WordPress Vulnerability Report

WordPress Vulnerability Report — January 31, 2024

In this week's report, a total of 53 vulnerabilities have been publicly disclosed. There are security patches for 36 of these plugins and themes. Run those updates as soon as possible. Also, there are 17 plugin vulnerabilities with no patch available yet.

Sarah Ulmer

In this report, 53 vulnerabilities have been publicly disclosed. Security patches for 36 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 17 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 35 Patched / 17 Unpatched

aBitGone CommentSafe

Plugin:
aBitGone CommentSafe
Plugin Slug:
abitgone-commentsafe
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add SVG Support for Media Uploader | inventivo

Plugin:
Add SVG Support for Media Uploader | inventivo
Plugin Slug:
add-svg-support-for-media-uploader-inventivo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Schedule Posts

Plugin:
Advanced Schedule Posts
Plugin Slug:
advanced-schedule-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Better Follow Button for Jetpack

Plugin:
Better Follow Button for Jetpack
Plugin Slug:
better-follow-button-for-jetpack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:
enigma chart.js
Plugin Slug:
enigma-chartjs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:
enigma chart.js
Plugin Slug:
enigma-chartjs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

(Simply) Guest Author Name

Plugin:
(Simply) Guest Author Name
Plugin Slug:
guest-author-name
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

lasTunes

Plugin:
lasTunes
Plugin Slug:
lastunes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
illi Link Party!
Plugin Slug:
link-party
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
illi Link Party!
Plugin Slug:
link-party
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
illi Link Party!
Plugin Slug:
link-party
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mang Board WP

Plugin:
Mang Board WP
Plugin Slug:
mangboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Splashscreen

Plugin:
Splashscreen
Plugin Slug:
splashscreen
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVG Uploads Support

Plugin:
SVG Uploads Support
Plugin Slug:
svg-uploads-support
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Noindex Nofollow Tool

Plugin:
Ultimate Noindex Nofollow Tool
Plugin Slug:
ultimate-noindex-nofollow-tool
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketing Twitter Bot

Plugin:
Marketing Twitter Bot
Plugin Slug:
wordpress-twitterbot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Reply Notify

Plugin:
WP-Reply Notify
Plugin Slug:
wp-reply-notify
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better Search Replace

Plugin Slug:
better-search-replace
Installations
1,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.5.

File Manager

Plugin Slug:
wp-file-manager
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.2.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.29.

Migration, Backup, Staging – WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.9.95
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.95.

Backuply – Backup, Restore, Migrate and Clone

Plugin Slug:
backuply
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.8.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.20.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.93
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.93.

VK Block Patterns

Plugin Slug:
vk-block-patterns
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.31.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.2.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

10Web AI Assistant – AI content writing assistant

Plugin Slug:
ai-assistant-by-10web
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.19.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

PDF Poster – PDF Embedder Plugin for WordPress

Plugin Slug:
pdf-poster
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.18.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.2.

Cryptocurrency Widgets – Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.6.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.3.

PDF Generator For Fluent Forms – The Contact Form Plugin

Plugin Slug:
fluentforms-pdf
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Category Discount Woocommerce

Plugin Slug:
woo-product-category-discount
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.12.

Category Discount Woocommerce

Plugin Slug:
woo-product-category-discount
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.13.

Sticky Buttons – floating buttons builder

Plugin Slug:
sticky-buttons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Dragfy Addons for Elementor

Plugin Slug:
dragfy-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.2.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
0.1.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.10.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.1.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.10.

Allow SVG

Plugin:
Allow SVG
Plugin Slug:
allow-svg
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

MaxButtons

Plugin:
MaxButtons
Plugin Slug:
maxbutton
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.7.

File Manager Pro

Plugin:
File Manager Pro
Plugin Slug:
wp-file-manager-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.5.

WPForms Pro

Plugin:
WPForms Pro
Plugin Slug:
wpforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.5.4.

WordPress Themes — 1 Patched / 0 Unpatched

ColorMag

Theme:
ColorMag
Theme Slug:
colormag
Downloads
3,799,423
Vulnerability:
Broken Access Control
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: