WordPress Vulnerability Report

WordPress Vulnerability Report — February 7, 2024

Since last week, 158 new vulnerabilities emerged in the WordPress ecosystem, including 1 in WordPress core, 1 in themes, and 156 in plugins. 37 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 158 vulnerabilities have been publicly disclosed, including 1 in WordPress core patched in the WordPress 6.4.3 update. Security patches for 120 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 37 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

WordPress Core

Vulnerability:
Arbitrary File Upload
Patched in Version:
6.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.3.

WordPress Plugins — 119 Patched / 37 Unpatched

MW WP Form

Plugin:
MW WP Form
Plugin Slug:
mw-wp-form
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
navz-photo-gallery
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Before Download

Plugin Slug:
email-before-download
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Restrict

Plugin Slug:
pagerestrict
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Load More Anything

Plugin Slug:
ajax-load-more-anything
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
lgx-owl-carousel
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Debug

Plugin:
Debug
Plugin Slug:
debug
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Don’t Muck My Markup

Plugin Slug:
dont-muck-my-markup
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility

Plugin Slug:
accessibility
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PilotPress

Plugin:
PilotPress
Plugin Slug:
pilotpress
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cincopa video and media plug-in

Plugin Slug:
video-playlist-and-gallery-plugin
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scheduling Plugin – Online Booking for WordPress

Plugin Slug:
calendar-booking
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CC BMI Calculator

Plugin Slug:
cc-bmi-calculator
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Plugin Slug:
click-to-tweet
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ERE Recently Viewed – Essential Real Estate Add-On

Plugin Slug:
ere-recently-viewed
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

W3SPEEDSTER

Plugin Slug:
w3speedster-wp
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-CFM

Plugin:
WP-CFM
Plugin Slug:
wp-cfm
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wp-Adv-Quiz

Plugin Slug:
advanced-quiz
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Autotitle for WordPress

Plugin:
Autotitle for WordPress
Plugin Slug:
autotitle-for-wordpress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CalculatorPro Calculators

Plugin:
CalculatorPro Calculators
Plugin Slug:
calculatorpro-calculators
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Coupon Referral Program

Plugin:
Coupon Referral Program
Plugin Slug:
coupon-referral-program
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Custom User CSS

Plugin:
Custom User CSS
Plugin Slug:
custom-user-css
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scroll Triggered Box

Plugin:
Scroll Triggered Box
Plugin Slug:
dreamgrow-scroll-triggered-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JTRT Responsive Tables

Plugin:
JTRT Responsive Tables
Plugin Slug:
jtrt-responsive-tables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mighty Addons for Elementor

Plugin:
Mighty Addons for Elementor
Plugin Slug:
mighty-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Plugin:
Order Delivery Date for WP e-Commerce
Plugin Slug:
order-delivery-date
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Persian Fonts

Plugin:
Persian Fonts
Plugin Slug:
persian-fonts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popup More Popups

Plugin:
Popup More Popups
Plugin Slug:
popup-more
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Thumbnail Editor

Plugin:
Post Thumbnail Editor
Plugin Slug:
post-thumbnail-editor
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PT Sign Ups

Plugin:
PT Sign Ups
Plugin Slug:
ptoffice-sign-ups
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quicksand Post Filter jQuery Plugin

Plugin:
Quicksand Post Filter jQuery Plugin
Plugin Slug:
quicksand-jquery-post-filter
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quicksand Post Filter jQuery Plugin

Plugin:
Quicksand Post Filter jQuery Plugin
Plugin Slug:
quicksand-jquery-post-filter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Toolbar

Plugin:
WordPress Toolbar
Plugin Slug:
wordpress-toolbar
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
800,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.2.5
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.2.5.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.17.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.2.

Admin Menu Editor

Plugin Slug:
admin-menu-editor
Installations
400,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.2.

Backuply – Backup, Restore, Migrate and Clone

Plugin Slug:
backuply
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Cloudflare

Plugin:
Cloudflare
Plugin Slug:
cloudflare
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.12.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.3.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.9.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.3.16.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.10.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.29.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.10.230
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.230.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.12.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.12.
Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.12.

Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider)

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.11.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.11.

Minimal Coming Soon – Coming Soon Page

Plugin Slug:
minimal-coming-soon-maintenance-mode
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.38
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.38.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.

The Plus Addons for Elementor

Plugin Slug:
the-plus-addons-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.4.
Plugin Slug:
wp-gdpr-compliance
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.23.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.0.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.53.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.88.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.17.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.10.

Starbox – the Author Box for Humans

Plugin Slug:
starbox
Installations
50,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.8.

WooCommerce Conversion Tracking

Plugin Slug:
woocommerce-conversion-tracking
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.12.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.2.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.9.5.

Affiliates Manager

Plugin Slug:
affiliates-manager
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.9.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.35.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.7.

Booking Calendar | Appointment Booking | BookIt

Plugin Slug:
bookit
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

Knowledge Base for Documentation, FAQs with AI Assistance

Plugin Slug:
echo-knowledge-base
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
11.31.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.31.0.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

Wonder Slider Lite

Plugin Slug:
wonderplugin-slider-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 14.0.

Woocommerce Vietnam Checkout

Plugin Slug:
woo-vietnam-checkout
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Woostify Sites Library

Plugin Slug:
woostify-sites-library
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.

Product Labels For Woocommerce (Sale Badges)

Plugin Slug:
aco-product-labels-for-woocommerce
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

FG Joomla to WordPress

Plugin Slug:
fg-joomla-to-wordpress
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.17.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.17.0.

Fatal Error Notify

Plugin Slug:
fatal-error-notify
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

GDPR Data Request Form

Plugin Slug:
gdpr-data-request-form
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Themify Builder

Plugin Slug:
themify-builder
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.6.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

WOLF – WordPress Posts Bulk Editor and Manager Professional

Plugin Slug:
bulk-editor
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.2.

PopupAlly

Plugin:
PopupAlly
Plugin Slug:
popupally
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Advanced Forms for ACF

Plugin Slug:
advanced-forms
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.3.

(Simply) Guest Author Name

Plugin Slug:
guest-author-name
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.35.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.24.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.0.

PropertyHive

Plugin Slug:
propertyhive
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

PropertyHive

Plugin Slug:
propertyhive
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.6.

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
4.70
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.70.

Add Customer for WooCommerce

Plugin Slug:
add-customer-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Anonymous Restricted Content

Plugin Slug:
anonymous-restricted-content
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
1.0.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.72.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.0.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.72.

FG Drupal to WordPress

Plugin Slug:
fg-drupal-to-wp
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.68.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.68.0.

FG PrestaShop to WooCommerce

Plugin Slug:
fg-prestashop-to-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.45.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.45.0.

Five Star Restaurant Reviews

Plugin Slug:
good-reviews-wp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.

Heateor Social Login WordPress

Plugin Slug:
heateor-social-login
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.31.

Icons Font Loader

Plugin Slug:
icons-font-loader
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Restrict Usernames Emails Characters

Plugin Slug:
restrict-usernames-emails-characters
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

WP Club Manager – WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.11.

Chartify – WordPress Chart Plugin

Plugin Slug:
chart-builder
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

Portugal CTT Tracking for WooCommerce

Plugin Slug:
portugal-ctt-tracking-woocommerce
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Wp-Adv-Quiz

Plugin Slug:
advanced-quiz
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Allow SVG

Plugin:
Allow SVG
Plugin Slug:
allow-svg
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

EventON Pro

Plugin:
EventON Pro
Plugin Slug:
eventon-wordpress-event-calendar-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.1.

PowerPack Pro for Elementor

Plugin:
PowerPack Pro for Elementor
Plugin Slug:
powerpack-elements
Vulnerability:
Settings Change
Patched in Version:
2.10.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.10.8.

PowerPack Pro for Elementor

Plugin:
PowerPack Pro for Elementor
Plugin Slug:
powerpack-elements
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.10.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.10.8.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.3.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.2.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.7.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.6.

WooCommerce Box Office

Plugin:
WooCommerce Box Office
Plugin Slug:
woocommerce-box-office
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

WordPress Themes — 1 Patched / 0 Unpatched

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
2,786,039
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.20.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: