WordPress Vulnerability Report

WordPress Vulnerability Report — August 21, 2024

Since last week, 183 new vulnerabilities emerged in the WordPress ecosystem including 174 plugins and 9 themes. 53 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 183 vulnerabilities have been publicly disclosed. Security patches for 129 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 53 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 126 Patched / 47 Unpatched

Plugin Slug:
cookie-notice
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Button contact VR

Plugin Slug:
button-contact-vr
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress – Backup Plugin

Plugin Slug:
wp-backitup
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP User Manager – User Profile Builder & Membership

Plugin Slug:
wp-user-manager
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Photo Engine (Media Organizer & Lightroom)

Plugin Slug:
wplr-sync
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Propovoice: All-in-One Client Management System

Plugin Slug:
propovoice
Installations
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Skitter Slideshow

Plugin Slug:
wp-skitter-slideshow
Installations
500+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Admission AppManager

Plugin:
Admission AppManager
Plugin Slug:
admission-appmanager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AdRotate

Plugin:
AdRotate
Plugin Slug:
adrotate1
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:
Bit Form Pro
Plugin Slug:
bitformpro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin:
Smart Online Order for Clover
Plugin Slug:
clover-online-orders
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin:
Smart Online Order for Clover
Plugin Slug:
clover-online-orders
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Compute Links
Plugin Slug:
compute-links
Vulnerability:
Remote File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

DL Robots.txt

Plugin:
DL Robots.txt
Plugin Slug:
dl-robotstxt
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Share

Plugin:
Simple Share
Plugin Slug:
dts-simple-share
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:
Leopard – WordPress offload media
Plugin Slug:
leopard-wordpress-offload-media
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:
Leopard – WordPress offload media
Plugin Slug:
leopard-wordpress-offload-media
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LOGIN AND REGISTRATION ATTEMPTS LIMIT

Plugin:
LOGIN AND REGISTRATION ATTEMPTS LIMIT
Plugin Slug:
login-attempts-limit-wp
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Create by Mediavine

Plugin:
Create by Mediavine
Plugin Slug:
mediavine-create
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore

Plugin:
MyBookTable Bookstore
Plugin Slug:
mybooktable
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Opti Marketing

Plugin:
Opti Marketing
Plugin Slug:
opti-marketing
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Order Export for WooCommerce

Plugin:
Order Export for WooCommerce
Plugin Slug:
order-export-and-more-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Snapshot Backup

Plugin:
Snapshot Backup
Plugin Slug:
snapshot-backup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Store Locator Plus

Plugin:
Store Locator Plus
Plugin Slug:
store-locator-le
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TrueBooker

Plugin:
TrueBooker
Plugin Slug:
truebooker-appointment-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

TrueBooker

Plugin:
TrueBooker
Plugin Slug:
truebooker-appointment-booking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:
Mega Addons For Elementor
Plugin Slug:
ultimate-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

InPost for WooCommerce

Plugin:
InPost for WooCommerce
Plugin Slug:
woo-inpost
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woo Products Widgets For Elementor

Plugin:
Woo Products Widgets For Elementor
Plugin Slug:
woo-products-widgets-for-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.3.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Privilege Escalation
Patched in Version:
6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.4.

Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts

Plugin Slug:
olympus-google-fonts
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.8.

SpeedyCache – Cache, Optimization, Performance

Plugin Slug:
speedycache
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

White Label CMS

Plugin Slug:
white-label-cms
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.5.

PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip

Plugin Slug:
3d-flipbook-dflip-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.56
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.56.

Stripe Payments For WooCommerce by Checkout Plugins

Plugin Slug:
checkout-plugins-stripe-woo
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.

Stripe Payments For WooCommerce by Checkout Plugins

Plugin Slug:
checkout-plugins-stripe-woo
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.2.

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.2.

EmbedPress – Embed PDF, PDF 3D FlipBook, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.10.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.2.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.14.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.14.2.

Insert PHP Code Snippet

Plugin Slug:
insert-php-code-snippet
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.23.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.0.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
12.3.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.3.20.

Asset CleanUp: Page Speed Booster

Plugin Slug:
wp-asset-clean-up
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.4.

Theme My Login

Plugin Slug:
theme-my-login
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.8.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
70,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.1.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.19.

Clone

Plugin:
Clone
Plugin Slug:
wp-clone-by-wp-academy
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.1.

Category Posts Widget

Plugin Slug:
category-posts
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.17.

Download Plugins and Themes in ZIP from Dashboard

Plugin Slug:
download-plugins-dashboard
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.8.

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.88
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.88.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

WP Last Modified Info

Plugin Slug:
wp-last-modified-info
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

HTML5 Video Player – mp4 Video Player Plugin and Block

Plugin Slug:
html5-video-player
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.5.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.32.

HTML5 Video Player – mp4 Video Player Plugin and Block

Plugin Slug:
html5-video-player
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.31.

Void Contact Form 7 Widget For Elementor Page Builder

Plugin Slug:
cf7-widget-elementor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

Child Theme Creator by Orbisius

Plugin Slug:
orbisius-child-theme-creator
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.5.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.24.9.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.5.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

WPBakery Page Builder Addons by Livemesh

Plugin Slug:
addons-for-visual-composer
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.1.

AFI – The Easiest Integration Plugin

Plugin Slug:
advanced-form-integration
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.89.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.89.6.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Cryptocurrency Widgets – Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.

E2Pdf – Export Pdf Tool for WordPress

Plugin Slug:
e2pdf
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.25.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.25.11.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.17.

Generate Images – Magic Post Thumbnail

Plugin Slug:
magic-post-thumbnail
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.8.

Modal Window – create popup modal window

Plugin Slug:
modal-window
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.4.

myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

Plugin Slug:
mycred
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.7.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.3.

myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

Plugin Slug:
mycred
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

WPC Frequently Bought Together for WooCommerce

Plugin Slug:
woo-bought-together
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.0.
Plugin Slug:
bp-profile-search
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.

Plugin Notes Plus

Plugin Slug:
plugin-notes-plus
Installations
8,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

InPost PL

Plugin:
InPost PL
Plugin Slug:
inpost-for-woocommerce
Installations
7,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.5.

Custom Layouts – Post + Product grids made easy

Plugin Slug:
custom-layouts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.12.

GEO my WP

Plugin:
GEO my WP
Plugin Slug:
geo-my-wp
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.5.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.0.2.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
5,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.8.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.7.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.7.

Salon Booking System

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Open Redirection
Patched in Version:
10.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.9.

Void Elementor Post Grid Addon for Elementor Page builder

Plugin Slug:
void-elementor-post-grid-addon-for-elementor-page-builder
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
5.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.3.
Plugin Slug:
wptelegram-widget
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.28.

Clever Addons for Elementor

Plugin Slug:
cafe-lite
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Meta Field Block

Plugin Slug:
display-a-meta-field-as-block
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.14.

Order Tracking – WordPress Status Tracking Plugin

Plugin Slug:
order-tracking
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.13.

Dark Mode for WP Dashboard

Plugin Slug:
dark-mode-for-wp-dashboard
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.9.1.

oik

Plugin:
oik
Plugin Slug:
oik
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.1.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.9.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.1.

JoomSport – for Sports: Team & League, Football, Hockey & more

Plugin Slug:
joomsport-sports-league-results-management
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.7.

Team Showcase

Plugin Slug:
team
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.22.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.22.24.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
23.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 23.1.3.

Custom Field For WP Job Manager

Plugin Slug:
custom-field-for-wp-job-manager
Installations
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.8.

FormFacade – WordPress plugin for Google Forms

Plugin Slug:
formfacade
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.

Invite Anyone

Plugin Slug:
invite-anyone
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.

PDF Builder for WPForms

Plugin Slug:
pdf-builder-for-wpforms
Installations
1,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
1.2.117
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.117.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

WP Bannerize Pro

Plugin Slug:
wp-bannerize-pro
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.33.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.33.21.

Login As Users

Plugin Slug:
login-as-users
Installations
300+
Vulnerability:
Privilege Escalation
Patched in Version:
1.4.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.3.

Grow by Tradedoubler – Advertiser Plugin for WooCommerce

Plugin Slug:
tradedoubler-affiliate-tracker
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.22.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.5.

Sheet to Table Live Sync for Google Sheet

Plugin Slug:
sheet-to-wp-table-for-google-sheet
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

PowerPack for Beaver Builder

Plugin:
PowerPack for Beaver Builder
Plugin Slug:
bbpowerpack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.37.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.37.4.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.6.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.7.

JetBlocks For Elementor

Plugin:
JetBlocks For Elementor
Plugin Slug:
jet-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.12.1.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.20.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.20.1.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.20.1.

JetSearch

Plugin:
JetSearch
Plugin Slug:
jet-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.3.1.

tagDiv Opt-In Builder

Plugin:
tagDiv Opt-In Builder
Plugin Slug:
td-subscription
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Term And Category Based Posts Widget

Plugin:
Term And Category Based Posts Widget
Plugin Slug:
term-and-category-based-posts-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.13.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Broken Authentication
Patched in Version:
2.7.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.6.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.6.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.6.

Zephyr Project Manager

Plugin:
Zephyr Project Manager
Plugin Slug:
zephyr-project-manager
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.3.101
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.101.

WordPress Themes — 3 Patched / 6 Unpatched

Allegiant

Theme Slug:
allegiant
Downloads
387,229
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Bravada

Theme:
Bravada
Theme Slug:
bravada
Downloads
381,818
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Busiprof

Theme:
Busiprof
Theme Slug:
busiprof
Downloads
519,971
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

GivingPress Lite

Theme Slug:
givingpress-lite
Downloads
74,402
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Visual Composer Starter

Theme Slug:
visual-composer-starter
Downloads
106,392
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Purity Of Soul

Theme:
Purity Of Soul
Theme Slug:
purity-of-soul
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hello Agency

Theme Slug:
hello-agency
Downloads
12,106
Vulnerability:
Broken Access Control
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Bricks Builder

Theme:
Bricks Builder
Theme Slug:
bricks
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.2.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security