WordPress Vulnerability Report

WordPress Vulnerability Report — July 10, 2024

Since last week, 182 new vulnerabilities emerged in the WordPress ecosystem including 159 plugins and 23 themes. 59 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 182 vulnerabilities have been publicly disclosed. Security patches for 123 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 59 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.5 is now available! This release features three security fixes. Because this is a security release, it is recommended that you update your sites immediately. This minor release also includes 3 bug fixes in Core.

WordPress 6.6 RC3 is ready for download and testing! The target release date for WordPress 6.6 is July 16, 2024. Your help testing RC versions is vital to ensuring the final release is everything it should be: stable, powerful, and intuitive.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 103 Patched / 56 Unpatched

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meks Easy Ads Widget

Plugin Slug:
meks-easy-ads-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPJAM Basic

Plugin Slug:
wpjam-basic
Installations
5,000+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CC & BCC for Woocommerce Order Emails

Plugin Slug:
cc-bcc-for-woocommerce-order-emails
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

nicen-localize-image

Plugin Slug:
nicen-localize-image
Installations
1,000+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tooltip for Gravity Forms

Plugin Slug:
tooltip-for-gravity-forms
Installations
1,000+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPFavicon

Plugin:
WPFavicon
Plugin Slug:
wpfavicon
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leaky Paywall

Plugin Slug:
leaky-paywall
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Taager

Plugin:
Taager
Plugin Slug:
taager
Installations
500+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weight Tracker

Plugin Slug:
weight-loss-tracker
Installations
500+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-to-bible
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Amelia Shortcode Extended

Plugin Slug:
theidealweb-amelia-shortcode-extended
Installations
200+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WS Theme Addons

Plugin Slug:
ws-theme-addons
Installations
200+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canvas-Nest.js

Plugin Slug:
canvas-nestjs
Installations
100+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Logic Hop – Dynamic Content Personalization for WordPress

Plugin Slug:
logic-hop
Installations
100+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meal Tracker

Plugin Slug:
meal-tracker
Installations
100+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WS Contact Form

Plugin Slug:
ws-contact-form
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Speedup by PageCDN

Plugin Slug:
pagecdn
Installations
30+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WebSitter Pro

Plugin Slug:
triagetrak
Installations
30+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magic Conversation For Gravity Forms

Plugin Slug:
magic-conversation-for-gravity-forms
Installations
10+
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Field Day

Plugin:
Field Day
Plugin Slug:
activityhub
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:
Livemesh Addons for Elementor
Plugin Slug:
addons-for-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:
Livemesh Addons for Elementor
Plugin Slug:
addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ADDRESSYA

Plugin:
ADDRESSYA
Plugin Slug:
addressya-for-woocommerce
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

alfred24 Click & Collect

Plugin:
alfred24 Click & Collect
Plugin Slug:
alfred-click-collect
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alfred Easy Shipping

Plugin:
Alfred Easy Shipping
Plugin Slug:
alfred-easy-shipping
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CommandBar for WP Admin

Plugin:
CommandBar for WP Admin
Plugin Slug:
commandbar-for-wp-admin
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Digital River Global Commerce

Plugin:
Digital River Global Commerce
Plugin Slug:
digital-river-global-commerce
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Custom Code (LESS/CSS/JS) – Live editing

Plugin:
Easy Custom Code (LESS/CSS/JS) – Live editing
Plugin Slug:
easy-custom-code
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Floating Social Buttons

Plugin:
Floating Social Buttons
Plugin Slug:
floating-social-buttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Floating Social Media Links
Plugin Slug:
floating-social-media-links
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Responsive Image Gallery, Gallery Album
Plugin Slug:
gallery-album
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ideaplus

Plugin:
Ideaplus
Plugin Slug:
ideaplus
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Image Hover Effects – Caption Hover with Carousel
Plugin Slug:
image-hover-effects-with-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jobs.af

Plugin:
Jobs.af
Plugin Slug:
jobs-af
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login Logo Editor

Plugin:
Login Logo Editor
Plugin Slug:
login-logo-editor-by-oizuled
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mine Video Player

Plugin:
Mine Video Player
Plugin Slug:
mine-video
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Get Better Reviews for WooCommerce

Plugin:
Get Better Reviews for WooCommerce
Plugin Slug:
more-better-reviews-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF plugin by Pdfcrowd

Plugin:
Save as PDF plugin by Pdfcrowd
Plugin Slug:
save-as-pdf-by-pdfcrowd
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Social Share

Plugin:
Simple Social Share
Plugin Slug:
simple-social-share
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simply Show Hooks

Plugin:
Simply Show Hooks
Plugin Slug:
simply-show-hooks
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

sitetweet

Plugin:
sitetweet
Plugin Slug:
sitetweet-tweets-user-behaviors-on-your-site-on-twitter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Addons, Widgets and Enhancements – Stax

Plugin:
Elementor Addons, Widgets and Enhancements – Stax
Plugin Slug:
stax-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Template Kit – Export

Plugin:
Template Kit – Export
Plugin Slug:
template-kit-export
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Widget

Plugin:
Testimonials Widget
Plugin Slug:
testimonials-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UltraAddons Elementor Lite

Plugin:
UltraAddons Elementor Lite
Plugin Slug:
ultraaddons-elementor-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viva Payments

Plugin:
Viva Payments
Plugin Slug:
viva-payments-simple-checkout
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Notification Bar

Plugin:
WordPress Notification Bar
Plugin Slug:
wordpress-notification-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wp-code-highlightjs

Plugin:
wp-code-highlightjs
Plugin Slug:
wp-code-highlightjs
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Cookie Law Info
Plugin Slug:
wp-cookie-law-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
header-footer-elementor
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.36.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.219
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.219.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
800,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.8.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
4.10.36
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.10.36.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.36.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.5.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.1.5.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Gutenberg

Plugin:
Gutenberg
Plugin Slug:
gutenberg
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
18.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 18.6.1.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.

Nested Pages

Plugin Slug:
wp-nested-pages
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.8.
Plugin Slug:
featured-image-from-url
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.3.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.6.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.8.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.6.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.8.2.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
70,000+
Vulnerability:
Backdoor
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.18.
Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.6.

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.2.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.7.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

Void Contact Form 7 Widget For Elementor Page Builder

Plugin Slug:
cf7-widget-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

Easy Google Maps

Plugin Slug:
google-maps-easy
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.16.

Rife Elementor Extensions & Templates

Plugin Slug:
rife-elementor-extensions
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

weForms – Easy Drag & Drop Contact Form Builder For WordPress

Plugin Slug:
weforms
Installations
20,000+
Vulnerability:
Backdoor
Patched in Version:
1.6.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.24.

AI Power: Complete AI Pack – Powered by GPT-4

Plugin Slug:
gpt3-ai-content-generator
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.67
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.67.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Mega Elements – Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Simple Newsletter Plugin – Noptin

Plugin Slug:
newsletter-optin-box
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

Swift Performance Lite

Plugin Slug:
swift-performance-lite
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.6.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.21.

Product Customer List for WooCommerce

Plugin Slug:
wc-product-customer-list
Installations
10,000+
Vulnerability:
Backdoor
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Word Balloon

Plugin Slug:
word-balloon
Installations
10,000+
Vulnerability:
Backdoor
Patched in Version:
4.22.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.2.

Motors – Car Dealer, Classifieds & Listing

Plugin Slug:
motors-car-dealership-classified-listings
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.11.

Tablesome – Responsive Table, Woocommerce Automation, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Forminator

Plugin Slug:
tablesome
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.34.

WordPress Sentry

Plugin Slug:
wp-sentry-integration
Installations
9,000+
Vulnerability:
Backdoor
Patched in Version:
7.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.9.0.

YITH WooCommerce Affiliates

Plugin Slug:
yith-woocommerce-affiliates
Installations
8,000+
Vulnerability:
Backdoor
Patched in Version:
3.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.

Create by Mediavine

Plugin Slug:
mediavine-create
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.8.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.8.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

Beaver Builder Addons by WPZOOM

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Snippet Shortcodes

Plugin Slug:
shortcode-variables
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.5.

AWSM Team – Team Showcase Plugin

Plugin Slug:
awsm-team
Installations
4,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

bbPress Notify (No-Spam)

Plugin Slug:
bbpress-notify-nospam
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.18.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.18.4.

Advanced Classifieds & Directory Pro

Plugin Slug:
advanced-classifieds-and-directory-pro
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.1.

FileBird Document Library

Plugin Slug:
filebird-document-library
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.1.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.10.

IMGspider – ????????

Plugin Slug:
imgspider
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.3.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.11.

ShopBuilder – Elementor WooCommerce Builder Addons

Plugin Slug:
shopbuilder
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

CRM Perks Forms – WordPress Form Builder

Plugin Slug:
crm-perks-forms
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

MakeCommerce for WooCommerce

Plugin Slug:
makecommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.3.

One Click Order Re-Order

Plugin Slug:
one-click-order-reorder
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.10.

Premium Blocks – Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.28.

YAHMAN Add-ons

Plugin Slug:
yahman-add-ons
Installations
2,000+
Vulnerability:
Backdoor
Patched in Version:
0.9.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.29.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.4.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.4.7.

IdeaPush

Plugin:
IdeaPush
Plugin Slug:
ideapush
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.66
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.66.

Newspack Newsletters

Plugin Slug:
newspack-newsletters
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.3.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

SuperSaaS – online appointment scheduling

Plugin Slug:
supersaas-appointment-scheduling
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.10.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.99
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.99.

Comment Reply Email

Plugin Slug:
comment-reply-email
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

ShipAny WooCommerce: Ship, Label, Tracking

Plugin Slug:
shipany
Installations
100+
Vulnerability:
Backdoor
Patched in Version:
1.1.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.53.

Integration for Luminate and Gravity Forms

Plugin Slug:
integration-for-luminate-and-gravity-forms
Installations
70+
Vulnerability:
Backdoor
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

Qualified Electronic Signatures by eID Easy

Plugin Slug:
eid-easy-qualified-electonic-signature
Installations
20+
Vulnerability:
Backdoor
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

BLAZE Retail Widget

Plugin:
BLAZE Retail Widget
Plugin Slug:
blaze-widget
Vulnerability:
Backdoor
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

Contact Form 7 Multi-Step Addon

Plugin:
Contact Form 7 Multi-Step Addon
Plugin Slug:
contact-form-7-multi-step-addon
Vulnerability:
Backdoor
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

XPlainer – WooCommerce Product FAQ

Plugin:
XPlainer – WooCommerce Product FAQ
Plugin Slug:
faq-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

JetThemeCore

Plugin:
JetThemeCore
Plugin Slug:
jet-theme-core
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.1.

Modern Events Calendar

Plugin:
Modern Events Calendar
Plugin Slug:
modern-events-calendar
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.12.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.12.0.

Modern Events Calendar Lite

Plugin:
Modern Events Calendar Lite
Plugin Slug:
modern-events-calendar-lite
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.12.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.12.0.

Newspack Ads

Plugin:
Newspack Ads
Plugin Slug:
newspack-ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.47.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.47.2.

Newspack Content Converter

Plugin:
Newspack Content Converter
Plugin Slug:
newspack-content-converter
Vulnerability:
Broken Access Control
Patched in Version:
1.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

Newspack Campaigns

Plugin:
Newspack Campaigns
Plugin Slug:
newspack-popups
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.31.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.31.2.

PayPlus Payment Gateway

Plugin:
PayPlus Payment Gateway
Plugin Slug:
payplus-payment-gateway
Vulnerability:
SQL Injection
Patched in Version:
6.6.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.6.9.

PayPlus Payment Gateway

Plugin:
PayPlus Payment Gateway
Plugin Slug:
payplus-payment-gateway
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.9.

Social Warfare

Plugin:
Social Warfare
Plugin Slug:
social-warfare
Vulnerability:
Backdoor
Patched in Version:
4.4.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.7.3.

Ultimate Addons for Elementor

Plugin:
Ultimate Addons for Elementor
Plugin Slug:
ultimate-elementor
Vulnerability:
Privilege Escalation
Patched in Version:
1.36.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.36.32.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.9.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Broken Access Control
Patched in Version:
5.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.9.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
PHP Object Injection
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

CopySafe Web Protection

Plugin:
CopySafe Web Protection
Plugin Slug:
wp-copysafe-web
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.15.

WP Directory Kit

Plugin:
WP Directory Kit
Plugin Slug:
wpdirectorykit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.

WPQA – Builder forms Addon

Plugin:
WPQA – Builder forms Addon
Plugin Slug:
wpqa
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.1.

WPQA – Builder forms Addon

Plugin:
WPQA – Builder forms Addon
Plugin Slug:
wpqa
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.1.

WordPress Themes — 20 Patched / 3 Unpatched

zBench

Theme:
zBench
Theme Slug:
zbench
Downloads
588,387
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Boot Store

Theme:
Boot Store
Theme Slug:
boot-store
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

counterpoint

Theme:
counterpoint
Theme Slug:
counterpoint
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ashe

Theme:
Ashe
Theme Slug:
ashe
Downloads
1,959,473
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.234
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.234.

Bakes And Cakes

Theme Slug:
bakes-and-cakes
Downloads
154,588
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Bard

Theme:
Bard
Theme Slug:
bard
Downloads
912,192
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.211
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.211.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,364,636
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

Business One Page

Theme Slug:
business-one-page
Downloads
211,071
Vulnerability:
Broken Access Control
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Construction Landing Page

Theme Slug:
construction-landing-page
Downloads
284,784
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Hestia

Theme:
Hestia
Theme Slug:
hestia
Downloads
4,067,479
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Highlight

Theme Slug:
highlight
Downloads
435,892
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.30.

Lawyer Landing Page

Theme Slug:
lawyer-landing-page
Downloads
128,839
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Metro Magazine

Theme Slug:
metro-magazine
Downloads
260,020
Vulnerability:
Broken Access Control
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Newsmatic

Theme Slug:
newsmatic
Downloads
217,113
Vulnerability:
Broken Access Control
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Posterity

Theme Slug:
posterity
Downloads
95,124
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

Rara Business

Theme Slug:
rara-business
Downloads
201,763
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Rife Free

Theme Slug:
rife-free
Downloads
696,099
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.19.

Trendy News

Theme Slug:
trendy-news
Downloads
24,718
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.16.

Basil

Theme:
Basil
Theme Slug:
basil
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

BookYourTravel

Theme:
BookYourTravel
Theme Slug:
bookyourtravel
Vulnerability:
Privilege Escalation
Patched in Version:
8.18.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.18.19.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security