WordPress Vulnerability Report

WordPress Vulnerability Report — June 12, 2024

Since last week, 228 new vulnerabilities emerged in the WordPress ecosystem including 217 in themes and 11 in plugins. 60 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 228 vulnerabilities have been publicly disclosed. Security patches for 168 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 60 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6 Beta 2 was released on June 11, 2024. This beta version of the WordPress software is under development. The target release date for WordPress 6.6 is July 16, 2024. Your help testing Beta and RC versions over the next five weeks is vital to making sure the final release is everything it should be: stable, powerful, and intuitive.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 157 Patched / 60 Unpatched

Plugin Slug:
album-and-image-gallery-plus-lightbox
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress
Installations
3,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weather Widget Pro

Plugin Slug:
weather-in-any-city-widget
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Notices Manager

Plugin:
Admin Notices Manager
Plugin Slug:
admin-notices-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Authorize.net Payment Gateway For WooCommerce

Plugin:
Authorize.net Payment Gateway For WooCommerce
Plugin Slug:
authorizenet-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Boostify Header Footer Builder for Elementor
Plugin Slug:
boostify-header-footer-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Cover

Plugin:
BuddyPress Cover
Plugin Slug:
bp-cover
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BuddyForms

Plugin:
BuddyForms
Plugin Slug:
buddyforms
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Members Only

Plugin:
BuddyPress Members Only
Plugin Slug:
buddypress-members-only
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Clever Addons for Elementor

Plugin:
Clever Addons for Elementor
Plugin Slug:
cafe-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Social Like Box – Popup – Sidebar Widget

Plugin:
Easy Social Like Box – Popup – Sidebar Widget
Plugin Slug:
cardoza-facebook-like-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Under Construction / Maintenance Mode from Acurax

Plugin:
Under Construction / Maintenance Mode from Acurax
Plugin Slug:
coming-soon-maintenance-mode-from-acurax
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder, Contact Widget

Plugin:
Contact Form Builder, Contact Widget
Plugin Slug:
contact-forms-builder
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cowidgets – Elementor Addons

Plugin:
Cowidgets – Elementor Addons
Plugin Slug:
cowidgets-elementor-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Dash

Plugin:
Custom Dash
Plugin Slug:
custom-dash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Attachments

Plugin:
Download Attachments
Plugin Slug:
download-attachments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyAzon

Plugin:
EasyAzon
Plugin Slug:
easyazon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ElementsReady Addons for Elementor

Plugin:
ElementsReady Addons for Elementor
Plugin Slug:
element-ready-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:
Essential Real Estate
Plugin Slug:
essential-real-estate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:
Essential Real Estate
Plugin Slug:
essential-real-estate
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fluid Notification Bar

Plugin:
Fluid Notification Bar
Plugin Slug:
fluid-notification-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Registration – Contact Form 7

Plugin:
Frontend Registration – Contact Form 7
Plugin Slug:
frontend-registration-contact-form-7
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Responsive Image Gallery, Gallery Album
Plugin Slug:
gallery-album
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google CSE

Plugin:
Google CSE
Plugin Slug:
google-cse
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Insert Post Ads

Plugin:
Insert Post Ads
Plugin Slug:
insert-post-ads
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:
MJ Update History
Plugin Slug:
mj-update-history
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nafeza Prayer Time

Plugin:
Nafeza Prayer Time
Plugin Slug:
nafeza-prayer-time
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ovic Importer

Plugin:
Ovic Importer
Plugin Slug:
ovic-import-demo
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

prettyPhoto

Plugin:
prettyPhoto
Plugin Slug:
prettyphoto
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Restrict for Elementor

Plugin:
Restrict for Elementor
Plugin Slug:
restrict-for-elementor
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rotating Tweets

Plugin:
Rotating Tweets
Plugin Slug:
rotatingtweets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SellKit

Plugin:
SellKit
Plugin Slug:
sellkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple COD Fees for WooCommerce

Plugin:
Simple COD Fees for WooCommerce
Plugin Slug:
simple-cod-fee-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Image Popup Shortcode

Plugin:
Simple Image Popup Shortcode
Plugin Slug:
simple-image-popup-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Link Pages
Plugin Slug:
social-link-pages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Login Lite For WooCommerce

Plugin:
Social Login Lite For WooCommerce
Plugin Slug:
social-login-lite-for-woocommerce
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Startklar Elementor Addons

Plugin:
Startklar Elementor Addons
Plugin Slug:
startklar-elmentor-forms-extwidgets
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Stellissimo Text Box

Plugin:
Stellissimo Text Box
Plugin Slug:
stellissimo-text-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Strategery Migrations

Plugin:
Strategery Migrations
Plugin Slug:
strategery-migrations
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TemplatesNext OnePager

Plugin:
TemplatesNext OnePager
Plugin Slug:
templatesnext-onepager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Moneytizer

Plugin:
The Moneytizer
Plugin Slug:
the-moneytizer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Moneytizer

Plugin:
The Moneytizer
Plugin Slug:
the-moneytizer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin:
Themesflat Addons For Elementor
Plugin Slug:
themesflat-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tooltip CK

Plugin:
Tooltip CK
Plugin Slug:
tooltip-ck
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Upload Fields for WPForms

Plugin:
Upload Fields for WPForms
Plugin Slug:
upload-fields-for-wpforms
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Upunzipper

Plugin:
Upunzipper
Plugin Slug:
upunzipper
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Claudio Sanches

Plugin:
Claudio Sanches
Plugin Slug:
woocommerce-checkout-cielo
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Dropshipping

Plugin:
WooCommerce Dropshipping
Plugin Slug:
woocommerce-dropshipping
Vulnerability:
Content Spoofing
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-DB-Table-Editor

Plugin:
WP-DB-Table-Editor
Plugin Slug:
wp-db-table-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SC filechecker

Plugin:
SC filechecker
Plugin Slug:
wp-file-checker
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Translate

Plugin:
WP Translate
Plugin Slug:
wp-translate
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPUpper Share Buttons

Plugin:
WPUpper Share Buttons
Plugin Slug:
wpupper-share-buttons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Forms for Mailchimp

Plugin:
Easy Forms for Mailchimp
Plugin Slug:
yikes-inc-easy-mailchimp-extender
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.

WPS Hide Login

Plugin Slug:
wps-hide-login
Installations
1,000,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.16.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
800,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.62.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.62.0.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.5.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.977
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.977.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.977
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.977.

WP Reset – Most Advanced WordPress Reset Tool

Plugin Slug:
wp-reset
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.03
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.03.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.24.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.3.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.3.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.277
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.277.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.94.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.1.

Minimal Coming Soon – Coming Soon Page

Plugin Slug:
minimal-coming-soon-maintenance-mode
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.39.

WP Mobile Menu – The Mobile-Friendly Responsive Menu

Plugin Slug:
mobile-menu
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.3.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.13.
Plugin Slug:
uk-cookie-consent
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

WP Force SSL & HTTPS SSL Redirect

Plugin Slug:
wp-force-ssl
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.67
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.67.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.6.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.8.1.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.44.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.44.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.19.

Clever Fox

Plugin:
Clever Fox
Plugin Slug:
clever-fox
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
25.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 25.2.1.

Clever Fox

Plugin:
Clever Fox
Plugin Slug:
clever-fox
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
25.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 25.2.1.
Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

CF7 Google Sheets Connector

Plugin Slug:
cf7-google-sheets-connector
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.10.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Login/Signup Popup ( Inline Form + Woocommerce )

Plugin Slug:
easy-login-woocommerce
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

Login/Signup Popup ( Inline Form + Woocommerce )

Plugin Slug:
easy-login-woocommerce
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.3.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

WP jQuery Lightbox

Plugin Slug:
wp-jquery-lightbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Visualizer: Tables and Charts Manager for WordPress

Plugin Slug:
visualizer
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.2.

WooCommerce Tools

Plugin Slug:
woo-tools
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.10.

YITH WooCommerce Tab Manager

Plugin Slug:
yith-woocommerce-tab-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.35.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.35.1.

Bosa Elementor Addons and Templates for WooCommerce

Plugin Slug:
bosa-elementor-for-woocommerce
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.13.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.25.

One Page Express Companion

Plugin Slug:
one-page-express-companion
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.38
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.38.

Product Addons & Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
Content Injection
Patched in Version:
32.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 32.0.21.

Advanced Woo Labels – Product Labels for WooCommerce

Plugin Slug:
advanced-woo-labels
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.94.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.8.

Countdown, Coming Soon, Maintenance – Countdown & Clock

Plugin Slug:
countdown-builder
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.7.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.8.1.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.4.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.4.

Open Graph

Plugin:
Open Graph
Plugin Slug:
opengraph
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.11.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.3.

Sensei LMS – Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.24.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.0.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons
Installations
10,000+
Vulnerability:
Content Injection
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

Database Cleaner: Clean, Optimize & Repair

Plugin Slug:
database-cleaner
Installations
9,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Materialis Companion

Plugin Slug:
materialis-companion
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.42.

ElasticPress

Plugin Slug:
elasticpress
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.2.

YITH Custom Login

Plugin Slug:
yith-custom-login
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Five Star Restaurant Menu and Food Ordering

Plugin Slug:
food-and-drink-menu
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.17.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.7.
Plugin Slug:
integrate-google-drive
Installations
6,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.3.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.94.

Pure Chat – Live Chat & More!

Plugin Slug:
pure-chat
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.
Plugin Slug:
testimonials-carousel-elementor
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.0.

Wbcom Designs – Custom Font Uploader

Plugin Slug:
custom-font-uploader
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.
Plugin Slug:
new-album-gallery
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Podlove Web Player

Plugin Slug:
podlove-web-player
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.4.

Salon Booking System

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.0.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.0.

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.42
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.42.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.7.

Auto Coupons for WooCommerce

Plugin Slug:
woo-auto-coupons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.15.

Mollie Forms

Plugin Slug:
mollie-forms
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.14.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.6.

PropertyHive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.14.

Simple Ajax Chat – Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20240412
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20240412.

Cards for Beaver Builder

Plugin Slug:
bb-bootstrap-cards
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.31.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.31.2.
Plugin Slug:
ninja-gdpr-compliance
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

RestroPress – Online Food Ordering System

Plugin Slug:
restropress
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.2.

Block for Font Awesome

Plugin Slug:
block-for-font-awesome
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

Kognetiks Chatbot for WordPress

Plugin Slug:
chatbot-chatgpt
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

Copymatic – AI Content Writer & Generator

Plugin Slug:
copymatic
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Dashboard To-Do List

Plugin Slug:
dashboard-to-do-list
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Emergency Password Reset

Plugin Slug:
emergency-password-reset
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.2.

Extra Product Options for WooCommerce

Plugin Slug:
extra-product-options-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.
Plugin Slug:
gamipress-link
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Heateor Social Login WordPress

Plugin Slug:
heateor-social-login
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.33.

Heateor Social Login WordPress

Plugin Slug:
heateor-social-login
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.33.

HT Feed

Plugin:
HT Feed
Plugin Slug:
ht-instagram
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

Market Exporter

Plugin Slug:
market-exporter
Installations
1,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.0.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.20.

Recurring PayPal Donations

Plugin Slug:
recurring-donation
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

WP Docs

Plugin:
WP Docs
Plugin Slug:
wp-docs
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.4.

WP Docs

Plugin:
WP Docs
Plugin Slug:
wp-docs
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

WP Flow Plus

Plugin Slug:
wp-imageflow2
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.3.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.12.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.11.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.14.34.

MelaPress Login Security

Plugin Slug:
melapress-login-security
Installations
600+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin Slug:
attire-blocks
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Music Store – WordPress eCommerce

Plugin Slug:
music-store
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
1.1.14
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.14.

Advanced Custom Fields PRO

Plugin:
Advanced Custom Fields PRO
Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.6.
Plugin:
Boostify Header Footer Builder for Elementor
Plugin Slug:
boostify-header-footer-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Essential Addons for Elementor Pro

Plugin:
Essential Addons for Elementor Pro
Plugin Slug:
essential-addons-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.16.

Widget Options – Extended

Plugin:
Widget Options – Extended
Plugin Slug:
extended-widget-options
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

Widget Options – Extended

Plugin:
Widget Options – Extended
Plugin Slug:
extended-widget-options
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

GP Premium

Plugin:
GP Premium
Plugin Slug:
gp-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

Otter Blocks PRO

Plugin:
Otter Blocks PRO
Plugin Slug:
otter-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.12.

MegaMenu

Plugin:
MegaMenu
Plugin Slug:
stm-megamenu
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.13.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

Checkout Field Editor for WooCommerce (Pro)

Plugin:
Checkout Field Editor for WooCommerce (Pro)
Plugin Slug:
woocommerce-checkout-field-editor-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.3.

Sensei Pro (WC Paid Courses)

Plugin:
Sensei Pro (WC Paid Courses)
Plugin Slug:
woothemes-sensei
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.0.1.24.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.0.1.24.0.

Sensei Pro (WC Paid Courses)

Plugin:
Sensei Pro (WC Paid Courses)
Plugin Slug:
woothemes-sensei
Vulnerability:
Broken Access Control
Patched in Version:
4.24.0.1.24.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.0.1.24.0.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.3.9.

WP Visitors Tracker

Plugin:
WP Visitors Tracker
Plugin Slug:
wp_visitorstracker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.

WPvivid Backup for MainWP

Plugin:
WPvivid Backup for MainWP
Plugin Slug:
wpvivid-backup-mainw
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.33.

WS Form Pro

Plugin:
WS Form Pro
Plugin Slug:
ws-form-pro
Vulnerability:
CSV Injection
Patched in Version:
1.9.218
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.218.

WordPress Themes — 11 Patched / 0 Unpatched

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,260,919
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.51
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.51.

Bloglo

Theme:
Bloglo
Theme Slug:
bloglo
Downloads
61,501
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Event

Theme:
Event
Theme Slug:
event
Downloads
140,599
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Formula

Theme:
Formula
Theme Slug:
formula
Downloads
75,879
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.5.2.

Formula

Theme:
Formula
Theme Slug:
formula
Downloads
75,879
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.5.2.

Idyllic

Theme:
Idyllic
Theme Slug:
idyllic
Downloads
155,730
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Pixgraphy

Theme Slug:
pixgraphy
Downloads
313,930
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Responsive

Theme Slug:
responsive
Downloads
4,505,360
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.1.

Rife Free

Theme Slug:
rife-free
Downloads
691,576
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.20.

Eduma

Theme:
Eduma
Theme Slug:
eduma
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.8.

Radcliffe 2

Theme:
Radcliffe 2
Theme Slug:
radcliffe-2
Vulnerability:
Broken Access Control
Patched in Version:
2.0.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.18.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security