WordPress Vulnerability Report

WordPress Vulnerability Report — July 31, 2024

Since last week, 80 new vulnerabilities emerged in the WordPress ecosystem including 75 plugins and 5 themes. 25 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 80 vulnerabilities have been publicly disclosed. Security patches for 55 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 25 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is now available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 55 Patched / 20 Unpatched

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable
Installations
30,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Admin CSS

Plugin:
Add Admin CSS
Plugin Slug:
add-admin-css
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Admin JavaScript

Plugin:
Add Admin JavaScript
Plugin Slug:
add-admin-javascript
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Post Navigation

Plugin:
Admin Post Navigation
Plugin Slug:
admin-post-navigation
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Trim Interface

Plugin:
Admin Trim Interface
Plugin Slug:
admin-trim-interface
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aramex Shipping WooCommerce

Plugin:
Aramex Shipping WooCommerce
Plugin Slug:
aramex-shipping-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flipbox Builder

Plugin:
Flipbox Builder
Plugin Slug:
flipbox-builder
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IgnitionDeck

Plugin:
IgnitionDeck
Plugin Slug:
ignitiondeck
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Intelligence

Plugin:
Intelligence
Plugin Slug:
intelligence
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:
ListingPro
Plugin Slug:
listingpro-plugin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Master Currency WP

Plugin:
Master Currency WP
Plugin Slug:
mastercurrency-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media.net Ads Manager

Plugin:
Media.net Ads Manager
Plugin Slug:
media-net-ads-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

One Click Close Comments

Plugin:
One Click Close Comments
Plugin Slug:
one-click-close-comments
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ParityPress

Plugin:
ParityPress
Plugin Slug:
paritypress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS – Migration Tool

Plugin:
Tutor LMS – Migration Tool
Plugin Slug:
tutor-lms-migration-tool
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Auction

Plugin:
Ultimate Auction
Plugin Slug:
ultimate-auction
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.

Redux Framework

Plugin Slug:
redux-framework
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.18.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.12.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.3.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.981
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.981.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.97.

Hide My WP Ghost – Security & Firewall

Plugin Slug:
hide-my-wp
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.2.02
Severity Score:
Low
The vulnerability has been patched, so you should update to version 5.2.02.
Plugin Slug:
intelly-related-posts
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.2.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.6.9.

WP ULike – Most Advanced Marketing Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.1.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
70,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

aThemes Starter Sites

Plugin Slug:
athemes-starter-sites
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.54
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.54.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.

WP Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.2.

Better Find and Replace

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.20.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.30.

WP Meteor Website Speed Optimization Addon

Plugin Slug:
wp-meteor
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.3.

Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells

Plugin Slug:
funnel-builder
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.7.

CM Popup Plugin for WordPress – Popup Maker

Plugin Slug:
cm-pop-up-banners
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Language Translate Widget for WP – ConveyThis

Plugin Slug:
conveythis-translate
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
235
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 235.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.33.

WP QuickLaTeX

Plugin Slug:
wp-quicklatex
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.8.

Campaign Monitor for WordPress

Plugin Slug:
forms-for-campaign-monitor
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.16.

WP EasyPay – Square for WordPress

Plugin Slug:
wp-easy-pay
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.4.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
23.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 23.1.3.

Image SEO – AI-Driven Image SEO Optimizer

Plugin Slug:
imageseo
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

Custom Query Blocks

Plugin Slug:
post-type-archive-mapping
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

Request a Quote

Plugin Slug:
request-a-quote
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Community Events

Plugin Slug:
community-events
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
20+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

PZ Frontend Manager

Plugin Slug:
pz-frontend-manager
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

PowerPack for Beaver Builder

Plugin:
PowerPack for Beaver Builder
Plugin Slug:
bbpowerpack
Vulnerability:
Privilege Escalation
Patched in Version:
2.33.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.33.1.

PowerPack Pro for Elementor

Plugin:
PowerPack Pro for Elementor
Plugin Slug:
powerpack-elements
Vulnerability:
Privilege Escalation
Patched in Version:
2.10.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.10.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.3.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Broken Access Control
Patched in Version:
5.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Broken Access Control
Patched in Version:
5.3.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.15.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Broken Access Control
Patched in Version:
5.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.15.

WooCommerce Product Table Lite

Plugin:
WooCommerce Product Table Lite
Plugin Slug:
wc-product-table-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.2.

WordPress Themes — 0 Patched / 5 Unpatched

Himalayas

Theme Slug:
himalayas
Downloads
334,420
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Edubin

Theme:
Edubin
Theme Slug:
edubin
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:
ListingPro
Theme Slug:
listingpro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security