WordPress Vulnerability Report

WordPress Vulnerability Report — January 10, 2024

In this report, 106 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins and one theme are available now, so run those updates as soon as possible. If you're a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Sarah Ulmer

In this report, 106 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins and one theme are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 44 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are a

mong the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 61 Patched / 44 Unpatched

Nginx Helper

Plugin Slug:
nginx-helper
Installations:
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Extension For Mailchimp

Plugin Slug:
contact-form-7-mailchimp-extension
Installations:
90,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Conversion Tracking

Plugin Slug:
woocommerce-conversion-tracking
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations:
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailerLite – WooCommerce integration

Plugin Slug:
woo-mailerlite
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailerLite – WooCommerce integration

Plugin Slug:
woo-mailerlite
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations:
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RabbitLoader

Plugin Slug:
rabbit-loader
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Revolut Gateway for WooCommerce

Plugin Slug:
revolut-gateway-for-woocommerce
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Word Replacer Pro

Plugin Slug:
word-replacer-ultra
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JS & CSS Script Optimizer

Plugin Slug:
js-css-script-optimizer
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Flamingo

Plugin Slug:
advanced-flamingo
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Laybuy Payment Extension for WooCommerce

Plugin Slug:
laybuy-gateway-for-woocommerce
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mapster WP Maps

Plugin Slug:
mapster-wp-maps
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 MP3 Player with Playlist Free

Plugin Slug:
html5-mp3-player-with-playlist
Installations:
600+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 SoundCloud Player with Playlist Free

Plugin Slug:
html5-soundcloud-player-with-playlist
Installations:
300+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Tranzila Payment Gateway

Plugin Slug:
woo-tranzila-gateway
Installations:
300+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gecka Terms Thumbnails

Plugin Slug:
gecka-terms-thumbnails
Installations:
100+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 MP3 Player with Folder Feedburner Playlist Free

Plugin Slug:
html5-mp3-player-with-mp3-folder-feedburner-playlist
Installations:
90+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ads Invalid Click Protection

Plugin:
Ads Invalid Click Protection
Plugin Slug:
ads-invalid-click-protection
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CformsII

Plugin:
CformsII
Plugin Slug:
cforms2
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coupon Referral Program

Plugin:
Coupon Referral Program
Plugin Slug:
coupon-referral-program
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
CPT Bootstrap Carousel
Plugin Slug:
cpt-bootstrap-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy SVG Allow

Plugin:
Easy SVG Allow
Plugin Slug:
easy-svg-image-allow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

1 click disable all

Plugin Slug:
first-graders-toolbox
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Footer Putter
Plugin Slug:
footer-putter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ideal Interactive Map

Plugin:
Ideal Interactive Map
Plugin Slug:
ideal-interactive-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infogram

Plugin:
Infogram
Plugin Slug:
infogram
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Keap Official Opt-in Forms

Plugin:
Keap Official Opt-in Forms
Plugin Slug:
infusionsoft-official-opt-in-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Live Composer

Plugin:
Page Builder: Live Composer
Plugin Slug:
live-composer-page-builder
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

oEmbed Gist

Plugin:
oEmbed Gist
Plugin Slug:
oembed-gist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Posts to Page

Plugin:
Posts to Page
Plugin Slug:
posts-to-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Private Google Calendars

Plugin:
Private Google Calendars
Plugin Slug:
private-google-calendars
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

pTypeConverter

Plugin:
pTypeConverter
Plugin Slug:
ptypeconverter
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Randomize

Plugin:
Randomize
Plugin Slug:
randomize
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Site Notes

Plugin:
Site Notes
Plugin Slug:
site-notes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TJ Shortcodes

Plugin:
TJ Shortcodes
Plugin Slug:
theme-junkie-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Users

Plugin:
WordPress Users
Plugin Slug:
wordpress-users
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Plugin Lister

Plugin:
WP Plugin Lister
Plugin Slug:
wp-plugin-lister
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Bookmark Menu

Plugin:
WP Social Bookmark Menu
Plugin Slug:
wp-social-bookmark-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations:
5,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.0.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations:
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

Hostinger

Plugin:
Hostinger
Plugin Slug:
hostinger
Installations:
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations:
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.0.

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.

Plugin Slug:
host-webfonts-local
Installations:
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.7.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.10.

Metform Elementor Contact Form Builder

Plugin Slug:
metform
Installations:
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.2.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.27.

Download Monitor

Plugin Slug:
download-monitor
Installations:
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.5.
Plugin Slug:
envira-gallery-lite
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.3.

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu)

Plugin Slug:
mystickymenu
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.7
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.7.

WP Job Manager

Plugin Slug:
wp-job-manager
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

WP Job Manager

Plugin Slug:
wp-job-manager
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations:
90,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.2.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.5.8.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations:
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.2.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.5.8.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations:
90,000+
Vulnerability:
SQL Injection
Patched in Version:
4.2.5.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.5.8.

Ajax Search Lite

Plugin Slug:
ajax-search-lite
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.11.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.11.5.

3D FlipBook – PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.15.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.15.3.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.88.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.14.

WP 2FA – Two-factor authentication for WordPress

Plugin Slug:
wp-2fa
Installations:
50,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

WP 2FA – Two-factor authentication for WordPress

Plugin Slug:
wp-2fa
Installations:
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Void Contact Form 7 Widget For Elementor Page Builder

Plugin Slug:
cf7-widget-elementor
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.

Constant Contact Forms

Plugin Slug:
constant-contact-forms
Installations:
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.3.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.5.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.1.2.

Swift SMTP (formerly Welcome Email Editor)

Plugin Slug:
welcome-email-editor
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.7.

ActivityPub

Plugin Slug:
activitypub
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

WordPress Live Chat Plugin for WooCommerce – LiveChat

Plugin Slug:
livechat-woocommerce
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.14.

WordPress Live Chat Plugin for WooCommerce – LiveChat

Plugin Slug:
livechat-woocommerce
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.17.

Product Delivery Date for WooCommerce – Lite

Plugin Slug:
product-delivery-date-for-woocommerce-lite
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

Football Pool

Plugin Slug:
football-pool
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.4.

GD Rating System

Plugin Slug:
gd-rating-system
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.0.

Booster Elite for WooCommerce

Plugin:
Booster Elite for WooCommerce
Plugin Slug:
booster-elite-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Booster Plus for WooCommerce

Plugin:
Booster Plus for WooCommerce
Plugin Slug:
booster-plus-for-woocommerce
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Booster Plus for WooCommerce

Plugin:
Booster Plus for WooCommerce
Plugin Slug:
booster-plus-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Booster Plus for WooCommerce

Plugin:
Booster Plus for WooCommerce
Plugin Slug:
booster-plus-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.3.

FooGallery Premium

Plugin:
FooGallery Premium
Plugin Slug:
foogallery-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

Page Builder: Live Composer

Plugin:
Page Builder: Live Composer
Plugin Slug:
live-composer-page-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.24.

MaxButtons

Plugin:
MaxButtons
Plugin Slug:
maxbutton
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.6.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygenbuilder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

WordPress Themes — 1 Patched / 0 Unpatched

Weaver Xtreme

Theme Slug:
weaver-xtreme
Downloads:
494,749
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.

Did you like this article? Spread the word: