WordPress Vulnerability Report — May 1, 2024
Since last week, 359 new vulnerabilities emerged in the WordPress ecosystem, including 28 in themes and 331 in plugins. 90 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 269 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 90 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.
The next major release will be version 6.6 planned for July 16, 2024.
WordPress Plugins — 248 Patched / 21 Unpatched
Auto Featured Image (Auto Post Thumbnail)
- Plugin Slug:
- auto-post-thumbnail
- Installations
- 70,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33629
FameTheme Demo Importer
- Plugin:
- FameTheme Demo Importer
- Plugin Slug:
- famethemes-demo-importer
- Installations
- 50,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33679
Piotnet Addons For Elementor
- Plugin:
- Piotnet Addons For Elementor
- Plugin Slug:
- piotnet-addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33630
AGCA – Custom Dashboard & Login Page
- Plugin Slug:
- ag-custom-admin
- Installations
- 30,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33627
Serious Slider
- Plugin:
- Serious Slider
- Plugin Slug:
- cryout-serious-slider
- Installations
- 30,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33650
Meks Smart Social Widget
- Plugin:
- Meks Smart Social Widget
- Plugin Slug:
- meks-smart-social-widget
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33693
Xserver Migrator
- Plugin:
- Xserver Migrator
- Plugin Slug:
- xserver-migrator
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33913
Annual Archive
- Plugin:
- Annual Archive
- Plugin Slug:
- anual-archive
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33598
rtMedia for WordPress, BuddyPress and bbPress
- Plugin Slug:
- buddypress-media
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
ClickCease Click Fraud Protection
- Plugin Slug:
- clickcease-click-fraud-protection
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33678
Democracy Poll
- Plugin:
- Democracy Poll
- Plugin Slug:
- democracy-poll
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33920
Login Logout Register Menu
- Plugin:
- Login Logout Register Menu
- Plugin Slug:
- login-logout-register-menu
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33932
Meks ThemeForest Smart Widget
- Plugin:
- Meks ThemeForest Smart Widget
- Plugin Slug:
- meks-themeforest-smart-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33694
Print-O-Matic
- Plugin:
- Print-O-Matic
- Plugin Slug:
- print-o-matic
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33936
Smart Recent Posts Widget
- Plugin:
- Smart Recent Posts Widget
- Plugin Slug:
- smart-recent-posts-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33692
CM Tooltip Glossary
- Plugin:
- CM Tooltip Glossary
- Plugin Slug:
- enhanced-tooltipglossary
- Installations
- 8,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4086
Customify Site Library
- Plugin:
- Customify Site Library
- Plugin Slug:
- customify-sites
- Installations
- 6,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33644
WordPress Ad Widget
- Plugin:
- WordPress Ad Widget
- Plugin Slug:
- ad-widget
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33696
PopupAlly
- Plugin:
- PopupAlly
- Plugin Slug:
- popupally
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33639
Pretty Google Calendar
- Plugin:
- Pretty Google Calendar
- Plugin Slug:
- pretty-google-calendar
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33640
Fan Page Widget by ThemeNcode
- Plugin:
- Fan Page Widget by ThemeNcode
- Plugin Slug:
- facebook-fan-page-widget
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33695
Filterable Portfolio
- Plugin:
- Filterable Portfolio
- Plugin Slug:
- filterable-portfolio
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4234
Share This Image
- Plugin:
- Share This Image
- Plugin Slug:
- share-this-image
- Installations
- 2,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33930
Smart Maintenance Mode
- Plugin:
- Smart Maintenance Mode
- Plugin Slug:
- smart-maintenance-mode
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33638
ENL Newsletter
- Plugin:
- ENL Newsletter
- Plugin Slug:
- enl-newsletter
- Installations
- 10+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-3060
ENL Newsletter
- Plugin:
- ENL Newsletter
- Plugin Slug:
- enl-newsletter
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3059
ENL Newsletter
- Plugin:
- ENL Newsletter
- Plugin Slug:
- enl-newsletter
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3058
Advanced Search
- Plugin:
- Advanced Search
- Plugin Slug:
- advance-search
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-3265
Advanced Most Recent Posts Mod
- Plugin:
- Advanced Most Recent Posts Mod
- Plugin Slug:
- advanced-most-recent-posts-mod
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33643
Advanced Post List
- Plugin:
- Advanced Post List
- Plugin Slug:
- advanced-post-list
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33642
AJAX Login and Registration modal popup + inline form
- Plugin:
- AJAX Login and Registration modal popup + inline form
- Plugin Slug:
- ajax-login-and-registration-modal-popup
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33918
Element Pack Pro
- Plugin:
- Element Pack Pro
- Plugin Slug:
- bdthemes-element-pack
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33568
CF7 File Download – File Download for CF7
- Plugin:
- CF7 File Download – File Download for CF7
- Plugin Slug:
- cf7-file-download
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33697
Client Dash
- Plugin:
- Client Dash
- Plugin Slug:
- client-dash
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33652
Contact Form 7 Extension For Mailchimp
- Plugin:
- Contact Form 7 Extension For Mailchimp
- Plugin Slug:
- contact-form-7-mailchimp-extension
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33677
CPO Companion
- Plugin:
- CPO Companion
- Plugin Slug:
- cpo-companion
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33916
Crelly Slider
- Plugin:
- Crelly Slider
- Plugin Slug:
- crelly-slider
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33542
Easy Set Favicon
- Plugin:
- Easy Set Favicon
- Plugin Slug:
- easy-set-favicon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33645
Embed Google Fonts
- Plugin:
- Embed Google Fonts
- Plugin Slug:
- embed-google-fonts
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33925
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33558
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33557
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33556
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33555
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33554
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33553
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33552
XStore Core
- Plugin:
- XStore Core
- Plugin Slug:
- et-core-plugin
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33551
Giphypress
- Plugin:
- Giphypress
- Plugin Slug:
- giphypress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33927
GWP-Histats
- Plugin:
- GWP-Histats
- Plugin Slug:
- gwp-histats
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33926
JW Player for WordPress
- Plugin:
- JW Player for WordPress
- Plugin Slug:
- jw-player-7-for-wp
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33931
MF Gig Calendar
- Plugin:
- MF Gig Calendar
- Plugin Slug:
- mf-gig-calendar
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33651
Mini Loops
- Plugin:
- Mini Loops
- Plugin Slug:
- mini-loops
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33934
Opal Widgets For Elementor
- Plugin:
- Opal Widgets For Elementor
- Plugin Slug:
- opal-widgets-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33649
CodeBard’s Patron Button and Widgets for Patreon
- Plugin:
- CodeBard’s Patron Button and Widgets for Patreon
- Plugin Slug:
- patron-button-and-widgets-by-codebard
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33928
PB MailCrypt
- Plugin:
- PB MailCrypt
- Plugin Slug:
- pb-mailcrypt-antispam-email-encryption
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33935
Piotnet Addons For Elementor Pro
- Plugin:
- Piotnet Addons For Elementor Pro
- Plugin Slug:
- piotnet-addons-for-elementor-pro
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33635
Piotnet Addons For Elementor Pro
- Plugin:
- Piotnet Addons For Elementor Pro
- Plugin Slug:
- piotnet-addons-for-elementor-pro
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33634
Piotnet Addons For Elementor Pro
- Plugin:
- Piotnet Addons For Elementor Pro
- Plugin Slug:
- piotnet-addons-for-elementor-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33633
Piotnet Addons For Elementor Pro
- Plugin:
- Piotnet Addons For Elementor Pro
- Plugin Slug:
- piotnet-addons-for-elementor-pro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33632
Piotnet Addons For Elementor Pro
- Plugin:
- Piotnet Addons For Elementor Pro
- Plugin Slug:
- piotnet-addons-for-elementor-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33631
Progressive WordPress (PWA)
- Plugin:
- Progressive WordPress (PWA)
- Plugin Slug:
- progressive-wp
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33937
Realtyna Organic IDX plugin
- Plugin:
- Realtyna Organic IDX plugin
- Plugin Slug:
- real-estate-listing-realtyna-wpl
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33924
Recencio Book Reviews
- Plugin:
- Recencio Book Reviews
- Plugin Slug:
- recencio-book-reviews
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33648
Regenerate post permalink
- Plugin:
- Regenerate post permalink
- Plugin Slug:
- regenerate-post-permalinks
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33681
School Management Pro
- Plugin:
- School Management Pro
- Plugin Slug:
- school-management-pro
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33911
Shortcode Addons
- Plugin:
- Shortcode Addons
- Plugin Slug:
- shortcode-addons
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
Sliding Widgets
- Plugin:
- Sliding Widgets
- Plugin Slug:
- sliding-widgets
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33938
Social Share Buttons by Supsystic
- Plugin:
- Social Share Buttons by Supsystic
- Plugin Slug:
- social-share-buttons-by-supsystic
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-22303
Solid Affiliate
- Plugin:
- Solid Affiliate
- Plugin Slug:
- solid-affiliate
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33637
SP Project & Document Manager
- Plugin:
- SP Project & Document Manager
- Plugin Slug:
- sp-client-document-manager
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33923
Sticky Anything
- Plugin:
- Sticky Anything
- Plugin Slug:
- toast-stick-anything
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33646
WidgetKit
- Plugin:
- WidgetKit
- Plugin Slug:
- widgetkit-for-elementor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33908
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33549
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33548
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33547
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33546
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33545
WZone
- Plugin:
- WZone
- Plugin Slug:
- woozone
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33544
WP GDPR Compliance
- Plugin:
- WP GDPR Compliance
- Plugin Slug:
- wp-gdpr-compliance
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33682
WP Masquerade
- Plugin:
- WP Masquerade
- Plugin Slug:
- wp-masquerade
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33550
WP Page Post Widget Clone
- Plugin:
- WP Page Post Widget Clone
- Plugin Slug:
- wp-page-post-widget-clone
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33636
WTI Like Post
- Plugin:
- WTI Like Post
- Plugin Slug:
- wti-like-post
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-33917
XforWooCommerce
- Plugin:
- XforWooCommerce
- Plugin Slug:
- xforwoocommerce
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33628
All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic
- Plugin Slug:
- all-in-one-seo-pack
- Installations
- 3,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.1.1
- Severity Score:
- Medium
- CVE:
- 2024-3554
Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
- Plugin:
- Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 5.9.16
- Severity Score:
- Medium
- CVE:
- 2024-3733
Rank Math SEO with AI Best SEO Tools
- Plugin Slug:
- seo-by-rank-math
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.217
- Severity Score:
- Medium
- CVE:
- 2024-3665
ElementsKit Elementor addons and Templates Library
- Plugin Slug:
- elementskit-lite
- Installations
- 1,000,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.1.1
- Severity Score:
- High
- CVE:
- 2024-3499
Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation
- Plugin:
- Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation
- Plugin Slug:
- optinmonster
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.16.0
- Severity Score:
- Medium
- CVE:
- 2024-33691
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.29
- Severity Score:
- Medium
- CVE:
- 2024-3885
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.26
- Severity Score:
- Medium
- CVE:
- 2024-32791
Spectra – WordPress Gutenberg Blocks
- Plugin Slug:
- ultimate-addons-for-gutenberg
- Installations
- 700,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 2.12.7
- Severity Score:
- Medium
- CVE:
- 2024-3107
Contact Form 7 Database Addon – CFDB7
- Plugin Slug:
- contact-form-cfdb7
- Installations
- 600,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.2.7
- Severity Score:
- Medium
- CVE:
- 2024-3870
WP Shortcodes Plugin — Shortcodes Ultimate
- Plugin Slug:
- shortcodes-ultimate
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.1.0
- Severity Score:
- Medium
- CVE:
- 2024-3188
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.7
- Severity Score:
- Medium
- CVE:
- 2024-3890
Duplicate Post
- Plugin:
- Duplicate Post
- Plugin Slug:
- copy-delete-posts
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.5
- Severity Score:
- Medium
- CVE:
- 2024-31435
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
- Plugin Slug:
- metform
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.8.4
- Severity Score:
- Medium
- CVE:
- 2024-33570
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.972
- Severity Score:
- Medium
- CVE:
- 2024-3675
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 300,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.3.95
- Severity Score:
- Medium
- CVE:
- 2024-32786
PDF Invoices & Packing Slips for WooCommerce
- Plugin Slug:
- woocommerce-pdf-invoices-packing-slips
- Installations
- 300,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 3.8.1
- Severity Score:
- High
- CVE:
- 2024-3047
PDF Invoices & Packing Slips for WooCommerce
- Plugin Slug:
- woocommerce-pdf-invoices-packing-slips
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.1
- Severity Score:
- High
- CVE:
- 2024-3045
Call Now Button – The #1 Click to Call Button for WordPress
- Plugin Slug:
- call-now-button
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.7
- Severity Score:
- Medium
- CVE:
- 2024-2908
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
- Plugin Slug:
- chaty
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.9
- Severity Score:
- Medium
- CVE:
- 2024-2972
Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels
- Plugin Slug:
- instant-images
- Installations
- 200,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 6.1.1
- Severity Score:
- High
- CVE:
- 2024-33569
Jeg Elementor Kit
- Plugin:
- Jeg Elementor Kit
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.5
- Severity Score:
- Medium
- CVE:
- 2024-3819
Jeg Elementor Kit
- Plugin:
- Jeg Elementor Kit
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.4
- Severity Score:
- Medium
- CVE:
- 2024-32721
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
- Plugin Slug:
- photo-gallery
- Installations
- 200,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.21
- Severity Score:
- Medium
- CVE:
- 2024-33586
Qi Addons For Elementor
- Plugin:
- Qi Addons For Elementor
- Plugin Slug:
- qi-addons-for-elementor
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1
- Severity Score:
- Medium
- CVE:
- 2024-3309
YITH WooCommerce Compare
- Plugin:
- YITH WooCommerce Compare
- Plugin Slug:
- yith-woocommerce-compare
- Installations
- 200,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.38.0
- Severity Score:
- Medium
- CVE:
- 2024-32699
Elementor Addon Elements
- Plugin:
- Elementor Addon Elements
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.4
- Severity Score:
- Medium
- CVE:
- 2024-3743
BackUpWordPress
- Plugin:
- BackUpWordPress
- Plugin Slug:
- backupwordpress
- Installations
- 100,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 3.14
- Severity Score:
- Low
- CVE:
- 2024-3034
Colibri Page Builder
- Plugin:
- Colibri Page Builder
- Plugin Slug:
- colibri-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.264
- Severity Score:
- Medium
- CVE:
- 2024-3338
Colibri Page Builder
- Plugin:
- Colibri Page Builder
- Plugin Slug:
- colibri-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.274
- Severity Score:
- Medium
- CVE:
- 2024-3340
Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode)
- Plugin Slug:
- content-views-query-and-display-post-page
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.1
- Severity Score:
- Medium
- CVE:
- 2024-3929
FileOrganizer – Manage WordPress and Website Files
- Plugin Slug:
- fileorganizer
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2024-2324
Table Rate Shipping Method for WooCommerce by Flexible Shipping
- Plugin Slug:
- flexible-shipping
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.24.16
- Severity Score:
- Medium
- CVE:
- 2024-32828
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.4.8
- Severity Score:
- Medium
- CVE:
- 2024-32782
Hummingbird – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript
- Plugin Slug:
- hummingbird-performance
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.7.4
- Severity Score:
- Medium
- CVE:
- 2024-32792
Social Sharing Plugin – Sassy Social Share
- Plugin Slug:
- sassy-social-share
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.61
- Severity Score:
- Medium
- CVE:
- 2024-2159
Schema & Structured Data for WP & AMP
- Plugin Slug:
- schema-and-structured-data-for-wp
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.30
- Severity Score:
- Medium
- CVE:
- 2024-3491
Strong Testimonials
- Plugin:
- Strong Testimonials
- Plugin Slug:
- strong-testimonials
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.12
- Severity Score:
- Medium
- CVE:
- 2024-3261
Social Media Share Buttons & Social Sharing Icons
- Plugin Slug:
- ultimate-social-media-icons
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.8.7
- Severity Score:
- Medium
- CVE:
- 2024-31435
WP Chat App
- Plugin:
- WP Chat App
- Plugin Slug:
- wp-whatsapp
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.4
- Severity Score:
- Medium
- CVE:
- 2024-2837
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
- Plugin Slug:
- paid-memberships-pro
- Installations
- 90,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.0
- Severity Score:
- Medium
- CVE:
- 2024-32794
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
- Plugin Slug:
- paid-memberships-pro
- Installations
- 90,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.0
- Severity Score:
- Medium
- CVE:
- 2024-32793
VK Block Patterns
- Plugin:
- VK Block Patterns
- Plugin Slug:
- vk-block-patterns
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.31.1.1
- Severity Score:
- Medium
- CVE:
- 2024-32826
WP STAGING WordPress Backup Plugin – Migration Backup Restore
- Plugin Slug:
- wp-staging
- Installations
- 90,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3682
Backup Migration
- Plugin:
- Backup Migration
- Plugin Slug:
- backup-backup
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2024-31435
Import and export users and customers
- Plugin Slug:
- import-users-from-csv-with-meta
- Installations
- 80,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.26.3
- Severity Score:
- Medium
- CVE:
- 2024-32817
MainWP Child Reports
- Plugin:
- MainWP Child Reports
- Plugin Slug:
- mainwp-child-reports
- Installations
- 80,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.2
- Severity Score:
- Medium
- CVE:
- 2024-33680
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.7.0
- Severity Score:
- Medium
- CVE:
- 2024-3553
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.0
- Severity Score:
- Medium
- CVE:
- 2024-3994
WP SMTP
WP ULike – Most Advanced WordPress Marketing Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.0
- Severity Score:
- Medium
- CVE:
- 2024-1572
WP ULike – Most Advanced WordPress Marketing Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.7.0
- Severity Score:
- High
- CVE:
- 2024-1797
WP ULike – Most Advanced WordPress Marketing Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.0
- Severity Score:
- Medium
- CVE:
- 2024-1759
Comments – wpDiscuz
- Plugin:
- Comments – wpDiscuz
- Plugin Slug:
- wpdiscuz
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6.16
- Severity Score:
- Medium
- CVE:
- 2024-2477
Database for Contact Form 7, WPforms, Elementor forms
- Plugin Slug:
- contact-form-entries
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.9
- Severity Score:
- High
- CVE:
- 2024-3715
Media Cleaner: Clean your WordPress!
- Plugin Slug:
- media-cleaner
- Installations
- 70,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 6.7.3
- Severity Score:
- Medium
- CVE:
- 2024-33922
Export and Import Users and Customers
- Plugin Slug:
- users-customers-import-export-for-wp-woocommerce
- Installations
- 70,000+
- Vulnerability:
- Deserialization of untrusted data
- Patched in Version:
- 2.5.4
- Severity Score:
- Medium
- CVE:
- 2024-32835
Blog2Social: Social Media Auto Post & Scheduler
- Plugin Slug:
- blog2social
- Installations
- 60,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 7.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3678
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.9.2
- Severity Score:
- Medium
- CVE:
- 2024-33914
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.9.4
- Severity Score:
- Medium
- CVE:
- 2024-2750
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.9.5
- Severity Score:
- Medium
- CVE:
- 2024-3489
Getwid – Gutenberg Blocks
- Plugin:
- Getwid – Gutenberg Blocks
- Plugin Slug:
- getwid
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.8
- Severity Score:
- Medium
- CVE:
- 2024-3588
FOX – Currency Switcher Professional for WooCommerce
- Plugin Slug:
- woocommerce-currency-switcher
- Installations
- 60,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.1.9
- Severity Score:
- Medium
- CVE:
- 2024-3734
WP-Members Membership Plugin
- Plugin:
- WP-Members Membership Plugin
- Plugin Slug:
- wp-members
- Installations
- 60,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.4.9.4
- Severity Score:
- Medium
- CVE:
- 2024-2920
Enhanced Text Widget
- Plugin:
- Enhanced Text Widget
- Plugin Slug:
- enhanced-text-widget
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.5
- Severity Score:
- Medium
- CVE:
- 2024-31435
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.25
- Severity Score:
- Medium
- CVE:
- 2024-2258
Collapse-O-Matic
- Plugin:
- Collapse-O-Matic
- Plugin Slug:
- jquery-collapse-o-matic
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.5.6
- Severity Score:
- Medium
- CVE:
- 2023-7030
Quick Featured Images
- Plugin:
- Quick Featured Images
- Plugin Slug:
- quick-featured-images
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 13.7.1
- Severity Score:
- Medium
- CVE:
- 2024-3664
Simple Membership
- Plugin:
- Simple Membership
- Plugin Slug:
- simple-membership
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.4.4
- Severity Score:
- Medium
- CVE:
- 2024-3730
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates)
- Plugin Slug:
- sina-extension-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.3
- Severity Score:
- Medium
- CVE:
- 2024-3988
Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
- Plugin:
- Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
- Plugin Slug:
- post-grid
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.2.79
- Severity Score:
- High
- CVE:
- 2024-32816
Simply Static
- Plugin:
- Simply Static
- Plugin Slug:
- simply-static
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1.4
- Severity Score:
- High
- CVE:
- 2024-32825
Print Invoice & Delivery Notes for WooCommerce
- Plugin Slug:
- woocommerce-delivery-notes
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.9.0
- Severity Score:
- Medium
- CVE:
- 2024-4233
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy)
- Plugin Slug:
- wp-analytify
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.2.4
- Severity Score:
- Medium
- CVE:
- 2024-1809
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy)
- Plugin Slug:
- wp-analytify
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.2.4
- Severity Score:
- Medium
- CVE:
- 2024-1584
AGCA – Custom Dashboard & Login Page
- Plugin Slug:
- ag-custom-admin
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.2.2
- Severity Score:
- Medium
- CVE:
- 2024-2907
Popup Box – Best WordPress Popup Plugin
- Plugin Slug:
- ays-popup-box
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.3.7
- Severity Score:
- Medium
- CVE:
- 2024-3897
FV Flowplayer Video Player
- Plugin:
- FV Flowplayer Video Player
- Plugin Slug:
- fv-wordpress-flowplayer
- Installations
- 30,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 7.5.45.7212
- Severity Score:
- Medium
- CVE:
- 2024-32955
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
- Plugin Slug:
- master-addons
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.5.6
- Severity Score:
- Medium
- CVE:
- 2024-33595
Timetable and Event Schedule by MotoPress
- Plugin Slug:
- mp-timetable
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.4.12
- Severity Score:
- High
- CVE:
- 2024-3342
Social Sharing Plugin – Social Warfare
- Plugin Slug:
- social-warfare
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.4.6.2
- Severity Score:
- Medium
- CVE:
- 2024-1959
VOD Infomaniak
- Plugin:
- VOD Infomaniak
- Plugin Slug:
- vod-infomaniak
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.7
- Severity Score:
- High
- CVE:
- 2024-33571
WP Google Review Slider
- Plugin:
- WP Google Review Slider
- Plugin Slug:
- wp-google-places-review-slider
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 13.6
- Severity Score:
- Medium
- CVE:
- 2024-2310
Hide Dashboard Notifications
- Plugin:
- Hide Dashboard Notifications
- Plugin Slug:
- wp-hide-backed-notices
- Installations
- 30,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.3
- Severity Score:
- Medium
- CVE:
- 2024-33683
Appointment Hour Booking – WordPress Booking Plugin
- Plugin Slug:
- appointment-hour-booking
- Installations
- 20,000+
- Vulnerability:
- Other Vulnerability Type
- Patched in Version:
- 1.4.57
- Severity Score:
- Medium
- CVE:
- 2024-32720
Payment Gateway Based Fees and Discounts for WooCommerce
- Plugin Slug:
- checkout-fees-for-woocommerce
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.12.2
- Severity Score:
- Medium
- CVE:
- 2024-33585
Data Tables Generator by Supsystic
- Plugin Slug:
- data-tables-generator-by-supsystic
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.10.32
- Severity Score:
- Medium
- CVE:
- 2024-32829
Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery
- Plugin Slug:
- gt3-photo-video-gallery
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.7.22
- Severity Score:
- Medium
- CVE:
- 2024-4035
Pricing Table by Supsystic
- Plugin:
- Pricing Table by Supsystic
- Plugin Slug:
- pricing-table-by-supsystic
- Installations
- 20,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 1.9.13
- Severity Score:
- Medium
- CVE:
- 2024-32790
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
- Plugin Slug:
- rafflepress
- Installations
- 20,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.12.11
- Severity Score:
- Medium
- CVE:
- 2024-32827
Rate My Post – Star Rating Plugin by FeedbackWP
- Plugin Slug:
- rate-my-post
- Installations
- 20,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.4.5
- Severity Score:
- Medium
- CVE:
- 2024-32823
Secure Copy Content Protection and Content Locking
- Plugin Slug:
- secure-copy-content-protection
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.1
- Severity Score:
- Medium
- CVE:
- 2024-33587
Secure Copy Content Protection and Content Locking
- Plugin Slug:
- secure-copy-content-protection
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.7.2
- Severity Score:
- Medium
- CVE:
- 2024-32787
Social Share Icons & Social Share Buttons
- Plugin Slug:
- ultimate-social-media-plus
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.2
- Severity Score:
- Medium
- CVE:
- 2024-31435
Social Share Icons & Social Share Buttons
- Plugin Slug:
- ultimate-social-media-plus
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.3
- Severity Score:
- Medium
- CVE:
- 2024-32820
Video Conferencing with Zoom
- Plugin:
- Video Conferencing with Zoom
- Plugin Slug:
- video-conferencing-with-zoom-api
- Installations
- 20,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 4.4.5
- Severity Score:
- Medium
- CVE:
- 2024-33584
Product Addons & Fields for WooCommerce
- Plugin Slug:
- woocommerce-product-addon
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 32.0.19
- Severity Score:
- Critical
- CVE:
- 2024-3962
Brevo for WooCommerce
- Plugin:
- Brevo for WooCommerce
- Plugin Slug:
- woocommerce-sendinblue-newsletter-subscription
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 4.0.18
- Severity Score:
- High
- CVE:
- 2024-32807
WPZOOM Addons for Elementor (Templates, Widgets)
- Plugin Slug:
- wpzoom-elementor-addons
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.36
- Severity Score:
- Medium
- CVE:
- 2024-33539
Advanced Floating Content Lite
- Plugin:
- Advanced Floating Content Lite
- Plugin Slug:
- advanced-floating-content-lite
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.6
- Severity Score:
- Medium
- CVE:
- 2024-32723
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss
- Plugin Slug:
- bp-better-messages
- Installations
- 10,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.4.33
- Severity Score:
- Medium
- CVE:
- 2024-32802
rtMedia for WordPress, BuddyPress and bbPress
- Plugin Slug:
- buddypress-media
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.6.19
- Severity Score:
- High
- CVE:
- 2024-3293
Classified Listing – Classified ads & Business Directory Plugin
- Plugin Slug:
- classified-listing
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.11
- Severity Score:
- Medium
- CVE:
- 2024-3893
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
- Plugin Slug:
- directorist
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.9.0
- Severity Score:
- Medium
- CVE:
- 2024-33929
Elespare – Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required!
- Plugin Slug:
- elespare
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.3
- Severity Score:
- Medium
- CVE:
- 2024-0900
Email Customizer for WooCommerce | Drag and Drop Email Templates Builder
- Plugin Slug:
- email-customizer-for-woocommerce
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.6.1
- Severity Score:
- High
- CVE:
- 2024-32781
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress
- Plugin:
- GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress
- Plugin Slug:
- gamipress
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.8.9
- Severity Score:
- Low
- CVE:
- 2024-2505
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory
- Plugin Slug:
- geodirectory
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.49
- Severity Score:
- Medium
- CVE:
- 2024-3732
SSL Mixed Content Fix
- Plugin:
- SSL Mixed Content Fix
- Plugin Slug:
- http-https-remover
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.7
- Severity Score:
- Medium
- CVE:
- 2024-31435
List Custom Taxonomy Widget
- Plugin:
- List Custom Taxonomy Widget
- Plugin Slug:
- list-custom-taxonomy-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2
- Severity Score:
- Medium
- CVE:
- 2024-32833
Page Builder: Live Composer
- Plugin:
- Page Builder: Live Composer
- Plugin Slug:
- live-composer-page-builder
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.39
- Severity Score:
- Medium
- CVE:
- 2024-32957
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.4
- Severity Score:
- Medium
- CVE:
- 2024-32711
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.11.1
- Severity Score:
- Medium
- CVE:
- 2024-32728
Pop-up
- Plugin:
- Pop-up
- Plugin Slug:
- pop-up-pop-up
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.4
- Severity Score:
- Medium
- CVE:
- 2024-31435
Five Star Restaurant Reservations – WordPress Booking Plugin
- Plugin Slug:
- restaurant-reservations
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.17
- Severity Score:
- Medium
- CVE:
- 2024-33596
ReviewX – Multi-criteria Rating & Reviews for WooCommerce
- Plugin Slug:
- reviewx
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.22
- Severity Score:
- Medium
- CVE:
- 2024-33921
RomethemeKit For Elementor
- Plugin:
- RomethemeKit For Elementor
- Plugin Slug:
- rometheme-for-elementor
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2024-33919
RomethemeKit For Elementor
- Plugin:
- RomethemeKit For Elementor
- Plugin Slug:
- rometheme-for-elementor
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2024-32956
Send PDF for Contact Form 7
- Plugin:
- Send PDF for Contact Form 7
- Plugin Slug:
- send-pdf-for-contact-form-7
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.2.4
- Severity Score:
- Medium
- CVE:
- 2024-3585
Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap
- Plugin:
- Social Share Buttons, Social Sharing Icons, Click to Tweet — Social Media Plugin by Social Snap
- Plugin Slug:
- socialsnap
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2024-32805
Ultimate Posts Widget
- Plugin:
- Ultimate Posts Widget
- Plugin Slug:
- ultimate-posts-widget
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3.0
- Severity Score:
- Medium
- CVE:
- 2024-31435
Easy Accept Payments via PayPal
- Plugin:
- Easy Accept Payments via PayPal
- Plugin Slug:
- wordpress-easy-paypal-payment-or-donation-accept-plugin
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.0
- Severity Score:
- High
- CVE:
- 2024-33591
WP Datepicker
- Plugin:
- WP Datepicker
- Plugin Slug:
- wp-datepicker
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.1.1
- Severity Score:
- High
- CVE:
- 2024-3895
SchedulePress – Best Editorial Calendar, Missed Schedule & Auto Social Share
- Plugin Slug:
- wp-scheduled-posts
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.0.9
- Severity Score:
- Medium
- CVE:
- 2024-32717
WP Travel Engine – Best Travel Booking WordPress Plugin
- Plugin Slug:
- wp-travel-engine
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.8.1
- Severity Score:
- High
- CVE:
- 2024-32798
Arconix FAQ
- Plugin:
- Arconix FAQ
- Plugin Slug:
- arconix-faq
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.4
- Severity Score:
- Medium
- CVE:
- 2024-4233
FG Joomla to WordPress
- Plugin:
- FG Joomla to WordPress
- Plugin Slug:
- fg-joomla-to-wordpress
- Installations
- 9,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.21.0
- Severity Score:
- Medium
- CVE:
- 2024-32788
RomethemeForm For Elementor
- Plugin:
- RomethemeForm For Elementor
- Plugin Slug:
- romethemeform
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.3
- Severity Score:
- Medium
- CVE:
- 2024-32727
Smart Forms – when you need more than just a contact form
- Plugin Slug:
- smart-forms
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.96
- Severity Score:
- Medium
- CVE:
- 2024-1905
Smart Forms – when you need more than just a contact form
- Plugin Slug:
- smart-forms
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.92
- Severity Score:
- Medium
- CVE:
- 2024-33593
WP LinkedIn Auto Publish
- Plugin:
- WP LinkedIn Auto Publish
- Plugin Slug:
- wp-linkedin-auto-publish
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.12
- Severity Score:
- Medium
- CVE:
- 2024-32797
WordPress Backup & Migration
- Plugin:
- WordPress Backup & Migration
- Plugin Slug:
- wp-migration-duplicator
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.9
- Severity Score:
- Medium
- CVE:
- 2024-3546
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
- Plugin:
- ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
- Plugin Slug:
- armember-membership
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.29
- Severity Score:
- Critical
- CVE:
- 2024-32948
Maintenance Mode
- Plugin:
- Maintenance Mode
- Plugin Slug:
- hkdev-maintenance-mode
- Installations
- 8,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 3.0.2
- Severity Score:
- Low
- CVE:
- 2024-32708
WPC Composite Products for WooCommerce
- Plugin Slug:
- wpc-composite-products
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.2.8
- Severity Score:
- Medium
- CVE:
- 2024-2838
ProfileGrid – User Profiles, Memberships, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 5.8.0
- Severity Score:
- Medium
- CVE:
- 2024-32808
ProfileGrid – User Profiles, Memberships, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 5.8.3
- Severity Score:
- Medium
- CVE:
- 2024-32774
ProfileGrid – User Profiles, Memberships, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 5.8.0
- Severity Score:
- Medium
- CVE:
- 2024-32772
The Plus Blocks for Block Editor | Gutenberg
- Plugin Slug:
- the-plus-addons-for-block-editor
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.6
- Severity Score:
- Medium
- CVE:
- 2024-33572
Better Elementor Addons
- Plugin:
- Better Elementor Addons
- Plugin Slug:
- better-elementor-addons
- Installations
- 6,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2024-33541
Easy Property Listings
- Plugin:
- Easy Property Listings
- Plugin Slug:
- easy-property-listings
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.4
- Severity Score:
- Medium
- CVE:
- 2024-32799
Image Slider
- Plugin:
- Image Slider
- Plugin Slug:
- image-slider-widget
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.127
- Severity Score:
- Medium
- CVE:
- 2024-32707
Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site
- Plugin Slug:
- integrate-google-drive
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.91
- Severity Score:
- High
- CVE:
- 2024-32949
Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site
- Plugin Slug:
- integrate-google-drive
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.91
- Severity Score:
- Medium
- CVE:
- 2024-32813
Print My Blog – Print, PDF, & eBook Converter WordPress Plugin
- Plugin Slug:
- print-my-blog
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.26.3
- Severity Score:
- Medium
- CVE:
- 2024-33907
Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress
- Plugin Slug:
- radio-player
- Installations
- 6,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.0.74
- Severity Score:
- Medium
- CVE:
- 2024-33592
Arconix Shortcodes
- Plugin:
- Arconix Shortcodes
- Plugin Slug:
- arconix-shortcodes
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.11
- Severity Score:
- Medium
- CVE:
- 2024-4233
Assistant – Every Day Productivity Apps
- Plugin Slug:
- assistant
- Installations
- 5,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.4.9.2
- Severity Score:
- Medium
- CVE:
- 2024-33538
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 5,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 4.0.12
- Severity Score:
- Medium
- CVE:
- 2024-32812
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.15
- Severity Score:
- High
- CVE:
- 2024-32712
Salon booking system
- Plugin:
- Salon booking system
- Plugin Slug:
- salon-booking-system
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.6.6
- Severity Score:
- Medium
- CVE:
- 2024-2603
Salon booking system
- Plugin:
- Salon booking system
- Plugin Slug:
- salon-booking-system
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.6.6
- Severity Score:
- Medium
- CVE:
- 2024-2439
Salon booking system
- Plugin:
- Salon booking system
- Plugin Slug:
- salon-booking-system
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 9.6.6
- Severity Score:
- Medium
- CVE:
- 2024-2429
Ultimate 410 Gone Status Code
- Plugin:
- Ultimate 410 Gone Status Code
- Plugin Slug:
- ultimate-410
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.5
- Severity Score:
- Medium
- CVE:
- 2024-3677
Advanced Local Pickup for WooCommerce
- Plugin Slug:
- advanced-local-pickup-for-woocommerce
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.2
- Severity Score:
- Medium
- CVE:
- 2024-32814
Embed Google Photos album
- Plugin:
- Embed Google Photos album
- Plugin Slug:
- embed-google-photos-album-easily
- Installations
- 4,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-32775
Import WP – Export and Import CSV and XML files to WordPress
- Plugin Slug:
- jc-importer
- Installations
- 4,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.13.1
- Severity Score:
- Medium
- CVE:
- 2023-7253
Tickera – WordPress Event Ticketing
- Plugin Slug:
- tickera-event-ticketing-system
- Installations
- 4,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.5.2.5
- Severity Score:
- Medium
- CVE:
- 2023-7252
VikRentCar Car Rental Management System
- Plugin Slug:
- vikrentcar
- Installations
- 4,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.3.3
- Severity Score:
- Medium
- CVE:
- 2024-32780
WP ADA Compliance Check Basic – Most Comprehensive Web Accessibility Solution for WordPress
- Plugin Slug:
- wp-ada-compliance-check-basic
- Installations
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.1.4
- Severity Score:
- Medium
- CVE:
- 2024-32947
WP Fusion Lite – Marketing Automation and CRM Integration for WordPress
- Plugin Slug:
- wp-fusion-lite
- Installations
- 4,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.43.0
- Severity Score:
- Medium
- CVE:
- 2024-32796
Coupon & Discount Code Reveal Button
- Plugin Slug:
- coupon-reveal-button
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.6
- Severity Score:
- Medium
- CVE:
- 2024-32722
Debug Log Manager
- Plugin:
- Debug Log Manager
- Plugin Slug:
- debug-log-manager
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3.2
- Severity Score:
- Medium
- CVE:
- 2024-33915
Newsletters
- Plugin:
- Newsletters
- Plugin Slug:
- newsletters-lite
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.9.6
- Severity Score:
- Critical
- CVE:
- 2024-32954
Newsletters
- Plugin:
- Newsletters
- Plugin Slug:
- newsletters-lite
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.9.6
- Severity Score:
- High
- CVE:
- 2024-32953
PropertyHive
- Plugin:
- PropertyHive
- Plugin Slug:
- propertyhive
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.13
- Severity Score:
- Medium
- CVE:
- 2024-3607
Vision – Image Map Builder
- Plugin:
- Vision – Image Map Builder
- Plugin Slug:
- vision
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.2
- Severity Score:
- Medium
- CVE:
- 2024-32779
Widget Post Slider
- Plugin:
- Widget Post Slider
- Plugin Slug:
- widget-post-slider
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2024-32801
WP-Lister Lite for eBay
- Plugin:
- WP-Lister Lite for eBay
- Plugin Slug:
- wp-lister-for-ebay
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.6.0
- Severity Score:
- Critical
- CVE:
- 2024-32836
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 16.26.6
- Severity Score:
- High
- CVE:
- 2024-32710
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 16.26.6
- Severity Score:
- Critical
- CVE:
- 2024-32709
Accessibility Widget
- Plugin:
- Accessibility Widget
- Plugin Slug:
- accessibility-widget
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-32831
Advanced Testimonial Carousel for Elementor
- Plugin Slug:
- advanced-testimonial-carousel-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.1
- Severity Score:
- Medium
- CVE:
- 2024-32783
All-in-one Like Widget
- Plugin:
- All-in-one Like Widget
- Plugin Slug:
- all-in-one-facebook-like-widget
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.8
- Severity Score:
- Medium
- CVE:
- 2024-32815
Knowledge Base documentation & wiki plugin – BasePress Docs
- Plugin Slug:
- basepress
- Installations
- 2,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.16.2.1
- Severity Score:
- Medium
- CVE:
- 2024-33590
Knowledge Base documentation & wiki plugin – BasePress Docs
- Plugin Slug:
- basepress
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.16.2.1
- Severity Score:
- Medium
- CVE:
- 2024-33588
CookieHub – Cookie Consent Banner (DSGVO, CCPA, RGPD and GDPR compliance)
- Plugin Slug:
- cookiehub
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-32784
Custom field finder
- Plugin:
- Custom field finder
- Plugin Slug:
- custom-field-finder
- Installations
- 2,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 0.4
- Severity Score:
- Medium
- CVE:
- 2024-33641
RSS Redirect & Feedburner Alternative
- Plugin Slug:
- feedburner-alternative-and-rss-redirect
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0
- Severity Score:
- Medium
- CVE:
- 2024-31435
InstaWP Connect – 1-click WP Staging & Migration
- Plugin Slug:
- instawp-connect
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 0.1.0.25
- Severity Score:
- Medium
- CVE:
- 2024-32701
iPages Flipbook For WordPress
- Plugin:
- iPages Flipbook For WordPress
- Plugin Slug:
- ipages-flipbook
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.2
- Severity Score:
- Medium
- CVE:
- 2024-33909
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)
- Plugin Slug:
- the-pack-addon
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.0.8.4
- Severity Score:
- High
- CVE:
- 2024-32785
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)
- Plugin Slug:
- the-pack-addon
- Installations
- 2,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.0.8.3
- Severity Score:
- Medium
- CVE:
- 2024-32718
User Meta – User Profile Builder and User management plugin
- Plugin Slug:
- user-meta
- Installations
- 2,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1
- Severity Score:
- Medium
- CVE:
- 2024-33575
SuperFaktura WooCommerce
- Plugin:
- SuperFaktura WooCommerce
- Plugin Slug:
- woocommerce-superfaktura
- Installations
- 2,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.40.4
- Severity Score:
- Medium
- CVE:
- 2024-32803
Academy LMS – eLearning and online course solution for WordPress
- Plugin Slug:
- academy
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.17
- Severity Score:
- High
- CVE:
- 2024-33912
Academy LMS – eLearning and online course solution for WordPress
- Plugin Slug:
- academy
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.17
- Severity Score:
- Medium
- CVE:
- 2024-32714
ActiveDEMAND
- Plugin:
- ActiveDEMAND
- Plugin Slug:
- activedemand
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.2.42
- Severity Score:
- Critical
- CVE:
- 2024-32809
Admin Bar Editor – Hide Toolbar by User Roles
- Plugin Slug:
- admin-bar
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.23
- Severity Score:
- Medium
- CVE:
- 2024-1716
AI Post Generator | AutoWriter
- Plugin:
- AI Post Generator | AutoWriter
- Plugin Slug:
- ai-post-generator
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4
- Severity Score:
- Medium
- CVE:
- 2024-32713
AppPresser – Mobile App Framework
- Plugin Slug:
- apppresser
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.3.1
- Severity Score:
- Medium
- CVE:
- 2024-32776
Booking Ultra Pro Appointments Booking Calendar Plugin
- Plugin Slug:
- booking-ultra-pro
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.1.13
- Severity Score:
- High
- CVE:
- 2024-32960
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
- Plugin Slug:
- buddyforms
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 2.8.9
- Severity Score:
- High
- CVE:
- 2024-32830
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 21.3.5
- Severity Score:
- High
- CVE:
- 2024-32778
ChatBot Conversational Forms
- Plugin:
- ChatBot Conversational Forms
- Plugin Slug:
- conversational-forms
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 1.2.0
- Severity Score:
- High
- CVE:
- 2024-32729
Culqi
- Plugin:
- Culqi
- Plugin Slug:
- culqi-checkout
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 3.0.15
- Severity Score:
- Medium
- CVE:
- 2024-32819
EPROLO Dropshipping
- Plugin:
- EPROLO Dropshipping
- Plugin Slug:
- eprolo-dropshipping
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.2
- Severity Score:
- Medium
- CVE:
- 2024-33573
USPS Shipping for WooCommerce – Live Rates
- Plugin Slug:
- flexible-shipping-usps
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.10.0
- Severity Score:
- Medium
- CVE:
- 2024-32811
Headline Analyzer
- Plugin:
- Headline Analyzer
- Plugin Slug:
- headline-analyzer
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.4
- Severity Score:
- Medium
- CVE:
- 2024-32806
KB Support – WordPress Help Desk and Knowledge Base
- Plugin Slug:
- kb-support
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.1
- Severity Score:
- Medium
- CVE:
- 2024-33589
Login with phone number
- Plugin:
- Login with phone number
- Plugin Slug:
- login-with-phone-number
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.94
- Severity Score:
- Critical
- CVE:
- 2024-32832
BizPrint – Print WooCommerce Order Receipts, Invoices, Labels & More.
- Plugin Slug:
- print-google-cloud-print-gcp-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.5.4
- Severity Score:
- High
- CVE:
- 2024-32777
Radio Station by netmix® – Manage and play your Show Schedule in WordPress!
- Plugin Slug:
- radio-station
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.5.8
- Severity Score:
- Medium
- CVE:
- 2024-33689
Reviews Plus
- Plugin:
- Reviews Plus
- Plugin Slug:
- reviews-plus
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-32822
Save as PDF Plugin by Pdfcrowd
- Plugin:
- Save as PDF Plugin by Pdfcrowd
- Plugin Slug:
- save-as-pdf-by-pdfcrowd
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.1
- Severity Score:
- Medium
- CVE:
- 2024-33684
Seers | GDPR & CCPA Cookie Consent & Compliance
- Plugin Slug:
- seers-cookie-consent-banner-privacy-policy
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 8.1.1
- Severity Score:
- High
- CVE:
- 2024-32789
Image Optimizer, Resizer and CDN – Sirv
- Plugin Slug:
- sirv
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 7.2.3
- Severity Score:
- High
- CVE:
- 2024-32959
StreamWeasels Twitch Integration
- Plugin:
- StreamWeasels Twitch Integration
- Plugin Slug:
- streamweasels-twitch-integration
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.8.0
- Severity Score:
- Medium
- CVE:
- 2024-32716
Poll | Vote | Contest – Best Poll Plugin for WordPress
- Plugin Slug:
- totalpoll-lite
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.10.0
- Severity Score:
- Medium
- CVE:
- 2024-32821
Vitepos – Point of sale (POS) plugin for WooCommerce
- Plugin Slug:
- vitepos-lite
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.2
- Severity Score:
- Medium
- CVE:
- 2024-33574
WP Club Manager – WordPress Sports Club Plugin
- Plugin Slug:
- wp-club-manager
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.12
- Severity Score:
- Medium
- CVE:
- 2024-32719
WP GoToWebinar
- Plugin:
- WP GoToWebinar
- Plugin Slug:
- wp-gotowebinar
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 15.1
- Severity Score:
- Medium
- CVE:
- 2024-32804
MDTF – Meta Data and Taxonomies Filter
- Plugin Slug:
- wp-meta-data-filter-and-taxonomy-filter
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.3.1
- Severity Score:
- Medium
- CVE:
- 2024-32818
WP Time Slots Booking Form
- Plugin:
- WP Time Slots Booking Form
- Plugin Slug:
- wp-time-slots-booking-form
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.07
- Severity Score:
- High
- CVE:
- 2024-33543
WPCal.io – Easy Meeting Scheduler
- Plugin Slug:
- wpcal
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 0.9.5.9
- Severity Score:
- Medium
- CVE:
- 2024-32795
WPPizza – A Restaurant Plugin
- Plugin:
- WPPizza – A Restaurant Plugin
- Plugin Slug:
- wppizza
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.18.11
- Severity Score:
- Medium
- CVE:
- 2024-33576
Frontend Dashboard
- Plugin:
- Frontend Dashboard
- Plugin Slug:
- frontend-dashboard
- Installations
- 900+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.2.4
- Severity Score:
- High
- CVE:
- 2024-32726
Leaky Paywall
- Plugin:
- Leaky Paywall
- Plugin Slug:
- leaky-paywall
- Installations
- 900+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.20.9
- Severity Score:
- High
- CVE:
- 2024-33594
Olive One Click Demo Import
- Plugin:
- Olive One Click Demo Import
- Plugin Slug:
- olive-one-click-demo-import
- Installations
- 900+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 1.1.2
- Severity Score:
- High
- CVE:
- 2024-32715
SharkDropship and Affiliate for AliExpress, eBay, Amazon, Etsy
- Plugin Slug:
- woo-aliexpress-dropshipping
- Installations
- 900+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 2.1.2
- Severity Score:
- High
- CVE:
- 2024-32724
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 800+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.5.4
- Severity Score:
- Critical
- CVE:
- 2024-33567
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 800+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.4
- Severity Score:
- Critical
- CVE:
- 2024-33565
Slash Admin
- Plugin:
- Slash Admin
- Plugin Slug:
- slash-admin
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.2
- Severity Score:
- High
- CVE:
- 2024-32958
Car Dealer (Dealership) and Vehicle sales
- Plugin Slug:
- cardealer
- Installations
- 700+
- Vulnerability:
- Content Injection
- Patched in Version:
- 4.16
- Severity Score:
- Low
- CVE:
- 2024-4214
ShortPixel Critical CSS
- Plugin:
- ShortPixel Critical CSS
- Plugin Slug:
- shortpixel-critical-css
- Installations
- 700+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.3
- Severity Score:
- High
- CVE:
- 2024-32810
Admin and Customer Messages After Order for WooCommerce: OrderConvo
- Plugin Slug:
- admin-and-client-message-after-order-for-woocommerce
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 12.5
- Severity Score:
- Critical
- CVE:
- 2024-33566
SSU – WordPress Amazon S3 & Wasabi Smart File Uploads Plugin
- Plugin Slug:
- wp-s3-smart-upload
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2024-33597
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
- Plugin Slug:
- evergreen-content-poster
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.3
- Severity Score:
- Medium
- CVE:
- 2024-32824
Build 5 Star Reviews on Google Reviews, Yelp, Facebook… easily and risk-free | RRatingg
- Plugin Slug:
- 5-stars-rating-funnel
- Installations
- 40+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.02
- Severity Score:
- Medium
- CVE:
- 2024-32725
Better Comments
- Plugin:
- Better Comments
- Plugin Slug:
- better-comments
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.6
- Severity Score:
- Medium
- CVE:
- 2024-2404
Better Comments
- Plugin:
- Better Comments
- Plugin Slug:
- better-comments
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.6
- Severity Score:
- Medium
- CVE:
- 2024-2402
Header Footer Code Manager Pro
- Plugin:
- Header Footer Code Manager Pro
- Plugin Slug:
- 99robots-header-footer-code-manager-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.17
- Severity Score:
- High
- CVE:
- 2024-3473
ARForms
- Plugin:
- ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- SQL Injection
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2024-32706
ARForms
- Plugin:
- ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Settings Change
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2024-32705
ARForms
- Plugin:
- ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Settings Change
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2024-32704
ARForms
- Plugin:
- ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2024-32703
ARForms
- Plugin:
- ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2024-32702
ARForms Form Builder
- Plugin:
- ARForms Form Builder
- Plugin Slug:
- arforms-form-builder
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.5
- Severity Score:
- High
- CVE:
- 2024-1945
Digital Publications by Supsystic
- Plugin:
- Digital Publications by Supsystic
- Plugin Slug:
- digital-publications-by-supsystic
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.8
- Severity Score:
- Medium
- CVE:
- 2024-33910
ElementsKit Pro
- Plugin:
- ElementsKit Pro
- Plugin Slug:
- elementskit
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.6.1
- Severity Score:
- High
- CVE:
- 2024-3500
Fancy Product Designer
- Plugin:
- Fancy Product Designer
- Plugin Slug:
- fancy-product-designer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.1.8
- Severity Score:
- High
- CVE:
- 2024-0905
Interactive World Maps
- Plugin:
- Interactive World Maps
- Plugin Slug:
- interactive-world-maps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5
- Severity Score:
- High
- CVE:
- 2024-3681
Max Addons Pro for Bricks
- Plugin:
- Max Addons Pro for Bricks
- Plugin Slug:
- max-addons-pro-bricks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.2
- Severity Score:
- High
- CVE:
- 2024-32952
Max Addons Pro for Bricks
- Plugin:
- Max Addons Pro for Bricks
- Plugin Slug:
- max-addons-pro-bricks
- Vulnerability:
- Settings Change
- Patched in Version:
- 1.6.2
- Severity Score:
- Medium
- CVE:
- 2024-32951
WooCommerce Shipping Label
- Plugin:
- WooCommerce Shipping Label
- Plugin Slug:
- shipping-labels-for-woo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.9
- Severity Score:
- Medium
- CVE:
- 2024-32834
WooCommerce Customers Manager
- Plugin:
- WooCommerce Customers Manager
- Plugin Slug:
- woocommerce-customers-manager
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 29.8
- Severity Score:
- Medium
- CVE:
- 2024-1756
WooCommerce Customers Manager
- Plugin:
- WooCommerce Customers Manager
- Plugin Slug:
- woocommerce-customers-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 29.8
- Severity Score:
- High
- CVE:
- 2024-1743
WP Media Category Management
- Plugin:
- WP Media Category Management
- Plugin Slug:
- wp-media-category-management
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.0
- Severity Score:
- High
- CVE:
- 2024-32950
Wp Staging Pro
- Plugin:
- Wp Staging Pro
- Plugin Slug:
- wp-staging-pro
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3682
WordPress Themes — 21 Patched / 7 Unpatched
UDesign
- Theme:
- UDesign
- Theme Slug:
- u-design
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-4077
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33564
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33563
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33562
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-33561
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33560
XStore
- Theme:
- XStore
- Theme Slug:
- xstore
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-33559
Accountra
- Theme:
- Accountra
- Theme Slug:
- accountra
- Downloads
- 20,885
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.4
- Severity Score:
- Medium
- CVE:
- 2024-33685
Althea WP
- Theme:
- Althea WP
- Theme Slug:
- althea-wp
- Downloads
- 52,642
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.16
- Severity Score:
- Medium
- CVE:
- 2024-33686
Blocksy
Blocksy
- Theme:
- Blocksy
- Theme Slug:
- blocksy
- Downloads
- 3,113,676
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.34
- Severity Score:
- Medium
- CVE:
- 2024-32961
Brite
- Theme:
- Brite
- Theme Slug:
- brite
- Downloads
- 125,207
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.15
- Severity Score:
- Medium
- CVE:
- 2024-33686
Colibri WP
- Theme:
- Colibri WP
- Theme Slug:
- colibri-wp
- Downloads
- 1,271,195
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.99
- Severity Score:
- Medium
- CVE:
- 2024-33686
ColorNews
- Theme:
- ColorNews
- Theme Slug:
- colornews
- Downloads
- 266,626
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.7
- Severity Score:
- Medium
- CVE:
- 2024-33540
Elevate WP
- Theme:
- Elevate WP
- Theme Slug:
- elevate-wp
- Downloads
- 70,130
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.17
- Severity Score:
- Medium
- CVE:
- 2024-33686
Financio
- Theme:
- Financio
- Theme Slug:
- financio
- Downloads
- 17,197
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.4
- Severity Score:
- Medium
- CVE:
- 2024-33690
Hugo WP
- Theme:
- Hugo WP
- Theme Slug:
- hugo-wp
- Downloads
- 59,334
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.10
- Severity Score:
- Medium
- CVE:
- 2024-33686
Intrace
- Theme:
- Intrace
- Theme Slug:
- intrace
- Downloads
- 84,888
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-33685
Pathway
- Theme:
- Pathway
- Theme Slug:
- pathway
- Downloads
- 57,050
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.16
- Severity Score:
- Medium
- CVE:
- 2024-33686
Photology
- Theme:
- Photology
- Theme Slug:
- photology
- Downloads
- 17,339
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.4
- Severity Score:
- Medium
- CVE:
- 2024-33685
Royal Elementor Kit
- Theme:
- Royal Elementor Kit
- Theme Slug:
- royal-elementor-kit
- Downloads
- 461,793
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.117
- Severity Score:
- Medium
- CVE:
- 2024-32773
Startupzy
- Theme:
- Startupzy
- Theme Slug:
- startupzy
- Downloads
- 66,824
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.2
- Severity Score:
- Medium
- CVE:
- 2024-33685
Teluro
- Theme:
- Teluro
- Theme Slug:
- teluro
- Downloads
- 188,771
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.36
- Severity Score:
- Medium
- CVE:
- 2024-33688
Travey
- Theme:
- Travey
- Theme Slug:
- travey
- Downloads
- 17,666
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.5
- Severity Score:
- Medium
- CVE:
- 2024-33685
Vertice
- Theme:
- Vertice
- Theme Slug:
- vertice
- Downloads
- 47,531
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.11
- Severity Score:
- Medium
- CVE:
- 2024-33686
Virtue
WP Portfolio
- Theme:
- WP Portfolio
- Theme Slug:
- wp-portfolio
- Downloads
- 82,208
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5
- Severity Score:
- Medium
- CVE:
- 2024-33537
Zeever
- Theme:
- Zeever
- Theme Slug:
- zeever
- Downloads
- 208,788
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-33685
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed