WordPress Vulnerability Report

WordPress Vulnerability Report — April 17, 2024

Since last week, 342 new vulnerabilities emerged in the WordPress ecosystem, including 1 in WordPress core, 26 in themes, and 315 in plugins. 88 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 342 vulnerabilities have been publicly disclosed. Security patches for 254 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 88 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.2.

WordPress Plugins — 234 Patched / 81 Unpatched

Product Feed PRO for WooCommerce

Plugin Slug:
woo-product-feed-pro
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

What’s New Generator

Plugin Slug:
whats-new-genarator
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zero Spam for WordPress

Plugin Slug:
zero-spam
Installations
30,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Subscribe2 – Form, Email Subscribers & Newsletters

Plugin Slug:
subscribe2
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leadinfo

Plugin:
Leadinfo
Plugin Slug:
leadinfo
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sync Post With Other Site

Plugin Slug:
sync-post-with-other-site
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Textillate

Plugin Slug:
easy-textillate
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoga Schedule Momoyoga

Plugin Slug:
momoyoga-integration
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bannerlid

Plugin:
Bannerlid
Plugin Slug:
bannerlid
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Access Category Password

Plugin:
Access Category Password
Plugin Slug:
access-category-password
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ads.txt Admin

Plugin:
Ads.txt Admin
Plugin Slug:
ads-txt-admin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Advanced Search
Plugin Slug:
advance-search
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Page Visit Counter

Plugin:
Advanced Page Visit Counter
Plugin Slug:
advanced-page-visit-counter
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post Block – Post Grid for WordPress block editor

Plugin:
Advanced Post Block – Post Grid for WordPress block editor
Plugin Slug:
advanced-post-block
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AIKit

Plugin:
AIKit
Plugin Slug:
aikit-wordpress-ai-writing-assistant-using-gpt3
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Aspose.Words Exporter

Plugin:
Aspose.Words Exporter
Plugin Slug:
aspose-doc-exporter
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:
Shortcodes and extra features for Phlox theme
Plugin Slug:
auxin-elements
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:
Shortcodes and extra features for Phlox theme
Plugin Slug:
auxin-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Before And After

Plugin:
Before And After
Plugin Slug:
before-and-after
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bizcalendar-web

Plugin:
bizcalendar-web
Plugin Slug:
bizcalendar-web
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Block Converter

Plugin:
Bulk Block Converter
Plugin Slug:
bulk-block-converter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Canva – Design beautiful blog graphics

Plugin:
Canva – Design beautiful blog graphics
Plugin Slug:
canva
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CBX Bookmark & Favorite

Plugin:
CBX Bookmark & Favorite
Plugin Slug:
cbxwpbookmark
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Citadela Listing

Plugin:
Citadela Listing
Plugin Slug:
citadela-directory
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Citadela Listing

Plugin:
Citadela Listing
Plugin Slug:
citadela-directory
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Convert Post Types

Plugin:
Convert Post Types
Plugin Slug:
convert-post-types
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crony Cronjob Manager

Plugin:
Crony Cronjob Manager
Plugin Slug:
crony
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Order Statuses for WooCommerce

Plugin:
Custom Order Statuses for WooCommerce
Plugin Slug:
custom-order-statuses-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Customily Product Personalizer

Plugin:
Customily Product Personalizer
Plugin Slug:
customily-v2
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Delete Custom Fields

Plugin:
Delete Custom Fields
Plugin Slug:
delete-custom-fields
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Disable Comments | WPZest

Plugin:
Disable Comments | WPZest
Plugin Slug:
disable-comments-wpz
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy CountDowner

Plugin:
Easy CountDowner
Plugin Slug:
easy-countdowner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Logo
Plugin Slug:
easylogo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EZ Form Calculator

Plugin:
EZ Form Calculator
Plugin Slug:
ez-form-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Filter Custom Fields & Taxonomies Light

Plugin:
Filter Custom Fields & Taxonomies Light
Plugin Slug:
filter-custom-fields-taxonomies-light
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Find Duplicates

Plugin:
Find Duplicates
Plugin Slug:
find-duplicates
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fixed HTML Toolbar

Plugin:
Fixed HTML Toolbar
Plugin Slug:
fixed-html-toolbar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flash Video Player

Plugin:
Flash Video Player
Plugin Slug:
flash-video-player
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:
Font Farsi
Plugin Slug:
font-farsi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook

Plugin:
Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook
Plugin Slug:
forms-to-zapier
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Freshdesk (official)

Plugin:
Freshdesk (official)
Plugin Slug:
freshdesk-support
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kimili Flash Embed

Plugin:
Kimili Flash Embed
Plugin Slug:
kimili-flash-embed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form & Lead Form Elementor Builder

Plugin:
Contact Form & Lead Form Elementor Builder
Plugin Slug:
lead-form-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form & Lead Form Elementor Builder

Plugin:
Contact Form & Lead Form Elementor Builder
Plugin Slug:
lead-form-builder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin:
Libsyn Publisher Hub
Plugin Slug:
libsyn-podcasting
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin:
Libsyn Publisher Hub
Plugin Slug:
libsyn-podcasting
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts for WordPress
Plugin Slug:
microkids-related-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:
MJ Update History
Plugin Slug:
mj-update-history
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ovic Addon Toolkit

Plugin:
Ovic Addon Toolkit
Plugin Slug:
ovic-addon-toolkit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin:
Payment Forms for Paystack
Plugin Slug:
payment-forms-for-paystack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Feed on WooCommerce for Google

Plugin:
Product Feed on WooCommerce for Google
Plugin Slug:
purple-xmls-google-product-feed-for-woocommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Insert Manager (Q2W3 Inc Manager)

Plugin:
Code Insert Manager (Q2W3 Inc Manager)
Plugin Slug:
q2w3-inc-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:
Realtyna Organic IDX plugin
Plugin Slug:
real-estate-listing-realtyna-wpl
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sangar Slider

Plugin:
Sangar Slider
Plugin Slug:
sangar-slider-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shopkeeper Extender

Plugin:
Shopkeeper Extender
Plugin Slug:
shopkeeper-extender
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Matterport Shortcode

Plugin:
WP Matterport Shortcode
Plugin Slug:
shortcode-gallery-for-matterport-showcase
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Short URL

Plugin:
Short URL
Plugin Slug:
shorten-url
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Testimonials Showcase

Plugin:
Simple Testimonials Showcase
Plugin Slug:
simple-testimonials-showcase
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:
Tax Rate Upload
Plugin Slug:
tax-rate-upload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Type Builder (PTB)

Plugin:
Post Type Builder (PTB)
Plugin Slug:
themify-ptb
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Type Builder (PTB)

Plugin:
Post Type Builder (PTB)
Plugin Slug:
themify-ptb
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:
Mega Addons For Elementor
Plugin Slug:
ultimate-addons-for-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Activity Log Pro

Plugin:
User Activity Log Pro
Plugin Slug:
user-activity-log-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Appointment Bookings for Zoom GoogleMeet and more – Wappointment

Plugin:
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
Plugin Slug:
wappointment
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:
WidgetKit
Plugin Slug:
widgetkit-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

2Checkout Payment Gateway for WooCommerce

Plugin:
2Checkout Payment Gateway for WooCommerce
Plugin Slug:
woocommerce-2checkout-payment
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Registration for WooCommerce

Plugin:
Simple Registration for WooCommerce
Plugin Slug:
woocommerce-simple-registration
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP-Cufon

Plugin:
WP-Cufon
Plugin Slug:
wp-cufon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP File Download Light

Plugin:
WP File Download Light
Plugin Slug:
wp-file-download-light
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Radio – Worldwide Online Radio Stations Directory for WordPress

Plugin:
WP Radio – Worldwide Online Radio Stations Directory for WordPress
Plugin Slug:
wp-radio
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Radio – Worldwide Online Radio Stations Directory for WordPress

Plugin:
WP Radio – Worldwide Online Radio Stations Directory for WordPress
Plugin Slug:
wp-radio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Search Keyword Redirect

Plugin:
Search Keyword Redirect
Plugin Slug:
wp-search-keyword-redirect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP TradingView

Plugin:
WP TradingView
Plugin Slug:
wp-tradingview
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin:
WP User Profile Avatar
Plugin Slug:
wp-user-profile-avatar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
5,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

EWWW Image Optimizer

Plugin Slug:
ewww-image-optimizer
Installations
1,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.0.

Smart Slider 3

Plugin Slug:
smart-slider-3
Installations
900,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.23.

Meta Box – WordPress Custom Fields Framework

Plugin Slug:
meta-box
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.4.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.28.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.25.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.25.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.17.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.

BackWPup – WordPress Backup Plugin

Plugin Slug:
backwpup
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.5.
Plugin Slug:
nextgen-gallery
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.59.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.59.1.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.2.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.12.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
400,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
9.0.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.35.

Migration, Backup, Staging – WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations
400,000+
Vulnerability:
PHP Object Injection
Patched in Version:
0.9.100
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.100.

Favicon by RealFaviconGenerator

Plugin Slug:
favicon-by-realfavicongenerator
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.30.

Gutenberg

Plugin:
Gutenberg
Plugin Slug:
gutenberg
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
18.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 18.1.0.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.0.7.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.29.

Smash Balloon Social Post Feed

Plugin Slug:
custom-facebook-feed
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.22.

Ivory Search – WordPress Search Plugin

Plugin Slug:
add-search-to-menu
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.6.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.2.83
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.83.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.0.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Import any XML or CSV File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.4.

Enhanced Media Library

Plugin Slug:
enhanced-media-library
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.10.
Plugin Slug:
remove-footer-credit
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.14.

WPZOOM Social Feed Widget & Block

Plugin Slug:
instagram-widget-by-wpzoom
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.14.

Real Media Library: Media Library Folder & File Manager

Plugin Slug:
real-media-library-lite
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.22.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.12.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.29.

Theme My Login

Plugin Slug:
theme-my-login
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

Clone

Plugin:
Clone
Plugin Slug:
wp-clone-by-wp-academy
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

BoldGrid Easy SEO – Simple and Effective SEO

Plugin Slug:
boldgrid-easy-seo
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.15.

ActiveCampaign – Forms, Site Tracking, Live Chat

Plugin Slug:
activecampaign-subscription-forms
Installations
60,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
8.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.1.15.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.7.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.7.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.3.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.96
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.96.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.47.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.47.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.1.

Redirection

Plugin Slug:
redirect-redirection
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Spotlight Social Feeds [Block, Shortcode, and Widget]

Plugin Slug:
spotlight-social-photo-feeds
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.11.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce

Plugin Slug:
wp-carousel-free
Installations
60,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.4.

Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce

Plugin Slug:
wp-carousel-free
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.4.
Plugin Slug:
carousel-slider
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.
Plugin Slug:
carousel-slider
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.10.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Advanced Cron Manager – debug & control

Plugin Slug:
advanced-cron-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer
Installations
30,000+
Vulnerability:
Unvalidated Redirects and Forwards
Patched in Version:
7.5.45.7212
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.45.7212.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.0.

Login With Ajax – Fast Logins, 2FA, Redirects

Plugin Slug:
login-with-ajax
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Testimonial Slider

Plugin Slug:
testimonial-slider-and-showcase
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.8.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews
Installations
30,000+
Vulnerability:
Unvalidated Redirects and Forwards
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.
Plugin Slug:
beaf-before-and-after-gallery
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

Dashboard Welcome for Elementor

Plugin Slug:
dashboard-welcome-for-elementor
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.12.

Import Users from CSV

Plugin Slug:
import-users-from-csv
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

IP2Location Country Blocker

Plugin Slug:
ip2location-country-blocker
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.34.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.34.3.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

Email Marketing for WooCommerce by Omnisend

Plugin Slug:
omnisend-connect
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.14.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.4.

Powerkit – Supercharge your WordPress Site

Plugin Slug:
powerkit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.2.

Top Bar

Plugin:
Top Bar
Plugin Slug:
top-bar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Top Bar

Plugin:
Top Bar
Plugin Slug:
top-bar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.0.

NextMove Lite – Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.18.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.18.2.

WP Accessibility Helper (WAH)

Plugin Slug:
wp-accessibility-helper
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.2.6.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.5.

bunny.net – WordPress CDN Plugin

Plugin Slug:
bunnycdn
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Language Translate Widget for WordPress – ConveyThis

Plugin Slug:
conveythis-translate
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
224
Severity Score:
High
The vulnerability has been patched, so you should update to version 224.

E2Pdf – Export To Pdf Tool for WordPress

Plugin Slug:
e2pdf
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.23.00
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.23.00.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.29.

eRoom – Zoom Meetings & Webinars

Plugin Slug:
eroom-zoom-meetings-webinar
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.19.

Jobs for WordPress

Plugin Slug:
job-postings
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.6.

LifterLMS – WordPress LMS Plugin for eLearning

Plugin Slug:
lifterlms
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.1.

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.36.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.21.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.0.

Popup by Supsystic

Plugin Slug:
popup-by-supsystic
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.28.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.9.

Simple Post Notes

Plugin Slug:
simple-post-notes
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.7.

Mail logging – WP Mail Catcher

Plugin Slug:
wp-mail-catcher
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.0.

Elements Plus!

Plugin Slug:
elements-plus
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.4.

WooCommerce UPS Shipping – Live Rates and Access Points

Plugin Slug:
flexible-shipping-ups
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5 .

Smart Forms – when you need more than just a contact form

Plugin Slug:
smart-forms
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.94.

Fatal Error Notify

Plugin Slug:
fatal-error-notify
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Unlimited Elementor Inner Sections By BoomDevs

Plugin Slug:
unlimited-elementor-inner-sections-by-boomdevs
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

WPvivid Backup for MainWP

Plugin Slug:
wpvivid-backup-mainwp
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.34.

Finale Lite – Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.18.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.18.1.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.9.

Ultimate Product Catalog

Plugin Slug:
ultimate-product-catalogue
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.16.

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.11.01
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.11.01.

Load More Anything

Plugin Slug:
ajax-load-more-anything
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.
Plugin Slug:
boostify-header-footer-builder
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Country State City Dropdown CF7

Plugin Slug:
country-state-city-auto-dropdown
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.
Plugin Slug:
responsive-gallery-grid
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.11.

Responsive Tabs

Plugin Slug:
responsive-tabs
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.7.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

WP Login and Logout Redirect

Plugin Slug:
wp-login-and-logout-redirect
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Church Content – Sermons, Events and More

Plugin Slug:
church-theme-content
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

GEO my WordPress

Plugin Slug:
geo-my-wp
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Intagrate Lite

Plugin Slug:
instagrate-to-wordpress
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.1.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
4.0.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.14.

WP Client Reports

Plugin Slug:
wp-client-reports
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
5.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.4.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.0.

CP Media Player – Audio Player and Video Player

Plugin Slug:
audio-and-video-player
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Contact Form Plugin

Plugin Slug:
contact-form-lite
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.25.

Marker.io – Visual Website Feedback

Plugin Slug:
marker-io
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

MultiParcels Shipping For WooCommerce

Plugin Slug:
multiparcels-shipping-for-woocommerce
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.16.9.

Account Engagement

Plugin Slug:
pardot
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

WordPress Hosting Benchmark tool

Plugin Slug:
wpbenchmark
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

WPC Grouped Product for WooCommerce

Plugin Slug:
wpc-grouped-product
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Zoho Campaigns

Plugin Slug:
zoho-campaigns
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Zoho Campaigns

Plugin Slug:
zoho-campaigns
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Premmerce Product Filter for WooCommerce

Plugin Slug:
premmerce-woocommerce-product-filter
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.3.

SEO Booster

Plugin Slug:
seo-booster
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.10.

TOP Table Of Contents

Plugin Slug:
top-table-of-contents
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.16.

Extra Product Options Builder for WooCommerce

Plugin Slug:
additional-product-fields-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.105
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.105.

Currency per Product for WooCommerce

Plugin Slug:
currency-per-product-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.
Plugin Slug:
gallery-box
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.34.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.1.0.23
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.1.0.23.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.23.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.1.

Benchmark Email Lite

Plugin Slug:
benchmark-email-lite
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.28.

TempTool [Show Current Template Info]

Plugin Slug:
current-template-name
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.13.

Dashboard To-Do List

Plugin Slug:
dashboard-to-do-list
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

USPS Shipping for WooCommerce – Live Rates

Plugin Slug:
flexible-shipping-usps
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.7.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.17.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.94
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.94.

MihanPanel – User Login , Registration and Dashboard

Plugin Slug:
mihanpanel-lite
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.7.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.

No-Bot Registration

Plugin Slug:
no-bot-registration
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Novelist

Plugin:
Novelist
Plugin Slug:
novelist
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

POEditor

Plugin:
POEditor
Plugin Slug:
poeditor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.9.

ReDi Restaurant Reservation

Plugin Slug:
redi-restaurant-reservation
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
24.0303
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 24.0303.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

Multi Currency For WooCommerce

Plugin Slug:
wc-multi-currency
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

WP Dynamic Keywords Injector

Plugin Slug:
wp-dynamic-keywords-injector
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.22.

MWW Disclaimer Buttons

Plugin Slug:
mww-disclaimer-buttons
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.

Siteimprove

Plugin Slug:
siteimprove
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

Popup Like box – Page Plugin

Plugin Slug:
ays-facebook-popup-likebox
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.3.

F4 Improvements

Plugin Slug:
f4-improvements
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

NPS computy

Plugin Slug:
nps-computy
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

NPS computy

Plugin Slug:
nps-computy
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

Save as Image Plugin by Pdfcrowd

Plugin Slug:
save-as-image-by-pdfcrowd
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

AffiEasy

Plugin:
AffiEasy
Plugin Slug:
affieasy
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

AWP Classifieds

Plugin:
AWP Classifieds
Plugin Slug:
another-wordpress-classifieds-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.

BWL Advanced FAQ Manager

Plugin:
BWL Advanced FAQ Manager
Plugin Slug:
bwl-advanced-faq-manager
Vulnerability:
SQL Injection
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Calendarista Basic Edition

Plugin:
Calendarista Basic Edition
Plugin Slug:
calendarista-basic-edition
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

Digital Publications by Supsystic

Plugin:
Digital Publications by Supsystic
Plugin Slug:
digital-publications-by-supsystic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Essential Grid

Plugin:
Essential Grid
Plugin Slug:
essential-grid
Vulnerability:
Broken Access Control
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.81.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

RestroPress

Plugin:
RestroPress
Plugin Slug:
restropress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.1.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.

Table & Contact Form 7 Database – Tablesome

Plugin:
Table & Contact Form 7 Database – Tablesome
Plugin Slug:
tablesome
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.26.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
SQL Injection
Patched in Version:
29.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 29.7.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
wp-estimation-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.1.76
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.1.76.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
wp-estimation-form
Vulnerability:
Broken Access Control
Patched in Version:
10.1.77
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.1.77.

WP Activity Log Premium

Plugin:
WP Activity Log Premium
Plugin Slug:
wp-security-audit-log-premium
Vulnerability:
SQL Injection
Patched in Version:
4.6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.4.1.

WPB Show Core

Plugin:
WPB Show Core
Plugin Slug:
wpb-show-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.

WPB Show Core

Plugin:
WPB Show Core
Plugin Slug:
wpb-show-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.

WordPress Themes — 19 Patched / 7 Unpatched

Decode

Theme:
Decode
Theme Slug:
decode
Downloads
269,521
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Gridsby

Theme:
Gridsby
Theme Slug:
gridsby
Downloads
288,716
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

GuCherry Blog

Theme Slug:
gucherry-blog
Downloads
136,966
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HappenStance

Theme Slug:
happenstance
Downloads
134,390
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

i-excel

Theme:
i-excel
Theme Slug:
i-excel
Downloads
262,257
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

i-max

Theme:
i-max
Theme Slug:
i-max
Downloads
270,530
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Sensible WP

Theme Slug:
sensible-wp
Downloads
277,690
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,056,299
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

CityLogic

Theme Slug:
citylogic
Downloads
292,720
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.30.

Default Mag

Theme Slug:
default-mag
Downloads
93,066
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Emmet Lite

Theme Slug:
emmet-lite
Downloads
104,881
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Lightning

Theme Slug:
lightning
Downloads
2,240,450
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
15.19.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.19.0.

Namaha

Theme:
Namaha
Theme Slug:
namaha
Downloads
63,477
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.41.

NewsXpress

Theme Slug:
newsxpress
Downloads
11,096
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

Panoramic

Theme Slug:
panoramic
Downloads
614,830
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.57
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.57.

PopularFX

Theme Slug:
popularfx
Downloads
773,374
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Sarada Lite

Theme Slug:
sarada-lite
Downloads
86,466
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Shopstar!

Theme Slug:
shopstar
Downloads
286,946
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.34.

Sliding Door

Theme Slug:
sliding-door
Downloads
537,017
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

Spa and Salon

Theme Slug:
spa-and-salon
Downloads
155,971
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Tainacan Interface

Theme Slug:
tainacan-interface
Downloads
16,543
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.

The Conference

Theme Slug:
the-conference
Downloads
52,521
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

X-T9

Theme:
X-T9
Theme Slug:
x-t9
Downloads
30,187
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.19.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.19.1.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.6.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Broken Access Control
Patched in Version:
8.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.6.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Broken Access Control
Patched in Version:
8.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.4.6.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: