WordPress Vulnerability Report

WordPress Vulnerability Report — April 24, 2024

Since last week, 358 new vulnerabilities emerged in the WordPress ecosystem, including 3 in themes and 355 in plugins. 46 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 358 vulnerabilities have been publicly disclosed. Security patches for 312 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 46 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 310 Patched / 45 Unpatched

What’s New Generator

Plugin Slug:
whats-new-genarator
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zero Spam for WordPress

Plugin Slug:
zero-spam
Installations
30,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Textillate

Plugin Slug:
easy-textillate
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoga Schedule Momoyoga

Plugin Slug:
momoyoga-integration
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QR Code Composer – Automatic QR code Generator

Plugin Slug:
qr-code-composer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Access Category Password

Plugin:
Access Category Password
Plugin Slug:
access-category-password
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Advanced Search
Plugin Slug:
advance-search
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post Block – Post Grid for WordPress block editor

Plugin:
Advanced Post Block – Post Grid for WordPress block editor
Plugin Slug:
advanced-post-block
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:
Shortcodes and extra features for Phlox theme
Plugin Slug:
auxin-elements
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:
Shortcodes and extra features for Phlox theme
Plugin Slug:
auxin-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Block Converter

Plugin:
Bulk Block Converter
Plugin Slug:
bulk-block-converter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Canva – Design beautiful blog graphics

Plugin:
Canva – Design beautiful blog graphics
Plugin Slug:
canva
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Order Statuses for WooCommerce

Plugin:
Custom Order Statuses for WooCommerce
Plugin Slug:
custom-order-statuses-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Delete Custom Fields

Plugin:
Delete Custom Fields
Plugin Slug:
delete-custom-fields
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy CountDowner

Plugin:
Easy CountDowner
Plugin Slug:
easy-countdowner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flash Video Player

Plugin:
Flash Video Player
Plugin Slug:
flash-video-player
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Knight Lab Timeline

Plugin:
Knight Lab Timeline
Plugin Slug:
knight-lab-timelinejs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LoginPress Pro

Plugin:
LoginPress Pro
Plugin Slug:
loginpress-pro
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LoginPress Pro

Plugin:
LoginPress Pro
Plugin Slug:
loginpress-pro
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts for WordPress
Plugin Slug:
microkids-related-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:
MJ Update History
Plugin Slug:
mj-update-history
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ovic Responsive WPBakery

Plugin:
Ovic Responsive WPBakery
Plugin Slug:
ovic-vc-addon
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev CF7 Database

Plugin:
PeproDev CF7 Database
Plugin Slug:
pepro-cf7-database
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Code Insert Manager (Q2W3 Inc Manager)

Plugin:
Code Insert Manager (Q2W3 Inc Manager)
Plugin Slug:
q2w3-inc-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shopkeeper Extender

Plugin:
Shopkeeper Extender
Plugin Slug:
shopkeeper-extender
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:
Shortcode Addons
Plugin Slug:
shortcode-addons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Testimonials Showcase

Plugin:
Simple Testimonials Showcase
Plugin Slug:
simple-testimonials-showcase
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Superfly Menu

Plugin:
Superfly Menu
Plugin Slug:
superfly-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:
Tax Rate Upload
Plugin Slug:
tax-rate-upload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:
Mega Addons For Elementor
Plugin Slug:
ultimate-addons-for-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:
WidgetKit
Plugin Slug:
widgetkit-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

2Checkout Payment Gateway for WooCommerce

Plugin:
2Checkout Payment Gateway for WooCommerce
Plugin Slug:
woocommerce-2checkout-payment
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Registration for WooCommerce

Plugin:
Simple Registration for WooCommerce
Plugin Slug:
woocommerce-simple-registration
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP-Cufon

Plugin:
WP-Cufon
Plugin Slug:
wp-cufon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP File Download Light

Plugin:
WP File Download Light
Plugin Slug:
wp-file-download-light
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP TradingView

Plugin:
WP TradingView
Plugin Slug:
wp-tradingview
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin:
WP User Profile Avatar
Plugin Slug:
wp-user-profile-avatar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:
Z Y N I T H
Plugin Slug:
zynith-seo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Really Simple SSL

Plugin Slug:
really-simple-ssl
Installations
5,000,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
8.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.0.0.

WooCommerce

Plugin Slug:
woocommerce
Installations
5,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.217
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.217.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

Smart Slider 3

Plugin Slug:
smart-slider-3
Installations
900,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.23.

Meta Box – WordPress Custom Fields Framework

Plugin Slug:
meta-box
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.4.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.26.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.5.

Click to Chat – HoliThemes

Plugin Slug:
click-to-chat-for-whatsapp
Installations
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.6.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Migration, Backup, Staging – WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations
400,000+
Vulnerability:
PHP Object Injection
Patched in Version:
0.9.100
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.100.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.972
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.972.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3.95
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.95.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.95
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.95.

FileBird – WordPress Media Library Folders & File Manager

Plugin Slug:
filebird
Installations
200,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.4.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.22.

YITH WooCommerce Compare

Plugin Slug:
yith-woocommerce-compare
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.38.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.38.0.

Ivory Search – WordPress Search Plugin

Plugin Slug:
add-search-to-menu
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.6.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.264
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.264.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.274
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.274.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.30.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.9.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
5.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.4.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.3.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.3.

Enhanced Media Library

Plugin Slug:
enhanced-media-library
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.10.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.5.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
90,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.7.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.9.

VK Block Patterns

Plugin Slug:
vk-block-patterns
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.31.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.1.1.

WP Show Posts

Plugin Slug:
wp-show-posts
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

Backup Migration

Plugin Slug:
backup-backup
Installations
80,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.26.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.3.

WPZOOM Social Feed Widget & Block

Plugin Slug:
instagram-widget-by-wpzoom
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.14.

Real Media Library: Media Library Folder & File Manager

Plugin Slug:
real-media-library-lite
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.22.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.12.

Theme My Login

Plugin Slug:
theme-my-login
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.16.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
70,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

Cornerstone

Plugin Slug:
cornerstone
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.8.1.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.48.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.48.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.47.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.47.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.47.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.47.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.4.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.5.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.3.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

WP 2FA – Two-factor authentication for WordPress

Plugin Slug:
wp-2fa
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.3.

hCaptcha for WordPress

Plugin Slug:
hcaptcha-for-forms-and-more
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.
Plugin Slug:
quick-featured-images
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
13.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.7.1.
Plugin Slug:
carousel-slider
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.
Plugin Slug:
carousel-slider
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.10.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.32.

Simply Static

Plugin Slug:
simply-static
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.4.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.5.

Gutenberg Block Editor Toolkit – EditorsKit

Plugin Slug:
block-options
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.40.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.40.5.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.5.45.7212
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.45.7212.

Slider by 10Web – Responsive Image Slider

Plugin Slug:
slider-wd
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.55
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.55.

Social Sharing Plugin – Social Warfare

Plugin Slug:
social-warfare
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.2.

Testimonial Slider

Plugin Slug:
testimonial-slider-and-showcase
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.8.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews
Installations
30,000+
Vulnerability:
Unvalidated Redirects and Forwards
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

Appointment Hour Booking – WordPress Booking Plugin

Plugin Slug:
appointment-hour-booking
Installations
20,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.4.57
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.57.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.32.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.12.

Pricing Table by Supsystic

Plugin Slug:
pricing-table-by-supsystic
Installations
20,000+
Vulnerability:
Content Injection
Patched in Version:
1.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.13.

Rate My Post – Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

Top Bar

Plugin:
Top Bar
Plugin Slug:
top-bar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription
Installations
20,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
4.0.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.18.

WP Meta SEO

Plugin Slug:
wp-meta-seo
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.5.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.13.

WP Meta SEO

Plugin Slug:
wp-meta-seo
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.13.

Advanced Floating Content Lite

Plugin Slug:
advanced-floating-content-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.9.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.9.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.19.

Language Translate Widget for WordPress – ConveyThis

Plugin Slug:
conveythis-translate
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
224
Severity Score:
High
The vulnerability has been patched, so you should update to version 224.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

Easy Custom Auto Excerpt

Plugin Slug:
easy-custom-auto-excerpt
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.33.
Plugin Slug:
elespare
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

eRoom – Zoom Meetings & Webinars

Plugin Slug:
eroom-zoom-meetings-webinar
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.19.

List Custom Taxonomy Widget

Plugin Slug:
list-custom-taxonomy-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Mega Elements – Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

WPC Frequently Bought Together for WooCommerce

Plugin Slug:
woo-bought-together
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.4.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
9,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.19.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.19.5.

Elements Plus!

Plugin Slug:
elements-plus
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.4.

FG Joomla to WordPress

Plugin Slug:
fg-joomla-to-wordpress
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.21.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.21.0.
Plugin Slug:
gdpr-cookie-consent
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.1.

RomethemeForm For Elementor

Plugin Slug:
romethemeform
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Smart Forms – when you need more than just a contact form

Plugin Slug:
smart-forms
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.94.

WP LinkedIn Auto Publish

Plugin Slug:
wp-linkedin-auto-publish
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.12.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.

WP Social Comments

Plugin Slug:
gs-facebook-comments
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Maintenance Mode

Plugin Slug:
hkdev-maintenance-mode
Installations
8,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.0.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.0.2.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.

Icon Widget

Plugin Slug:
icon-widget
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.0.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.3.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.0.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.4.

Country State City Dropdown CF7

Plugin Slug:
country-state-city-auto-dropdown
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

Easy Property Listings

Plugin Slug:
easy-property-listings
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

EnvíaloSimple: Email Marketing y Newsletters

Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

Image Slider

Plugin Slug:
image-slider-widget
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.127
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.127.

Poll Maker – Best WordPress Poll Plugin

Plugin Slug:
poll-maker
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.9.

Poll Maker – Best WordPress Poll Plugin

Plugin Slug:
poll-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.9.

Responsive Tabs

Plugin Slug:
responsive-tabs
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.7.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.15.

Salon booking system

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.6.3.

TrackShip for WooCommerce

Plugin Slug:
trackship-for-woocommerce
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.6.

Ultimate 410 Gone Status Code

Plugin Slug:
ultimate-410
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
5.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.4.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Embed Google Photos album

Plugin Slug:
embed-google-photos-album-easily
Installations
4,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

RSS Feed Widget

Plugin Slug:
rss-feed-widget
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.8.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system
Installations
4,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.5.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.5.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator
Installations
4,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
3.3.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.0.

WPC Grouped Product for WooCommerce

Plugin Slug:
wpc-grouped-product
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Coupon & Discount Code Reveal Button

Plugin Slug:
coupon-reveal-button
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.2.

WP-FormAssembly

Plugin Slug:
formassembly-web-forms
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

MaxGalleria

Plugin Slug:
maxgalleria
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.3.

Navigation menu as Dropdown Widget

Plugin Slug:
navigation-menu-as-dropdown-widget
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.9.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.6.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.6.

Vision – Image Map Builder

Plugin Slug:
vision
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Widget Post Slider

Plugin Slug:
widget-post-slider
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.6.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.0.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
16.26.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 16.26.6.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
16.26.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 16.26.6.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
3,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
16.26.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.6.

WP Stripe Checkout

Plugin Slug:
wp-stripe-checkout
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.42.

Accessibility Widget

Plugin Slug:
accessibility-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.
Plugin Slug:
advanced-testimonial-carousel-for-elementor
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

All-in-one Like Widget

Plugin Slug:
all-in-one-facebook-like-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.0.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.0.25.

Kattene

Plugin:
Kattene
Plugin Slug:
kattene
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.23.

Mortgage Calculators WP

Plugin Slug:
mortgage-calculators-wp
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.60.

SuperFaktura WooCommerce

Plugin Slug:
woocommerce-superfaktura
Installations
2,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.40.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.40.4.

WP Helper Premium

Plugin Slug:
wp-helper-lite
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.0.

ActiveDEMAND

Plugin Slug:
activedemand
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.2.42
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.2.42.

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

EleForms – All In One Form Integration including DB for Elementor

Plugin Slug:
all-contact-form-integration-for-elementor
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.9.8.

EleForms – All In One Form Integration including DB for Elementor

Plugin Slug:
all-contact-form-integration-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.9.8.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.1.

Attesa Extra

Plugin Slug:
attesa-extra
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Backend Designer

Plugin Slug:
backend-designer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Import Content in WordPress & WooCommerce with Excel

Plugin Slug:
content-excel-importer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.

Culqi

Plugin:
Culqi
Plugin Slug:
culqi-checkout
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.15.

DSGVO Youtube

Plugin Slug:
dsgvo-youtube
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.

USPS Shipping for WooCommerce – Live Rates

Plugin Slug:
flexible-shipping-usps
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.0.

Headline Analyzer

Plugin Slug:
headline-analyzer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.8.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.94
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.94.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.7.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.17.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.

Reviews Plus

Plugin Slug:
reviews-plus
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.
Plugin Slug:
seers-cookie-consent-banner-privacy-policy
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.1.

WooCommerce Shipping Label

Plugin Slug:
shipping-labels-for-woo
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.9.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Poll | Vote | Contest – Best Poll Plugin for WordPress

Plugin Slug:
totalpoll-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.0.

Void Elementor WHMCS Elements For Elementor Page Builder

Plugin Slug:
void-elementor-whmcs-elements
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Multi Currency For WooCommerce

Plugin Slug:
wc-multi-currency
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Order Limit for WooCommerce

Plugin Slug:
wc-order-limit-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP Club Manager – WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

WP Club Manager – WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

WP Dynamic Keywords Injector

Plugin Slug:
wp-dynamic-keywords-injector
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.22.

WP GoToWebinar

Plugin Slug:
wp-gotowebinar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
15.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.1.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.1.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.

WP Smart Import : Import any XML File to WordPress

Plugin Slug:
wp-smart-import
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

WPCal.io – Easy Meeting Scheduler

Plugin Slug:
wpcal
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.5.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

Olive One Click Demo Import

Plugin Slug:
olive-one-click-demo-import
Installations
900+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Language Switcher for Transposh

Plugin Slug:
language-switcher-for-transposh
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.0.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

ShortPixel Critical CSS

Plugin Slug:
shortpixel-critical-css
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.3.

Fixed HTML Toolbar

Plugin Slug:
fixed-html-toolbar
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

NPS computy

Plugin Slug:
nps-computy
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

NPS computy

Plugin Slug:
nps-computy
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
SQL Injection
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Settings Change
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Settings Change
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Arbitrary File Deletion
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

Barcode Scanner with Inventory & Order Manager

Plugin:
Barcode Scanner with Inventory & Order Manager
Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

CBX Bookmark & Favorite

Plugin:
CBX Bookmark & Favorite
Plugin Slug:
cbxwpbookmark
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.22.

Chauffeur Taxi Booking System for WordPress

Plugin:
Chauffeur Taxi Booking System for WordPress
Plugin Slug:
chauffeur-booking-system
Vulnerability:
Broken Authentication
Patched in Version:
7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.

Conversational Forms for ChatBot

Plugin:
Conversational Forms for ChatBot
Plugin Slug:
conversational-forms
Vulnerability:
Arbitrary File Download
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Essential Addons for Elementor Pro

Plugin:
Essential Addons for Elementor Pro
Plugin Slug:
essential-addons-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.12.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.81.

Integrate Google Drive

Plugin:
Integrate Google Drive
Plugin Slug:
integrate-google-drive
Vulnerability:
Broken Access Control
Patched in Version:
1.3.91
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.91.

Integrate Google Drive

Plugin:
Integrate Google Drive
Plugin Slug:
integrate-google-drive
Vulnerability:
Broken Access Control
Patched in Version:
1.3.91
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.91.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

Max Addons Pro for Bricks

Plugin:
Max Addons Pro for Bricks
Plugin Slug:
max-addons-pro-bricks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

Max Addons Pro for Bricks

Plugin:
Max Addons Pro for Bricks
Plugin Slug:
max-addons-pro-bricks
Vulnerability:
Settings Change
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
SQL Injection
Patched in Version:
29.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 29.7.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.93.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.93.0.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
wp-estimation-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.1.76
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.1.76.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
wp-estimation-form
Vulnerability:
Broken Access Control
Patched in Version:
10.1.77
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.1.77.

WP Media Category Management

Plugin:
WP Media Category Management
Plugin Slug:
wp-media-category-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.0.

Wp Staging Pro

Plugin:
Wp Staging Pro
Plugin Slug:
wp-staging-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.0.

WordPress Themes — 2 Patched / 1 Unpatched

GuCherry Blog

Theme Slug:
gucherry-blog
Downloads
137,149
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit
Downloads
457,475
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.117
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.117.

Tainacan Interface

Theme Slug:
tainacan-interface
Downloads
16,620
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security