WordPress Security

WordPress Vulnerability Report — December 13, 2023

Since our last report, 110 new vulnerabilities have been publicly disclosed. Security patches for 49 plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Dan Knauss

Since our last report, 110 new vulnerabilities have been publicly disclosed. Security patches for 49 plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 61 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 49 Patched / 61 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Login

Plugin Slug:
custom-login
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login With Ajax

Plugin Slug:
login-with-ajax
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Media Feather | social media sharing

Plugin Slug:
social-media-feather
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations:
30,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LiveChat – WP live chat plugin for WordPress

Plugin Slug:
wp-live-chat-software-for-wordpress
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Timeline Widget

Plugin Slug:
3r-elementor-timeline-widget
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Annual Archive

Plugin Slug:
anual-archive
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rocket Maintenance Mode & Coming Soon Page

Plugin Slug:
rocket-maintenance-mode
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Author Avatars List/Block

Plugin Slug:
author-avatars
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alt Manager

Plugin Slug:
alt-manager
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type Page Template

Plugin Slug:
custom-post-type-page-template
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

First Order Discount Woocommerce

Plugin Slug:
first-order-discount-woocommerce
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Enquiry for WooCommerce

Plugin Slug:
gm-woocommerce-quote-popup
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Redirects

Plugin:
Redirects
Plugin Slug:
redirects
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Currency For WooCommerce

Plugin Slug:
wc-multi-currency
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPPerformanceTester

Plugin Slug:
wpperformancetester
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alma – Pay in installments or later for WooCommerce

Plugin Slug:
alma-gateway-for-woocommerce
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Menu Bar Cart Icon For WooCommerce By Binary Carpenter

Plugin Slug:
bc-menu-cart-woo
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block for Font Awesome

Plugin Slug:
block-for-font-awesome
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Edit Post Titles

Plugin Slug:
bulk-edit-post-titles
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Slick Slider WordPress

Plugin Slug:
responsive-slick-slider
Installations:
1,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Square Thumbnails

Plugin Slug:
square-thumbnails
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPsoonOnlinePage

Plugin Slug:
wp-soononline-page
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SharkDropship & Affiliate for AliExpress, eBay, Amazon, Etsy

Plugin Slug:
woo-aliexpress-dropshipping
Installations:
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Photo Album Plus

Plugin:
WP Photo Album Plus
Plugin Slug:
wp-photo-album-plus
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Photo Album Plus

Plugin:
WP Photo Album Plus
Plugin Slug:
wp-photo-album-plus
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Photo Album Plus

Plugin:
WP Photo Album Plus
Plugin Slug:
wp-photo-album-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooDiscuz – WooCommerce Comments

Plugin:
WooDiscuz – WooCommerce Comments
Plugin Slug:
woodiscuz-woocommerce-comments
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Webflow Pages

Plugin:
Webflow Pages
Plugin Slug:
webflow-pages
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WappPress

Plugin:
WappPress
Plugin Slug:
wapppress-builds-android-app-for-website
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Symbiostock Lite

Plugin:
Symbiostock Lite
Plugin Slug:
symbiostock
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sayfa Sayaç

Plugin:
Sayfa Sayaç
Plugin Slug:
sayfa-sayac
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sayfa Sayaç

Plugin:
Sayfa Sayaç
Plugin Slug:
sayfa-sayac
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PayTR Taksit Tablosu

Plugin:
PayTR Taksit Tablosu
Plugin Slug:
paytr-taksit-tablosu-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Partdo Core

Plugin:
Partdo Core
Plugin Slug:
partdo-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Optin Forms

Plugin:
Optin Forms
Plugin Slug:
optin-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Medibazar Core

Plugin:
Medibazar Core
Plugin Slug:
medibazar-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Smart External Link Click Monitor [Link Log]
Plugin Slug:
link-log
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Smart External Link Click Monitor [Link Log]
Plugin Slug:
link-log
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Genesis Simple Love

Plugin:
Genesis Simple Love
Plugin Slug:
genesis-simple-love
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Furnob Core

Plugin:
Furnob Core
Plugin Slug:
furnob-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flexible Woocommerce Checkout Field Editor

Plugin:
Flexible Woocommerce Checkout Field Editor
Plugin Slug:
flexible-woocommerce-checkout-field-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fix My Feed RSS Repair

Plugin:
Fix My Feed RSS Repair
Plugin Slug:
fix-my-feed-rss-repair
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Digital Publications by Supsystic

Plugin:
Digital Publications by Supsystic
Plugin Slug:
digital-publications-by-supsystic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV Importer

Plugin:
CSV Importer
Plugin Slug:
csv-importer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSprite

Plugin:
CSprite
Plugin Slug:
csprite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cosmetsy Core

Plugin:
Cosmetsy Core
Plugin Slug:
cosmetsy-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clotya Core

Plugin:
Clotya Core
Plugin Slug:
clotya-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BCorp Shortcodes

Plugin:
BCorp Shortcodes
Plugin Slug:
bcorp-shortcodes
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bacola Core

Plugin:
Bacola Core
Plugin Slug:
bacola-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations:
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.10.

MW WP Form

Plugin:
MW WP Form
Plugin Slug:
mw-wp-form
Installations:
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.2.

Post Duplicator

Plugin Slug:
post-duplicator
Installations:
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.32.

Advanced Database Cleaner

Plugin Slug:
advanced-database-cleaner
Installations:
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.3.

Shortcoder — Create Shortcodes for Anything

Plugin Slug:
shortcoder
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.

SpeedyCache – Cache, Optimization, Performance

Plugin Slug:
speedycache
Installations:
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Backup Migration

Plugin Slug:
backup-backup
Installations:
90,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.8.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.24.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.24.4.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations:
80,000+
Vulnerability:
Path Traversal
Patched in Version:
1.24.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.24.3.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.41.

Site Reviews

Plugin Slug:
site-reviews
Installations:
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.10.3.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations:
60,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.7.11
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.7.11.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations:
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.5.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

Ultimate Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.1.

Ibtana – WordPress Website Builder

Plugin Slug:
ibtana-visual-editor
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.1.

Rate my Post – WP Rating System

Plugin Slug:
rate-my-post
Installations:
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

Code Embed

Plugin:
Code Embed
Plugin Slug:
simple-embed-code
Installations:
20,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations:
20,000+
Vulnerability:
Path Traversal
Patched in Version:
2.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.7.

WPBakery Page Builder Addons by Livemesh

Plugin Slug:
addons-for-visual-composer
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.
Plugin:
Cookie Bar
Plugin Slug:
cookie-bar
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

WP Booking System – Booking Calendar

Plugin Slug:
wp-booking-system
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.19.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.19.3.

Product Catalog Feed by PixelYourSite

Plugin Slug:
product-catalog-feed
Installations:
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Guest Author

Plugin Slug:
guest-author
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.

Dashboard Widgets Suite

Plugin Slug:
dashboard-widgets-suite
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

Gift Up Gift Cards for WordPress and WooCommerce

Plugin Slug:
gift-up
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.22.
Plugin Slug:
integrate-google-drive
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Caddy – Smart Side Cart for WooCommerce

Plugin Slug:
caddy
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.8.

Email Subscription Popup

Plugin Slug:
email-subscribe
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.19.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.6.

System Dashboard

Plugin Slug:
system-dashboard
Installations:
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

System Dashboard

Plugin Slug:
system-dashboard
Installations:
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

System Dashboard

Plugin Slug:
system-dashboard
Installations:
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

System Dashboard

Plugin Slug:
system-dashboard
Installations:
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

System Dashboard

Plugin Slug:
system-dashboard
Installations:
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

ArtPlacer Widget

Plugin Slug:
artplacer-widget
Installations:
200+
Vulnerability:
SQL Injection
Patched in Version:
2.20.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.20.7.

Couponis Demo

Plugin:
Couponis Demo
Plugin Slug:
couponis-demo
Vulnerability:
SQL Injection
Patched in Version:
2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.

Burst Statistics Pro

Plugin:
Burst Statistics Pro
Plugin Slug:
burst-pro
Vulnerability:
SQL Injection
Patched in Version:
1.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.1.

Astra Pro

Plugin:
Astra Pro
Plugin Slug:
astra-addon
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3.2.

Adifier System

Plugin:
Adifier System
Plugin Slug:
adifier-system
Vulnerability:
SQL Injection
Patched in Version:
3.1.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.4.

Adifier System

Plugin:
Adifier System
Plugin Slug:
adifier-system
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.4 .

WordPress Themes — 0 Patched / 0 Unpatched

No new theme vulnerabilities were disclosed this week.

Did you like this article? Spread the word: