WordPress Vulnerability Report — January 17, 2024
In this report, 77 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins are available now, so run those updates as soon as possible. If you're a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

In this report, 77 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
Free Online Training Event! Register Now!

January 24, 2024 @ 1:00 PM – 2:00 PM (CST)
Not all WordPress threats and vulnerabilities are “created equal.” Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.
This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.
Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.
WordPress Core
WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.
WordPress Plugins — 61 Patched / 16 Unpatched
Seraphinite Accelerator
- Plugin:
- Seraphinite Accelerator
- Plugin Slug:
- seraphinite-accelerator
- Installations
- 20,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-22138
WordPress Manutenção
- Plugin:
- WordPress Manutenção
- Plugin Slug:
- wp-manutencao
- Installations
- 10,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- No Fix
- Severity Score:
- Low
- CVE:
- 2024-22139
Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder
- Plugin Slug:
- droit-elementor-addons
- Installations
- 8,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-22136
Constant Contact Forms by MailMunch
- Plugin Slug:
- constant-contact-forms-by-mailmunch
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-22137
Revolut Gateway for WooCommerce
- Plugin:
- Revolut Gateway for WooCommerce
- Plugin Slug:
- revolut-gateway-for-woocommerce
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-52224
Shortcodes Finder
- Plugin:
- Shortcodes Finder
- Plugin Slug:
- shortcodes-finder
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-21750
Word Replacer Pro
- Plugin:
- Word Replacer Pro
- Plugin Slug:
- word-replacer-ultra
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-52229
Beds24 Online Booking
- Plugin:
- Beds24 Online Booking
- Plugin Slug:
- beds24-online-booking
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-52228
Advanced Flamingo
- Plugin:
- Advanced Flamingo
- Plugin Slug:
- advanced-flamingo
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-52226
CformsII
- Plugin:
- CformsII
- Plugin Slug:
- cforms2
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-22149
Contact Form 7 Extension For Mailchimp
- Plugin:
- Contact Form 7 Extension For Mailchimp
- Plugin Slug:
- contact-form-7-mailchimp-extension
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-22134
Easy SVG Allow
- Plugin:
- Easy SVG Allow
- Plugin Slug:
- easy-svg-image-allow
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-7089
Voting Record
- Plugin:
- Voting Record
- Plugin Slug:
- voting-record
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-7083
Voting Record
- Plugin:
- Voting Record
- Plugin Slug:
- voting-record
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-7084
WP Smart Editor
- Plugin:
- WP Smart Editor
- Plugin Slug:
- wp-smart-editor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-22148
WP Social Bookmark Menu
- Plugin:
- WP Social Bookmark Menu
- Plugin Slug:
- wp-social-bookmark-menu
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-7074
ElementsKit Elementor addons
- Plugin:
- ElementsKit Elementor addons
- Plugin Slug:
- elementskit-lite
- Installations
- 1,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.0.4
- Severity Score:
- Medium
- CVE:
- 2023-6582
Hostinger
WPS Hide Login
- Plugin:
- WPS Hide Login
- Plugin Slug:
- wps-hide-login
- Installations
- 1,000,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.9.12
- Severity Score:
- Low
- CVE:
- 2023-49748
The Events Calendar
- Plugin:
- The Events Calendar
- Plugin Slug:
- the-events-calendar
- Installations
- 700,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 6.2.9
- Severity Score:
- Medium
- CVE:
- 2023-6557
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
- Plugin Slug:
- wp-maintenance-mode
- Installations
- 700,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.9
- Severity Score:
- Medium
- CVE:
- 2023-7019
Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
- Plugin:
- Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
- Plugin Slug:
- formidable
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.7.1
- Severity Score:
- Medium
- CVE:
- 2023-6842
Metform Elementor Contact Form Builder
- Plugin Slug:
- metform
- Installations
- 300,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.8.2
- Severity Score:
- Medium
- CVE:
- 2023-6788
POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications
- Plugin Slug:
- post-smtp
- Installations
- 300,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.8.8
- Severity Score:
- Critical
- CVE:
- 2023-6875
PDF Invoices & Packing Slips for WooCommerce
- Plugin Slug:
- woocommerce-pdf-invoices-packing-slips
- Installations
- 300,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.7.6
- Severity Score:
- High
- CVE:
- 2024-22147
Orbit Fox by ThemeIsle
- Plugin:
- Orbit Fox by ThemeIsle
- Plugin Slug:
- themeisle-companion
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.10.28
- Severity Score:
- Medium
- CVE:
- 2024-0508
Orbit Fox by ThemeIsle
- Plugin:
- Orbit Fox by ThemeIsle
- Plugin Slug:
- themeisle-companion
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.10.27
- Severity Score:
- Medium
- CVE:
- 2023-6781
Contact Form 7 – Dynamic Text Extension
- Plugin Slug:
- contact-form-7-dynamic-text-extension
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.2.0
- Severity Score:
- Medium
- CVE:
- 2023-6630
Download Monitor
- Plugin:
- Download Monitor
- Plugin Slug:
- download-monitor
- Installations
- 100,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.9.5
- Severity Score:
- High
Gallery Plugin for WordPress – Envira Photo Gallery
- Plugin Slug:
- envira-gallery-lite
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.7.3
- Severity Score:
- Medium
- CVE:
- 2023-6742
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
- Plugin Slug:
- essential-blocks
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.4.7
- Severity Score:
- Medium
- CVE:
- 2023-7071
List category posts
- Plugin:
- List category posts
- Plugin Slug:
- list-category-posts
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.89.4
- Severity Score:
- Medium
- CVE:
- 2023-6994
Schema & Structured Data for WP & AMP
- Plugin Slug:
- schema-and-structured-data-for-wp
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.26
- Severity Score:
- Medium
- CVE:
- 2024-22146
Plugin for Google Reviews
- Plugin:
- Plugin for Google Reviews
- Plugin Slug:
- widget-google-reviews
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2
- Severity Score:
- Medium
- CVE:
- 2023-6884
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
- Plugin Slug:
- paid-memberships-pro
- Installations
- 90,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.12.7
- Severity Score:
- Medium
Email Encoder – Protect Email Addresses and Phone Numbers
- Plugin Slug:
- email-encoder-bundle
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.10
- Severity Score:
- Medium
- CVE:
- 2023-7070
Advanced Woo Search
- Plugin:
- Advanced Woo Search
- Plugin Slug:
- advanced-woo-search
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.97
- Severity Score:
- High
- CVE:
- 2024-0251
Customer Reviews for WooCommerce
- Plugin:
- Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations
- 60,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 5.38.10
- Severity Score:
- Critical
- CVE:
- 2023-6979
AI Engine: Chatbots, Generators, Assistants, GPT 4 and more!
- Plugin Slug:
- ai-engine
- Installations
- 50,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.9.99
- Severity Score:
- Critical
- CVE:
- 2023-51409
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
- Plugin:
- RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
- Plugin Slug:
- feedzy-rss-feeds
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.3.3
- Severity Score:
- Low
- CVE:
- 2023-6798
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
- Plugin:
- RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
- Plugin Slug:
- feedzy-rss-feeds
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3.3
- Severity Score:
- Medium
- CVE:
- 2023-6801
Order Export & Order Import for WooCommerce
- Plugin Slug:
- order-import-export-for-woocommerce
- Installations
- 50,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.4.4
- Severity Score:
- High
- CVE:
- 2024-22135
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Plugin Slug:
- profile-builder
- Installations
- 50,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.10.8
- Severity Score:
- Medium
- CVE:
- 2023-6504
OneClick Chat to Order
- Plugin:
- OneClick Chat to Order
- Plugin Slug:
- oneclick-whatsapp-order
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
Index Now
MailerLite – WooCommerce integration
- Plugin Slug:
- woo-mailerlite
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
- CVE:
- 2023-52227
MailerLite – WooCommerce integration
- Plugin Slug:
- woo-mailerlite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
- CVE:
- 2023-52223
Swift SMTP (formerly Welcome Email Editor)
- Plugin Slug:
- welcome-email-editor
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.0.7
- Severity Score:
- Medium
Woocommerce Vietnam Checkout
- Plugin:
- Woocommerce Vietnam Checkout
- Plugin Slug:
- woo-vietnam-checkout
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.8
- Severity Score:
- Medium
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc
- Plugin Slug:
- wp-sms
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.2
- Severity Score:
- Medium
Contact Form 7 Connector
- Plugin:
- Contact Form 7 Connector
- Plugin Slug:
- ari-cf7-connector
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.3
- Severity Score:
- Medium
EventON
EventON
EventON
RabbitLoader
- Plugin:
- RabbitLoader
- Plugin Slug:
- rabbit-loader
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.19.14
- Severity Score:
- Medium
- CVE:
- 2024-21751
WP Testimonials
- Plugin:
- WP Testimonials
- Plugin Slug:
- testimonial-widgets
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.4.4
- Severity Score:
- High
WP Spell Check
- Plugin:
- WP Spell Check
- Plugin Slug:
- wp-spell-check
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 9.18
- Severity Score:
- Medium
- CVE:
- 2024-22143
Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list
- Plugin Slug:
- export-woocommerce-customer-list
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
WordPress Live Chat Plugin for WooCommerce – LiveChat
- Plugin Slug:
- livechat-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.14
- Severity Score:
- Medium
WordPress Live Chat Plugin for WooCommerce – LiveChat
- Plugin Slug:
- livechat-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.2.17
- Severity Score:
- Medium
Football Pool
- Plugin:
- Football Pool
- Plugin Slug:
- football-pool
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.11.4
- Severity Score:
- Medium
GD Rating System
- Plugin:
- GD Rating System
- Plugin Slug:
- gd-rating-system
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.1
- Severity Score:
- Medium
InstaWP Connect – 1-click WP Staging & Migration
- Plugin Slug:
- instawp-connect
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 0.1.0.9
- Severity Score:
- High
- CVE:
- 2024-22145
TNC PDF viewer
- Plugin:
- TNC PDF viewer
- Plugin Slug:
- pdf-viewer-by-themencode
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.0
- Severity Score:
- Medium
Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce
- Plugin:
- Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 800+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.5.2
- Severity Score:
- Critical
- CVE:
- 2023-52221
Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce
- Plugin:
- Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 800+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.2
- Severity Score:
- Critical
- CVE:
- 2023-52215
WP Register Profile With Shortcode
- Plugin Slug:
- wp-register-profile-with-shortcode
- Installations
- 700+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.6.0
- Severity Score:
- High
- CVE:
- 2023-5448
Seraphinite Alternative Slugs Manager
- Plugin Slug:
- seraphinite-old-slugs-mgr
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.4
- Severity Score:
- Medium
Email Newsletter
- Plugin:
- Email Newsletter
- Plugin Slug:
- email-newsletter
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 8.0.7
- Severity Score:
- Medium
EventON Pro
- Plugin:
- EventON Pro
- Plugin Slug:
- eventon-wordpress-event-calendar-plugin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.5.5
- Severity Score:
- Medium
- CVE:
- 2023-6242
EventON Pro
- Plugin:
- EventON Pro
- Plugin Slug:
- eventon-wordpress-event-calendar-plugin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.5.5
- Severity Score:
- Medium
- CVE:
- 2023-6244
EventON Pro
- Plugin:
- EventON Pro
- Plugin Slug:
- eventon-wordpress-event-calendar-plugin
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.5.5
- Severity Score:
- Medium
- CVE:
- 2023-6158
MaxButtons
- Plugin:
- MaxButtons
- Plugin Slug:
- maxbutton
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.7.6
- Severity Score:
- Medium
- CVE:
- 2023-6594
Oxygen Builder
- Plugin:
- Oxygen Builder
- Plugin Slug:
- oxygenbuilder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.1
- Severity Score:
- Medium
- CVE:
- 2023-6938
Profile Builder Pro
- Plugin:
- Profile Builder Pro
- Plugin Slug:
- profile-builder-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.1
- Severity Score:
- High
- CVE:
- 2024-22142
Profile Builder Pro
- Plugin:
- Profile Builder Pro
- Plugin Slug:
- profile-builder-pro
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.10.1
- Severity Score:
- Medium
- CVE:
- 2024-22141
Profile Builder Pro
- Plugin:
- Profile Builder Pro
- Plugin Slug:
- profile-builder-pro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.10.1
- Severity Score:
- High
- CVE:
- 2024-22140
WordPress Themes — 0 Patched / 0 Unpatched
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed