WordPress Vulnerability Report

WordPress Vulnerability Report — January 29, 2025

This last week, 234 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 44 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 234 vulnerabilities have been publicly disclosed. Security patches for 190 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 44 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 183 Patched / 42 Unpatched

Product Size Charts Plugin for WooCommerce

Plugin Slug:
woo-advanced-product-size-chart
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scroll Styler

Plugin Slug:
scroll-styler
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Designer – Elementor Addons

Plugin Slug:
designer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
internal-link-builder
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Estatebud – Properties & Listings

Plugin Slug:
estatebud-properties-listings
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Linear

Plugin:
Linear
Plugin Slug:
linear
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

1003 Mortgage Application

Plugin:
1003 Mortgage Application
Plugin Slug:
1003-mortgage-application
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:
ABC Notation
Plugin Slug:
abc-notation
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:
Altra Side Menu
Plugin Slug:
altra-side-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:
Altra Side Menu
Plugin Slug:
altra-side-menu
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AnyRoad

Plugin:
AnyRoad
Plugin Slug:
anyguide
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ask Me Anything (Anonymously)

Plugin:
Ask Me Anything (Anonymously)
Plugin Slug:
ask-me-anything-anonymously
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Automate Hub

Plugin:
Automate Hub
Plugin Slug:
automate-hub-free-by-sperse-io
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Automate Hub

Plugin:
Automate Hub
Plugin Slug:
automate-hub-free-by-sperse-io
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BMLT Meeting Map

Plugin:
BMLT Meeting Map
Plugin Slug:
bmlt-meeting-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

brodos.net Onlineshop Plugin

Plugin:
brodos.net Onlineshop Plugin
Plugin Slug:
brodos-net-onlineshop
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Connections

Plugin:
Connections
Plugin Slug:
connections1
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dental Optimizer Patient Generator App

Plugin:
Dental Optimizer Patient Generator App
Plugin Slug:
dental-optimizer-patient-generator-app
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:
Dyn Business Panel
Plugin Slug:
dyn-business-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:
Dyn Business Panel
Plugin Slug:
dyn-business-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Real Estate

Plugin:
Easy Real Estate
Plugin Slug:
easy-real-estate
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Etsy Importer

Plugin:
Etsy Importer
Plugin Slug:
etsy-importer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fare Calculator

Plugin:
Fare Calculator
Plugin Slug:
fare-calculator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FlashCounter

Plugin:
FlashCounter
Plugin Slug:
flashcounter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Title (TypeWriter)

Plugin:
Post Title (TypeWriter)
Plugin Slug:
flashnews-typewriter-pearlbells
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Full Circle

Plugin:
Full Circle
Plugin Slug:
full-circle
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Issuu Panel

Plugin:
Issuu Panel
Plugin Slug:
issuu-panel
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Masy Gallery
Plugin Slug:
masy-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NOTICE BOARD BY TOWKIR

Plugin:
NOTICE BOARD BY TOWKIR
Plugin Slug:
notice-board-by-towkir
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress SEO Friendly Accordion FAQ

Plugin:
WordPress SEO Friendly Accordion FAQ
Plugin Slug:
notice-faq
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel Slider

Plugin:
Post Carousel Slider
Plugin Slug:
post-carousel-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Power Ups for Elementor

Plugin:
Power Ups for Elementor
Plugin Slug:
power-ups-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PPO Call To Actions

Plugin:
PPO Call To Actions
Plugin Slug:
ppo-call-to-actions
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SEO Blogger to WordPress Migration using 301 Redirection

Plugin:
SEO Blogger to WordPress Migration using 301 Redirection
Plugin Slug:
seo-blogger-to-wordpress-301-redirector
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons for WordPress

Plugin:
Social Share Buttons for WordPress
Plugin Slug:
share-buttons
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form7 Email Spam Blocker

Plugin:
WP Contact Form7 Email Spam Blocker
Plugin Slug:
wp-contact-form7-email-spam-blocker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:
WP Triggers Lite
Plugin Slug:
wp-triggers-lite
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:
WP Triggers Lite
Plugin Slug:
wp-triggers-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.1.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.0.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.41.

Call Now Button – The #1 Click to Call Button for WordPress

Plugin Slug:
call-now-button
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.14.

Post Duplicator

Plugin Slug:
post-duplicator
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.36.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.3.

Stackable – Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.13.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.12.

String locator

Plugin Slug:
string-locator
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.7.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.5.1.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Open Redirection
Patched in Version:
4.2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.2.

List category posts

Plugin Slug:
list-category-posts
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.90.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.90.3.

Nested Pages

Plugin Slug:
wp-nested-pages
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.10.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.27.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.13.

Better Find and Replace

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.

WP-Polls

Plugin:
WP-Polls
Plugin Slug:
wp-polls
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
2.77.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.77.3.
Plugin Slug:
wow-carousel-for-divi-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.

IP2Location Country Blocker

Plugin Slug:
ip2location-country-blocker
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.38.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.38.4.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Simple Download Monitor

Plugin Slug:
simple-download-monitor
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.26.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

PPOM – Product Addons & Custom Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
33.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 33.0.9.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.53.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.5.

AI Power: Complete AI Pack

Plugin Slug:
gpt3-ai-content-generator
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.97.

AI Power: Complete AI Pack

Plugin Slug:
gpt3-ai-content-generator
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.8.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.97.

AI Power: Complete AI Pack

Plugin Slug:
gpt3-ai-content-generator
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.8.97
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.97.

AI Chatbot for WordPress – Hyve Lite

Plugin Slug:
hyve-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

JSM Show Post Metadata

Plugin Slug:
jsm-show-post-meta
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.1.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.7.3.

Modal Window – create popup modal window

Plugin Slug:
modal-window
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.5.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.14.
Plugin Slug:
seo-automated-link-building
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.0.

Countdown Timer – Widget Countdown

Plugin Slug:
widget-countdown
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.

Essential Real Estate

Plugin Slug:
essential-real-estate
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.9.

Sticky Buttons – floating buttons builder

Plugin Slug:
sticky-buttons
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.2.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.3.
Plugin Slug:
woo-product-carousel-slider-and-grid-ultimate
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.1.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Xagio SEO

Plugin:
Xagio SEO
Plugin Slug:
xagio-seo
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.0.21.

Side Menu Lite – add sticky fixed buttons

Plugin Slug:
side-menu-lite
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.2.

Themify Builder

Plugin Slug:
themify-builder
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.7.

Button Generator – easily Button Builder

Plugin Slug:
button-generation
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Variation Swatches for WooCommerce

Plugin Slug:
th-variation-swatches
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Custom Product Tabs Lite for WooCommerce

Plugin Slug:
woocommerce-custom-product-tabs-lite
Installations
5,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

Popup Box: Create Popups Easily

Plugin Slug:
popup-box
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

RSVP and Event Management

Plugin Slug:
rsvp
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
2.7.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.15.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.7.

XML for Google Merchant Center

Plugin Slug:
xml-for-google-merchant-center
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.12.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.12.

Multiple Page Generator Plugin – MPG

Plugin Slug:
multiple-pages-generator-by-porthas
Installations
3,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.6.

Patreon WordPress

Plugin Slug:
patreon-connect
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
4.4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.12.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Auction Nudge – Your eBay on Your Site

Plugin Slug:
auction-nudge
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

Chained Quiz

Plugin Slug:
chained-quiz
Installations
2,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Email Subscription Popup

Plugin Slug:
email-subscribe
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
= 1.2.24
Severity Score:
High
The vulnerability has been patched, so you should update to version = 1.2.24.

Plethora Plugins Tabs + Accordions

Plugin Slug:
plethora-tabs-accordions
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Plethora Plugins Tabs + Accordions

Plugin Slug:
plethora-tabs-accordions
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Comment Edit Core – Simple Comment Editing

Plugin Slug:
simple-comment-editing
Installations
2,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Product Table by WBW

Plugin Slug:
woo-product-tables
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.3.

WooCommerce Quick View

Plugin Slug:
woo-quick-view
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.4.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.13.

Event post

Plugin:
Event post
Plugin Slug:
event-post
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.8.

Flexmls® IDX Plugin

Plugin Slug:
flexmls-idx
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.27.
Plugin Slug:
fulltext-search
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.79.262
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.79.262.
Plugin Slug:
fulltext-search
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.79.262
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.79.262.
Plugin Slug:
ninja-gdpr-compliance
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

GoHero Store Customizer for WooCommerce

Plugin Slug:
personalize-woocommerce-cart-page
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.4.1.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
0.21.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.21.13.

Tamara Checkout

Plugin Slug:
tamara-checkout
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.1.

Toocheke Companion

Plugin Slug:
toocheke-companion
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.167
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.167.
Plugin Slug:
woocommerce-cloak-affiliate-links
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.36.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.7.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations
800+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.16.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.16.6.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations
800+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
3.16.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.16.6.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.56
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.56.
Plugin Slug:
easy-youtube-gallery
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

FireCask Like & Share Button

Plugin Slug:
facebook-like-send-button
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Wishlist for WooCommerce

Plugin Slug:
wt-woocommerce-wishlist
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Create with Code

Plugin Slug:
create-with-code
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.60.

Ketchup Shortcodes

Plugin Slug:
ketchup-shortcodes-pack
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.1.

Listamester

Plugin Slug:
listamester
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

WP Multi Store Locator

Plugin Slug:
wp-multi-store-locator
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.1.

Form Builder CP

Plugin Slug:
cp-easy-form-builder
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
1.2.42
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.42.

MachForm Shortcode

Plugin Slug:
machform-shortcode
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

SERPed.net

Plugin:
SERPed.net
Plugin Slug:
serped-net
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.

aDirectory – WordPress Directory Listing Plugin

Plugin Slug:
adirectory
Installations
300+
Vulnerability:
PHP Object Injection
Patched in Version:
1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.

All Embed – Elementor Addons

Plugin Slug:
all-embed-addons-for-elementor
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin Slug:
attire-blocks
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.7.

RSVPMaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
11.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.4.6.

Build Private Store For Woocommerce

Plugin Slug:
build-private-store-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
1..1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1..1.

WP Duplicate – WordPress Migration Plugin

Plugin Slug:
local-sync
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Magic the Gathering Card Tooltips

Plugin Slug:
magic-the-gathering-card-tooltips
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

ShMapper by Teplitsa

Plugin Slug:
shmapper-by-teplitsa
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Taxonomy/Term and Role based Discounts for WooCommerce

Plugin Slug:
taxonomy-discounts-woocommerce
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.

Advanced Notifications

Plugin Slug:
advanced-notifications
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Blur Text

Plugin:
Blur Text
Plugin Slug:
blur-text
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.4.

Bug Library

Plugin Slug:
bug-library
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.

Linet ERP-Woocommerce Integration Plugin

Plugin Slug:
linet-erp-woocommerce-integration
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.8.

Morkva UA Shipping

Plugin Slug:
morkva-ua-shipping
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.20.

Orbisius Simple Notice

Plugin Slug:
orbisius-simple-notice
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

People Lists

Plugin Slug:
people-lists
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Precious Metals Charts and Widgets for WordPress

Plugin Slug:
precious-metals-chart-and-widgets
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

Roi Calculator

Plugin Slug:
roi-calculator
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.

Show/Hide Shortcode

Plugin Slug:
showhide-shortcode
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Simple Downloads List

Plugin Slug:
simple-downloads-list
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

FV Thoughtful Comments

Plugin Slug:
thoughtful-comments
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
0.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.6.

WP-BibTeX

Plugin:
WP-BibTeX
Plugin Slug:
wp-bibtex
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.2.

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Restrict Anonymous Access

Plugin Slug:
restrict-anonymous-access
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
80+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.6.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.10.
Plugin Slug:
simple-gallery-with-filter
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Bilingual Linker

Plugin Slug:
bilingual-linker
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Cliptakes

Plugin:
Cliptakes
Plugin Slug:
cliptakes
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

FAQ Builder AYS

Plugin Slug:
faq-builder-ays
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Radius Blocks – WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

wp-greet

Plugin:
wp-greet
Plugin Slug:
wp-greet
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.

Boom Fest

Plugin:
Boom Fest
Plugin Slug:
boom-fest
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
caching-compatible-cookie-optin-and-javascript
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.0.11.

Subscription DNA®

Plugin Slug:
subscriptiondna
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

KBucket: Your Curated Content in WordPress

Plugin Slug:
kbucket
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.2.

ReviewsTap

Plugin:
ReviewsTap
Plugin Slug:
reviewstap
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

Admin and Site Enhancements (ASE) Pro

Plugin:
Admin and Site Enhancements (ASE) Pro
Plugin Slug:
admin-site-enhancements-pro
Vulnerability:
Broken Access Control
Patched in Version:
7.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.3.

BMLT Meeting Map

Plugin:
BMLT Meeting Map
Plugin Slug:
bmlt-meeting-map
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

Bridge Core

Plugin:
Bridge Core
Plugin Slug:
bridge-core
Vulnerability:
Broken Access Control
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.12.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

Oshine Modules

Plugin:
Oshine Modules
Plugin Slug:
oshine-modules
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.8.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Broken Access Control
Patched in Version:
4.20.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.20.0.3.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Local File Inclusion
Patched in Version:
2.34.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.34.0.

VideoWhisper Live Streaming Integration

Plugin:
VideoWhisper Live Streaming Integration
Plugin Slug:
videowhisper-live-streaming-integration
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.10.

WPBot Pro WordPress Chatbot

Plugin:
WPBot Pro WordPress Chatbot
Plugin Slug:
wpbot-pro
Vulnerability:
Broken Access Control
Patched in Version:
13.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.5.6.

WPBot Pro WordPress Chatbot

Plugin:
WPBot Pro WordPress Chatbot
Plugin Slug:
wpbot-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
13.5.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 13.5.6.

WPJobBoard

Plugin:
WPJobBoard
Plugin Slug:
wpjobboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.11.1.

WordPress Themes — 7 Patched / 2 Unpatched

Bootstrap Ultimate

Theme:
Bootstrap Ultimate
Theme Slug:
bootstrap-ultimate
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

RealHomes

Theme:
RealHomes
Theme Slug:
realhomes
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

AdForest

Theme:
AdForest
Theme Slug:
adforest
Vulnerability:
Broken Authentication
Patched in Version:
5.1.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.9.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Broken Access Control
Patched in Version:
7.11.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.11.11.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
27.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 27.6.2.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Broken Access Control
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Broken Access Control
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

uDesign

Theme:
uDesign
Theme Slug:
udesign
Vulnerability:
Broken Access Control
Patched in Version:
4.11.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.11.3.

Zox News

Theme:
Zox News
Theme Slug:
zox-news
Vulnerability:
Broken Access Control
Patched in Version:
3.17.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.17.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security