Between last Monday (October 2) and Monday this week (October 9), 101 new vulnerabilities were publicly disclosed.1 They may affect nearly two million WordPress sites. There are 42 plugin vulnerabilities with security patches, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 59 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
- This report comes out on Wednesdays and covers the last seven days of public disclosures in the Patchstack vulnerability database from the previous to the current Monday. It excludes any vulnerabilities added to the database in the last 48 hours. However, that up-to-the-minute vulnerability data powers Solid Security Pro. Solid Security Pro automatically protects WordPress sites from active exploits aimed at unpatched vulnerabilities. ↩︎
WordPress Core Vulnerabilities
WordPress Plugin Vulnerabilities (59 Unpatched / 42 Patched)
Contact Form builder with drag & drop for WordPress – Kali Forms
- Plugin Slug:
- kali-forms
- Installations:
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45275
Contact Form by Supsystic
- Plugin:
- Contact Form by Supsystic
- Plugin Slug:
- contact-form-by-supsystic
- Installations:
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45068
Video Gallery – Best WordPress YouTube Gallery Plugin
- Plugin Slug:
- gallery-videos
- Installations:
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45069
WP Custom Widget area
- Plugin:
- WP Custom Widget area
- Plugin Slug:
- wp-custom-widget-area
- Installations:
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45045
Export All Posts, Products, Orders, Refunds & Users
- Plugin Slug:
- wp-ultimate-exporter
- Installations:
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-2487
WP Power Stats
- Plugin:
- WP Power Stats
- Plugin Slug:
- wp-power-stats
- Installations:
- 9,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45011
Simple SEO
- Plugin:
- Simple SEO
- Plugin Slug:
- cds-simple-seo
- Installations:
- 8,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45269
WP Forms Puzzle Captcha
- Plugin:
- WP Forms Puzzle Captcha
- Plugin Slug:
- wp-forms-puzzle-captcha
- Installations:
- 7,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44997
Post View Count
- Plugin:
- Post View Count
- Plugin Slug:
- wp-simple-post-view
- Installations:
- 6,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44996
Pinpoint Booking System – #1 WordPress Booking Plugin
- Plugin Slug:
- booking-system
- Installations:
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45270
Complete Open Graph
- Plugin:
- Complete Open Graph
- Plugin Slug:
- complete-open-graph
- Installations:
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45010
AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One
- Plugin:
- AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One
- Plugin Slug:
- ai-content-writing-assistant
- Installations:
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45063
Sp*tify Play Button for WordPress
- Plugin Slug:
- spotify-play-button-for-wordpress
- Installations:
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-41131
Permalinks Customizer
- Plugin:
- Permalinks Customizer
- Plugin Slug:
- permalinks-customizer
- Installations:
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45103
Urvanov Syntax Highlighter
- Plugin:
- Urvanov Syntax Highlighter
- Plugin Slug:
- urvanov-syntax-highlighter
- Installations:
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45106
WooCommerce Login Redirect
- Plugin:
- WooCommerce Login Redirect
- Plugin Slug:
- woo-login-redirect
- Installations:
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44995
GoodBarber
- Plugin:
- GoodBarber
- Plugin Slug:
- goodbarber
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45107
Gumroad
- Plugin:
- Gumroad
- Plugin Slug:
- gumroad
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45059
ShortCodes UI
- Plugin:
- ShortCodes UI
- Plugin Slug:
- shortcodes-ui
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44994
Short URL
- Plugin:
- Short URL
- Plugin Slug:
- shorten-url
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45058
Social Feed | Custom Feed for Social Media Networks
- Plugin Slug:
- wp-social-feed
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45003
Blog Manager Light
- Plugin:
- Blog Manager Light
- Plugin Slug:
- blog-manager-light
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45102
WooODT Lite – WooCommerce Order Delivery or Pickup with Date Time Location
- Plugin Slug:
- byconsole-woo-order-delivery-time
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45006
canvasio3D Light
- Plugin:
- canvasio3D Light
- Plugin Slug:
- canvasio3d-light
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45062
Contact Form Generator : Creative form builder for WordPress
- Plugin Slug:
- contact-form-generator
- Installations:
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-35911
Copy or Move Comments
- Plugin:
- Copy or Move Comments
- Plugin Slug:
- copy-or-move-comments
- Installations:
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-28748
Ebook Store
- Plugin:
- Ebook Store
- Plugin Slug:
- ebook-store
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45602
Hitsteps Web Analytics
- Plugin:
- Hitsteps Web Analytics
- Plugin Slug:
- hitsteps-visitor-manager
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45268
Hitsteps Web Analytics
- Plugin:
- Hitsteps Web Analytics
- Plugin Slug:
- hitsteps-visitor-manager
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45057
Interactive World Map
- Plugin:
- Interactive World Map
- Plugin Slug:
- interactive-world-map
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45060
LeadSquared Suite
- Plugin:
- LeadSquared Suite
- Plugin Slug:
- leadsquared-suite
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45047
Mailrelay
- Plugin:
- Mailrelay
- Plugin Slug:
- mailrelay
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45108
OPcache Dashboard
- Plugin:
- OPcache Dashboard
- Plugin Slug:
- opcache
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45064
Order auto complete for WooCommerce
- Plugin Slug:
- order-auto-complete-for-woocommerce
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45072
SendPulse Free Web Push
- Plugin:
- SendPulse Free Web Push
- Plugin Slug:
- sendpulse-web-push
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45274
Social proof testimonials and reviews by Repuso
- Plugin Slug:
- social-testimonials-and-reviews-widget
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45048
Timely Booking Button
- Plugin:
- Timely Booking Button
- Plugin Slug:
- timely-booking-button
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44987
WhitePage
- Plugin:
- WhitePage
- Plugin Slug:
- white-page-publication
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45109
IRivYou – Add reviews from AliExpress and Amazon to woocommerce
- Plugin Slug:
- wooreviews-importer
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45267
Sharkdropship for AliExpress Dropship and Affiliate
- Plugin Slug:
- wooshark-aliexpress-importer
- Installations:
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-30870
WordPress Simple HTML Sitemap
- Plugin Slug:
- wp-simple-html-sitemap
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45067
Image vertical reel scroll slideshow
- Plugin Slug:
- image-vertical-reel-scroll-slideshow
- Installations:
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45051
Stout Google Calendar
- Plugin:
- Stout Google Calendar
- Plugin Slug:
- stout-google-calendar
- Installations:
- 800+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45273
Category Meta plugin
- Plugin:
- Category Meta plugin
- Plugin Slug:
- wp-category-meta
- Installations:
- 800+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-44998
User Location and IP
- Plugin:
- User Location and IP
- Plugin Slug:
- user-location-and-ip
- Installations:
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-31217
Fotomoto
- Plugin:
- Fotomoto
- Plugin Slug:
- fotomoto
- Installations:
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45007
Mendeley Plugin
- Plugin:
- Mendeley Plugin
- Plugin Slug:
- mendeleyplugin
- Installations:
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45073
Publish Confirm Message
- Plugin:
- Publish Confirm Message
- Plugin Slug:
- publish-confirm-message
- Installations:
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-32124
AmpedSense – AdSense Split Tester
- Plugin Slug:
- ampedsense-adsense-split-tester
- Installations:
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-25476
Automated Editor
- Plugin:
- Automated Editor
- Plugin Slug:
- automated-editor
- Installations:
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45276
Dropshipping & Affiliation with Amazon
- Plugin:
- Dropshipping & Affiliation with Amazon
- Plugin Slug:
- wp-amazon-shop
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2023-31215
Woo Custom Emails
- Plugin:
- Woo Custom Emails
- Plugin Slug:
- woo-custom-emails
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45004
Slick Contact Forms
- Plugin:
- Slick Contact Forms
- Plugin Slug:
- slick-contact-forms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-5468
WP Responsive header image slide
- Plugin:
- WP Responsive header image slide
- Plugin Slug:
- responsive-header-image-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-5334
Product Category Tree
- Plugin:
- Product Category Tree
- Plugin Slug:
- product-category-tree
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-45054
Pressference Exporter
- Plugin:
- Pressference Exporter
- Plugin Slug:
- pressference-exporter
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-45046
Instagram for WordPress
- Plugin:
- Instagram for WordPress
- Plugin Slug:
- instagram-for-wordpress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-5357
Hotjar
- Plugin:
- Hotjar
- Plugin Slug:
- hotjar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-1259
Contact form Form For All
- Plugin:
- Contact form Form For All
- Plugin Slug:
- formforall
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-5337
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
- Plugin:
- POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
- Plugin Slug:
- post-smtp
- Installations:
- 300,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.6.1
- Severity Score:
- High
Redirection for Contact Form 7
- Plugin Slug:
- wpcf7-redirect
- Installations:
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.0
- Severity Score:
- High
- CVE:
- 2023-39920
WordPress Popular Posts
- Plugin:
- WordPress Popular Posts
- Plugin Slug:
- wordpress-popular-posts
- Installations:
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.3.3
- Severity Score:
- Medium
- CVE:
- 2023-45607
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
- Plugin Slug:
- wp-user-avatar
- Installations:
- 200,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.13.3
- Severity Score:
- High
- CVE:
- 2023-44150
Media Library Assistant
- Plugin:
- Media Library Assistant
- Plugin Slug:
- media-library-assistant
- Installations:
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.12
- Severity Score:
- Medium
- CVE:
- 2023-24385
Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations:
- 60,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.36.1
- Severity Score:
- Medium
- CVE:
- 2023-45101
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations:
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.19
- Severity Score:
- High
- CVE:
- 2023-45071
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations:
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.19
- Severity Score:
- High
- CVE:
- 2023-45070
Booster for WooCommerce
- Plugin:
- Booster for WooCommerce
- Plugin Slug:
- woocommerce-jetpack
- Installations:
- 60,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 7.1.2
- Severity Score:
- Medium
- CVE:
- 2023-40002
Abandoned Cart Lite for WooCommerce
- Plugin Slug:
- woocommerce-abandoned-cart
- Installations:
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.16.0
- Severity Score:
- Medium
- CVE:
- 2023-44986
WP Custom Admin Interface
- Plugin:
- WP Custom Admin Interface
- Plugin Slug:
- wp-custom-admin-interface
- Installations:
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.33
- Severity Score:
- Medium
- CVE:
- 2023-44988
WP Job Openings – Job Listing, Career Page and Recruitment Plugin
- Plugin Slug:
- wp-job-openings
- Installations:
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.2
- Severity Score:
- Medium
- CVE:
- 2023-45061
User Submitted Posts – Enable Users to Submit Posts from the Front End
- Plugin Slug:
- user-submitted-posts
- Installations:
- 20,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 20230914
- Severity Score:
- Critical
- CVE:
- 2023-45603
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin
- Plugin Slug:
- wp-user-frontend
- Installations:
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.9
- Severity Score:
- Medium
- CVE:
- 2023-45002
Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress
- Plugin Slug:
- advanced-page-visit-counter
- Installations:
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 8.0.1
- Severity Score:
- High
- CVE:
- 2023-45074
Bold Timeline Lite
- Plugin:
- Bold Timeline Lite
- Plugin Slug:
- bold-timeline-lite
- Installations:
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
- 2023-45110
10Web Map Builder for Google Maps
- Plugin Slug:
- wd-google-maps
- Installations:
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.74
- Severity Score:
- Medium
- CVE:
- 2023-45272
bbp style pack
- Plugin:
- bbp style pack
- Plugin Slug:
- bbp-style-pack
- Installations:
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.8
- Severity Score:
- Medium
- CVE:
- 2023-44984
Blog Filter – Advanced Post Filtering with Categories Or Tags, Post Portfolio Gallery, Blog Design Template, Post Layout
- Plugin Slug:
- blog-filter
- Installations:
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.4
- Severity Score:
- Medium
- CVE:
- 2023-5291
Podcast Subscribe Buttons
- Plugin:
- Podcast Subscribe Buttons
- Plugin Slug:
- podcast-subscribe-buttons
- Installations:
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.9
- Severity Score:
- Medium
- CVE:
- 2023-5308
Seriously Simple Stats
- Plugin:
- Seriously Simple Stats
- Plugin Slug:
- seriously-simple-stats
- Installations:
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2023-45001
Seriously Simple Stats
- Plugin:
- Seriously Simple Stats
- Plugin Slug:
- seriously-simple-stats
- Installations:
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.2
- Severity Score:
- High
- CVE:
- 2023-45005
WOLF – WordPress Posts Bulk Editor and Manager Professional
- Plugin Slug:
- bulk-editor
- Installations:
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7.2
- Severity Score:
- Medium
- CVE:
- 2023-44990
GEO my WordPress
- Plugin:
- GEO my WordPress
- Plugin Slug:
- geo-my-wp
- Installations:
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.1
- Severity Score:
- Medium
- CVE:
- 2023-5467
Connect to external APIs – WPGetAPI
- Plugin Slug:
- wpgetapi
- Installations:
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.2
- Severity Score:
- Medium
Captcha/Honeypot (CF7, Avada, Elementor, Comments, WPForms) – GDPR ready
- Plugin Slug:
- captcha-for-contact-form-7
- Installations:
- 4,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.11.4
- Severity Score:
- Medium
- CVE:
- 2023-45009
AI ChatBot
- Plugin:
- AI ChatBot
- Plugin Slug:
- chatbot
- Installations:
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.7.9
- Severity Score:
- Medium
- CVE:
- 2023-44993
MStore API
- Plugin:
- MStore API
- Plugin Slug:
- mstore-api
- Installations:
- 4,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.0.7
- Severity Score:
- High
- CVE:
- 2023-45055
Smart Cookie Kit
- Plugin:
- Smart Cookie Kit
- Plugin Slug:
- smart-cookie-kit
- Installations:
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.2
- Severity Score:
- Medium
- CVE:
- 2023-45608
ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks
- Plugin Slug:
- product-blocks
- Installations:
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.0
- Severity Score:
- Medium
- CVE:
- 2023-45271
WP Content Pilot – Autoblogging & Affiliate Marketing Plugin
- Plugin Slug:
- wp-content-pilot
- Installations:
- 3,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 1.3.4
- Severity Score:
- Medium
- CVE:
- 2023-45053
affiliate-toolkit – WordPress Affiliate Plugin
- Plugin Slug:
- affiliate-toolkit-starter
- Installations:
- 2,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 3.4.0
- Severity Score:
- Medium
- CVE:
- 2023-45105
Open User Map
- Plugin:
- Open User Map
- Plugin Slug:
- open-user-map
- Installations:
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.27
- Severity Score:
- Medium
- CVE:
- 2023-45056
Profile Extra Fields by BestWebSoft
- Plugin Slug:
- profile-extra-fields
- Installations:
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.8
- Severity Score:
- Medium
- CVE:
- 2023-4469
WP Bing Map Pro
- Plugin:
- WP Bing Map Pro
- Plugin Slug:
- api-bing-map-2018
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.0
- Severity Score:
- Medium
- CVE:
- 2023-45052
BuddyMeet
- Plugin:
- BuddyMeet
- Plugin Slug:
- buddymeet
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.0
- Severity Score:
- Medium
- CVE:
- 2023-44985
Bulk NoIndex & NoFollow Toolkit
- Plugin Slug:
- bulk-noindex-nofollow-toolkit-by-mad-fish
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2023-45065
Geo Controller
- Plugin:
- Geo Controller
- Plugin Slug:
- cf-geoplugin
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.3
- Severity Score:
- Medium
YouTube Playlist Player
- Plugin:
- YouTube Playlist Player
- Plugin Slug:
- youtube-playlist-player
- Installations:
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.8
- Severity Score:
- Medium
- CVE:
- 2023-45049
Comment Reply Email
- Plugin:
- Comment Reply Email
- Plugin Slug:
- comment-reply-email
- Installations:
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.4
- Severity Score:
- Medium
- CVE:
- 2023-45008
WP Mail SMTP Pro
- Plugin:
- WP Mail SMTP Pro
- Plugin Slug:
- wp-mail-smtp-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.8.1
- Severity Score:
- Medium
- CVE:
- 2023-3213
Optimize Database after Deleting Revisions
- Plugin:
- Optimize Database after Deleting Revisions
- Plugin Slug:
- rvg-optimize-database
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.1
- Severity Score:
- Medium
WordPress Theme Vulnerabilities
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
