WordPress Vulnerability Report

WordPress Vulnerability Report — July 24, 2024

Since last week, 93 new vulnerabilities emerged in the WordPress ecosystem including 87 plugins and 6 themes. 21 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 93 vulnerabilities have been publicly disclosed. Security patches for 72 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 21 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is now available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 72 Patched / 15 Unpatched

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable
Installations
30,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smartsupp – live chat, chatbots, AI and lead generation

Plugin Slug:
smartsupp-live-chat
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booking Ultra Pro

Plugin:
Booking Ultra Pro
Plugin Slug:
booking-ultra-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Testimonials

Plugin:
Easy Testimonials
Plugin Slug:
easy-testimonials
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Keydatas

Plugin:
Keydatas
Plugin Slug:
keydatas
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Light Poll

Plugin:
Light Poll
Plugin Slug:
light-poll
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

RegLevel

Plugin:
RegLevel
Plugin Slug:
reglevel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVG Support

Plugin:
SVG Support
Plugin Slug:
svg-support
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Telegram Bot & Channel

Plugin:
Telegram Bot & Channel
Plugin Slug:
telegram-bot
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:
Timeline Event History
Plugin Slug:
timeline-event-history
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

Redux Framework

Plugin Slug:
redux-framework
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.18.

Security Optimizer – The All-In-One Protection Plugin

Plugin Slug:
sg-security
Installations
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

WPS Hide Login

Plugin Slug:
wps-hide-login
Installations
1,000,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.16.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.16.4.

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.14.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.34.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.34.1.

CTX Feed – WooCommerce Product Feed Manager Plugin

Plugin Slug:
webappick-product-feed-for-woocommerce
Installations
100,000+
Vulnerability:
Privilege Escalation
Patched in Version:
6.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.7.

Mercado Pago payments for WooCommerce

Plugin Slug:
woocommerce-mercadopago
Installations
100,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
7.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.2.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.6.1.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.4.45
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.45.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.45
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.45.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
70,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.3.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

Image Hover Effects – Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
7.5.47.7212
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.5.47.7212.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Directory Traversal
Patched in Version:
4.24.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.8.

BSK PDF Manager

Plugin Slug:
bsk-pdf-manager
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

CM Popup Plugin for WordPress – Popup Maker

Plugin Slug:
cm-pop-up-banners
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Language Translate Widget for WP – ConveyThis

Plugin Slug:
conveythis-translate
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
235
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 235.

JetWidgets for Elementor and WooCommerce

Plugin Slug:
jetwoo-widgets-for-elementor
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Plugin Slug:
leaflet-maps-marker
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.10.

SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher

Plugin Slug:
wp-scheduled-posts
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

Arconix FAQ

Plugin Slug:
arconix-faq
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.5.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.33.

YITH Essential Kit for WooCommerce #1

Plugin Slug:
yith-essential-kit-for-woocommerce-1
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.35.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.35.0.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.12.

AI ChatBot for WordPress – WPBot

Plugin Slug:
chatbot
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.8.

WP QuickLaTeX

Plugin Slug:
wp-quicklatex
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.8.

Livemesh Addons for Beaver Builder

Plugin Slug:
addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
4,000+
Vulnerability:
Content Injection
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

AForms — Form Builder for Price Calculator & Cost Estimation

Plugin Slug:
aforms-form-builder-for-price-calculator-cost-estimation
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.3000000024
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3000000024.

Addonify – Quick View For WooCommerce

Plugin Slug:
addonify-quick-view
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.17.

Glossary

Plugin:
Glossary
Plugin Slug:
glossary-by-codeat
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.27.

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
fulltext-search
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.70.236
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.70.236.

Custom Query Blocks

Plugin Slug:
post-type-archive-mapping
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

Filter & Grids

Plugin Slug:
ymc-smart-filter
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.8.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.33.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
7.5.18
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.5.18.

ArtPlacer Widget

Plugin Slug:
artplacer-widget
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.21.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.21.2.

ArtPlacer Widget

Plugin Slug:
artplacer-widget
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.21.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.21.2.

Bug Library

Plugin Slug:
bug-library
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

PZ Frontend Manager

Plugin Slug:
pz-frontend-manager
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

CopySafe Web Protection

Plugin:
CopySafe Web Protection
Plugin Slug:
wp-copysafe-web
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.

WP GoToWebinar

Plugin:
WP GoToWebinar
Plugin Slug:
wp-gotowebinar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
15.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 15.8.

WPForms User Registration

Plugin:
WPForms User Registration
Plugin Slug:
wpforms-user-registration
Vulnerability:
Privilege Escalation
Patched in Version:
2.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.2.

WordPress Themes — 0 Patched / 6 Unpatched

CoziPress

Theme Slug:
cozipress
Downloads
144,938
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Himalayas

Theme Slug:
himalayas
Downloads
334,322
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Zenon Lite

Theme:
Zenon Lite
Theme Slug:
zenon-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security