WordPress Security

WordPress Vulnerability Report — January 24, 2024

In this report, 88 new vulnerabilities have been publicly disclosed. Security patches for 29 of these plugins and themes are available now, so run those updates as soon as possible. If you're a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Sarah Ulmer

In this report, 88 new vulnerabilities have been publicly disclosed. Security patches for 29 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 59 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

Free Online Training Event! TODAY! Register Now!

TODAY! January 24, 2024 @ 1:00 PM – 2:00 PM (CST)

Not all WordPress threats and vulnerabilities are “created equal.” Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.

This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.

Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 28 Patched / 59 Unpatched

Ninja Tables – Best Data Table Plugin for WordPress

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Tables – Best Data Table Plugin for WordPress

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer & 3D PDF Flipbook – DearPDF

Plugin Slug:
dearpdf-lite
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Browser Theme Color

Plugin Slug:
browser-theme-color
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FreshMail For WordPress

Plugin Slug:
freshmail-integration
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Albo Pretorio On line

Plugin Slug:
albo-pretorio-on-line
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Albo Pretorio On line

Plugin Slug:
albo-pretorio-on-line
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BA Plus

Plugin:
BA Plus
Plugin Slug:
ba-plus-before-after-image-slider-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Better Anchor Links
Plugin Slug:
better-anchor-links
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CformsII

Plugin:
CformsII
Plugin Slug:
cforms2
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Dashboard Widgets

Plugin:
Custom Dashboard Widgets
Plugin Slug:
custom-dashboard-widgets
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Delhivery Logistics Courier

Plugin:
Delhivery Logistics Courier
Plugin Slug:
delhivery-logistics-courier
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:
enigma chart.js
Plugin Slug:
enigma-chartjs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:
enigma chart.js
Plugin Slug:
enigma-chartjs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontpage Manager

Plugin:
Frontpage Manager
Plugin Slug:
frontpage-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Tag Manager

Plugin:
Image Tag Manager
Plugin Slug:
image-tag-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

lasTunes

Plugin:
lasTunes
Plugin Slug:
lastunes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post views Stats

Plugin:
Post views Stats
Plugin Slug:
post-views-stats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SimpleMap Store Locator

Plugin:
SimpleMap Store Locator
Plugin Slug:
simplemap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Splashscreen

Plugin:
Splashscreen
Plugin Slug:
splashscreen
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Addons for WPBakery Page Builder

Plugin:
Unlimited Addons for WPBakery Page Builder
Plugin Slug:
unlimited-addons-for-wpbakery-page-builder
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Smart Editor

Plugin:
WP Smart Editor
Plugin Slug:
wp-smart-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.5.

Migration, Backup, Staging – WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.9.95
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.95.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
SQL Injection
Patched in Version:
3.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.6.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.8.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.20.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.28.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.

Product Import Export for WooCommerce

Plugin Slug:
product-import-export-for-woo
Installations
90,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.8.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.24.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.24.7.

VK Block Patterns

Plugin Slug:
vk-block-patterns
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.31.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.2.0.
Plugin Slug:
advanced-woo-search
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.97
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.97.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.94.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
50,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.18.

Simple Membership

Plugin Slug:
simple-membership
Installations
50,000+
Vulnerability:
Open Redirection
Patched in Version:
4.4.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.4.2.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Path Traversal
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

IP2Location Country Blocker

Plugin Slug:
ip2location-country-blocker
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.33.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.33.4.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.0.

Cryptocurrency Widgets – Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.6.

Stripe Payment Plugin for WooCommerce

Plugin Slug:
payment-gateway-stripe-and-woocommerce-integration
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.0.
Plugin Slug:
portfolio-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.
Plugin Slug:
bp-profile-search
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.

HD Quiz

Plugin:
HD Quiz
Plugin Slug:
hd-quiz
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.12.

ChatBot with AI

Plugin Slug:
chatbot
Installations
5,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.1.

Slider by Supsystic

Plugin Slug:
slider-by-supsystic
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

FastDup – Fastest WordPress Migration & Duplicator

Plugin Slug:
fastdup
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.0.

Formzu WP

Plugin:
Formzu WP
Plugin Slug:
formzu-wp
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.8.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.8.

WP Spell Check

Plugin Slug:
wp-spell-check
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.18.

WPZOOM Shortcodes

Plugin Slug:
wpzoom-shortcodes
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.2.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
0.1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.9.

Display custom fields in the frontend – Post and User Profile Fields

Plugin Slug:
shortcode-to-display-post-and-user-data
Installations
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Stock Locations for WooCommerce

Plugin Slug:
stock-locations-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Advanced Custom Fields PRO

Plugin:
Advanced Custom Fields PRO
Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.5.

GeneratePress Premium

Plugin:
GeneratePress Premium
Plugin Slug:
generatepress-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

PeepSo Core: Photos

Plugin:
PeepSo Core: Photos
Plugin Slug:
peepso-photos
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.0.

SalesKing

Plugin:
SalesKing
Plugin Slug:
salesking
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.30
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.30.

SalesKing

Plugin:
SalesKing
Plugin Slug:
salesking
Vulnerability:
Settings Change
Patched in Version:
1.6.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.30.

SalesKing

Plugin:
SalesKing
Plugin Slug:
salesking
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.6.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.30.

WooCommerce Subscriptions

Plugin:
WooCommerce Subscriptions
Plugin Slug:
woocommerce-subscriptions
Vulnerability:
Broken Access Control
Patched in Version:
5.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.0.

WPForms Pro

Plugin:
WPForms Pro
Plugin Slug:
wpforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.5.4.

WordPress Themes — 1 Patched / 0 Unpatched

ColorMag

Theme:
ColorMag
Theme Slug:
colormag
Downloads
3,787,317
Vulnerability:
Broken Access Control
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Did you like this article? Spread the word: