WordPress Vulnerability Report

WordPress Vulnerability Report — February 28, 2024

Since last week, 73 new vulnerabilities emerged in the WordPress ecosystem, including 2 in themes and 71 in plugins. 25 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 73 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 25 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 25 Unpatched

Addon Library

Plugin:
Addon Library
Plugin Slug:
addon-library
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:
Admin side data storage for Contact Form 7
Plugin Slug:
admin-side-data-storage-for-contact-form-7
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:
Admin side data storage for Contact Form 7
Plugin Slug:
admin-side-data-storage-for-contact-form-7
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:
Admin side data storage for Contact Form 7
Plugin Slug:
admin-side-data-storage-for-contact-form-7
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:
Admin side data storage for Contact Form 7
Plugin Slug:
admin-side-data-storage-for-contact-form-7
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Adsmonetizer

Plugin:
Adsmonetizer
Plugin Slug:
adsensei-b30
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BeePress

Plugin:
BeePress
Plugin Slug:
beepress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Configure SMTP

Plugin:
Configure SMTP
Plugin Slug:
configure-smtp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Download Media

Plugin:
Download Media
Plugin Slug:
download-media
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Duitku Payment Gateway

Plugin:
Duitku Payment Gateway
Plugin Slug:
duitku-social-payment-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fontific | Google Fonts

Plugin:
Fontific | Google Fonts
Plugin Slug:
fontific
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gestpay for WooCommerce

Plugin:
Gestpay for WooCommerce
Plugin Slug:
gestpay-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketo Forms and Tracking

Plugin:
Marketo Forms and Tracking
Plugin Slug:
marketo-forms-and-tracking
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Alt Renamer

Plugin:
Media Alt Renamer
Plugin Slug:
media-alt-renamer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin:
WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit
Plugin Slug:
myshopkit-popup-smartbar-slidein
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayU India

Plugin:
PayU India
Plugin Slug:
payu-india
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Play.ht

Plugin:
Play.ht
Plugin Slug:
play-ht
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

postMash – custom post order

Plugin:
postMash – custom post order
Plugin Slug:
postmash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rolo Slider

Plugin:
Rolo Slider
Plugin Slug:
rolo-slider
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slivery Extender

Plugin:
Slivery Extender
Plugin Slug:
slivery-extender
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SoundCloud Shortcode

Plugin:
SoundCloud Shortcode
Plugin Slug:
soundcloud-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tabs Shortcode and Widget

Plugin:
Tabs Shortcode and Widget
Plugin Slug:
tabs-shortcode-and-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Shortcodes Plus

Plugin:
User Shortcodes Plus
Plugin Slug:
user-shortcodes-plus
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Watermark RELOADED

Plugin:
Watermark RELOADED
Plugin Slug:
watermark-reloaded
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.0.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.0.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.19.

BackWPup – WordPress Backup Plugin

Plugin Slug:
backwpup
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.0.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.0.3.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.32.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.31.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.13.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.260
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.260.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.260
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.260.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Directory Traversal
Patched in Version:
2.4.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.41.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.41.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.4.41
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.41.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.41.

Event Tickets and Registration

Plugin Slug:
event-tickets
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.2.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes
Installations
30,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.4.

Maintenance Page

Plugin Slug:
maintenance-page
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

Maintenance Page

Plugin Slug:
maintenance-page
Installations
5,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.9.

Archivist – Custom Archive Templates

Plugin Slug:
archivist-custom-archive-templates
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.6.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

KODO Qiniu

Plugin:
KODO Qiniu
Plugin Slug:
kodo-qiniu
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Backup

Plugin:
Backup
Plugin Slug:
backup2
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.9.9.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.19.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.3.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Authentication
Patched in Version:
2.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.4.

WP Social Widget

Plugin:
WP Social Widget
Plugin Slug:
wp-social-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

WordPress Themes — 2 Patched /0 Unpatched

Colibri WP

Theme Slug:
colibri-wp
Downloads
1,232,050
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.101
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.101.

Socialdriver

Theme:
Socialdriver
Theme Slug:
socialdriver
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024
Severity Score:
High
The vulnerability has been patched, so you should update to version 2024.

Did you like this article? Spread the word: