WordPress Vulnerability Report

WordPress Vulnerability Report — August 14, 2024

Since last week, 181 new vulnerabilities emerged in the WordPress ecosystem including 172 plugins and 9 themes. 63 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 181 vulnerabilities have been publicly disclosed. Security patches for 118 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 63 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 114 Patched / 58 Unpatched

PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip

Plugin Slug:
3d-flipbook-dflip-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Slider Feed

Plugin Slug:
instagram-slider-widget
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mediavine Control Panel

Plugin Slug:
mediavine-control-panel
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Create by Mediavine

Plugin Slug:
mediavine-create
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Order Export for WooCommerce

Plugin Slug:
order-export-and-more-for-woocommerce
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin Slug:
kodex-posts-likes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Filr – Secure document library

Plugin Slug:
filr-protection
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

affiliate-toolkit

Plugin:
affiliate-toolkit
Plugin Slug:
affiliate-toolkit-starter
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blox Page Builder

Plugin:
Blox Page Builder
Plugin Slug:
blox-page-builder
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Compute Links
Plugin Slug:
compute-links
Vulnerability:
Remote File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

House Manager

Plugin:
House Manager
Plugin Slug:
house-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:
Leopard – WordPress offload media
Plugin Slug:
leopard-wordpress-offload-media
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:
Leopard – WordPress offload media
Plugin Slug:
leopard-wordpress-offload-media
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Linkify Text

Plugin:
Linkify Text
Plugin Slug:
linkify-text
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Custom CSS PHP & ADS

Plugin:
My Custom CSS PHP & ADS
Plugin Slug:
my-custom-css
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore

Plugin:
MyBookTable Bookstore
Plugin Slug:
mybooktable
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

No Update Nag

Plugin:
No Update Nag
Plugin Slug:
no-update-nag
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Obfuscate Email

Plugin:
Obfuscate Email
Plugin Slug:
obfuscate-email
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opal Membership

Plugin:
Opal Membership
Plugin Slug:
opal-membership
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Opal Membership

Plugin:
Opal Membership
Plugin Slug:
opal-membership
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reveal Template

Plugin:
Reveal Template
Plugin Slug:
reveal-template
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Send Emails with Mandrill

Plugin:
Send Emails with Mandrill
Plugin Slug:
send-emails-with-mandrill
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Store Locator Plus

Plugin:
Store Locator Plus
Plugin Slug:
store-locator-le
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Traffic Manager

Plugin:
Traffic Manager
Plugin Slug:
traffic-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:
Mega Addons For Elementor
Plugin Slug:
ultimate-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Unite Gallery Lite
Plugin Slug:
unite-gallery-lite
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woo Products Widgets For Elementor

Plugin:
Woo Products Widgets For Elementor
Plugin Slug:
woo-products-widgets-for-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bitly

Plugin:
Bitly
Plugin Slug:
wp-bitly
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.39.

Meta Box – WordPress Custom Fields Framework

Plugin Slug:
meta-box
Installations
600,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.11.

Easy Table of Contents

Plugin Slug:
easy-table-of-contents
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.68
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.68.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.97.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.13.

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Lightbox & Modal Popup WordPress Plugin – FooBox

Plugin Slug:
foobox-image-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.32.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.14.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.14.2.

Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Plugin Slug:
hummingbird-performance
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Plugin Slug:
hummingbird-performance
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

Robin image optimizer — save money on image compression

Plugin Slug:
robin-image-optimizer
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Simple Local Avatars

Plugin Slug:
simple-local-avatars
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.11.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.3.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.6.2.

TypeSquare Webfonts for ????????

Plugin Slug:
xserver-typesquare-webfonts
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
SQL Injection
Patched in Version:
4.2.6.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.6.9.4.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.1.

??????? ?????

Plugin Slug:
persian-woocommerce
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.0.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

Ajax Search Lite

Plugin Slug:
ajax-search-lite
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.1.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.26.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.26.9.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

3D FlipBook – PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.15.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.15.7.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.19.

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Category Posts Widget

Plugin Slug:
category-posts
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.17.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.45.

Gutenberg Blocks, Page Builder – ComboBlocks

Plugin Slug:
post-grid
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.87
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.87.

Advanced Cron Manager – debug & control

Plugin Slug:
advanced-cron-manager
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.10.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.16
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.16.

Accept Stripe Payments

Plugin Slug:
stripe-payments
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.87
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.87.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.10.

Fuse Social Floating Sidebar

Plugin Slug:
fuse-social-floating-sidebar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.11.

Slider by 10Web – Responsive Image Slider

Plugin Slug:
slider-wd
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
1.2.58
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.58.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal
Installations
20,000+
Vulnerability:
Open Redirection
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.8.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.8.

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.3.

Gutenberg Page Builder Blocks & Ready-Made Patterns Library for Blogs, Magazines, Newspapers, and Business Websites. Easy One-Click Import, No Coding Needed! – Blockspare

Plugin Slug:
blockspare
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Horizontal scrolling announcements

Plugin Slug:
horizontal-scrolling-announcements
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.

myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

Plugin Slug:
mycred
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Content Injection
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

Participants Database

Plugin Slug:
participants-database
Installations
9,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.5.9.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.9.3.

Selection Lite

Plugin Slug:
selection-lite
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.

Themify Shortcodes

Plugin Slug:
themify-shortcodes
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Chatbot for WordPress by Collect.chat ??

Plugin Slug:
collectchat
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.9.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Installations
7,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

Timeline and History slider

Plugin Slug:
timeline-and-history-slider
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
5,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.8.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.7.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.7.

Organization chart

Plugin Slug:
organization-chart
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.9.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.9.4.8.

Card Elements for Elementor

Plugin Slug:
card-elements-for-elementor
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

FormCraft – Form Builder

Plugin Slug:
formcraft-form-builder
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.11.

Waitlist Woocommerce ( Back in stock notifier )

Plugin Slug:
waitlist-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.0.

Products, Order & Customers Export for WooCommerce

Plugin Slug:
export-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.12.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.4.

WP Search Analytics

Plugin Slug:
search-analytics
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.10.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.11.

Christmasify!

Plugin Slug:
christmasify
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.6.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.53.

Football Pool

Plugin Slug:
football-pool
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.10.

Football Pool

Plugin Slug:
football-pool
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.1.

StreamCast – Radio Player for WordPress

Plugin Slug:
streamcast
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

WP Bannerize Pro

Plugin Slug:
wp-bannerize-pro
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

WPSection

Plugin:
WPSection
Plugin Slug:
wpsection
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Local File Inclusion
Patched in Version:
7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.

Modern Events Calendar

Plugin:
Modern Events Calendar
Plugin Slug:
modern-events-calendar
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.13.0.

Modern Events Calendar Lite

Plugin:
Modern Events Calendar Lite
Plugin Slug:
modern-events-calendar-lite
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.13.0.

Search Filter Pro

Plugin:
Search Filter Pro
Plugin Slug:
search-filter-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.18.

Shortcodes Ultimate Pro

Plugin:
Shortcodes Ultimate Pro
Plugin Slug:
shortcodes-ultimate-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

Term And Category Based Posts Widget

Plugin:
Term And Category Based Posts Widget
Plugin Slug:
term-and-category-based-posts-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.13.

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin:
Docket (WooCommerce Collections / Wishlist / Watchlist)
Plugin Slug:
woocommerce-collections
Vulnerability:
SQL Injection
Patched in Version:
1.7.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.0.

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin:
Docket (WooCommerce Collections / Wishlist / Watchlist)
Plugin Slug:
woocommerce-collections
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
1.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.0.

WooCommerce Multiple Customer Addresses & Shipping

Plugin:
WooCommerce Multiple Customer Addresses & Shipping
Plugin Slug:
woocommerce-multiple-customer-addresses
Vulnerability:
Multiple Vulnerabilities
Patched in Version:
24.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 24.9.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.6.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.7.0.

WordPress Themes — 4 Patched / 5 Unpatched

Busiprof

Theme:
Busiprof
Theme Slug:
busiprof
Downloads
519,822
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Visual Composer Starter

Theme Slug:
visual-composer-starter
Downloads
106,347
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Multipurpose

Theme:
Multipurpose
Theme Slug:
multipurpose
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

News Flash

Theme:
News Flash
Theme Slug:
news-flash
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

The Next LVL

Theme:
The Next LVL
Theme Slug:
the-next
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Orchid Store

Theme Slug:
orchid-store
Downloads
349,182
Vulnerability:
Broken Access Control
Patched in Version:
1.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.7.

MDx

Theme:
MDx
Theme Slug:
MDx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Privilege Escalation
Patched in Version:
5.4.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.12.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security