In this report, 80 vulnerabilities have been publicly disclosed. Security patches for 55 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 25 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.6.1 is now available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.
WordPress Plugins — 55 Patched / 20 Unpatched
Timetable and Event Schedule by MotoPress
- Plugin Slug:
- mp-timetable
- Installations
- 30,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-39630
Pretty Simple Popup Builder
- Plugin:
- Pretty Simple Popup Builder
- Plugin Slug:
- pretty-simple-popup-builder
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-39626
Add Admin CSS
- Plugin:
- Add Admin CSS
- Plugin Slug:
- add-admin-css
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6547
Add Admin JavaScript
- Plugin:
- Add Admin JavaScript
- Plugin Slug:
- add-admin-javascript
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6548
Admin Post Navigation
- Plugin:
- Admin Post Navigation
- Plugin Slug:
- admin-post-navigation
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6549
Admin Trim Interface
- Plugin:
- Admin Trim Interface
- Plugin Slug:
- admin-trim-interface
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6545
Aramex Shipping WooCommerce
- Plugin:
- Aramex Shipping WooCommerce
- Plugin Slug:
- aramex-shipping-woocommerce
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6566
Flipbox Builder
- Plugin:
- Flipbox Builder
- Plugin Slug:
- flipbox-builder
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-6152
IgnitionDeck
- Plugin:
- IgnitionDeck
- Plugin Slug:
- ignitiondeck
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4410
Intelligence
- Plugin:
- Intelligence
- Plugin Slug:
- intelligence
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6573
ListingPro
- Plugin:
- ListingPro
- Plugin Slug:
- listingpro-plugin
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-39621
ListingPro
- Plugin:
- ListingPro
- Plugin Slug:
- listingpro-plugin
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-39620
ListingPro
- Plugin:
- ListingPro
- Plugin Slug:
- listingpro-plugin
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-39619
ListingPro
- Plugin:
- ListingPro
- Plugin Slug:
- listingpro-plugin
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-38795
Master Currency WP
- Plugin:
- Master Currency WP
- Plugin Slug:
- mastercurrency-wp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6634
Media.net Ads Manager
- Plugin:
- Media.net Ads Manager
- Plugin Slug:
- media-net-ads-manager
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-6431
One Click Close Comments
- Plugin:
- One Click Close Comments
- Plugin Slug:
- one-click-close-comments
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6546
ParityPress
- Plugin:
- ParityPress
- Plugin Slug:
- paritypress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6661
Tutor LMS – Migration Tool
- Plugin:
- Tutor LMS – Migration Tool
- Plugin Slug:
- tutor-lms-migration-tool
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-1798
Ultimate Auction
- Plugin:
- Ultimate Auction
- Plugin Slug:
- ultimate-auction
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6591
LiteSpeed Cache
- Plugin:
- LiteSpeed Cache
- Plugin Slug:
- litespeed-cache
- Installations
- 5,000,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.3
- Severity Score:
- High
- CVE:
- 2024-3246
Redux Framework
- Plugin:
- Redux Framework
- Plugin Slug:
- redux-framework
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.4.18
- Severity Score:
- High
- CVE:
- 2024-6828
Ninja Forms – The Contact Form Builder That Grows With You
- Plugin Slug:
- ninja-forms
- Installations
- 800,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.8.7
- Severity Score:
- Medium
- CVE:
- 2024-39628
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
- Plugin Slug:
- nextgen-gallery
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.59.4
- Severity Score:
- Medium
- CVE:
- 2024-39627
Page Builder Gutenberg Blocks – CoBlocks
- Plugin Slug:
- coblocks
- Installations
- 400,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 3.1.12
- Severity Score:
- Medium
- CVE:
- 2024-4260
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Plugin Slug:
- fluentform
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.20
- Severity Score:
- Medium
- CVE:
- 2024-6520
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.11.3
- Severity Score:
- Medium
- CVE:
- 2024-6627
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.981
- Severity Score:
- Medium
- CVE:
- 2024-5818
AMP for WP – Accelerated Mobile Pages
- Plugin Slug:
- accelerated-mobile-pages
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.97
- Severity Score:
- Medium
- CVE:
- 2024-6896
Hide My WP Ghost – Security & Firewall
- Plugin Slug:
- hide-my-wp
- Installations
- 100,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 5.2.02
- Severity Score:
- Low
- CVE:
- 2024-6420
Inline Related Posts
- Plugin:
- Inline Related Posts
- Plugin Slug:
- intelly-related-posts
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.0
- Severity Score:
- Medium
- CVE:
- 2024-6487
Email Encoder – Protect Email Addresses and Phone Numbers
- Plugin Slug:
- email-encoder-bundle
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.2
- Severity Score:
- Medium
- CVE:
- 2024-4483
LearnPress – WordPress LMS Plugin
- Plugin Slug:
- learnpress
- Installations
- 90,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.2.6.9
- Severity Score:
- High
- CVE:
- 2024-6589
WP ULike – Most Advanced Marketing Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.1
- Severity Score:
- Medium
- CVE:
- 2024-6094
AI Engine
- Plugin:
- AI Engine
- Plugin Slug:
- ai-engine
- Installations
- 70,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.4.8
- Severity Score:
- Medium
- CVE:
- 2024-38791
aThemes Starter Sites
- Plugin:
- aThemes Starter Sites
- Plugin Slug:
- athemes-starter-sites
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.54
- Severity Score:
- Medium
- CVE:
- 2024-6897
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.0.3
- Severity Score:
- Medium
- CVE:
- 2024-7100
WP Booking Calendar
- Plugin:
- WP Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.2.2
- Severity Score:
- Medium
- CVE:
- 2024-6930
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Plugin Slug:
- profile-builder
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.11.8
- Severity Score:
- Medium
- CVE:
- 2024-6366
Better Find and Replace
- Plugin:
- Better Find and Replace
- Plugin Slug:
- real-time-auto-find-and-replace
- Installations
- 50,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6.2
- Severity Score:
- High
- CVE:
- 2024-39636
Photo Gallery, Images, Slider in Rbs Image Gallery
- Plugin Slug:
- robo-gallery
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.20
- Severity Score:
- Medium
- CVE:
- 2024-3896
Piotnet Addons For Elementor
- Plugin:
- Piotnet Addons For Elementor
- Plugin Slug:
- piotnet-addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.4.30
- Severity Score:
- Medium
- CVE:
- 2024-5614
WP Meteor Website Speed Optimization Addon
- Plugin Slug:
- wp-meteor
- Installations
- 30,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.4.4
- Severity Score:
- Medium
- CVE:
- 2024-6553
All-in-One Video Gallery
- Plugin:
- All-in-One Video Gallery
- Plugin Slug:
- all-in-one-video-gallery
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.3
- Severity Score:
- Medium
- CVE:
- 2024-6629
Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells
- Plugin Slug:
- funnel-builder
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.7
- Severity Score:
- Medium
- CVE:
- 2024-6836
Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA
- Plugin Slug:
- icegram
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.1.25
- Severity Score:
- Medium
- CVE:
- 2024-39625
CM Popup Plugin for WordPress – Popup Maker
- Plugin Slug:
- cm-pop-up-banners
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.6
- Severity Score:
- Medium
- CVE:
- 2024-5004
Language Translate Widget for WP – ConveyThis
- Plugin Slug:
- conveythis-translate
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 235
- Severity Score:
- Medium
- CVE:
- 2024-38792
MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Plugin Slug:
- masterstudy-lms-learning-management-system
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.3.24
- Severity Score:
- High
- CVE:
- 2024-5973
HTML Forms – Simple WordPress Forms Plugin
- Plugin Slug:
- html-forms
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.33
- Severity Score:
- Medium
- CVE:
- 2024-6243
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin:
- Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin Slug:
- youzify
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.8
- Severity Score:
- Medium
- CVE:
- 2024-39635
WP QuickLaTeX
- Plugin:
- WP QuickLaTeX
- Plugin Slug:
- wp-quicklatex
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.8
- Severity Score:
- Medium
- CVE:
- 2024-5529
Campaign Monitor for WordPress
- Plugin:
- Campaign Monitor for WordPress
- Plugin Slug:
- forms-for-campaign-monitor
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.8.16
- Severity Score:
- Medium
- CVE:
- 2024-6569
WP EasyPay – Square for WordPress
- Plugin Slug:
- wp-easy-pay
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.2.4
- Severity Score:
- Medium
- CVE:
- 2024-5861
Great Restaurant Menu WP
- Plugin:
- Great Restaurant Menu WP
- Plugin Slug:
- best-restaurant-menu-by-pricelisto
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.4.2
- Severity Score:
- High
- CVE:
- 2024-38793
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 23.1.3
- Severity Score:
- High
- CVE:
- 2024-39631
Image SEO – AI-Driven Image SEO Optimizer
- Plugin Slug:
- imageseo
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1.2
- Severity Score:
- Medium
- CVE:
- 2024-6571
MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles
- Plugin Slug:
- maxi-blocks
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 1.9.3
- Severity Score:
- High
- CVE:
- 2024-6885
Custom Query Blocks
- Plugin:
- Custom Query Blocks
- Plugin Slug:
- post-type-archive-mapping
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.0
- Severity Score:
- Medium
- CVE:
- 2024-38794
Request a Quote
- Plugin:
- Request a Quote
- Plugin Slug:
- request-a-quote
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.1
- Severity Score:
- Medium
- CVE:
- 2024-6231
Community Events
- Plugin:
- Community Events
- Plugin Slug:
- community-events
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.5
- Severity Score:
- Medium
- CVE:
- 2024-6271
Ultimate Classified Listings
- Plugin:
- Ultimate Classified Listings
- Plugin Slug:
- ultimate-classified-listings
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2024-5883
Ultimate Classified Listings
- Plugin:
- Ultimate Classified Listings
- Plugin Slug:
- ultimate-classified-listings
- Installations
- 20+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2024-5882
PZ Frontend Manager
- Plugin:
- PZ Frontend Manager
- Plugin Slug:
- pz-frontend-manager
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2024-6244
PowerPack for Beaver Builder
- Plugin:
- PowerPack for Beaver Builder
- Plugin Slug:
- bbpowerpack
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.33.1
- Severity Score:
- High
- CVE:
- 2024-39633
PowerPack Pro for Elementor
- Plugin:
- PowerPack Pro for Elementor
- Plugin Slug:
- powerpack-elements
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.10.15
- Severity Score:
- High
- CVE:
- 2024-39634
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 5.3.15
- Severity Score:
- Critical
- CVE:
- 2024-6756
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.15
- Severity Score:
- Medium
- CVE:
- 2024-6754
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.15
- Severity Score:
- Medium
- CVE:
- 2024-6752
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.15
- Severity Score:
- High
- CVE:
- 2024-6750
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.15
- Severity Score:
- High
- CVE:
- 2024-6753
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.3.15
- Severity Score:
- Medium
- CVE:
- 2024-6751
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.15
- Severity Score:
- Medium
- CVE:
- 2024-6755
WooCommerce Product Table Lite
- Plugin:
- WooCommerce Product Table Lite
- Plugin Slug:
- wc-product-table-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.6
- Severity Score:
- Medium
- CVE:
- 2024-6458
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.5.2
- Severity Score:
- Medium
- CVE:
- 2024-5285
WordPress Themes — 0 Patched / 5 Unpatched
Himalayas
- Theme:
- Himalayas
- Theme Slug:
- himalayas
- Downloads
- 334,420
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-39629
Edubin
- Theme:
- Edubin
- Theme Slug:
- edubin
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-39637
ListingPro
- Theme:
- ListingPro
- Theme Slug:
- listingpro
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-39624
ListingPro
- Theme:
- ListingPro
- Theme Slug:
- listingpro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-39623
ListingPro
- Theme:
- ListingPro
- Theme Slug:
- listingpro
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-39622
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
