WordPress Vulnerability Report

WordPress Vulnerability Report — June 19, 2024

Since last week, 87 new vulnerabilities emerged in the WordPress ecosystem including 85 plugins and 2 themes. 14 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 87 vulnerabilities have been publicly disclosed. Security patches for 73 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 14 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6 Beta 3 was released on June 18, 2024. The target release date for WordPress 6.6 is July 16, 2024. Your help testing Beta and RC versions over the next four weeks is vital to making sure the final release is everything it should be: stable, powerful, and intuitive.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 71 Patched / 14 Unpatched

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Suite

Plugin Slug:
custom-field-suite
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
elespare
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shariff for WordPress

Plugin Slug:
shariff-sharing
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scheduling Plugin – Online Booking for WordPress

Plugin:
Scheduling Plugin – Online Booking for WordPress
Plugin Slug:
calendar-booking
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Collapse-O-Matic

Plugin:
Collapse-O-Matic
Plugin Slug:
jquery-collapse-o-matic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:
Master Slider
Plugin Slug:
master-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin:
PDF Viewer for Elementor
Plugin Slug:
pdf-viewer-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Schema App Structured Data

Plugin:
Schema App Structured Data
Plugin Slug:
schema-app-structured-data-for-schemaorg
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Where I Was, Where I Will Be

Plugin:
Where I Was, Where I Will Be
Plugin Slug:
where-i-was-where-i-will-be
Vulnerability:
Remote File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Video Gallery
Plugin Slug:
yotuwp-easy-youtube-embed
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Video Gallery
Plugin Slug:
yotuwp-easy-youtube-embed
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.9.3.
Plugin Slug:
header-footer-elementor
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.36.

WPS Hide Login

Plugin Slug:
wps-hide-login
Installations
1,000,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.16.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.34.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.62.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.62.0.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.39.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.39.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.6.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.90
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.90.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.87
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.87.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.94.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.63
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.63.

Search & Replace

Plugin Slug:
search-and-replace
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.8.

Simple Sitemap – Create a Responsive HTML Sitemap

Plugin Slug:
simple-sitemap
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.5.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.14.

WordPress Online Booking and Scheduling Plugin – Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
23.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 23.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
7.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.4.2.

Divi Torque Lite – Divi Theme and Extra Theme

Plugin Slug:
addons-for-divi
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.9.4.

Stratum – Elementor Widgets

Plugin Slug:
stratum
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Serious Slider

Plugin Slug:
cryout-serious-slider
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Futurio Extra

Plugin Slug:
futurio-extra
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

Restaurant Menu – Food Ordering System – Table Reservation

Plugin Slug:
menu-ordering-reservations
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

WordPress Header Builder Plugin – Pearl

Plugin Slug:
pearl-header-builder
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Themify Builder

Plugin Slug:
themify-builder
Installations
7,000+
Vulnerability:
Open Redirection
Patched in Version:
7.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.8.

Dashboard Widgets Suite

Plugin Slug:
dashboard-widgets-suite
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.4.

WP Job Portal – A Complete Job Board

Plugin Slug:
wp-job-portal
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

WP Job Portal – A Complete Job Board

Plugin Slug:
wp-job-portal
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.0.39
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.1.0.39.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.9.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.1.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.5.

Easy Age Verify

Plugin Slug:
easy-age-verify
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.5.

Activity Reactions For Buddypress

Plugin Slug:
activity-reactions-for-buddypress
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.5.1.
Plugin Slug:
left-right-image-slideshow-gallery
Installations
90+
Vulnerability:
SQL Injection
Patched in Version:
1.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.2.

Dokan Pro

Plugin:
Dokan Pro
Plugin Slug:
dokan-pro
Vulnerability:
SQL Injection
Patched in Version:
3.11.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.11.0.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Folders Pro

Plugin:
Folders Pro
Plugin Slug:
folders-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.3.

Folders Pro

Plugin:
Folders Pro
Plugin Slug:
folders-pro
Vulnerability:
Path Traversal
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

FooEvents for WooCommerce

Plugin:
FooEvents for WooCommerce
Plugin Slug:
fooevents
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.19.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.19.21.

FooGallery Premium

Plugin:
FooGallery Premium
Plugin Slug:
foogallery-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

Ibtana

Plugin:
Ibtana
Plugin Slug:
ibtana-visual-editor
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.4.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Broken Access Control
Patched in Version:
4.9.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.1.

Newsletter – API addon (Premium)

Plugin:
Newsletter – API addon (Premium)
Plugin Slug:
newsletter-api
Vulnerability:
Broken Access Control
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Broken Access Control
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.3.

Wp Staging Pro

Plugin:
Wp Staging Pro
Plugin Slug:
wp-staging-pro
Vulnerability:
Local File Inclusion
Patched in Version:
5.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.1.

WordPress Themes — 2 Patched / 0 Unpatched

Excellent

Theme Slug:
excellent
Downloads
116,551
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Interface

Theme Slug:
interface
Downloads
429,770
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security