
Step by Step
- Plugin:
- Step by Step
- Plugin Slug:
- step-by-step
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50535
Sticky Social Bar
- Plugin:
- Sticky Social Bar
- Plugin Slug:
- sticky-social-bar
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51631
Super Addons for Elementor
- Plugin:
- Super Addons for Elementor
- Plugin Slug:
- super-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51588
SVT Simple
- Plugin:
- SVT Simple
- Plugin Slug:
- svt-simple
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51759
T(-) Countdown
- Plugin:
- T(-) Countdown
- Plugin Slug:
- t-countdown
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9884
Team Showcase and Slider – Team Members Builder
- Plugin:
- Team Showcase and Slider – Team Members Builder
- Plugin Slug:
- team-showcase-ultimate
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51763
TeleAdmin
- Plugin:
- TeleAdmin
- Plugin Slug:
- teleadmin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51709
Themedy Toolbox
- Plugin:
- Themedy Toolbox
- Plugin Slug:
- themedy-toolbox
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50547
ThemeFuse Maintenance Mode
- Plugin:
- ThemeFuse Maintenance Mode
- Plugin Slug:
- themefuse-maintenance-mode
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51645
ThemeShark Templates & Widgets for Elementor
- Plugin:
- ThemeShark Templates & Widgets for Elementor
- Plugin Slug:
- themeshark-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51597
TradeMe widgets
- Plugin:
- TradeMe widgets
- Plugin Slug:
- trademe-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51613
SrcSet Responsive Images for WordPress
- Plugin:
- SrcSet Responsive Images for WordPress
- Plugin Slug:
- truenorth-srcset
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51702
Twitter @Anywhere Plus
- Plugin:
- Twitter @Anywhere Plus
- Plugin Slug:
- twitter-anywhere-plus
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51659
Twitter real time search scrolling
- Plugin:
- Twitter real time search scrolling
- Plugin Slug:
- twitter-real-time-search-scrolling
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51716
???? ????? UAH
- Plugin:
- ???? ????? UAH
- Plugin Slug:
- ukrainian-currency
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51593
TinyMCE
- Plugin:
- TinyMCE
- Plugin Slug:
- ultimate-tinymce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8627
UPDATE NOTIFICATIONS
- Plugin:
- UPDATE NOTIFICATIONS
- Plugin Slug:
- update-notifications
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51653
User Password Reset
- Plugin:
- User Password Reset
- Plugin Slug:
- user-password-reset
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51714
UW Freelancer
- Plugin:
- UW Freelancer
- Plugin Slug:
- uw-freelancer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51706
Webriti Custom Login
- Plugin:
- Webriti Custom Login
- Plugin Slug:
- webriti-custom-login-page
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51634
WeChat Subscribers Lite
- Plugin:
- WeChat Subscribers Lite
- Plugin Slug:
- wechat-subscribers-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50522
While Loading
- Plugin:
- While Loading
- Plugin Slug:
- while-it-is-loading
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51635
Widget or Sidebar Shortcode
- Plugin:
- Widget or Sidebar Shortcode
- Plugin Slug:
- widget-or-sidebar-per-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9885
WM Zoom
- Plugin:
- WM Zoom
- Plugin Slug:
- wm-zoom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-50556
Woo Manage Fraud Orders
- Plugin:
- Woo Manage Fraud Orders
- Plugin Slug:
- woo-manage-fraud-orders
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-10544
Woocommerce Product Design
- Plugin:
- Woocommerce Product Design
- Plugin Slug:
- woo-product-design
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50509
Woocommerce Product Design
- Plugin:
- Woocommerce Product Design
- Plugin Slug:
- woo-product-design
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50508
Woocommerce Quote Calculator
- Plugin:
- Woocommerce Quote Calculator
- Plugin Slug:
- woo-quote-calculator-order
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51626
World Prayer Time
- Plugin:
- World Prayer Time
- Plugin Slug:
- world-prayer-time
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-50534
WP Baidu Map
- Plugin:
- WP Baidu Map
- Plugin Slug:
- wp-baidu-map
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9886
WP-Basics
- Plugin:
- WP-Basics
- Plugin Slug:
- wp-basics
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51703
WP Course Manager
- Plugin:
- WP Course Manager
- Plugin Slug:
- wp-course-manager
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51658
WP donimedia carousel
- Plugin:
- WP donimedia carousel
- Plugin Slug:
- wp-donimedia-carousel
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-50511
Download-Mirror-Counter
- Plugin:
- Download-Mirror-Counter
- Plugin Slug:
- wp-download-mirror-counter
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51621
WP EASY RECIPE
- Plugin:
- WP EASY RECIPE
- Plugin Slug:
- wp-easy-recipe
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51622
WP EIS
- Plugin:
- WP EIS
- Plugin Slug:
- wp-eis
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51623
WP Feature Box
- Plugin:
- WP Feature Box
- Plugin Slug:
- wp-feature-box
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51611
imPress
- Plugin:
- imPress
- Plugin Slug:
- wp-js-impress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51704
WP MMenu Lite
- Plugin:
- WP MMenu Lite
- Plugin Slug:
- wp-mmenu-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51705
WP Simple Anchors Links
- Plugin:
- WP Simple Anchors Links
- Plugin Slug:
- wp-simple-anchors-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9446
Wp Slide Categorywise
- Plugin:
- Wp Slide Categorywise
- Plugin Slug:
- wp-slide-categorywise
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51690
WP Visual Adverts
- Plugin:
- WP Visual Adverts
- Plugin Slug:
- wp-visual-adverts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51707
WPGlobus Translate Options
- Plugin:
- WPGlobus Translate Options
- Plugin Slug:
- wpglobus-translate-options
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9434
WPHelpful
- Plugin:
- WPHelpful
- Plugin Slug:
- wphelpful
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51761
Admin Amplify
- Plugin:
- Admin Amplify
- Plugin Slug:
- wpr-admin-amplify
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51691
LiteSpeed Cache
- Plugin:
- LiteSpeed Cache
- Plugin Slug:
- litespeed-cache
- Installations
- 6,000,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 6.5.2
- Severity Score:
- High
- CVE:
- 2024-50550
All-in-One WP Migration and Backup
- Plugin Slug:
- all-in-one-wp-migration
- Installations
- 5,000,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 7.87
- Severity Score:
- High
- CVE:
- 2024-9162
Loginizer
- Plugin:
- Loginizer
- Plugin Slug:
- loginizer
- Installations
- 1,000,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.9.3
- Severity Score:
- High
- CVE:
- 2024-10097
Ninja Forms – The Contact Form Builder That Grows With You
- Plugin Slug:
- ninja-forms
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.18
- Severity Score:
- Medium
- CVE:
- 2024-50515
Ninja Forms – The Contact Form Builder That Grows With You
- Plugin Slug:
- ninja-forms
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.18
- Severity Score:
- Medium
- CVE:
- 2024-50514
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.61
- Severity Score:
- Medium
- CVE:
- 2024-10266
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
- Plugin Slug:
- forminator
- Installations
- 500,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.36.1
- Severity Score:
- Medium
- CVE:
- 2024-9700
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
- Plugin Slug:
- forminator
- Installations
- 500,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.36.0
- Severity Score:
- High
- CVE:
- 2024-10402
Gutenberg Blocks with AI by Kadence WP – Page Builder Features
- Plugin Slug:
- kadence-blocks
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.2
- Severity Score:
- Medium
- CVE:
- 2024-9655
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Plugin Slug:
- otter-blocks
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.5
- Severity Score:
- Medium
- CVE:
- 2024-10367
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Plugin Slug:
- otter-blocks
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.4
- Severity Score:
- Low
- CVE:
- 2024-51671
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Plugin Slug:
- otter-blocks
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.5
- Severity Score:
- Medium
- CVE:
- 2024-10367
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
- Plugin Slug:
- photo-gallery
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.31
- Severity Score:
- Medium
- CVE:
- 2024-9878
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.3
- Severity Score:
- Medium
- CVE:
- 2024-9657
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.2
- Severity Score:
- Medium
- CVE:
- 2024-9868
Beaver Builder – WordPress Page Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.4.3
- Severity Score:
- Medium
- CVE:
- 2024-9505
Download Manager
- Plugin:
- Download Manager
- Plugin Slug:
- download-manager
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.00
- Severity Score:
- Medium
- CVE:
- 2024-8444
FileOrganizer – Manage WordPress and Website Files
- Plugin Slug:
- fileorganizer
- Installations
- 100,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.0
- Severity Score:
- High
- CVE:
- 2024-7985
Download Monitor
- Plugin:
- Download Monitor
- Plugin Slug:
- download-monitor
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.0.14
- Severity Score:
- Medium
- CVE:
- 2024-10399
Media Library Assistant
- Plugin:
- Media Library Assistant
- Plugin Slug:
- media-library-assistant
- Installations
- 70,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 3.20
- Severity Score:
- Critical
- CVE:
- 2024-51661
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.7.5
- Severity Score:
- Medium
- CVE:
- 2024-10312
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX
- Plugin Slug:
- ultimate-post
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1.16
- Severity Score:
- Medium
- CVE:
- 2024-50513
Seriously Simple Podcasting
- Plugin:
- Seriously Simple Podcasting
- Plugin Slug:
- seriously-simple-podcasting
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.0
- Severity Score:
- High
- CVE:
- 2024-9667
Subscribe to Comments
- Plugin:
- Subscribe to Comments
- Plugin Slug:
- subscribe-to-comments
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.1
- Severity Score:
- High
- CVE:
- 2024-8792
BetterLinks – An Advanced Plugin for Affiliate Links, Link Shortening, Link Tracking, Link Branding & Marketing
- Plugin Slug:
- betterlinks
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.1.8
- Severity Score:
- High
- CVE:
- 2024-51672
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress
- Plugin Slug:
- bookingpress-appointment-booking
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.1.17
- Severity Score:
- High
- CVE:
- 2024-10540
Dynamic Widgets
- Plugin:
- Dynamic Widgets
- Plugin Slug:
- dynamic-widgets
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.6.5
- Severity Score:
- Medium
- CVE:
- 2024-51669
Wp Social Login and Register Social Counter
- Plugin Slug:
- wp-social
- Installations
- 20,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 3.0.8
- Severity Score:
- Critical
- CVE:
- 2024-9501
140+ Widgets | Xpro Addons For Elementor – FREE
- Plugin Slug:
- xpro-elementor-addons
- Installations
- 20,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.4.6.1
- Severity Score:
- Medium
- CVE:
- 2024-10319
Contact Form 7 + Telegram
- Plugin:
- Contact Form 7 + Telegram
- Plugin Slug:
- cf7-telegram
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 0.8.6
- Severity Score:
- Medium
- CVE:
- 2024-9629
Pricing Tables WordPress Plugin – Easy Pricing Tables
- Plugin Slug:
- easy-pricing-tables
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.6
- Severity Score:
- High
- CVE:
- 2024-8871
AI Power: Complete AI Pack
- Plugin:
- AI Power: Complete AI Pack
- Plugin Slug:
- gpt3-ai-content-generator
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.8.90
- Severity Score:
- Critical
- CVE:
- 2024-10392
ReCaptcha Integration for WordPress
- Plugin Slug:
- wp-recaptcha-integration
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.6
- Severity Score:
- High
- CVE:
- 2024-8739
Bricksable for Bricks Builder
- Plugin:
- Bricksable for Bricks Builder
- Plugin Slug:
- bricksable
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.60
- Severity Score:
- Medium
- CVE:
- 2024-51663
Ultimate Bootstrap Elements for Elementor
- Plugin Slug:
- ultimate-bootstrap-elements-for-elementor
- Installations
- 7,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.4.7
- Severity Score:
- Medium
- CVE:
- 2024-10329
XT Floating Cart for WooCommerce
- Plugin:
- XT Floating Cart for WooCommerce
- Plugin Slug:
- woo-floating-cart-lite
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.3
- Severity Score:
- Medium
- CVE:
- 2024-9178
WPAdverts – Classifieds Plugin
- Plugin:
- WPAdverts – Classifieds Plugin
- Plugin Slug:
- wpadverts
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.7
- Severity Score:
- High
- CVE:
- 2024-10108
Arconix Shortcodes
- Plugin:
- Arconix Shortcodes
- Plugin Slug:
- arconix-shortcodes
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.14
- Severity Score:
- Medium
- CVE:
- 2024-10226
ElementsReady Addons for Elementor
- Plugin Slug:
- element-ready-lite
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.4
- Severity Score:
- Medium
- CVE:
- 2024-51787
JS Help Desk – The Ultimate Help Desk & Support Plugin
- Plugin Slug:
- js-support-ticket
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.8
- Severity Score:
- Medium
- CVE:
- 2024-51670
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
- Plugin Slug:
- magical-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.2.3
- Severity Score:
- Medium
- CVE:
- 2024-51665
SMS Alert Order Notifications – WooCommerce
- Plugin Slug:
- sms-alert
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.6
- Severity Score:
- Medium
- CVE:
- 2024-10233
Easy Accordion Gutenberg Block
- Plugin:
- Easy Accordion Gutenberg Block
- Plugin Slug:
- easy-accordion-block
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
- 2024-51660
Move Addons for Elementor
- Plugin:
- Move Addons for Elementor
- Plugin Slug:
- move-addons
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2024-10360
Multiple Page Generator Plugin – MPG
- Plugin Slug:
- multiple-pages-generator-by-porthas
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.2
- Severity Score:
- Medium
- CVE:
- 2024-7424
Newsletters
- Plugin:
- Newsletters
- Plugin Slug:
- newsletters-lite
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.9.5
- Severity Score:
- Medium
- CVE:
- 2024-10181
Paytium: Mollie payment forms & donations
- Plugin Slug:
- paytium
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.4.11
- Severity Score:
- Medium
- CVE:
- 2024-51667
Tickera – WordPress Event Ticketing
- Plugin Slug:
- tickera-event-ticketing-system
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.4.6
- Severity Score:
- Medium
- CVE:
- 2024-10263
affiliate-toolkit
- Plugin:
- affiliate-toolkit
- Plugin Slug:
- affiliate-toolkit-starter
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.6
- Severity Score:
- Medium
- CVE:
- 2024-10227
Beds24 Online Booking
- Plugin:
- Beds24 Online Booking
- Plugin Slug:
- beds24-online-booking
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.26
- Severity Score:
- Medium
- CVE:
- 2024-51664
Masteriyo LMS – eLearning and Online Course Builder for WordPress
- Plugin Slug:
- learning-management-system
- Installations
- 2,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.13.4
- Severity Score:
- High
- CVE:
- 2024-10008
Masteriyo LMS – eLearning and Online Course Builder for WordPress
- Plugin Slug:
- learning-management-system
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.4
- Severity Score:
- Medium
- CVE:
- 2024-10000
Responsive Filterable Portfolio
- Plugin:
- Responsive Filterable Portfolio
- Plugin Slug:
- responsive-filterable-portfolio
- Installations
- 2,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.0.23
- Severity Score:
- Medium
- CVE:
- 2024-51785
Restaurant & Cafe Addon for Elementor
- Plugin Slug:
- restaurant-cafe-addon-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.7
- Severity Score:
- Medium
- CVE:
- 2024-51581
Zotpress
aThemes Addons for Elementor
- Plugin:
- aThemes Addons for Elementor
- Plugin Slug:
- athemes-addons-for-elementor-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.8
- Severity Score:
- Medium
- CVE:
- 2024-51675
BBP Core – Expand bbPress powered forums with useful features
- Plugin Slug:
- bbp-core
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.6
- Severity Score:
- High
- CVE:
- 2024-9896
Black Widgets For Elementor
- Plugin:
- Black Widgets For Elementor
- Plugin Slug:
- black-widgets
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
- 2024-51662
Black Widgets For Elementor
- Plugin:
- Black Widgets For Elementor
- Plugin Slug:
- black-widgets
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.8
- Severity Score:
- Medium
- CVE:
- 2024-9388
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 24.0.4
- Severity Score:
- Critical
- CVE:
- 2024-10687
WooCommerce Report
- Plugin:
- WooCommerce Report
- Plugin Slug:
- ithemelandco-woo-report
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.5.2
- Severity Score:
- High
- CVE:
- 2024-10711
Manage User Columns
- Plugin:
- Manage User Columns
- Plugin Slug:
- manage-user-columns
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2024-51686
MyCurator Content Curation
- Plugin:
- MyCurator Content Curation
- Plugin Slug:
- mycurator
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.79
- Severity Score:
- Medium
- CVE:
- 2024-51668
Post Status Notifier Lite
- Plugin:
- Post Status Notifier Lite
- Plugin Slug:
- post-status-notifier-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.11.7
- Severity Score:
- High
- CVE:
- 2024-10048
Posti Shipping
- Plugin:
- Posti Shipping
- Plugin Slug:
- posti-shipping
- Installations
- 1,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 3.10.3
- Severity Score:
- Medium
- CVE:
- 2024-50512
SEUR Oficial
- Plugin:
- SEUR Oficial
- Plugin Slug:
- seur
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.12
- Severity Score:
- High
- CVE:
- 2024-9438
W3SPEEDSTER
- Plugin:
- W3SPEEDSTER
- Plugin Slug:
- w3speedster-wp
- Installations
- 1,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 7.27
- Severity Score:
- Critical
- CVE:
- 2024-8512
WPC Smart Messages for WooCommerce
- Plugin Slug:
- wpc-smart-messages
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.2.2
- Severity Score:
- Medium
- CVE:
- 2024-10437
WPC Smart Messages for WooCommerce
- Plugin Slug:
- wpc-smart-messages
- Installations
- 1,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.2.2
- Severity Score:
- High
- CVE:
- 2024-10436
Group Chat & Video Chat by AtomChat
- Plugin Slug:
- atomchat
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2024-10232
StreamWeasels YouTube Integration
- Plugin Slug:
- streamweasels-youtube-integration
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.3
- Severity Score:
- Medium
- CVE:
- 2024-10185
WP Team – WordPress Team Member Plugin
- Plugin Slug:
- ht-team-member
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.5
- Severity Score:
- Medium
- CVE:
- 2024-10223
Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates
- Plugin Slug:
- sastra-essential-addons-for-elementor
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2024-51674
HT Builder – WordPress Theme Builder for Elementor
- Plugin Slug:
- ht-builder
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- Medium
- CVE:
- 2024-51682
Kata Plus – Addons for Elementor – Widgets, Extensions and Templates
- Plugin Slug:
- kata-plus
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
- 2024-9376
Custom post type templates for Elementor
- Plugin Slug:
- custom-post-type-templates-for-elementor
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.12
- Severity Score:
- Medium
- CVE:
- 2024-51683
HT Politic – For Political WordPress Themes / Website
- Plugin Slug:
- wp-politic
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.5
- Severity Score:
- Medium
- CVE:
- 2024-51673
Delisho – Recipe Widgets and Blocks
- Plugin Slug:
- dr-widgets-blocks
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2024-51676
Shortcodes Blocks Creator Ultimate
- Plugin Slug:
- ultimate-shortcodes-creator
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.0
- Severity Score:
- Medium
- CVE:
- 2024-10340
Appointmind
- Plugin:
- Appointmind
- Plugin Slug:
- appointmind
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.1.0
- Severity Score:
- High
- CVE:
- 2024-51679
Basticom Framework
- Plugin:
- Basticom Framework
- Plugin Slug:
- basticom-framework
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-9443
Knowledge Base
- Plugin:
- Knowledge Base
- Plugin Slug:
- knowledgebase
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-51677
RLM Elementor Widgets Pack
- Plugin:
- RLM Elementor Widgets Pack
- Plugin Slug:
- rlm-elementor-widgets-pack
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.0
- Severity Score:
- Medium
- CVE:
- 2024-50542
StreamWeasels Kick Integration
- Plugin:
- StreamWeasels Kick Integration
- Plugin Slug:
- streamweasels-kick-integration
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.2
- Severity Score:
- Medium
- CVE:
- 2024-10184
User Toolkit
- Plugin:
- User Toolkit
- Plugin Slug:
- user-toolkit
- Installations
- 100+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.2.4
- Severity Score:
- Critical
- CVE:
- 2024-50503
WP Pocket URLs
- Plugin:
- WP Pocket URLs
- Plugin Slug:
- wp-pocket-urls
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.4
- Severity Score:
- Medium
- CVE:
- 2024-51681
Elo Rating Shortcode
- Plugin:
- Elo Rating Shortcode
- Plugin Slug:
- elo-rating-shortcode
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.4
- Severity Score:
- Medium
- CVE:
- 2024-51678
W3P SEO
- Plugin:
- W3P SEO
- Plugin Slug:
- wp-perfect-plugin
- Installations
- 50+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.8.6
- Severity Score:
- High
- CVE:
- 2024-51684
SmartLink Dynamic URLs
- Plugin:
- SmartLink Dynamic URLs
- Plugin Slug:
- smartlink-dinamic-urls
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.1
- Severity Score:
- High
- CVE:
- 2024-51657
Platform.ly Official
- Plugin:
- Platform.ly Official
- Plugin Slug:
- platformly
- Installations
- 30+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.14
- Severity Score:
- High
- CVE:
- 2024-51687
Realty by BestWebSoft
- Plugin:
- Realty by BestWebSoft
- Plugin Slug:
- realty
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2024-51786
Accordion title for Elementor
- Plugin:
- Accordion title for Elementor
- Plugin Slug:
- accordion-title-for-elementor
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2024-51685
Cresta Addons for Elementor
- Plugin:
- Cresta Addons for Elementor
- Plugin Slug:
- cresta-addons-for-elementor
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.0
- Severity Score:
- Medium
- CVE:
- 2024-51680
FraudLabs Pro SMS Verification
- Plugin:
- FraudLabs Pro SMS Verification
- Plugin Slug:
- fraudlabs-pro-sms-verification
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.10.2
- Severity Score:
- High
- CVE:
- 2024-51688
RSVPMaker for Toastmasters
- Plugin:
- RSVPMaker for Toastmasters
- Plugin Slug:
- rsvpmaker-for-toastmasters
- Installations
- 10+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 6.2.5
- Severity Score:
- Critical
- CVE:
- 2024-50531
Audio Comparison Lite
- Plugin:
- Audio Comparison Lite
- Plugin Slug:
- audio-comparison-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5
- Severity Score:
- Medium
- CVE:
- 2024-51627
Loginizer Security
- Plugin:
- Loginizer Security
- Plugin Slug:
- loginizer-security
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.9.3
- Severity Score:
- High
- CVE:
- 2024-10097
Post Status Notifier Premium
- Plugin:
- Post Status Notifier Premium
- Plugin Slug:
- post-status-notifier
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.11.7
- Severity Score:
- High
- CVE:
- 2024-10048
WooCommerce Social Login
- Plugin:
- WooCommerce Social Login
- Plugin Slug:
- woo-social-login
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.7.8
- Severity Score:
- High
- CVE:
- 2024-10114
WordPress Themes — 0 Patched / 0 Unpatched
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
