WordPress Vulnerability Report

WordPress Vulnerability Report — January 17, 2024

In this report, 77 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins are available now, so run those updates as soon as possible. If you're a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Avatar photo
Sarah Ulmer

In this report, 77 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

Free Online Training Event! Register Now!

January 24, 2024 @ 1:00 PM – 2:00 PM (CST)

Not all WordPress threats and vulnerabilities are “created equal.” Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.

This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.

Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 61 Patched / 16 Unpatched

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Manutenção

Plugin Slug:
wp-manutencao
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact Forms by MailMunch

Plugin Slug:
constant-contact-forms-by-mailmunch
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Revolut Gateway for WooCommerce

Plugin Slug:
revolut-gateway-for-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Finder

Plugin Slug:
shortcodes-finder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Word Replacer Pro

Plugin Slug:
word-replacer-ultra
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Flamingo

Plugin Slug:
advanced-flamingo
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CformsII

Plugin:
CformsII
Plugin Slug:
cforms2
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Extension For Mailchimp

Plugin:
Contact Form 7 Extension For Mailchimp
Plugin Slug:
contact-form-7-mailchimp-extension
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy SVG Allow

Plugin:
Easy SVG Allow
Plugin Slug:
easy-svg-image-allow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Voting Record

Plugin:
Voting Record
Plugin Slug:
voting-record
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Voting Record

Plugin:
Voting Record
Plugin Slug:
voting-record
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Smart Editor

Plugin:
WP Smart Editor
Plugin Slug:
wp-smart-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Bookmark Menu

Plugin:
WP Social Bookmark Menu
Plugin Slug:
wp-social-bookmark-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

Hostinger

Plugin:
Hostinger
Plugin Slug:
hostinger
Installations
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.8.

WPS Hide Login

Plugin Slug:
wps-hide-login
Installations
1,000,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.12
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.9.12.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.9.

Metform Elementor Contact Form Builder

Plugin Slug:
metform
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.2.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
SQL Injection
Patched in Version:
3.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.6.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.28.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.27.

Contact Form 7 – Dynamic Text Extension

Plugin Slug:
contact-form-7-dynamic-text-extension
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Download Monitor

Plugin Slug:
download-monitor
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.
Plugin Slug:
envira-gallery-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.3.

List category posts

Plugin Slug:
list-category-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.89.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.89.4.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.

Plugin for Google Reviews

Plugin Slug:
widget-google-reviews
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.10.
Plugin Slug:
advanced-woo-search
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.97
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.97.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.38.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.38.10.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.4.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Index Now

Plugin:
Index Now
Plugin Slug:
mihdan-index-now
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.4.

MailerLite – WooCommerce integration

Plugin Slug:
woo-mailerlite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

MailerLite – WooCommerce integration

Plugin Slug:
woo-mailerlite
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Swift SMTP (formerly Welcome Email Editor)

Plugin Slug:
welcome-email-editor
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.7.

Woocommerce Vietnam Checkout

Plugin Slug:
woo-vietnam-checkout
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

RabbitLoader

Plugin Slug:
rabbit-loader
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.19.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.19.14.

WP Testimonials

Plugin Slug:
testimonial-widgets
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

WP Spell Check

Plugin Slug:
wp-spell-check
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.18.

WordPress Live Chat Plugin for WooCommerce – LiveChat

Plugin Slug:
livechat-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.14.

WordPress Live Chat Plugin for WooCommerce – LiveChat

Plugin Slug:
livechat-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.17.

Football Pool

Plugin Slug:
football-pool
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.4.

GD Rating System

Plugin Slug:
gd-rating-system
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
0.1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.9.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

WP Register Profile With Shortcode

Plugin Slug:
wp-register-profile-with-shortcode
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.0.

Seraphinite Alternative Slugs Manager

Plugin Slug:
seraphinite-old-slugs-mgr
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Email Newsletter

Plugin:
Email Newsletter
Plugin Slug:
email-newsletter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.0.7.

EventON Pro

Plugin:
EventON Pro
Plugin Slug:
eventon-wordpress-event-calendar-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

EventON Pro

Plugin:
EventON Pro
Plugin Slug:
eventon-wordpress-event-calendar-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

EventON Pro

Plugin:
EventON Pro
Plugin Slug:
eventon-wordpress-event-calendar-plugin
Vulnerability:
Broken Access Control
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

MaxButtons

Plugin:
MaxButtons
Plugin Slug:
maxbutton
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.6.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygenbuilder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Profile Builder Pro

Plugin:
Profile Builder Pro
Plugin Slug:
profile-builder-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.1.

Profile Builder Pro

Plugin:
Profile Builder Pro
Plugin Slug:
profile-builder-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.1.

Profile Builder Pro

Plugin:
Profile Builder Pro
Plugin Slug:
profile-builder-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.10.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.1.

WordPress Themes — 0 Patched / 0 Unpatched

No new theme vulnerabilities were disclosed this week.