WordPress Vulnerability Report

WordPress Vulnerability Report — December 18, 2024

This last week, 345 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 181 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 345 vulnerabilities have been publicly disclosed. Security patches for 164 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 181 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 156 Patched / 179 Unpatched

WP Mega Menu

Plugin Slug:
wp-megamenu
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo
Installations
10,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

News Ticker for Elementor

Plugin Slug:
news-ticker-for-elementor
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Menu Image

Plugin Slug:
wp-menu-image
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smaily for WP

Plugin Slug:
smaily-for-wp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SQL Chart Builder

Plugin Slug:
sql-chart-builder
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SIP Calculator

Plugin Slug:
sip-calculator
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LDD Directory Lite

Plugin Slug:
ldd-directory-lite
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Permalinker

Plugin Slug:
the-permalinker
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nias course | ???? ??? ????

Plugin Slug:
nias-course
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Role Includer

Plugin Slug:
role-includer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks – WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Cookies Enabler

Plugin Slug:
wp-cookies-enabler
Installations
30+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Blog Post Block

Plugin Slug:
advanced-blog-post-block
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Blocks – Woolook

Plugin Slug:
woolook
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-NERD Toolkit

Plugin Slug:
wp-nerd-toolkit
Installations
10+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

3D Avatar User Profile

Plugin:
3D Avatar User Profile
Plugin Slug:
3d-avatar-user-profile
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add image to Post

Plugin:
Add image to Post
Plugin Slug:
add-image-to-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advance Menu Manager

Plugin:
Advance Menu Manager
Plugin Slug:
advance-menu-manager
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Data Table For Elementor

Plugin:
Advanced Data Table For Elementor
Plugin Slug:
advanced-data-table-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Fancybox

Plugin:
Advanced Fancybox
Plugin Slug:
advanced-fancybox
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced What should we write next about

Plugin:
Advanced What should we write next about
Plugin Slug:
advanced-what-should-we-write-about-next
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AI Post Generator | AutoWriter

Plugin:
AI Post Generator | AutoWriter
Plugin Slug:
ai-post-generator
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zita Site Builder

Plugin:
Zita Site Builder
Plugin Slug:
ai-site-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Product Price

Plugin:
Amazon Product Price
Plugin Slug:
amazon-product-price
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Animated Counters

Plugin:
Animated Counters
Plugin Slug:
animated-counters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aphorismus

Plugin:
Aphorismus
Plugin Slug:
aphorismus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AppMaps

Plugin:
AppMaps
Plugin Slug:
appmaps
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Appsplate

Plugin:
Appsplate
Plugin Slug:
appsplate
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Arabic Webfonts

Plugin:
Arabic Webfonts
Plugin Slug:
arabic-webfonts
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM – Live Blogging for real-time events

Plugin:
Arena.IM – Live Blogging for real-time events
Plugin Slug:
arena-liveblog-and-chat-tool
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM – Live Blogging for real-time events

Plugin:
Arena.IM – Live Blogging for real-time events
Plugin Slug:
arena-liveblog-and-chat-tool
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Firebase OTP Authentication

Plugin:
Firebase OTP Authentication
Plugin Slug:
authentication-via-otp-using-firebase
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Banner System

Plugin:
Banner System
Plugin Slug:
banner-system
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bet sport Free

Plugin:
Bet sport Free
Plugin Slug:
bet-sport-free
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better WP Login Page

Plugin:
Better WP Login Page
Plugin Slug:
better-wp-login-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Buttons

Plugin:
Bootstrap Buttons
Plugin Slug:
bootstrap-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Buk

Plugin:
Buk
Plugin Slug:
buk-appointments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Caldera SMTP Mailer

Plugin:
Caldera SMTP Mailer
Plugin Slug:
caldera-smtp-mailer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mollie for Contact Form 7

Plugin:
Mollie for Contact Form 7
Plugin Slug:
cf7-mollie
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

??????

Plugin:
??????
Plugin Slug:
changyan
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CK and SyntaxHighlighter

Plugin:
CK and SyntaxHighlighter
Plugin Slug:
ck-and-syntaxhighlighter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Generator Pro

Plugin:
Code Generator Pro
Plugin Slug:
code-generator-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Comments On Feed

Plugin:
Comments On Feed
Plugin Slug:
comments-on-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Companion Portfolio

Plugin:
Companion Portfolio
Plugin Slug:
companion-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Connatix Video Embed

Plugin:
Connatix Video Embed
Plugin Slug:
connatix-video-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CoSchool LMS

Plugin:
CoSchool LMS
Plugin Slug:
coschool
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Crafthemes Demo Import

Plugin:
Crafthemes Demo Import
Plugin Slug:
crafthemes-demo-import
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Cricket Live Score

Plugin:
Cricket Live Score
Plugin Slug:
cricket-score
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Critical Site Intel

Plugin:
Critical Site Intel
Plugin Slug:
critical-site-intel-stats
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CRUDLab Google Plus Button

Plugin:
CRUDLab Google Plus Button
Plugin Slug:
crudlab-google-plus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV to html

Plugin:
CSV to html
Plugin Slug:
csv-to-html
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Skins Contact Form 7

Plugin:
Custom Skins Contact Form 7
Plugin Slug:
custom-skins-contact-form-7
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Endpoints With Rest Api

Plugin:
Ultimate Endpoints With Rest Api
Plugin Slug:
custom-wp-rest-api
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mimoos

Plugin:
Mimoos
Plugin Slug:
devoluciones-packback
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Display Future Posts

Plugin:
Display Future Posts
Plugin Slug:
display-future-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dr Affiliate

Plugin:
Dr Affiliate
Plugin Slug:
dr-affiliate
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DTC Documents

Plugin:
DTC Documents
Plugin Slug:
dtc-documents
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Site Importer

Plugin:
Easy Site Importer
Plugin Slug:
easy-site-importer
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
ECT Product Carousel
Plugin Slug:
ect-product-carousel
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ECT Social Share

Plugin:
ECT Social Share
Plugin Slug:
ect-social-share
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EELV Newsletter

Plugin:
EELV Newsletter
Plugin Slug:
eelv-newsletter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mandrill WP

Plugin:
Mandrill WP
Plugin Slug:
email-form-under-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

eTemplates

Plugin:
eTemplates
Plugin Slug:
etemplates
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Evernote Sync

Plugin:
Evernote Sync
Plugin Slug:
evernote-sync
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Feedpress Generator

Plugin:
Feedpress Generator
Plugin Slug:
feedpress-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin:
Flaming Forms
Plugin Slug:
flaming-forms
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flash News / Post (Responsive)

Plugin:
Flash News / Post (Responsive)
Plugin Slug:
flashnews-fading-effect-pearlbells
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Floating Video Player

Plugin:
Floating Video Player
Plugin Slug:
floating-player
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gaxx Keywords

Plugin:
Gaxx Keywords
Plugin Slug:
gaxx-keywords
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Geoportail Shortcode

Plugin:
Geoportail Shortcode
Plugin Slug:
geoportail-shortcode
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Get Post Content Shortcode

Plugin:
Get Post Content Shortcode
Plugin Slug:
get-post-content-shortcode
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GitSync

Plugin:
GitSync
Plugin Slug:
git-sync
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

glomex oEmbed

Plugin:
glomex oEmbed
Plugin Slug:
glomex-oembed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Go Animate

Plugin:
Go Animate
Plugin Slug:
goanimate
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus

Plugin:
Grid Plus
Plugin Slug:
grid-plus
Vulnerability:
Arbitrary Code Execution
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gutensee

Plugin:
Gutensee
Plugin Slug:
gutensee
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opt-In Downloads

Plugin:
Opt-In Downloads
Plugin Slug:
halfdata-optin-downloads
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hello In All Languages

Plugin:
Hello In All Languages
Plugin Slug:
hello-in-all-languages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Horizontal scroll image slideshow

Plugin:
Horizontal scroll image slideshow
Plugin Slug:
horizontal-scroll-image-slideshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HostFact bestelformulier integratie

Plugin:
HostFact bestelformulier integratie
Plugin Slug:
hostfact-bestelformulier-integratie
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HQ Rental Software

Plugin:
HQ Rental Software
Plugin Slug:
hq-rental-software
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IDer Login

Plugin:
IDer Login
Plugin Slug:
ider-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Mapper

Plugin:
Image Mapper
Plugin Slug:
image-mapper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Increase Sociability

Plugin:
Increase Sociability
Plugin Slug:
increase-sociability
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Insertify

Plugin:
Insertify
Plugin Slug:
insertify
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:
Instant Appointment
Plugin Slug:
instant-appointment
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

jCarousel

Plugin:
jCarousel
Plugin Slug:
jcarousel-for-wordpress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Jet Footer Code
Plugin Slug:
jet-footer-code
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

KH Easy User Settings

Plugin:
KH Easy User Settings
Plugin Slug:
kh-easy-user-settings
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kredeum NFTs

Plugin:
Kredeum NFTs
Plugin Slug:
kredeum-nfts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

kvCORE IDX

Plugin:
kvCORE IDX
Plugin Slug:
kvcore-idx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LaunchPage.app Importer

Plugin:
LaunchPage.app Importer
Plugin Slug:
launchpage-app-importer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Leader

Plugin:
Leader
Plugin Slug:
leader
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LeaderBoard Plugin

Plugin:
LeaderBoard Plugin
Plugin Slug:
leaderboard-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:
Library Management System
Plugin Slug:
library-management-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Like in Vk.com

Plugin:
Like in Vk.com
Plugin Slug:
like-on-vkontakte
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Category of Posts

Plugin:
Category of Posts
Plugin Slug:
list-one-category-of-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListApp Mobile Manager

Plugin:
ListApp Mobile Manager
Plugin Slug:
listapp-mobile-manager
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LionScripts: Site Maintenance & Noindex Nofollow Plugin

Plugin:
LionScripts: Site Maintenance & Noindex Nofollow Plugin
Plugin Slug:
maintenance-and-noindex-nofollow
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MDC Comment Toolbar

Plugin:
MDC Comment Toolbar
Plugin Slug:
mdc-comment-toolbar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Metrika

Plugin:
Metrika
Plugin Slug:
metrika
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Minterpress

Plugin:
Minterpress
Plugin Slug:
minterpress
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Multiple Admin Emails

Plugin:
Multiple Admin Emails
Plugin Slug:
multiple-admin-emails
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
My IDX Home Search
Plugin Slug:
my-idx-home-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

addWeather

Plugin:
addWeather
Plugin Slug:
myweather
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Nabz Image Gallery
Plugin Slug:
nabz-image-gallery
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Navayan CSV Export

Plugin:
Navayan CSV Export
Plugin Slug:
navayan-csv-export
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Subscriptions

Plugin:
Newsletter Subscriptions
Plugin Slug:
newsletter-subscriptions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Onlywire Multi Autosubmitter

Plugin:
Onlywire Multi Autosubmitter
Plugin Slug:
onlywire-multi-autosubmitter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery & Pickup Location Date Time

Plugin:
Order Delivery & Pickup Location Date Time
Plugin Slug:
order-delivery-pickup-location-date-time-free-version
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

phZoom

Plugin:
phZoom
Plugin Slug:
phzoom
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PixProof

Plugin:
PixProof
Plugin Slug:
pixproof
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popup Surveys & Polls for WordPress (Mare.io)

Plugin:
Popup Surveys & Polls for WordPress (Mare.io)
Plugin Slug:
popup-surveys
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Portfolio – Filterable Masonry Portfolio Gallery for Professionals
Plugin Slug:
portfolio-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel & Slider

Plugin:
Post Carousel & Slider
Plugin Slug:
post-types-carousel-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Posts and Products Views for WooCommerce

Plugin:
Posts and Products Views for WooCommerce
Plugin Slug:
posts-and-products-views
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Posts Date Ranges

Plugin:
Posts Date Ranges
Plugin Slug:
posts-date-ranges
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PowerFormBuilder

Plugin:
PowerFormBuilder
Plugin Slug:
power-forms-builder
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart

Plugin:
Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart
Plugin Slug:
push-monkey-desktop-push-notifications
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quietly Insights

Plugin:
Quietly Insights
Plugin Slug:
quietly-insights
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Share Buttons – Social Media

Plugin:
Share Buttons – Social Media
Plugin Slug:
rich-web-share-button
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Saksh Escrow System

Plugin:
Saksh Escrow System
Plugin Slug:
saksh-escrow-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Saoshyant Element

Plugin:
Saoshyant Element
Plugin Slug:
saoshyant-element
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:
SeedProd Pro
Plugin Slug:
seedprod-coming-soon-pro-5
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:
SeedProd Pro
Plugin Slug:
seedprod-coming-soon-pro-5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:
SeedProd Pro
Plugin Slug:
seedprod-coming-soon-pro-5
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Service

Plugin:
Service
Plugin Slug:
service
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sign In With Google

Plugin:
Sign In With Google
Plugin Slug:
sign-in-with-google
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple Booking Widget

Plugin:
Simple Booking Widget
Plugin Slug:
simple-booking-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slope Widgets

Plugin:
Slope Widgets
Plugin Slug:
slope-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Media Sharing

Plugin:
Social Media Sharing
Plugin Slug:
social-media-sharing
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SOPA Blackout

Plugin:
SOPA Blackout
Plugin Slug:
sopa-blackout
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Pay Lite Manager

Plugin:
WP Simple Pay Lite Manager
Plugin Slug:
stripe-manager
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Surbma | SalesAutopilot Shortcode

Plugin:
Surbma | SalesAutopilot Shortcode
Plugin Slug:
surbma-salesautopilot-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVG Shortcode

Plugin:
SVG Shortcode
Plugin Slug:
svg-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TagGator

Plugin:
TagGator
Plugin Slug:
taggator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TCBD Popover

Plugin:
TCBD Popover
Plugin Slug:
tcbd-popover
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tidy Up

Plugin:
Tidy Up
Plugin Slug:
tidy-up
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TPG Get Posts

Plugin:
TPG Get Posts
Plugin Slug:
tpg-get-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TSB Occasion Editor

Plugin:
TSB Occasion Editor
Plugin Slug:
tsb-occasion-editor
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ui Slider Filter By Price

Plugin:
Ui Slider Filter By Price
Plugin Slug:
ui-slider-filter-by-price
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Utech World Time

Plugin:
Utech World Time
Plugin Slug:
utech-world-time-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

vBSSO-lite

Plugin:
vBSSO-lite
Plugin Slug:
vbsso-lite
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Visual Recent Posts

Plugin:
Visual Recent Posts
Plugin Slug:
visual-recent-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Visualmodo Elements

Plugin:
Visualmodo Elements
Plugin Slug:
visualmodo-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Website Toolbox Community

Plugin:
Website Toolbox Community
Plugin Slug:
website-toolbox-forums
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Cart Count Shortcode

Plugin:
WooCommerce Cart Count Shortcode
Plugin Slug:
woo-cart-count-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Basic Ordernumbers

Plugin:
WooCommerce Basic Ordernumbers
Plugin Slug:
woocommerce-basic-ordernumbers
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Filter

Plugin:
WordPress Filter
Plugin Slug:
wordpress-filter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wovax IDX

Plugin:
Wovax IDX
Plugin Slug:
wovax-idx
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Ban-User

Plugin:
WP-Ban-User
Plugin Slug:
wp-ban-user
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Fiddle

Plugin:
WP Fiddle
Plugin Slug:
wp-fiddle
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Flipkart Importer

Plugin:
WP Flipkart Importer
Plugin Slug:
wp-flipkart-importer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-HideThat

Plugin:
WP-HideThat
Plugin Slug:
wp-hide-that
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp Login with Ajax

Plugin:
Wp Login with Ajax
Plugin Slug:
wp-login-with-ajax
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Controller

Plugin:
WP Controller
Plugin Slug:
wp-management-controller
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp NssUser Register

Plugin:
Wp NssUser Register
Plugin Slug:
wp-nssuser-register
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Wp photo text slider 50

Plugin:
Wp photo text slider 50
Plugin Slug:
wp-photo-text-slider-50
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Service Payment Form With Authorize.net

Plugin:
WP Service Payment Form With Authorize.net
Plugin Slug:
wp-service-payment-form-with-authorizenet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tithe.ly Giving Button

Plugin:
Tithe.ly Giving Button
Plugin Slug:
wp-tithely
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP?????

Plugin:
WP?????
Plugin Slug:
wp-weixin-robot
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Admin Customization

Plugin:
Admin Customization
Plugin Slug:
wpp-customization
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:
Wr Age Verification
Plugin Slug:
wr-age-verification
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:
Wr Age Verification
Plugin Slug:
wr-age-verification
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

XML Multilanguage Sitemap Generator

Plugin:
XML Multilanguage Sitemap Generator
Plugin Slug:
xml-multilanguage-sitemap-generator
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

XPD Reduce Image Filesize

Plugin:
XPD Reduce Image Filesize
Plugin Slug:
xpd-reduce-image-filesize
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

YDS Support Ticket System

Plugin:
YDS Support Ticket System
Plugin Slug:
yds-support-ticket-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

States Map US

Plugin:
States Map US
Plugin Slug:
ymc-states-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YooBar

Plugin:
YooBar
Plugin Slug:
yoo-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Youtube Video Grid

Plugin:
Youtube Video Grid
Plugin Slug:
youmax-channel-embeds-for-youtube-businesses
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.8.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.8.2.1.

User Role Editor

Plugin Slug:
user-role-editor
Installations
700,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.64.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.64.4.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.64.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.64.1.

Members – Membership & User Role Editor Plugin

Plugin Slug:
members
Installations
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.11.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.3.

Image Widget

Plugin Slug:
image-widget
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.11.

LuckyWP Table of Contents

Plugin Slug:
luckywp-table-of-contents
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Web Stories

Plugin Slug:
web-stories
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.38.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.38.0.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.4.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.5.

Ajax Search Lite – Live Search & Filter

Plugin Slug:
ajax-search-lite
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.12.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.4.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Path Traversal
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
50,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
5.2.64
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.64.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
9.9.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.9.9.4.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.6.

FULL – Cliente

Plugin Slug:
full-customer
Installations
30,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.26.

NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar

Plugin Slug:
notificationx
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.

PPWP – Password Protect Pages

Plugin Slug:
password-protect-page
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.6.

New User Approve

Plugin Slug:
new-user-approve
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Rate My Post – Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.5.

Minify HTML

Plugin Slug:
minify-html-markup
Installations
10,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
2.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.11.

Simple Side Tab

Plugin Slug:
simple-side-tab
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Essential Real Estate

Plugin Slug:
essential-real-estate
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.7.

MyParcel

Plugin:
MyParcel
Plugin Slug:
woocommerce-myparcel
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.2.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Notibar – Notification Bar for WordPress

Plugin Slug:
notibar
Installations
7,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Notibar – Notification Bar for WordPress

Plugin Slug:
notibar
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.
Plugin Slug:
vimeography
Installations
7,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

OAuth Single Sign On – SSO (OAuth Client)

Plugin Slug:
miniorange-login-with-eve-online-google-facebook
Installations
6,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.26.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.26.4.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage
Installations
5,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
5.16.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.16.7.2.

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja
Installations
5,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
11.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.53.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.9.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.6.0.

GEO my WP

Plugin:
GEO my WP
Plugin Slug:
geo-my-wp
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.1.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

Hash Form – Drag & Drop Form Builder

Plugin Slug:
hash-form
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Cognito Forms

Plugin Slug:
cognito-forms
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Falcon – WordPress Optimizations & Tweaks

Plugin Slug:
falcon
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.2.

Responsive Filterable Portfolio

Plugin Slug:
responsive-filterable-portfolio
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.0.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.9.

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.9.
Plugin Slug:
simple-link-directory
Installations
2,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
8.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.1.

360 Javascript Viewer

Plugin Slug:
360deg-javascript-viewer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.30.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.7.

FormFacade – WordPress plugin for Google Forms

Plugin Slug:
formfacade
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.7.

ForumWP – Forum & Discussion Board

Plugin Slug:
forumwp
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.1.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.17.

Memberful – Membership Plugin

Plugin Slug:
memberful-wp
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.74.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.74.0.

Posti Shipping

Plugin Slug:
posti-shipping
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.4.

Simple Restrict

Plugin Slug:
simple-restrict
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

RapidLoad – Optimize Web Vitals Automatically

Plugin Slug:
unusedcss
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.3.

NiceJob

Plugin:
NiceJob
Plugin Slug:
nicejob
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

Property Hive Mortgage Calculator

Plugin Slug:
property-hive-mortgage-calculator
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Property Hive Stamp Duty Calculator

Plugin Slug:
property-hive-stamp-duty-calculator
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

WPC Order Notes for WooCommerce

Plugin Slug:
woo-order-notes
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.22.

Waymark

Plugin:
Waymark
Plugin Slug:
waymark
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

AR for WordPress

Plugin Slug:
ar-for-wordpress
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
7.4
Severity Score:
Low
The vulnerability has been patched, so you should update to version 7.4.

Car Dealer (Dealership) and Vehicle sales

Plugin Slug:
cardealer
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
4.48
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.48.

Device Detector

Plugin Slug:
device-detector
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.1.

Last Viewed Posts by WPBeginner

Plugin Slug:
last-viewed-posts
Installations
600+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Out of the Block: OpenStreetMap

Plugin Slug:
ootb-openstreetmap
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

AIcomments – ??????????? ? ?????? ChatGPT

Plugin Slug:
aicomments
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

CM Answers – Powerful WordPress Forum Plugin

Plugin Slug:
cm-answers
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

Cryptocurrency Price Widget

Plugin Slug:
cryptocurrency-price-widget
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

iChart – Easy Charts and Graphs

Plugin Slug:
ichart
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

Mark New Posts

Plugin Slug:
mark-new-posts
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WP Email Log – PostBox

Plugin Slug:
postbox-email-logs
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

Themify Store Locator

Plugin Slug:
themify-store-locator
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

WooCommerce Additional Fees On Checkout (Free)

Plugin Slug:
woo-additional-fees-on-checkout-wordpress
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin Slug:
attire-blocks
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.6.

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core
Installations
400+
Vulnerability:
Broken Authentication
Patched in Version:
5.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.8.

Payment Gateway Per Product for WooCommerce

Plugin Slug:
woocommerce-product-payments
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.9.

Check Pincode For Woocommerce

Plugin Slug:
check-pincode-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.

Currency Converter Widget ? PRO

Plugin Slug:
currency-converter-widget-pro
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

NewsmanApp

Plugin:
NewsmanApp
Plugin Slug:
newsmanapp
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Print Science Designer

Plugin Slug:
print-science-designer
Installations
300+
Vulnerability:
PHP Object Injection
Patched in Version:
1.3.153
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.153.

Stop Registration Spam

Plugin Slug:
stop-registration-spam
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.24.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.2.

WP Mailster

Plugin Slug:
wp-mailster
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.18.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.18.0.

AutoWP – AI Content Writer & Rewriter

Plugin Slug:
autowp-ai-content-writer-rewriter
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Booking System Trafft

Plugin Slug:
booking-system-trafft
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

dejure.org Vernetzungsfunktion

Plugin Slug:
dejureorg-vernetzungsfunktion
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.98.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.98.0.

Email Reminders

Plugin Slug:
email-reminders
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

J&T Express Malaysia

Plugin Slug:
jt-express
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.15.

Revi.io – Customer & Products Reviews

Plugin Slug:
revi-io-customer-and-product-reviews
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.0.

WordPress Post Grid Layouts with Pagination – Sogrid

Plugin Slug:
sogrid
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.5.

Staggs – Product Configurator Toolkit

Plugin Slug:
staggs
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.0.
Plugin Slug:
gallery-for-ultimate-member
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.1.

Gou Manage My Account Menu – User Roles

Plugin Slug:
gou-wc-account-tabs
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.9.

ICDSoft Reseller Store

Plugin Slug:
icdsoft-reseller-store
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.0.

Ksher

Plugin:
Ksher
Plugin Slug:
ksher-payment
Installations
100+
Vulnerability:
Settings Change
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Media Downloader

Plugin Slug:
media-downloader
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.4.7.5.

Invoice Payment for WooCommerce

Plugin Slug:
invoice-payment-for-woocommerce
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

Seraphinite Bulk Discounts for WooCommerce

Plugin Slug:
seraphinite-discount-for-woocommerce
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

Hurrakify

Plugin:
Hurrakify
Plugin Slug:
hurrakify
Installations
80+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
8.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.0.1.

SMS for WooCommerce

Plugin Slug:
wc-sms
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.1.

LabelGrid Tools

Plugin Slug:
label-grid-tools
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.59
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.59.

Simple Payment

Plugin Slug:
simple-payment
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.8.

CarDealerPress

Plugin Slug:
cardealerpress
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.2411.00
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.7.2411.00.

CE21 Suite

Plugin:
CE21 Suite
Plugin Slug:
ce21-suite
Installations
30+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.1.

EduAdmin Booking

Plugin Slug:
eduadmin-booking
Installations
30+
Vulnerability:
Local File Inclusion
Patched in Version:
5.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.0.

Hack-Info

Plugin:
Hack-Info
Plugin Slug:
hack-info
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.18.

FloristPress – Customize your Woo store for your Florist

Plugin Slug:
bakkbone-florist-companion
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.0.
Plugin Slug:
clevernode-related-content
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.6.

Connect Contact Form 7 to Constant Contact V3

Plugin Slug:
connect-contact-form-7-to-constant-contact-v3
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Fancy Roller Scroller

Plugin Slug:
fancy-roller-scroller
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.1.

I Plant A Tree

Plugin Slug:
i-plant-a-tree
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

ImmoToolBox Connect

Plugin Slug:
immotoolbox-connect
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.0.

Simple Presenter

Plugin Slug:
simple-presenter
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.2.

SMSify

Plugin:
SMSify
Plugin Slug:
smsify
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.0.

UNIVERSAM

Plugin:
UNIVERSAM
Plugin Slug:
universam-demo
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.59
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.59.

WP Currency Exchange Rates

Plugin Slug:
wp-currency-exchange-rates
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

WP Quick Shop

Plugin Slug:
wp-quick-shop
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.2.

DX Dark Site

Plugin Slug:
devrix-dark-site
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

FooGallery Premium

Plugin:
FooGallery Premium
Plugin Slug:
foogallery-premium
Vulnerability:
Directory Traversal
Patched in Version:
2.4.27
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.27.

GeoFlickr

Plugin:
GeoFlickr
Plugin Slug:
geoflickr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Hello Event Widgets For Elementor

Plugin Slug:
hello-event-widgets-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

WP SuperBackup

Plugin:
WP SuperBackup
Plugin Slug:
indeed-wp-superbackup
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.

Kundgenerator

Plugin:
Kundgenerator
Plugin Slug:
kundgenerator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

Quran Phrases About Most People Shortcodes

Plugin Slug:
quran-phrases-about-most-people-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Responsive Google Maps | by imbaa

Plugin:
Responsive Google Maps | by imbaa
Plugin Slug:
responsive-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Termin-Kalender

Plugin:
Termin-Kalender
Plugin Slug:
termin-kalender
Vulnerability:
Broken Access Control
Patched in Version:
1.00.04
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.00.04.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Privilege Escalation
Patched in Version:
4.9.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.9.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.4.

WordPress Themes — 8 Patched / 2 Unpatched

Olivia

Theme:
Olivia
Theme Slug:
olivia
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zerif Lite

Theme:
Zerif Lite
Theme Slug:
zerif-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Barter

Theme:
Barter
Theme Slug:
barter
Downloads
7,610
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Bicycleshop

Theme Slug:
bicycleshop
Downloads
9,127
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

Brand

Theme:
Brand
Theme Slug:
brand
Downloads
32,921
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

hmd

Theme:
hmd
Theme Slug:
hmd
Downloads
892
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Plain Post

Theme Slug:
plain-post
Downloads
1,459
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.11.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.11.11.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Broken Authentication
Patched in Version:
5.4.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.15.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Arbitrary Code Execution
Patched in Version:
8.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.0.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security