WordPress Vulnerability Report

WordPress Vulnerability Report — April 10, 2024

Since last week, 200 new vulnerabilities emerged in the WordPress ecosystem, including 1 in WordPress core, 4 in themes, and 195 in plugins. 18 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 200 vulnerabilities have been publicly disclosed. Security patches for 182 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 18 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

WordPress Core

Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.

WordPress Plugins — 177 Patched / 18 Unpatched

User Activity Log

Plugin Slug:
user-activity-log
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
slideshow-gallery
Installations
9,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
slideshow-gallery
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
slideshow-gallery
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bannerlid

Plugin:
Bannerlid
Plugin Slug:
bannerlid
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Auto Poster

Plugin:
Auto Poster
Plugin Slug:
auto-poster
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CGC Maintenance Mode

Plugin:
CGC Maintenance Mode
Plugin Slug:
cgc-maintenance-mode
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Passster – Password Protection

Plugin:
Passster – Password Protection
Plugin Slug:
content-protector
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Login Styler – White Label Admin Login Page for WordPress

Plugin:
Easy Login Styler – White Label Admin Login Page for WordPress
Plugin Slug:
easy-login-styler
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EnvíaloSimple

Plugin:
EnvíaloSimple
Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:
Font Farsi
Plugin Slug:
font-farsi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Global Elementor Buttons

Plugin:
Global Elementor Buttons
Plugin Slug:
global-elementor-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gradient Text Widget for Elementor

Plugin:
Gradient Text Widget for Elementor
Plugin Slug:
gradient-text-widget-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygen
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WordPress Gallery Exporter
Plugin Slug:
wp-gallery-exporter
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
5,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.0.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

File Manager

Plugin Slug:
wp-file-manager
Installations
1,000,000+
Vulnerability:
Path Traversal
Patched in Version:
7.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.6.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.23.

BackWPup – WordPress Backup Plugin

Plugin Slug:
backwpup
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.4.
Plugin Slug:
nextgen-gallery
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.59.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.59.1.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.26.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.32.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.18.

CMB2

Plugin:
CMB2
Plugin Slug:
cmb2
Installations
300,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.11.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.0.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.95
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.95.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.22.

Post Views Counter

Plugin Slug:
post-views-counter
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.
Plugin Slug:
responsive-lightbox
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

WooCommerce Cart Abandonment Recovery

Plugin Slug:
woo-cart-abandonment-recovery
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.27.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.7.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.270
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.270.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

Genesis Blocks

Plugin Slug:
genesis-blocks
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.22.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.2.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
CSV Injection
Patched in Version:
4.22.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.2.

Template Kit – Import

Plugin Slug:
template-kit-import
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.15.

Tracking Code Manager

Plugin Slug:
tracking-code-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Advanced Order Export For WooCommerce

Plugin Slug:
woo-order-export-lite
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.5.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.15.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.9.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.12.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.1.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.4.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.4.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.29.

BoldGrid Easy SEO – Simple and Effective SEO

Plugin Slug:
boldgrid-easy-seo
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.15.

WordPress Tag and Category Manager – AI Autotagger

Plugin Slug:
simple-tags
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.0.

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce

Plugin Slug:
wp-carousel-free
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.9.3.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.4.

Image Watermark

Plugin Slug:
image-watermark
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Hubbub Lite – Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.33.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.33.1.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

SecuPress Free — WordPress Security

Plugin Slug:
secupress
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.2.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite
Installations
40,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.9.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.27.

Easy Google Maps

Plugin Slug:
google-maps-easy
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.11.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.12.

Sumo – Boost Conversion and Sales

Plugin Slug:
sumome
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.35
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.35.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

Ecwid Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.12.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.11.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar
Installations
20,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.

My Calendar

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.24.

Powerkit – Supercharge your WordPress Site

Plugin Slug:
powerkit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.2.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.6.

bunny.net – WordPress CDN Plugin

Plugin Slug:
bunnycdn
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.45.

Favorites

Plugin:
Favorites
Plugin Slug:
favorites
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

LifterLMS – WordPress LMS Plugin for eLearning

Plugin Slug:
lifterlms
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.1.

MailMunch – Grow your Email List

Plugin Slug:
mailmunch
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Subscribe To Comments Reloaded

Plugin Slug:
subscribe-to-comments-reloaded
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
240119
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 240119.

Ultimate Maps by Supsystic

Plugin Slug:
ultimate-maps-by-supsystic
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.17.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.6.03.005
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.6.03.005.

WP Server Health Stats

Plugin Slug:
wp-server-stats
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
9,000+
Vulnerability:
Directory Traversal
Patched in Version:
8.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.1.9.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.8
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.4.8.

Generate Child Theme

Plugin Slug:
generate-child-theme
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WPvivid Backup for MainWP

Plugin Slug:
wpvivid-backup-mainwp
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.34.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.9.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.7.

Announce from the Dashboard

Plugin Slug:
announce-from-the-dashboard
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

WordPress Tooltips

Plugin Slug:
wordpress-tooltips
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.5.9.

WP Sort Order

Plugin Slug:
wp-sort-order
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Edwiser Bridge – WordPress Moodle LMS Integration

Plugin Slug:
edwiser-bridge
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
3.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.4.

JS Help Desk – Best Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

WP-Stateless – Google Cloud Storage

Plugin Slug:
wp-stateless
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.1.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.3.

Custom post types, Custom Fields & more

Plugin Slug:
custom-post-types
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.5.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.1.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.1.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.5.

Products, Order & Customers Export for WooCommerce

Plugin Slug:
export-woocommerce
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Import XML and RSS Feeds

Plugin Slug:
import-xml-feed
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.6.

Multiple Page Generator Plugin – MPG

Plugin Slug:
multiple-pages-generator-by-porthas
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

WP OAuth Server (OAuth Authentication)

Plugin Slug:
oauth2-provider
Installations
3,000+
Vulnerability:
Open Redirection
Patched in Version:
4.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.0.

Premmerce Product Filter for WooCommerce

Plugin Slug:
premmerce-woocommerce-product-filter
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.3.

Super Testimonials

Plugin Slug:
super-testimonial
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

Product Sort and Display for WooCommerce

Plugin Slug:
woocommerce-product-sort-and-display
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Form to Chat App ??

Plugin Slug:
form-to-chat
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Loan Repayment Calculator and Application Form

Plugin Slug:
quick-interest-slider
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.5.

SearchIQ – The Search Solution

Plugin Slug:
searchiq
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.

User Spam Remover

Plugin Slug:
user-spam-remover
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

WooCommerce Checkout Field Editor (Checkout Manager)

Plugin Slug:
woo-checkout-regsiter-field-editor
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.1.

Benchmark Email Lite

Plugin Slug:
benchmark-email-lite
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.7.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.1.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.6.

Creative Addons for Elementor

Plugin Slug:
creative-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

FG Drupal to WordPress

Plugin Slug:
fg-drupal-to-wp
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.71.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.71.0.

Product Designer

Plugin Slug:
product-designer
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.33.

ReDi Restaurant Reservation

Plugin Slug:
redi-restaurant-reservation
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
24.0303
Severity Score:
High
The vulnerability has been patched, so you should update to version 24.0303.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

Transcoder

Plugin:
Transcoder
Plugin Slug:
transcoder
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

RapidLoad 2.2 – Speed Monster in One Plugin

Plugin Slug:
unusedcss
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.2.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.12.

Sharkdropship Dropshipping & Affiliate for for AliExpress

Plugin Slug:
wooshark-aliexpress-importer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.33.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.33.10.

AWP Classifieds

Plugin:
AWP Classifieds
Plugin Slug:
another-wordpress-classifieds-plugin
Vulnerability:
Broken Access Control
Patched in Version:
4.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.

Beaver Themer

Plugin:
Beaver Themer
Plugin Slug:
beaver-themer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.1.

Bricksforge

Plugin:
Bricksforge
Plugin Slug:
bricksforge
Vulnerability:
Settings Change
Patched in Version:
2.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.1.

Bricksforge

Plugin:
Bricksforge
Plugin Slug:
bricksforge
Vulnerability:
Settings Change
Patched in Version:
2.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.1.

Bricksforge

Plugin:
Bricksforge
Plugin Slug:
bricksforge
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Demo My WordPress

Plugin:
Demo My WordPress
Plugin Slug:
demo-my-wordpress
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.0.

Easy Social Share Buttons

Plugin:
Easy Social Share Buttons
Plugin Slug:
easy-social-share-buttons3
Vulnerability:
Broken Access Control
Patched in Version:
9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.5.

Easy Social Share Buttons

Plugin:
Easy Social Share Buttons
Plugin Slug:
easy-social-share-buttons3
Vulnerability:
Local File Inclusion
Patched in Version:
9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.5.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
SQL Injection
Patched in Version:
7.10.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.10.1.

REHub Framework

Plugin:
REHub Framework
Plugin Slug:
rehub-framework
Vulnerability:
SQL Injection
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
Broken Access Control
Patched in Version:
2.25.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.2.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
CSV Injection
Patched in Version:
2.25.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.2.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.

Wholesale For WooCommerce

Plugin:
Wholesale For WooCommerce
Plugin Slug:
woocommerce-wholesale-pricing
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
2.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.1.

WPB Show Core

Plugin:
WPB Show Core
Plugin Slug:
wpb-show-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.

WPB Show Core

Plugin:
WPB Show Core
Plugin Slug:
wpb-show-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.

WordPress Themes — 4 Patched / 0 Unpatched

Hello Elementor

Theme Slug:
hello-elementor
Downloads
6,963,021
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
SQL Injection
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Local File Inclusion
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Local File Inclusion
Patched in Version:
19.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 19.6.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: