In this report, 300 vulnerabilities have been publicly disclosed. Security patches for 168 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 132 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
Say hello to WordPress 6.6 “Dorsey,” named after the legendary American Big Band leader, Tommy Dorsey. Explore the new features and enhancements of WordPress 6.6.
WordPress Plugins — 167 Patched / 118 Unpatched
Genesis Blocks
- Plugin:
- Genesis Blocks
- Plugin Slug:
- genesis-blocks
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3563
Search & Replace
- Plugin:
- Search & Replace
- Plugin Slug:
- search-and-replace
- Installations
- 100,000+
- Vulnerability:
- Deserialization of untrusted data
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38759
VK All in One Expansion Unit
- Plugin:
- VK All in One Expansion Unit
- Plugin Slug:
- vk-all-in-one-expansion-unit
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37956
Titan Anti-spam & Security
- Plugin:
- Titan Anti-spam & Security
- Plugin Slug:
- anti-spam
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38777
Matomo Analytics – Ethical Stats. Powerful Insights.
- Plugin Slug:
- matomo
- Installations
- 80,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38766
Meks Smart Author Widget
- Plugin:
- Meks Smart Author Widget
- Plugin Slug:
- meks-smart-author-widget
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37958
Packlink PRO shipping module
- Plugin:
- Packlink PRO shipping module
- Plugin Slug:
- packlink-pro-shipping
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38740
ReCaptcha Integration for WordPress
- Plugin Slug:
- wp-recaptcha-integration
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37946
Generate PDF using Contact Form 7
- Plugin Slug:
- generate-pdf-using-contact-form-7
- Installations
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-37555
Generate PDF using Contact Form 7
- Plugin Slug:
- generate-pdf-using-contact-form-7
- Installations
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-6317
Panda Video
- Plugin:
- Panda Video
- Plugin Slug:
- pandavideo
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5457
Panda Video
- Plugin:
- Panda Video
- Plugin Slug:
- pandavideo
- Installations
- 4,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-5456
Realtyna Organic IDX plugin + WPL Real Estate
- Plugin Slug:
- real-estate-listing-realtyna-wpl
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-38736
Timeline Module for Beaver Builder
- Plugin Slug:
- timeline-for-beaver-builder
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37919
WP User Switch
- Plugin:
- WP User Switch
- Plugin Slug:
- wp-user-switch
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37560
Admin Dashboard RSS Feed
- Plugin:
- Admin Dashboard RSS Feed
- Plugin Slug:
- admin-dashboard-rss-feed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38725
Google Adsense & Banner Ads by AdsforWP
- Plugin:
- Google Adsense & Banner Ads by AdsforWP
- Plugin Slug:
- ads-for-wp
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38751
AdPush
- Plugin:
- AdPush
- Plugin Slug:
- adsense-plugin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38672
Advanced AJAX Page Loader
- Plugin:
- Advanced AJAX Page Loader
- Plugin Slug:
- advanced-ajax-page-loader
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6310
Advanced post slider
- Plugin:
- Advanced post slider
- Plugin Slug:
- advanced-post-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38750
EleForms
- Plugin:
- EleForms
- Plugin Slug:
- all-contact-form-integration-for-elementor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38748
Amazing Hover Effects
- Plugin:
- Amazing Hover Effects
- Plugin Slug:
- amazing-hover-effects
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38741
Animated Typed JS Shortcode
- Plugin:
- Animated Typed JS Shortcode
- Plugin Slug:
- animated-typed-js-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38679
Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps
- Plugin:
- Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps
- Plugin Slug:
- appmaker-woocommerce-mobile-app-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38680
Arkhe Blocks
- Plugin:
- Arkhe Blocks
- Plugin Slug:
- arkhe-blocks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38675
Attachment File Icons
- Plugin:
- Attachment File Icons
- Plugin Slug:
- attachment-file-icons
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6309
Auto Featured Image (Auto Post Thumbnail)
- Plugin:
- Auto Featured Image (Auto Post Thumbnail)
- Plugin Slug:
- auto-post-thumbnail
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38719
Booking Ultra Pro
- Plugin:
- Booking Ultra Pro
- Plugin Slug:
- booking-ultra-pro
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38717
Booking Ultra Pro
- Plugin:
- Booking Ultra Pro
- Plugin Slug:
- booking-ultra-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38676
Caxton – Create Pro page layouts in Gutenberg
- Plugin:
- Caxton – Create Pro page layouts in Gutenberg
- Plugin Slug:
- caxton
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37948
Cliengo – Chatbot
- Plugin:
- Cliengo – Chatbot
- Plugin Slug:
- cliengo
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37923
Cliengo – Chatbot
- Plugin:
- Cliengo – Chatbot
- Plugin Slug:
- cliengo
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5993
Cliengo – Chatbot
- Plugin:
- Cliengo – Chatbot
- Plugin Slug:
- cliengo
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5992
CodePen Embedded Pens Shortcode
- Plugin:
- CodePen Embedded Pens Shortcode
- Plugin Slug:
- codepen-embedded-pen-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37960
codoc
- Plugin:
- codoc
- Plugin Slug:
- codoc
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37961
Comment Images Reloaded
- Plugin:
- Comment Images Reloaded
- Plugin Slug:
- comment-images-reloaded
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5856
Animated Rotating Words
- Plugin:
- Animated Rotating Words
- Plugin Slug:
- css3-rotating-words
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38753
WPCS
- Plugin:
- WPCS
- Plugin Slug:
- currency-switcher
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38700
Default Thumbnail Plus
- Plugin:
- Default Thumbnail Plus
- Plugin Slug:
- default-thumbnail-plus
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6161
DirectoryPress
- Plugin:
- DirectoryPress
- Plugin Slug:
- directorypress
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38755
Download Button for Elementor
- Plugin:
- Download Button for Elementor
- Plugin Slug:
- download-button-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38718
Easy Pixels
- Plugin:
- Easy Pixels
- Plugin Slug:
- easy-pixels-by-jevnet
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-5479
EazyDocs
- Plugin:
- EazyDocs
- Plugin Slug:
- eazydocs
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38721
EazyDocs
- Plugin:
- EazyDocs
- Plugin Slug:
- eazydocs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38720
Pricing Table
- Plugin:
- Pricing Table
- Plugin Slug:
- elfsight-pricing-table
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4102
Pricing Table
- Plugin:
- Pricing Table
- Plugin Slug:
- elfsight-pricing-table
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4100
Power BI Embedded for WordPress
- Plugin:
- Power BI Embedded for WordPress
- Plugin Slug:
- embed-power-bi
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37959
Event post
- Plugin:
- Event post
- Plugin Slug:
- event-post
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-1375
Event post
- Plugin:
- Event post
- Plugin Slug:
- event-post
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38735
EventON
- Plugin:
- EventON
- Plugin Slug:
- eventon-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-6180
Events Calendar for Google
- Plugin:
- Events Calendar for Google
- Plugin Slug:
- events-calendar-for-google
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38716
ExS Widgets
- Plugin:
- ExS Widgets
- Plugin Slug:
- exs-widgets
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38715
Extensions for Elementor
- Plugin:
- Extensions for Elementor
- Plugin Slug:
- extensions-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4868
XPlainer – WooCommerce Product FAQ
- Plugin:
- XPlainer – WooCommerce Product FAQ
- Plugin Slug:
- faq-for-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5704
XPlainer – WooCommerce Product FAQ
- Plugin:
- XPlainer – WooCommerce Product FAQ
- Plugin Slug:
- faq-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5669
File Manager Advanced Shortcode
- Plugin:
- File Manager Advanced Shortcode
- Plugin Slug:
- file-manager-advanced-shortcode
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2023-7061
WordPress Form Builder Plugin – Gutenberg Forms
- Plugin:
- WordPress Form Builder Plugin – Gutenberg Forms
- Plugin Slug:
- forms-gutenberg
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6313
Fusion
- Plugin:
- Fusion
- Plugin Slug:
- fusion
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37962
SCSS Happy Compiler
- Plugin:
- SCSS Happy Compiler
- Plugin Slug:
- happy-scss-compiler
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5600
HitPay Payment Gateway for WooCommerce
- Plugin:
- HitPay Payment Gateway for WooCommerce
- Plugin Slug:
- hitpay-payment-gateway
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38747
Import Spreadsheets from Microsoft Excel
- Plugin:
- Import Spreadsheets from Microsoft Excel
- Plugin Slug:
- import-spreadsheets-from-microsoft-excel
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-38734
IQ Testimonials
- Plugin:
- IQ Testimonials
- Plugin Slug:
- iq-testimonials
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6314
WooCommerce Report
- Plugin:
- WooCommerce Report
- Plugin Slug:
- ithemelandco-woo-report
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38683
Job Board Manager
- Plugin:
- Job Board Manager
- Plugin Slug:
- job-board-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38722
Just Custom Fields
- Plugin:
- Just Custom Fields
- Plugin Slug:
- just-custom-fields
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6168
Just Custom Fields
- Plugin:
- Just Custom Fields
- Plugin Slug:
- just-custom-fields
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6167
Laposta
- Plugin:
- Laposta
- Plugin Slug:
- laposta
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6574
Light Poll
- Plugin:
- Light Poll
- Plugin Slug:
- light-poll
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6720
Magical Addons For Elementor
- Plugin:
- Magical Addons For Elementor
- Plugin Slug:
- magical-addons-for-elementor
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38730
Magical Addons For Elementor
- Plugin:
- Magical Addons For Elementor
- Plugin Slug:
- magical-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38681
Magical Posts Display – Elementor & Gutenberg Posts Blocks
- Plugin:
- Magical Posts Display – Elementor & Gutenberg Posts Blocks
- Plugin Slug:
- magical-posts-display
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37951
MBE eShip
- Plugin:
- MBE eShip
- Plugin Slug:
- mail-boxes-etc
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38742
MBE eShip
- Plugin:
- MBE eShip
- Plugin Slug:
- mail-boxes-etc
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38729
MBE eShip
- Plugin:
- MBE eShip
- Plugin Slug:
- mail-boxes-etc
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37953
Master Popups
- Plugin:
- Master Popups
- Plugin Slug:
- master-popups-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37950
Meks Video Importer
- Plugin:
- Meks Video Importer
- Plugin Slug:
- meks-video-importer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38733
URL Shortener by MyThemeShop
- Plugin:
- URL Shortener by MyThemeShop
- Plugin Slug:
- mts-url-shortener
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5802
Olive One Click Demo Import
- Plugin:
- Olive One Click Demo Import
- Plugin Slug:
- olive-one-click-demo-import
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38749
OSM – OpenStreetMap
- Plugin:
- OSM – OpenStreetMap
- Plugin Slug:
- osm
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-3604
Payflex Payment Gateway
- Plugin:
- Payflex Payment Gateway
- Plugin Slug:
- payflex-payment-gateway
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-0619
Pie Register
- Plugin:
- Pie Register
- Plugin Slug:
- pie-register
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6069
Plugin Notes Plus
- Plugin:
- Plugin Notes Plus
- Plugin Slug:
- plugin-notes-plus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37561
Post Layouts for Gutenberg
- Plugin:
- Post Layouts for Gutenberg
- Plugin Slug:
- post-layouts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38682
Product Designer
- Plugin:
- Product Designer
- Plugin Slug:
- product-designer
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38726
Product Designer
- Plugin:
- Product Designer
- Plugin Slug:
- product-designer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3608
Plum: Spin Wheel & Email Pop-up
- Plugin:
- Plum: Spin Wheel & Email Pop-up
- Plugin Slug:
- qodeblock
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38744
Plum: Spin Wheel & Email Pop-up
- Plugin:
- Plum: Spin Wheel & Email Pop-up
- Plugin Slug:
- qodeblock
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38743
Coming Soon
- Plugin:
- Coming Soon
- Plugin Slug:
- responsive-coming-soon-page
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38756
REVIEWS.io
- Plugin:
- REVIEWS.io
- Plugin Slug:
- reviewscouk-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38677
ScrollTo Bottom
- Plugin:
- ScrollTo Bottom
- Plugin Slug:
- scrollto-bottom
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6321
ScrollTo Top
- Plugin:
- ScrollTo Top
- Plugin Slug:
- scrollto-top
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6320
Seraphinite Post .DOCX Source
- Plugin:
- Seraphinite Post .DOCX Source
- Plugin Slug:
- seraphinite-post-docx-source
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38728
Seraphinite Post .DOCX Source
- Plugin:
- Seraphinite Post .DOCX Source
- Plugin Slug:
- seraphinite-post-docx-source
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38727
Simple Alert Boxes
- Plugin:
- Simple Alert Boxes
- Plugin Slug:
- simple-alert-boxes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5937
Simple Post Notes
- Plugin:
- Simple Post Notes
- Plugin Slug:
- simple-post-notes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37562
Simple Responsive Slider
- Plugin:
- Simple Responsive Slider
- Plugin Slug:
- simple-responsive-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37954
SKT Addons for Elementor
- Plugin:
- SKT Addons for Elementor
- Plugin Slug:
- skt-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38674
Sky Addons for Elementor
- Plugin:
- Sky Addons for Elementor
- Plugin Slug:
- sky-elementor-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38687
GutSlider – All in One Block Slider
- Plugin:
- GutSlider – All in One Block Slider
- Plugin Slug:
- slider-blocks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37955
Tabs For WPBakery Page Builder
- Plugin:
- Tabs For WPBakery Page Builder
- Plugin Slug:
- tabs-for-visual-composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37936
Taggbox
- Plugin:
- Taggbox
- Plugin Slug:
- taggbox-widget
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38754
TOCHAT.BE
- Plugin:
- TOCHAT.BE
- Plugin Slug:
- tochat-be
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37563
UltraAddons Elementor Lite
- Plugin:
- UltraAddons Elementor Lite
- Plugin Slug:
- ultraaddons-elementor-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4866
User Activity Log Pro
- Plugin:
- User Activity Log Pro
- Plugin Slug:
- user-activity-log-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37929
WappPress
- Plugin:
- WappPress
- Plugin Slug:
- wapppress-builds-android-app-for-website
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38758
Webico Slider Flatsome Addons
- Plugin:
- Webico Slider Flatsome Addons
- Plugin Slug:
- webico-slider-flatsome-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5881
LearnDash LMS – Reports
- Plugin:
- LearnDash LMS – Reports
- Plugin Slug:
- wisdm-reports-for-learndash
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5648
Woocommerce OpenPos
- Plugin:
- Woocommerce OpenPos
- Plugin Slug:
- woocommerce-openpos
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37935
Woocommerce OpenPos
- Plugin:
- Woocommerce OpenPos
- Plugin Slug:
- woocommerce-openpos
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-37933
Woocommerce OpenPos
- Plugin:
- Woocommerce OpenPos
- Plugin Slug:
- woocommerce-openpos
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37932
WooCommerce Predictive Search
- Plugin:
- WooCommerce Predictive Search
- Plugin Slug:
- woocommerce-predictive-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38669
Change From Email
- Plugin:
- Change From Email
- Plugin Slug:
- wp-from-email
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38738
WP GoToWebinar
- Plugin:
- WP GoToWebinar
- Plugin Slug:
- wp-gotowebinar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38671
Multisite Content Copier/Updater
- Plugin:
- Multisite Content Copier/Updater
- Plugin Slug:
- wp-multisite-content-copier
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-38673
WP2Speed Faster
- Plugin:
- WP2Speed Faster
- Plugin Slug:
- wp2speed
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37924
WP2Speed Faster
- Plugin:
- WP2Speed Faster
- Plugin Slug:
- wp2speed
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5810
Recipe Maker For Your Food Blog from Zip Recipes
- Plugin:
- Recipe Maker For Your Food Blog from Zip Recipes
- Plugin Slug:
- zip-recipes
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38688
Zoho Campaigns
- Plugin:
- Zoho Campaigns
- Plugin Slug:
- zoho-campaigns
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38752
Duplicator – Migration & Backup Plugin
- Plugin Slug:
- duplicator
- Installations
- 1,000,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 1.5.10
- Severity Score:
- Medium
- CVE:
- 2024-6210
WPS Hide Login
- Plugin:
- WPS Hide Login
- Plugin Slug:
- wps-hide-login
- Installations
- 1,000,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.9.16.4
- Severity Score:
- Medium
- CVE:
- 2024-6289
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.37
- Severity Score:
- Medium
- CVE:
- 2024-6495
Premium Addons for Elementor
- Plugin:
- Premium Addons for Elementor
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.35
- Severity Score:
- Medium
- CVE:
- 2024-37922
Easy Table of Contents
- Plugin:
- Easy Table of Contents
- Plugin Slug:
- easy-table-of-contents
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.67.1
- Severity Score:
- Medium
- CVE:
- 2024-6334
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
- Plugin Slug:
- nextgen-gallery
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.59.3
- Severity Score:
- Medium
- CVE:
- 2024-5442
SEOPress – On-site SEO
- Plugin:
- SEOPress – On-site SEO
- Plugin Slug:
- wp-seopress
- Installations
- 300,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 7.9
- Severity Score:
- High
- CVE:
- 2024-5488
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 200,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.5.113
- Severity Score:
- Medium
- CVE:
- 2024-6171
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.113
- Severity Score:
- Medium
- CVE:
- 2024-6169
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 200,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.113
- Severity Score:
- High
- CVE:
- 2024-6166
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
- Plugin Slug:
- userfeedback-lite
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.16
- Severity Score:
- High
- CVE:
- 2024-5902
Feeds for YouTube (YouTube video, channel, and gallery plugin)
- Plugin Slug:
- feeds-for-youtube
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.2
- Severity Score:
- Medium
- CVE:
- 2024-6256
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 100,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 2.5.8
- Severity Score:
- Medium
- CVE:
- 2024-38706
Inline Related Posts
- Plugin:
- Inline Related Posts
- Plugin Slug:
- intelly-related-posts
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.0
- Severity Score:
- High
- CVE:
- 2024-5626
WordPress Button Plugin MaxButtons
- Plugin Slug:
- maxbuttons
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.7.8
- Severity Score:
- Medium
- CVE:
- 2024-3026
HUSKY – Products Filter Professional for WooCommerce
- Plugin Slug:
- woocommerce-products-filter
- Installations
- 100,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.3.6.1
- Severity Score:
- Critical
- CVE:
- 2024-6457
EmbedPress – Embed PDF, PDF 3D FlipBook, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor
- Plugin Slug:
- embedpress
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.5
- Severity Score:
- Medium
- CVE:
- 2024-38707
Event Tickets and Registration
- Plugin:
- Event Tickets and Registration
- Plugin Slug:
- event-tickets
- Installations
- 90,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.11.0.5
- Severity Score:
- Medium
- CVE:
- 2024-38762
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.3
- Severity Score:
- Medium
- CVE:
- 2024-37947
Brizy – Page Builder
- Plugin:
- Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.45
- Severity Score:
- High
- CVE:
- 2024-1937
YITH WooCommerce Ajax Product Filter
- Plugin Slug:
- yith-woocommerce-ajax-navigation
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.2.0
- Severity Score:
- Medium
- CVE:
- 2024-37943
Premium Portfolio Features for Phlox theme
- Plugin Slug:
- auxin-portfolio
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.3
- Severity Score:
- Medium
- CVE:
- 2024-3587
Image Hover Effects – Elementor Addon
- Plugin Slug:
- image-hover-effects-addon-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.4
- Severity Score:
- Medium
- CVE:
- 2024-4780
Internal Link Juicer: SEO Auto Linker for WordPress
- Plugin Slug:
- internal-links
- Installations
- 50,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.24.4
- Severity Score:
- Medium
- CVE:
- 2024-37941
Ultimate Blocks – WordPress Blocks Plugin
- Plugin Slug:
- ultimate-blocks
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.9
- Severity Score:
- Medium
- CVE:
- 2024-4655
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
- Plugin Slug:
- wp-rss-aggregator
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.23.12
- Severity Score:
- Medium
- CVE:
- 2024-6621
Ditty – Responsive News Tickers, Sliders, and Lists
- Plugin Slug:
- ditty-news-ticker
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.43
- Severity Score:
- Medium
- CVE:
- 2024-5575
PowerPress Podcasting plugin by Blubrry
- Plugin Slug:
- powerpress
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 11.9.11
- Severity Score:
- Medium
- CVE:
- 2024-6588
Qi Blocks
- Plugin:
- Qi Blocks
- Plugin Slug:
- qi-blocks
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- Medium
- CVE:
- 2024-38712
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
- Plugin Slug:
- quiz-master-next
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.0.5
- Severity Score:
- Medium
- CVE:
- 2024-6025
Social Media Widget
- Plugin:
- Social Media Widget
- Plugin Slug:
- social-media-widget
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.9
- Severity Score:
- Medium
- CVE:
- 2024-0974
FULL – Cliente
- Plugin:
- FULL – Cliente
- Plugin Slug:
- full-customer
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.13
- Severity Score:
- High
- CVE:
- 2024-6447
Index WP MySQL For Speed
- Plugin:
- Index WP MySQL For Speed
- Plugin Slug:
- index-wp-mysql-for-speed
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.18
- Severity Score:
- High
- CVE:
- 2024-4977
Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
- Plugin Slug:
- master-addons
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.6.3
- Severity Score:
- Medium
- CVE:
- 2024-38710
Seriously Simple Podcasting
- Plugin:
- Seriously Simple Podcasting
- Plugin Slug:
- seriously-simple-podcasting
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.0
- Severity Score:
- Medium
- CVE:
- 2024-3751
Team Members
- Plugin:
- Team Members
- Plugin Slug:
- team-members
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.4
- Severity Score:
- Medium
- CVE:
- 2024-38670
WP Popups – WordPress Popup builder
- Plugin Slug:
- wp-popups-lite
- Installations
- 30,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 2.2.0.2
- Severity Score:
- Medium
- CVE:
- 2024-6555
Login by Auth0
- Plugin:
- Login by Auth0
- Plugin Slug:
- auth0
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.1
- Severity Score:
- High
- CVE:
- 2023-6813
Branda – White Label WordPress, Custom Login Page Customizer
- Plugin Slug:
- branda-white-labeling
- Installations
- 20,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 3.4.19
- Severity Score:
- Medium
- CVE:
- 2024-6554
Image Photo Gallery Final Tiles Grid
- Plugin Slug:
- final-tiles-grid-gallery-lite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.0
- Severity Score:
- Medium
- CVE:
- 2024-3710
Form Vibes – Database Manager for Forms
- Plugin Slug:
- form-vibes
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.4.11
- Severity Score:
- High
- CVE:
- 2024-5325
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar
- Plugin Slug:
- mp3-music-player-by-sonaar
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6
- Severity Score:
- Medium
- CVE:
- 2024-5664
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
- Plugin Slug:
- rafflepress
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.12.14
- Severity Score:
- Medium
- CVE:
- 2024-3963
Secure Copy Content Protection and Content Locking
- Plugin Slug:
- secure-copy-content-protection
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.9
- Severity Score:
- Medium
- CVE:
- 2024-6138
Slider by 10Web – Responsive Image Slider
- Plugin Slug:
- slider-wd
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.56
- Severity Score:
- Medium
- CVE:
- 2024-6026
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer
- Plugin Slug:
- smartcrawl-seo
- Installations
- 20,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 3.10.9
- Severity Score:
- Medium
- CVE:
- 2024-6556
User Submitted Posts – Enable Users to Submit Posts from the Front End
- Plugin Slug:
- user-submitted-posts
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 20240516
- Severity Score:
- Medium
- CVE:
- 2024-5002
Wallet for WooCommerce
- Plugin:
- Wallet for WooCommerce
- Plugin Slug:
- woo-wallet
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.5
- Severity Score:
- High
- CVE:
- 2024-6353
Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More
- Plugin Slug:
- woocommerce-wholesale-prices
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.0
- Severity Score:
- Medium
- CVE:
- 2024-38745
WP Accessibility Helper (WAH)
- Plugin:
- WP Accessibility Helper (WAH)
- Plugin Slug:
- wp-accessibility-helper
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 0.6.3
- Severity Score:
- Medium
- CVE:
- 2024-37926
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
- Plugin Slug:
- wp-event-manager
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.44
- Severity Score:
- Medium
- CVE:
- 2024-2691
WordPress File Upload
- Plugin:
- WordPress File Upload
- Plugin Slug:
- wp-file-upload
- Installations
- 20,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 4.24.8
- Severity Score:
- Medium
- CVE:
- 2024-5852
Backup and Staging by WP Time Capsule
- Plugin Slug:
- wp-time-capsule
- Installations
- 20,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.22.21
- Severity Score:
- Critical
- CVE:
- 2024-38770
Goftino
- Plugin:
- Goftino
- Plugin Slug:
- goftino
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7
- Severity Score:
- Medium
- CVE:
- 2024-38697
Gum Elementor Addon
- Plugin:
- Gum Elementor Addon
- Plugin Slug:
- gum-elementor-addon
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2024-37565
Link Library
- Plugin:
- Link Library
- Plugin Slug:
- link-library
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.7.2
- Severity Score:
- High
- CVE:
- 2024-38711
Metorik – Reports & Email Automation for WooCommerce
- Plugin Slug:
- metorik-helper
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.7.2
- Severity Score:
- Medium
- CVE:
- 2024-38691
Product Enquiry for WooCommerce
- Plugin:
- Product Enquiry for WooCommerce
- Plugin Slug:
- product-enquiry-for-woocommerce
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.8
- Severity Score:
- Medium
- CVE:
- 2024-3964
WP Photo Album Plus
- Plugin:
- WP Photo Album Plus
- Plugin Slug:
- wp-photo-album-plus
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.8.02.003
- Severity Score:
- Medium
- CVE:
- 2024-38713
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
- Plugin Slug:
- wp-scheduled-posts
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 5.1.4
- Severity Score:
- Medium
- CVE:
- 2024-6557
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
- Plugin Slug:
- wp-travel-engine
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.2
- Severity Score:
- Medium
- CVE:
- 2024-37944
Backup, Restore and Migrate WordPress Sites With the XCloner Plugin
- Plugin Slug:
- xcloner-backup-and-restore
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.7.4
- Severity Score:
- Medium
- CVE:
- 2024-6559
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
- Plugin:
- WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting
- Plugin Slug:
- erp
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.13.1
- Severity Score:
- High
- CVE:
- 2024-6666
If-So Dynamic Content Personalization
- Plugin Slug:
- if-so
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.0.4
- Severity Score:
- Medium
- CVE:
- 2024-6070
If-So Dynamic Content Personalization
- Plugin Slug:
- if-so
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.0.4
- Severity Score:
- High
- CVE:
- 2024-5713
Get Use APIs – JSON Content Importer
- Plugin Slug:
- json-content-importer
- Installations
- 8,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.6.0
- Severity Score:
- Medium
- CVE:
- 2024-38723
iPanorama 360 – WordPress Virtual Tour Builder
- Plugin Slug:
- ipanorama-360-virtual-tour-builder-lite
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.4
- Severity Score:
- Medium
- CVE:
- 2024-38690
Social Sharing Plugin – Kiwi
- Plugin:
- Social Sharing Plugin – Kiwi
- Plugin Slug:
- kiwi-social-share
- Installations
- 7,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.1.8
- Severity Score:
- Medium
- CVE:
- 2024-3228
ProfileGrid – User Profiles, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 5.9.0
- Severity Score:
- Medium
- CVE:
- 2024-6410
ProfileGrid – User Profiles, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 5.9.0
- Severity Score:
- High
- CVE:
- 2024-6411
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder
- Plugin Slug:
- bit-form
- Installations
- 6,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.13.4
- Severity Score:
- Critical
- CVE:
- 2024-6123
InstaWP Connect – 1-click WP Staging & Migration
- Plugin Slug:
- instawp-connect
- Installations
- 5,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 0.1.0.45
- Severity Score:
- Critical
- CVE:
- 2024-6397
Send Users Email
- Plugin:
- Send Users Email
- Plugin Slug:
- send-users-email
- Installations
- 5,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.5.2
- Severity Score:
- Medium
- CVE:
- 2024-38760
WP Links Page
- Plugin:
- WP Links Page
- Plugin Slug:
- wp-links-page
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.9.6
- Severity Score:
- Medium
- CVE:
- 2024-6465
WP QuickLaTeX
- Plugin:
- WP QuickLaTeX
- Plugin Slug:
- wp-quicklatex
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.7
- Severity Score:
- Medium
- CVE:
- 2024-5472
CM WordPress Search And Replace Plugin
- Plugin Slug:
- cm-on-demand-search-and-replace
- Installations
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.9
- Severity Score:
- Medium
- CVE:
- 2024-5028
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
- 2024-38705
MStore API – Create Native Android & iOS Apps On The Cloud
- Plugin Slug:
- mstore-api
- Installations
- 4,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 4.15.0
- Severity Score:
- Critical
- CVE:
- 2024-6328
Typebot | Create advanced chat experiences without coding
- Plugin Slug:
- typebot
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.1
- Severity Score:
- Medium
- CVE:
- 2024-38757
VikRentCar Car Rental Management System
- Plugin Slug:
- vikrentcar
- Installations
- 4,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2024-1845
Watu Quiz
Zoho CRM Lead Magnet
- Plugin:
- Zoho CRM Lead Magnet
- Plugin Slug:
- zoho-crm-forms
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.8.9
- Severity Score:
- High
- CVE:
- 2024-38696
AForms — Form Builder for Price Calculator & Cost Estimation
- Plugin Slug:
- aforms-form-builder-for-price-calculator-cost-estimation
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.2.7
- Severity Score:
- Medium
- CVE:
- 2024-6565
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder
- Plugin Slug:
- arforms-form-builder
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.8
- Severity Score:
- High
- CVE:
- 2024-37920
ConeBlog – Elementor Blog Widgets
- Plugin Slug:
- coneblog-widgets
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.9
- Severity Score:
- Medium
- CVE:
- 2024-37918
Insert or Embed Articulate Content into WordPress
- Plugin Slug:
- insert-or-embed-articulate-content-into-wordpress
- Installations
- 3,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.3000000024
- Severity Score:
- Critical
- CVE:
- 2024-5630
oik
Spiffy Calendar
- Plugin:
- Spiffy Calendar
- Plugin Slug:
- spiffy-calendar
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.9.12
- Severity Score:
- High
- CVE:
- 2024-38692
Wallet System for WooCommerce – Wallet, Digital Wallet, Cashback, Recharge User Wallets, Partial Payments, Wallet restriction, Refunds
- Plugin Slug:
- wallet-system-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.5.14
- Severity Score:
- High
- CVE:
- 2024-38699
Chained Quiz
- Plugin:
- Chained Quiz
- Plugin Slug:
- chained-quiz
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.2.9
- Severity Score:
- Medium
- CVE:
- 2024-37921
Featured Image Generator
- Plugin:
- Featured Image Generator
- Plugin Slug:
- featured-image-generator
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.3
- Severity Score:
- Medium
- CVE:
- 2024-5677
Glossary
JSON API User
- Plugin:
- JSON API User
- Plugin Slug:
- json-api-user
- Installations
- 2,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.9.4
- Severity Score:
- Critical
- CVE:
- 2024-6624
MakeStories (for Google Web Stories)
- Plugin Slug:
- makestories-helper
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 3.0.4
- Severity Score:
- High
- CVE:
- 2024-38746
Media Hygiene: Remove or Delete Unused Images and More!
- Plugin Slug:
- media-hygiene
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.2
- Severity Score:
- Medium
- CVE:
- 2024-5855
Product Delivery Date for WooCommerce – Lite
- Plugin Slug:
- product-delivery-date-for-woocommerce-lite
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.7.3
- Severity Score:
- Medium
- CVE:
- 2024-38702
Simple Popup Plugin
- Plugin:
- Simple Popup Plugin
- Plugin Slug:
- simple-popup-plugin
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5
- Severity Score:
- Medium
- CVE:
- 2024-38689
SKT Skill Bar
- Plugin:
- SKT Skill Bar
- Plugin Slug:
- skt-skill-bar
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1
- Severity Score:
- Medium
- CVE:
- 2024-38698
SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels)
- Plugin Slug:
- slingblocks
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
- 2024-38684
SVG Block
Web and WooCommerce Addons for WPBakery Builder
- Plugin Slug:
- vc-addons-by-bit14
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.6
- Severity Score:
- Medium
- CVE:
- 2024-6579
Product Table by WBW
- Plugin:
- Product Table by WBW
- Plugin Slug:
- woo-product-tables
- Installations
- 2,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 2.0.2
- Severity Score:
- Critical
- CVE:
- 2024-6365
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into WordPress
- Plugin Slug:
- wp-event-aggregator
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.0
- Severity Score:
- Medium
- CVE:
- 2024-38703
Academy LMS – eLearning and online course solution for WordPress
- Plugin Slug:
- academy
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.5
- Severity Score:
- Medium
- CVE:
- 2024-38701
Blog, Posts and Category Filter for Elementor
- Plugin Slug:
- blog-posts-and-category-for-elementor
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.0
- Severity Score:
- Medium
- CVE:
- 2024-4667
Bradmax Player
- Plugin:
- Bradmax Player
- Plugin Slug:
- bradmax-player
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.28
- Severity Score:
- Medium
- CVE:
- 2024-37957
CM Email Registration Blacklist and Whitelist
- Plugin Slug:
- cm-email-blacklist
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.4.9
- Severity Score:
- Medium
- CVE:
- 2024-5167
WP Fast Total Search – The Power of Indexed Search
- Plugin Slug:
- fulltext-search
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.69.234
- Severity Score:
- Medium
- CVE:
- 2024-38714
GD Rating System
- Plugin:
- GD Rating System
- Plugin Slug:
- gd-rating-system
- Installations
- 1,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.6.1
- Severity Score:
- Medium
- CVE:
- 2024-38709
Gravity Forms: Multiple Form Instances
- Plugin Slug:
- gravity-forms-multiple-form-instances
- Installations
- 1,000+
- Vulnerability:
- Full Path Disclosure (FPD)
- Patched in Version:
- 1.1.2
- Severity Score:
- Medium
- CVE:
- 2024-6550
FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor
- Plugin:
- FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor
- Plugin Slug:
- post-block
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.2
- Severity Score:
- Medium
- CVE:
- 2024-38686
Quotes and Tips by BestWebSoft
- Plugin:
- Quotes and Tips by BestWebSoft
- Plugin Slug:
- quotes-and-tips
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.45
- Severity Score:
- Critical
- CVE:
- 2024-3112
Image Optimizer, Resizer and CDN – Sirv
- Plugin Slug:
- sirv
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.2.8
- Severity Score:
- Medium
- CVE:
- 2024-6392
Squelch Tabs and Accordions Shortcodes
- Plugin Slug:
- squelch-tabs-and-accordions-shortcodes
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.4.9
- Severity Score:
- Medium
- CVE:
- 2024-5946
Team Manager – WordPress Showcase Team Members
- Plugin Slug:
- wp-team-manager
- Installations
- 1,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.1.13
- Severity Score:
- Medium
- CVE:
- 2024-38704
WPBITS Addons For Elementor Page Builder
- Plugin Slug:
- wpbits-addons-for-elementor
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-37945
WPBITS Addons For Elementor Page Builder
- Plugin Slug:
- wpbits-addons-for-elementor
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-4862
BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
- Plugin Slug:
- searchpro
- Installations
- 900+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.7.6
- Severity Score:
- High
- CVE:
- 2024-37942
Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 800+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.6.2
- Severity Score:
- High
- CVE:
- 2024-38708
DN Footer Contacts
- Plugin:
- DN Footer Contacts
- Plugin Slug:
- dn-footer-contacts
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.3
- Severity Score:
- Medium
- CVE:
- 2024-3410
Smart Image Gallery
- Plugin:
- Smart Image Gallery
- Plugin Slug:
- photoshow
- Installations
- 200+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.19
- Severity Score:
- Medium
- CVE:
- 2024-3632
Tournamatch
- Plugin:
- Tournamatch
- Plugin Slug:
- tournamatch
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.1
- Severity Score:
- Medium
- CVE:
- 2024-5644
Tournamatch
- Plugin:
- Tournamatch
- Plugin Slug:
- tournamatch
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.1
- Severity Score:
- Medium
- CVE:
- 2024-5627
Bug Library
- Plugin:
- Bug Library
- Plugin Slug:
- bug-library
- Installations
- 100+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 2.1.1
- Severity Score:
- Critical
- CVE:
- 2024-5450
Embed Peertube Playlist
- Plugin:
- Embed Peertube Playlist
- Plugin Slug:
- embed-peertube-playlist
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.10
- Severity Score:
- Medium
- CVE:
- 2024-4602
Website Content in Page or Post
- Plugin:
- Website Content in Page or Post
- Plugin Slug:
- show-website-content-in-wordpress-page-or-post
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2024.04.09
- Severity Score:
- Medium
- CVE:
- 2024-2430
Hostel
WP Announcement | Dynamic Announcement, Banner, & Countdown Timer for Effective Promotions
- Plugin Slug:
- sp-announcement
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
- CVE:
- 2024-38685
OpenPGP Form Encryption for WordPress
- Plugin Slug:
- openpgp-form-encryption
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-3919
WP Total Branding – Complete branding solution for WordPress
- Plugin Slug:
- wp-total-branding
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3
- Severity Score:
- Medium
- CVE:
- 2024-6625
SULly
SULly
SULly
SULly
Simple Video Directory
- Plugin:
- Simple Video Directory
- Plugin Slug:
- simple-media-directory
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.4
- Severity Score:
- Medium
- CVE:
- 2024-5811
Support SVG – Upload svg files in wordpress without hassle
- Plugin Slug:
- support-svg
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.0
- Severity Score:
- Medium
- CVE:
- 2024-4272
BSK PDF Manager
- Plugin:
- BSK PDF Manager
- Plugin Slug:
- bsk-pdf-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.1
- Severity Score:
- Medium
- CVE:
- 2024-38767
Contact Form 7 Summary and Print
- Plugin:
- Contact Form 7 Summary and Print
- Plugin Slug:
- cf7-summary-and-print
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.6
- Severity Score:
- High
- CVE:
- 2024-38724
EventON
- Plugin:
- EventON
- Plugin Slug:
- eventon-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.15
- Severity Score:
- Medium
- CVE:
- 2024-4752
File Manager Advanced Shortcode
- Plugin:
- File Manager Advanced Shortcode
- Plugin Slug:
- file-manager-advanced-shortcode
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 2.4.1
- Severity Score:
- High
- CVE:
- 2023-7062
Houzez CRM
- Plugin:
- Houzez CRM
- Plugin Slug:
- houzez-crm
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.4.3
- Severity Score:
- High
- CVE:
- 2024-5792
Houzez Theme – Functionality
- Plugin:
- Houzez Theme – Functionality
- Plugin Slug:
- houzez-theme-functionality
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.2.3
- Severity Score:
- High
- CVE:
- 2024-5793
Calendar.online / Kalender.digital
- Plugin:
- Calendar.online / Kalender.digital
- Plugin Slug:
- kalender-digital
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.9
- Severity Score:
- Medium
- CVE:
- 2024-38678
Modern Events Calendar
- Plugin:
- Modern Events Calendar
- Plugin Slug:
- modern-events-calendar
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 7.12.0
- Severity Score:
- High
- CVE:
- 2024-5441
Modern Events Calendar Lite
- Plugin:
- Modern Events Calendar Lite
- Plugin Slug:
- modern-events-calendar-lite
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 7.12.0
- Severity Score:
- High
- CVE:
- 2024-5441
Moloni
- Plugin:
- Moloni
- Plugin Slug:
- moloni
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.0
- Severity Score:
- High
- CVE:
- 2024-38694
PayPlus Payment Gateway
- Plugin:
- PayPlus Payment Gateway
- Plugin Slug:
- payplus-payment-gateway
- Vulnerability:
- SQL Injection
- Patched in Version:
- 7.0.8
- Severity Score:
- High
- CVE:
- 2024-37564
ReDi Restaurant Reservation
- Plugin:
- ReDi Restaurant Reservation
- Plugin Slug:
- redi-restaurant-reservation
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 24.0712
- Severity Score:
- Medium
- CVE:
- 2024-38737
Seraphinite Accelerator (Full, premium)
- Plugin:
- Seraphinite Accelerator (Full, premium)
- Plugin Slug:
- seraphinite-accelerator-ext
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.21.13.1
- Severity Score:
- High
- CVE:
- 2024-37940
Shortcodes Ultimate Pro
- Plugin:
- Shortcodes Ultimate Pro
- Plugin Slug:
- shortcodes-ultimate-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.1.5
- Severity Score:
- Medium
- CVE:
- 2024-4217
FormFlow: WhatsApp & Social Form Builder for Leads
- Plugin Slug:
- simple-form
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.12.2
- Severity Score:
- Medium
- CVE:
- 2024-3113
Swift Framework Page Builder
- Plugin:
- Swift Framework Page Builder
- Plugin Slug:
- socialdriver-framework
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2024.04.30
- Severity Score:
- High
- CVE:
- 2024-2870
Swift Framework Page Builder
- Plugin:
- Swift Framework Page Builder
- Plugin Slug:
- socialdriver-framework
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2024.04.30
- Severity Score:
- Medium
- CVE:
- 2024-2696
Uncanny Automator Pro
- Plugin:
- Uncanny Automator Pro
- Plugin Slug:
- uncanny-automator-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.0.1
- Severity Score:
- High
- CVE:
- 2024-37117
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.5.1
- Severity Score:
- Medium
- CVE:
- 2024-5287
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5284
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5280
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 8.5.5
- Severity Score:
- Medium
- CVE:
- 2024-6075
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.5
- Severity Score:
- High
- CVE:
- 2024-6072
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.7
- Severity Score:
- High
- CVE:
- 2024-5715
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 10.6.6
- Severity Score:
- Medium
- CVE:
- 2024-5080
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.7
- Severity Score:
- High
- CVE:
- 2024-5079
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 10.6.6
- Severity Score:
- High
- CVE:
- 2024-5077
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 10.6.6
- Severity Score:
- Medium
- CVE:
- 2024-5076
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.6
- Severity Score:
- High
- CVE:
- 2024-5074
WP GoToWebinar
- Plugin:
- WP GoToWebinar
- Plugin Slug:
- wp-gotowebinar
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 15.7
- Severity Score:
- Medium
- CVE:
- 2024-38695
Zephyr Project Manager
- Plugin:
- Zephyr Project Manager
- Plugin Slug:
- zephyr-project-manager
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.3.100
- Severity Score:
- High
- CVE:
- 2024-38761
WordPress Themes — 1 Patched / 14 Unpatched
Oceanic
- Theme:
- Oceanic
- Theme Slug:
- oceanic
- Downloads
- 88,451
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38765
OnePress
- Theme:
- OnePress
- Theme Slug:
- onepress
- Downloads
- 2,266,939
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38739
Popularis Verse
- Theme:
- Popularis Verse
- Theme Slug:
- popularis-verse
- Downloads
- 22,912
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38763
Responsive Mobile
- Theme:
- Responsive Mobile
- Theme Slug:
- responsive-mobile
- Downloads
- 240,681
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37949
counterpoint
- Theme:
- counterpoint
- Theme Slug:
- counterpoint
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37559
i-amaze
- Theme:
- i-amaze
- Theme Slug:
- i-amaze
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38731
i-transform
- Theme:
- i-transform
- Theme Slug:
- i-transform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38764
Jobmonster
- Theme:
- Jobmonster
- Theme Slug:
- noo-jobmonster
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-37928
Jobmonster
- Theme:
- Jobmonster
- Theme Slug:
- noo-jobmonster
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-37927
Patricia Blog
- Theme:
- Patricia Blog
- Theme Slug:
- patricia-blog
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-38732
Patricia Lite
- Theme:
- Patricia Lite
- Theme Slug:
- patricia-lite
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37939
Point
- Theme:
- Point
- Theme Slug:
- point
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37931
SmartMag
- Theme:
- SmartMag
- Theme Slug:
- smartmag-responsive-retina-wordpress-magazine
- Vulnerability:
- Multiple Vulnerabilities
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37930
SociallyViral
- Theme:
- SociallyViral
- Theme Slug:
- sociallyviral
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-37938
BuddyBoss Theme
- Theme:
- BuddyBoss Theme
- Theme Slug:
- buddyboss-theme
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.5.01
- Severity Score:
- Medium
- CVE:
- 2024-37925
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
