WordPress Vulnerability Report

WordPress Vulnerability Report — August 7, 2024

Since last week, 108 new vulnerabilities emerged in the WordPress ecosystem including 107 plugins and 1 theme. 17 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 108 vulnerabilities have been publicly disclosed. Security patches for 91 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 17 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 91 Patched / 16 Unpatched

?????? ?????? ??????

Plugin Slug:
pardakht-delkhah
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blox Page Builder

Plugin Slug:
blox-page-builder
Installations
500+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:
Business Card
Plugin Slug:
business-card-by-esterox-100
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CZ Loan Management

Plugin:
CZ Loan Management
Plugin Slug:
cz-loan-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Donation Block For PayPal

Plugin:
Donation Block For PayPal
Plugin Slug:
donations-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin:
Ebook Store
Plugin Slug:
ebook-store
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Remote Content Shortcode

Plugin:
Remote Content Shortcode
Plugin Slug:
remote-content-shortcode
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Tabs

Plugin:
Responsive Tabs
Plugin Slug:
responsive-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Send email only on Reply to My Comment

Plugin:
Send email only on Reply to My Comment
Plugin Slug:
send-email-only-on-reply-to-my-comment
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Send email only on Reply to My Comment

Plugin:
Send email only on Reply to My Comment
Plugin Slug:
send-email-only-on-reply-to-my-comment
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SpiderContacts

Plugin:
SpiderContacts
Plugin Slug:
spider-contacts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Traffic Manager

Plugin:
Traffic Manager
Plugin Slug:
traffic-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Ajax Contact Form

Plugin:
WP Ajax Contact Form
Plugin Slug:
wp-ajax-contact-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Ajax Contact Form

Plugin:
WP Ajax Contact Form
Plugin Slug:
wp-ajax-contact-form
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WpStickyBar

Plugin:
WpStickyBar
Plugin Slug:
wpstickybar-sticky-bar-sticky-header
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WpStickyBar

Plugin:
WpStickyBar
Plugin Slug:
wpstickybar-sticky-bar-sticky-header
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.62.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.62.3.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.98
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.98.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu)

Plugin Slug:
mystickymenu
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
insta-gallery
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.0.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.9.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.9.

WP Mobile Menu – The Mobile-Friendly Responsive Menu

Plugin Slug:
mobile-menu
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Content Injection
Patched in Version:
7.6.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.22.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.5.

File Manager Pro – Filester

Plugin Slug:
filester
Installations
60,000+
Vulnerability:
Settings Change
Patched in Version:
1.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.3.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
60,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.4.2.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.

Better Find and Replace

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.45.

Kubio AI Page Builder

Plugin Slug:
kubio
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Gutenberg Blocks, Page Builder – ComboBlocks

Plugin Slug:
post-grid
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.86
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.86.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.0.

WP-PostRatings

Plugin Slug:
wp-postratings
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.91.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.91.2.

Slider by 10Web – Responsive Image Slider

Plugin Slug:
slider-wd
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.57
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.57.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.24.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.8.

Custom 404 Pro

Plugin Slug:
custom-404-pro
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.2.

Horizontal scrolling announcements

Plugin Slug:
horizontal-scrolling-announcements
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.22.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.34.

Chatbot for WordPress by Collect.chat ??

Plugin Slug:
collectchat
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

Salon Booking System

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
10.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.8.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.9.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.9.4.8.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

TemplateSpare: Quick & Easy WordPress Site Builder – 475+ Ready-Made Demos for News, Blogs, eCommerce, and More. One-Click Import, No Coding Needed

Plugin Slug:
templatespare
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.3.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.1.

Sync Post With Other Site

Plugin Slug:
sync-post-with-other-site
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Photo Engine (Media Organizer & Lightroom)

Plugin Slug:
wplr-sync
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.4.

FundEngine – Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation
Installations
2,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

Black Widgets For Elementor

Plugin Slug:
black-widgets
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Black Widgets For Elementor

Plugin Slug:
black-widgets
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Extensions for Elementor

Plugin Slug:
extensions-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.32.
Plugin Slug:
fulltext-search
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.69.234
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.69.234.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.13.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
0.21.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.21.8.

LiquidPoll – Polls, Surveys, NPS and Feedback Reviews

Plugin Slug:
wp-poll
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.78
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.78.

YayExtra – WooCommerce Extra Product Options

Plugin Slug:
yayextra
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.8.

Filter & Grids

Plugin Slug:
ymc-smart-filter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.3.

Filter & Grids

Plugin Slug:
ymc-smart-filter
Installations
1,000+
Vulnerability:
Broken Authentication
Patched in Version:
2.8.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.34.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.101
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.101.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.99
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.99.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

CTT Expresso para WooCommerce

Plugin Slug:
ctt-expresso-para-woocommerce
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

News Element Elementor Blog Magazine

Plugin Slug:
news-element
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.6.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
30+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Element Pack Pro

Plugin:
Element Pack Pro
Plugin Slug:
bdthemes-element-pack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.9.1.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Broken Access Control
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Local File Inclusion
Patched in Version:
7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.

Paid Memberships Pro – Member Directory Add On

Plugin:
Paid Memberships Pro – Member Directory Add On
Plugin Slug:
pmpro-member-directory
Vulnerability:
SQL Injection
Patched in Version:
1.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.

Pmpro Membership Maps

Plugin:
Pmpro Membership Maps
Plugin Slug:
pmpro-membership-maps
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.

Swift Framework Page Builder

Plugin:
Swift Framework Page Builder
Plugin Slug:
socialdriver-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024.04.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.04.30.

Spectra Pro

Plugin:
Spectra Pro
Plugin Slug:
spectra-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Superfly Menu

Plugin:
Superfly Menu
Plugin Slug:
superfly-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.0.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.30.

Tin Canny Reporting for LearnDash

Plugin:
Tin Canny Reporting for LearnDash
Plugin Slug:
tin-canny-learndash-reporting
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.0.8.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
30.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 30.1.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
30.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 30.2.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Multiple Vulnerabilities
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.2.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.7.0.

WordPress Themes — 0 Patched / 1 Unpatched

Edubin

Theme:
Edubin
Theme Slug:
edubin
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security