WordPress Vulnerability Report

WordPress Vulnerability Report — February 21, 2024

Since last week, 96 new vulnerabilities emerged in the WordPress ecosystem, including 1 in themes and 95 in plugins. 20 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 96 vulnerabilities have been publicly disclosed. Security patches for 76 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 20 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 75 Patched / 20 Unpatched

Plugin Slug:
featured-image-from-url
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Malware Scanner

Plugin Slug:
miniorange-malware-protection
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comments Like Dislike

Plugin Slug:
comments-like-dislike
Installations
9,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PJ News Ticker

Plugin Slug:
pj-news-ticker
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE and TinyMCE Advanced Professsional Formats and Styles

Plugin Slug:
tinymce-and-tinymce-advanced-professsional-formats-and-styles
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyWaze

Plugin:
MyWaze
Plugin Slug:
my-waze
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PB oEmbed HTML5 Audio – with Cache Support

Plugin Slug:
pb-oembed-html5-audio-with-cache-support
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

GigPress

Plugin:
GigPress
Plugin Slug:
gigpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
Denial of Service Attack
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:
MoveTo
Plugin Slug:
moveto
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Oliver POS

Plugin:
Oliver POS
Plugin Slug:
oliver-pos
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

postMash – custom post order

Plugin:
postMash – custom post order
Plugin Slug:
postmash
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sitepact’s Contact Form 7 Extension For Klaviyo

Plugin:
Sitepact’s Contact Form 7 Extension For Klaviyo
Plugin Slug:
sitepact-klaviyo-contact-form-7
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widgets Controller

Plugin:
Widgets Controller
Plugin Slug:
widgets-controller
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pexels: Free Stock Photos

Plugin:
Pexels: Free Stock Photos
Plugin Slug:
wp-pexels-free-stock-photos
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Forms for Mailchimp

Plugin:
Easy Forms for Mailchimp
Plugin Slug:
yikes-inc-easy-mailchimp-extender
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.19.
Plugin Slug:
broken-link-checker
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.4.

WP Activity Log

Plugin Slug:
wp-security-audit-log
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.2.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

Login Lockdown – Protect Login Form

Plugin Slug:
login-lockdown
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.09
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.09.

Page scroll to id

Plugin Slug:
page-scroll-to-id
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.9.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.9.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.9.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.1.

Simple Share Buttons Adder

Plugin Slug:
simple-share-buttons-adder
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.12.

Microsoft Clarity

Plugin Slug:
microsoft-clarity
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.4.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.88.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.16.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.88.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.15.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

WP Maintenance

Plugin Slug:
wp-maintenance
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.7.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

WP Editor

Plugin:
WP Editor
Plugin Slug:
wp-editor
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Maspik – Spam Blacklist

Plugin Slug:
contact-forms-anti-spam
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.10.7.

My Private Site

Plugin Slug:
jonradio-private-site
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

My Calendar

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.24.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.1.

Coming Soon Maintenance Mode

Plugin Slug:
coming-soon-maintenance-mode
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

WP Testimonials

Plugin Slug:
testimonial-widgets
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Piraeus Bank WooCommerce Payment Gateway

Plugin Slug:
woo-payment-gateway-for-piraeus-bank
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.7.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.0.

WPify Woo Czech

Plugin Slug:
wpify-woo
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.9.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

SKT Page Builder

Plugin Slug:
skt-builder
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.
Plugin Slug:
doofinder-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
2,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
0.1.0.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.1.0.9.

SMTP Mail

Plugin:
SMTP Mail
Plugin Slug:
smtp-mail
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.21.

GD Rating System

Plugin Slug:
gd-rating-system
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.1.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
22.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 22.8.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

Peach Payments Gateway

Plugin Slug:
wc-peach-payments-gateway
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Ultimate Reviews

Plugin Slug:
ultimate-reviews
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.9.

Action Network

Plugin Slug:
wp-action-network
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

Web3 – Crypto wallet Login & NFT token gating

Plugin Slug:
web3-authentication
Installations
200+
Vulnerability:
Broken Authentication
Patched in Version:
3.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

Cwicly

Plugin:
Cwicly
Plugin Slug:
cwicly
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.4.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.0.3.

WooCommerce Easy Checkout Field Editor, Fees & Discounts

Plugin:
WooCommerce Easy Checkout Field Editor, Fees & Discounts
Plugin Slug:
phppoet-checkout-fields
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.5.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.13.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.7.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Settings Change
Patched in Version:
5.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:
WP Media folder
Plugin Slug:
wp-media-folder
Vulnerability:
Settings Change
Patched in Version:
5.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.3.

WP Setup Wizard

Plugin:
WP Setup Wizard
Plugin Slug:
wp-setup-wizard
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.2.

WordPress Themes — 1 Patched / 0 Unpatched

Bricks Builder

Theme:
Bricks Builder
Theme Slug:
bricks
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.6.1.

Did you like this article? Spread the word: