WordPress Vulnerability Report

WordPress Vulnerability Report — April 3, 2024

Since last week, 255 new vulnerabilities emerged in the WordPress ecosystem, including 3 in themes and 252 in plugins. 77 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 255 vulnerabilities have been publicly disclosed. Security patches for 178 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 77 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5 “Regina” was released on April 2, 2024, as the first major release of 2024. With the new release, you can add and manage fonts across your site, get more from your revisions, play with enhanced background and shadow tools, discover new Data Views, and so much more.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 175 Patched / 77 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin Slug:
pdf-viewer-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GetResponse for WordPress

Plugin Slug:
getresponse-integration
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Plugin Slug:
better-elementor-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoo Slider

Plugin:
Yoo Slider
Plugin Slug:
yoo-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive flipbook

Plugin:
Responsive flipbook
Plugin Slug:
wppdf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Mega Fan Box Widget

Plugin:
WP Twitter Mega Fan Box Widget
Plugin Slug:
wp-twitter-mega-fan-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sponsors

Plugin:
Sponsors
Plugin Slug:
wp-sponsors
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Eggdrop

Plugin:
WP-Eggdrop
Plugin Slug:
wp-eggdrop
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Eggdrop

Plugin:
WP-Eggdrop
Plugin Slug:
wp-eggdrop
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Broken Images

Plugin:
Broken Images
Plugin Slug:
wp-broken-images
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Popup Cart Lite for WooCommerce

Plugin:
Popup Cart Lite for WooCommerce
Plugin Slug:
woocommerce-woocart-popup-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Social Media Share Buttons

Plugin:
Woocommerce Social Media Share Buttons
Plugin Slug:
woocommerce-social-media-share-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bookings Calendar

Plugin:
WooCommerce Bookings Calendar
Plugin Slug:
woo-bookings-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Whizzy

Plugin:
Whizzy
Plugin Slug:
whizzy
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Whizzy

Plugin:
Whizzy
Plugin Slug:
whizzy
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weekly Class Schedule

Plugin:
Weekly Class Schedule
Plugin Slug:
weekly-class-schedule
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

10Web Map Builder for Google Maps

Plugin:
10Web Map Builder for Google Maps
Plugin Slug:
wd-google-maps
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Rights Access Manager

Plugin:
User Rights Access Manager
Plugin Slug:
user-rights-access-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Social Comments – Email Notification & Lazy Load

Plugin:
Ultimate Social Comments – Email Notification & Lazy Load
Plugin Slug:
ultimate-facebook-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Anything

Plugin:
Sticky Anything
Plugin Slug:
toast-stick-anything
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Thumbs Rating

Plugin:
Thumbs Rating
Plugin Slug:
thumbs-rating
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:
Tax Rate Upload
Plugin Slug:
tax-rate-upload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spin 360 deg and 3D Model Viewer

Plugin:
Spin 360 deg and 3D Model Viewer
Plugin Slug:
spin360
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpiderFAQ

Plugin:
SpiderFAQ
Plugin Slug:
spider-faq
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Special Box for Content

Plugin:
Special Box for Content
Plugin Slug:
special-box-for-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Author Bio

Plugin:
Social Author Bio
Plugin Slug:
social-autho-bio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Lightbox slider – Responsive Lightbox Gallery
Plugin Slug:
simple-lightbox-gallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:
Shortcode Addons
Plugin Slug:
shortcode-addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SEO Title Tag

Plugin:
SEO Title Tag
Plugin Slug:
seo-title-tag
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Prenotazioni

Plugin:
Prenotazioni
Plugin Slug:
prenotazioni
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post-Plugin Library

Plugin:
Post-Plugin Library
Plugin Slug:
post-plugin-library
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pocket News Generator

Plugin:
Pocket News Generator
Plugin Slug:
pocket-news-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pocket News Generator

Plugin:
Pocket News Generator
Plugin Slug:
pocket-news-generator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Platinum SEO

Plugin:
Platinum SEO
Plugin Slug:
platinum-seo-pack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

pageMash > Page Management

Plugin:
pageMash > Page Management
Plugin Slug:
pagemash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygen
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

OpenID

Plugin:
OpenID
Plugin Slug:
openid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

News Wall

Plugin:
News Wall
Plugin Slug:
news-wall
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

New Order Notification for Woocommerce

Plugin:
New Order Notification for Woocommerce
Plugin Slug:
new-order-notification-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lordicon Animated Icons

Plugin:
Lordicon Animated Icons
Plugin Slug:
lordicon-interactive-icons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Plugin:
Kanban Boards for WordPress
Plugin Slug:
kanban
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mighty Classic Pros And Cons

Plugin:
Mighty Classic Pros And Cons
Plugin Slug:
joomdev-wp-pros-cons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IP Blocker Lite

Plugin:
IP Blocker Lite
Plugin Slug:
ip-address-blocker
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iFlyChat – WordPress Chat

Plugin:
iFlyChat – WordPress Chat
Plugin Slug:
iflychat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HeartThis

Plugin:
HeartThis
Plugin Slug:
heart-this
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Header Image Slider

Plugin:
Header Image Slider
Plugin Slug:
header-image-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Responsive Image Gallery, Gallery Album
Plugin Slug:
gallery-album
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Responsive Image Gallery, Gallery Album
Plugin Slug:
gallery-album
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Filter Custom Fields & Taxonomies Light

Plugin:
Filter Custom Fields & Taxonomies Light
Plugin Slug:
filter-custom-fields-taxonomies-light
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:
WP ERP
Plugin Slug:
erp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:
WP ERP
Plugin Slug:
erp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:
WP ERP
Plugin Slug:
erp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EnvíaloSimple

Plugin:
EnvíaloSimple
Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

DX-Watermark

Plugin:
DX-Watermark
Plugin Slug:
dx-watermark
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hacklog Down As PDF

Plugin:
Hacklog Down As PDF
Plugin Slug:
down-as-pdf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DD Rating

Plugin:
DD Rating
Plugin Slug:
dd-rating
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Bulk Editor

Plugin:
Custom Field Bulk Editor
Plugin Slug:
custom-field-bulk-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Convert Post Types

Plugin:
Convert Post Types
Plugin Slug:
convert-post-types
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Forms by Cimatti

Plugin:
Contact Forms by Cimatti
Plugin Slug:
contact-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Newsletter

Plugin:
Contact Form 7 Newsletter
Plugin Slug:
contact-form-7-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comic Easel

Plugin:
Comic Easel
Plugin Slug:
comic-easel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Christmas Greetings

Plugin:
Christmas Greetings
Plugin Slug:
christmas-greetings
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chauffeur Taxi Booking System for WordPress

Plugin:
Chauffeur Taxi Booking System for WordPress
Plugin Slug:
chauffeur-booking-system
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Change default login logo,url and title

Plugin:
Change default login logo,url and title
Plugin Slug:
change-default-login-logo-url-and-title
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CGC Maintenance Mode

Plugin:
CGC Maintenance Mode
Plugin Slug:
cgc-maintenance-mode
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Carousel Anything For WPBakery Page Builder
Plugin Slug:
carousel-anything
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Button

Plugin:
Button
Plugin Slug:
button
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Appointment Calendar

Plugin:
Appointment Calendar
Plugin Slug:
appointment-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All In One Redirection

Plugin:
All In One Redirection
Plugin Slug:
all-in-one-redirection-404-pages-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AI Twitter Feeds (Twitter widget & shortcode)

Plugin:
AI Twitter Feeds (Twitter widget & shortcode)
Plugin Slug:
ai-twitter-feeds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aesop Story Engine

Plugin:
Aesop Story Engine
Plugin Slug:
aesop-story-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AdsPlace’r – Ad Manager, Inserter, AdSense Ads

Plugin:
AdsPlace’r – Ad Manager, Inserter, AdSense Ads
Plugin Slug:
adsplacer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Shortcodes Actions And Filters

Plugin:
Add Shortcodes Actions And Filters
Plugin Slug:
add-actions-and-filters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All-In-One Security (AIOS) – Security and Firewall

Plugin Slug:
all-in-one-wp-security-and-firewall
Installations
1,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.7.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.7.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.18.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.2.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.26.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
8.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.1.

CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance
Installations
200,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.11.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.97.

WooCommerce Cart Abandonment Recovery

Plugin Slug:
woo-cart-abandonment-recovery
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.27.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.2.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.3.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.7.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.5.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.270
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.270.

Download Monitor

Plugin Slug:
download-monitor
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.

Genesis Blocks

Plugin Slug:
genesis-blocks
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

List category posts

Plugin Slug:
list-category-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.89.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.89.7.

Meta Tag Manager

Plugin Slug:
meta-tag-manager
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.10.2.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.0.10.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.10.2.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.0.10.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.10.2.

Social Icons Widget & Block by WPZOOM

Plugin Slug:
social-icons-widget-by-wpzoom
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.16.

Stackable – Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.12.

Template Kit – Import

Plugin Slug:
template-kit-import
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.15.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.5.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.3.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.2.

WP Chat App

Plugin Slug:
wp-whatsapp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.7.2.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.7.2.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.7.2.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.

BoldGrid Easy SEO – Simple and Effective SEO

Plugin Slug:
boldgrid-easy-seo
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.14.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
70,000+
Vulnerability:
Path Traversal
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

underConstruction

Plugin Slug:
underconstruction
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.22.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.8.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.9.3.

WordPress Infinite Scroll – Ajax Load More

Plugin Slug:
ajax-load-more
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.2.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Hubbub Lite – Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.33.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.33.1.

Hubbub Lite – Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.33.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.33.2.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

Klarna Payments for WooCommerce

Plugin Slug:
klarna-payments-for-woocommerce
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

SecuPress Free — WordPress Security

Plugin Slug:
secupress
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.2.

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Easy Appointments

Plugin Slug:
easy-appointments
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.19.

Easy Appointments

Plugin Slug:
easy-appointments
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.11.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.19.

Ecwid Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.12.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.11.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.1.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.1.

My Calendar

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.24.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.6.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.8.

Booking Package

Plugin Slug:
booking-package
Installations
10,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.6.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.29.

Favorites

Plugin:
Favorites
Plugin Slug:
favorites
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

LWS Optimize

Plugin Slug:
lws-optimize
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Mang Board WP

Plugin Slug:
mangboard
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Simple Revisions Delete

Plugin Slug:
simple-revisions-delete
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

VS Contact Form

Plugin Slug:
very-simple-contact-form
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
14.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.8.

140+ Widgets | Best Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
9,000+
Vulnerability:
SQL Injection
Patched in Version:
8.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.8.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.3.

Collect.chat – Chatbot ??

Plugin Slug:
collectchat
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

Finale Lite – Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount
Installations
7,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.18.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.18.1.

Hash Elements

Plugin Slug:
hash-elements
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.3.

The Plus Blocks for Block Editor | Gutenberg

Plugin Slug:
the-plus-addons-for-block-editor
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.6.

wp-forecast

Plugin Slug:
wp-forecast
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.3.

Announce from the Dashboard

Plugin Slug:
announce-from-the-dashboard
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Better Elementor Addons

Plugin Slug:
better-elementor-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

JCH Optimize

Plugin Slug:
jch-optimize
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

Salon booking system

Plugin Slug:
salon-booking-system
Installations
6,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
9.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.5.1.

Sliced Invoices – WordPress Invoice Plugin

Plugin Slug:
sliced-invoices
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

Beaver Builder Addons by WPZOOM

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Booking Activities

Plugin Slug:
booking-activities
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.15.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.15.20.

Paid Memberships Pro – Mailchimp Add On

Plugin Slug:
pmpro-mailchimp
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

B Slider – Slider for your block editor

Plugin Slug:
b-slider
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.13.
Plugin Slug:
remove-old-slugspermalinks
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Builderall Builder for WordPress

Plugin Slug:
builderall-cheetah-for-wp
Installations
3,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.13.

Landingi Landing Pages

Plugin Slug:
landingi-landing-pages
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

Move Addons for Elementor

Plugin Slug:
move-addons
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.11.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.10.

Themify Event Post

Plugin Slug:
themify-event-post
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Product Sort and Display for WooCommerce

Plugin Slug:
woocommerce-product-sort-and-display
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.5.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Layouts for Elementor

Plugin Slug:
layouts-for-elementor
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.

WP Responsive Tabs horizontal vertical and accordion Tabs

Plugin Slug:
responsive-horizontal-vertical-and-accordion-tabs
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.1.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.18.

RT Easy Builder – Advanced addons for Elementor

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

WP Express Checkout (Accept PayPal Payments Easily)

Plugin Slug:
wp-express-checkout
Installations
2,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
2.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.8.

WPC Badge Management for WooCommerce

Plugin Slug:
wpc-badge-management
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

WordPress Page Builder – Zion Builder

Plugin Slug:
zionbuilder
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.10.

Zotpress

Plugin:
Zotpress
Plugin Slug:
zotpress
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
7.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.8.

Announcement & Notification Banner – Bulletin

Plugin Slug:
bulletin-announcements
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.0.

Geo Controller

Plugin Slug:
cf-geoplugin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.5.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.19.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.8.

Creative Addons for Elementor

Plugin Slug:
creative-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

WPCS – WordPress Currency Switcher Professional

Plugin Slug:
currency-switcher
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.2.

Easy Form Builder

Plugin Slug:
easy-form-builder
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
3.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.5.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.48
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.48.

FG PrestaShop to WooCommerce

Plugin Slug:
fg-prestashop-to-woocommerce
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.47.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.47.0.

Web Icons

Plugin:
Web Icons
Plugin Slug:
icon
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.11.

OSS Aliyun

Plugin:
OSS Aliyun
Plugin Slug:
oss-aliyun
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.11.

Paid Memberships Pro – Payfast Gateway Add On

Plugin Slug:
pmpro-payfast
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Print Page block – Print the entire page or Section.

Plugin Slug:
print-page
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.20.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.20.8.

Tumult Hype Animations

Plugin Slug:
tumult-hype-animations
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.12.

Tumult Hype Animations

Plugin Slug:
tumult-hype-animations
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.12.

Sharkdropship Dropshipping & Affiliate for for AliExpress

Plugin Slug:
wooshark-aliexpress-importer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

WordPress CRM Plugin – WP-CRM System

Plugin Slug:
wp-crm-system
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.9.1.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.2.

DELUCKS SEO

Plugin Slug:
delucks-seo
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.5.

Creative Image Slider – Responsive Slider Plugin

Plugin Slug:
creative-image-slider
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.0.

YITH WooCommerce Account Funds Premium

Plugin:
YITH WooCommerce Account Funds Premium
Plugin Slug:
yith-woocommerce-account-funds-premium
Vulnerability:
Broken Access Control
Patched in Version:
1.34.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.34.0.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
wp-estimation-form
Vulnerability:
SQL Injection
Patched in Version:
10.1.76
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.1.76.

Wholesale For WooCommerce

Plugin:
Wholesale For WooCommerce
Plugin Slug:
woocommerce-wholesale-pricing
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Slider by Supsystic

Plugin:
Slider by Supsystic
Plugin Slug:
slider-by-supsystic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.11.

REHub Framework

Plugin:
REHub Framework
Plugin Slug:
rehub-framework
Vulnerability:
SQL Injection
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Limit Attempts by BestWebSoft

Plugin:
Limit Attempts by BestWebSoft
Plugin Slug:
limit-attempts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
SQL Injection
Patched in Version:
7.10.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.10.1.

WP ERP

Plugin:
WP ERP
Plugin Slug:
erp
Vulnerability:
SQL Injection
Patched in Version:
1.30.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.30.0.

Calendarista Basic Edition

Plugin:
Calendarista Basic Edition
Plugin Slug:
calendarista-basic-edition
Vulnerability:
Broken Access Control
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

WordPress Themes — 3 Patched / 0 Unpatched

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
SQL Injection
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Local File Inclusion
Patched in Version:
19.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Local File Inclusion
Patched in Version:
19.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 19.6.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: