WordPress Vulnerability Report

WordPress Vulnerability Report — February 14, 2024

Since last week, 146 new vulnerabilities emerged in the WordPress ecosystem, including 3 in themes and 143 in plugins. 28 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 146 vulnerabilities have been publicly disclosed. Security patches for 118 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 28 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 117 Patched / 26 Unpatched

Malware Scanner

Plugin Slug:
miniorange-malware-protection
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comments Like Dislike

Plugin Slug:
comments-like-dislike
Installations
9,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PJ News Ticker

Plugin Slug:
pj-news-ticker
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE and TinyMCE Advanced Professsional Formats and Styles

Plugin Slug:
tinymce-and-tinymce-advanced-professsional-formats-and-styles
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form

Plugin Slug:
wp-contact-form
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Before After Image Slider WP

Plugin Slug:
before-after-image-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Cards

Plugin Slug:
content-cards
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyWaze

Plugin:
MyWaze
Plugin Slug:
my-waze
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PB oEmbed HTML5 Audio – with Cache Support

Plugin Slug:
pb-oembed-html5-audio-with-cache-support
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Installations
100+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Buttons Shortcode and Widget

Plugin:
Buttons Shortcode and Widget
Plugin Slug:
buttons-shortcode-and-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coupon Referral Program

Plugin:
Coupon Referral Program
Plugin Slug:
coupon-referral-program
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

GigPress

Plugin:
GigPress
Plugin Slug:
gigpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Honeypot for WP Comment

Plugin:
Honeypot for WP Comment
Plugin Slug:
honeypot-for-wp-comment
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Honeypot for WP Comment

Plugin:
Honeypot for WP Comment
Plugin Slug:
honeypot-for-wp-comment
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Denial of Service Attack
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin:
Payment Forms for Paystack
Plugin Slug:
payment-forms-for-paystack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMTP Mail

Plugin:
SMTP Mail
Plugin Slug:
smtp-mail
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VK Poster Group

Plugin:
VK Poster Group
Plugin Slug:
vk-poster-group
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pexels: Free Stock Photos

Plugin:
Pexels: Free Stock Photos
Plugin Slug:
wp-pexels-free-stock-photos
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Basic Log Viewer

Plugin:
Basic Log Viewer
Plugin Slug:
wpsimpletools-log-viewer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Forms for Mailchimp

Plugin:
Easy Forms for Mailchimp
Plugin Slug:
yikes-inc-easy-mailchimp-extender
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Website Builder – More than Just a Page Builder

Plugin Slug:
elementor
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.0.

All-In-One Security (AIOS) – Security and Firewall

Plugin Slug:
all-in-one-wp-security-and-firewall
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.6.
Plugin Slug:
broken-link-checker
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Meta Box – WordPress Custom Fields Framework

Plugin Slug:
meta-box
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.3.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.2.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.4.

Admin Menu Editor

Plugin Slug:
admin-menu-editor
Installations
400,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.88
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.88
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.88
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.81.

Backuply – Backup, Restore, Migrate and Clone

Plugin Slug:
backuply
Installations
200,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
1.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.

InfiniteWP Client

Plugin Slug:
iwp-client
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.12.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.3.1.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.93.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.93.2.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.12.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.12.

Advanced Database Cleaner

Plugin Slug:
advanced-database-cleaner
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider)

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.11.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.11.

Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Insert PHP Code Snippet

Plugin Slug:
insert-php-code-snippet
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Login Lockdown – Protect Login Form

Plugin Slug:
login-lockdown
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.09
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.09.

Minimal Coming Soon – Coming Soon Page

Plugin Slug:
minimal-coming-soon-maintenance-mode
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.38
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.38.

Matomo Analytics – Ethical Stats. Powerful Insights.

Plugin Slug:
matomo
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.1.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.1.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.3.

WP Booking Calendar

Plugin Slug:
booking
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
9.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.9.1.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.39.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.39.0.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.
Plugin Slug:
internal-links
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.23.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.23.5.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.88.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.16.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.88.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.15.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.10.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.2.0.

Starbox – the Author Box for Humans

Plugin Slug:
starbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Starbox – the Author Box for Humans

Plugin Slug:
starbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

WP Editor

Plugin:
WP Editor
Plugin Slug:
wp-editor
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Gutenberg Block Editor Toolkit – EditorsKit

Plugin Slug:
block-options
Installations
30,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.40.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.40.4.

PPWP – Password Protect Pages

Plugin Slug:
password-protect-page
Installations
30,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.0.

All 404 Pages Redirect to Homepage

Plugin Slug:
all-404-pages-redirect-to-homepage
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Maspik – Spam Blacklist

Plugin Slug:
contact-forms-anti-spam
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.10.7.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.5.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.2.5.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.5.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.2.5.

NextMove Lite – Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite
Installations
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.18.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.18.0.

Passster – Password Protect Pages and Content

Plugin Slug:
content-protector
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.3.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

Wonder Slider Lite

Plugin Slug:
wonderplugin-slider-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 14.0.

Woocommerce Vietnam Checkout

Plugin Slug:
woo-vietnam-checkout
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Product Labels For Woocommerce (Sale Badges)

Plugin Slug:
aco-product-labels-for-woocommerce
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

Themify Builder

Plugin Slug:
themify-builder
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.6.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.12.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Advanced Forms for ACF

Plugin Slug:
advanced-forms
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.3.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

Podlove Subscribe button

Plugin Slug:
podlove-subscribe-button
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.11.

SKT Page Builder

Plugin Slug:
skt-builder
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.
Plugin Slug:
doofinder-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

Simple Page Access Restriction

Plugin Slug:
simple-page-access-restriction
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

Anonymous Restricted Content

Plugin Slug:
anonymous-restricted-content
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
1.0.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.72.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.0.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.72.

GD Rating System

Plugin Slug:
gd-rating-system
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.1.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
22.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 22.8.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

WP Club Manager – WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.11.

Ultimate Reviews

Plugin Slug:
ultimate-reviews
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.9.

Portugal CTT Tracking for WooCommerce

Plugin Slug:
portugal-ctt-tracking-woocommerce
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Web3 – Crypto wallet Login & NFT token gating

Plugin Slug:
web3-authentication
Installations
200+
Vulnerability:
Broken Authentication
Patched in Version:
3.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.3.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.2.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.2.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.7.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Settings Change
Patched in Version:
5.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Settings Change
Patched in Version:
5.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.3.

WordPress Themes — 1 Patched / 2 Unpatched

Brooklyn

Theme:
Brooklyn
Theme Slug:
brooklyn
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Brooklyn

Theme:
Brooklyn
Theme Slug:
brooklyn
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
2,812,211
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.20.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security