WordPress Vulnerability Report

WordPress Vulnerability Report — June 5, 2024

Since last week, 128 new vulnerabilities emerged in the WordPress ecosystem including 1 in themes and 127 in plugins. 49 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 128 vulnerabilities have been publicly disclosed. Security patches for 79 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6 Beta 1 was released on June 4, 2024. The scheduled final release date for WordPress 6.6 is July 16, 2024. Your help testing Beta and RC versions over the next six weeks is vital to making sure the final release is everything it should be: stable, powerful, and intuitive.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 78 Patched / 49 Unpatched

List categories

Plugin Slug:
list-categories
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
testimonials-carousel-elementor
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress
Installations
3,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Spoiler

Plugin Slug:
simple-spoiler
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Random Banner

Plugin Slug:
random-banner
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AffiEasy

Plugin:
AffiEasy
Plugin Slug:
affieasy
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Playlist for Youtube

Plugin Slug:
playlist-for-youtube
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ActiveDEMAND

Plugin:
ActiveDEMAND
Plugin Slug:
activedemand
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Notices Manager

Plugin:
Admin Notices Manager
Plugin Slug:
admin-notices-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Authorize.net Payment Gateway For WooCommerce

Plugin:
Authorize.net Payment Gateway For WooCommerce
Plugin Slug:
authorizenet-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyForms

Plugin:
BuddyForms
Plugin Slug:
buddyforms
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:
Comparison Slider
Plugin Slug:
comparison-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:
Comparison Slider
Plugin Slug:
comparison-slider
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:
Comparison Slider
Plugin Slug:
comparison-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cowidgets – Elementor Addons

Plugin:
Cowidgets – Elementor Addons
Plugin Slug:
cowidgets-elementor-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Attachments

Plugin:
Download Attachments
Plugin Slug:
download-attachments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:
Essential Real Estate
Plugin Slug:
essential-real-estate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:
Essential Real Estate
Plugin Slug:
essential-real-estate
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fluid Notification Bar

Plugin:
Fluid Notification Bar
Plugin Slug:
fluid-notification-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Registration – Contact Form 7

Plugin:
Frontend Registration – Contact Form 7
Plugin Slug:
frontend-registration-contact-form-7
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gianism

Plugin:
Gianism
Plugin Slug:
gianism
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Global Notification Bar

Plugin:
Global Notification Bar
Plugin Slug:
global-notification-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Insert Post Ads

Plugin:
Insert Post Ads
Plugin Slug:
insert-post-ads
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:
MJ Update History
Plugin Slug:
mj-update-history
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nafeza Prayer Time

Plugin:
Nafeza Prayer Time
Plugin Slug:
nafeza-prayer-time
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

QQWorld Auto Save Images

Plugin:
QQWorld Auto Save Images
Plugin Slug:
qqworld-auto-save-images
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Remote Content Shortcode

Plugin:
Remote Content Shortcode
Plugin Slug:
remote-content-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple COD Fees for WooCommerce

Plugin:
Simple COD Fees for WooCommerce
Plugin Slug:
simple-cod-fee-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smartarget Message Bar

Plugin Slug:
smartarget-message-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Link Pages
Plugin Slug:
social-link-pages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Login Lite For WooCommerce

Plugin:
Social Login Lite For WooCommerce
Plugin Slug:
social-login-lite-for-woocommerce
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

StopBadBots

Plugin:
StopBadBots
Plugin Slug:
stopbadbots
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin:
Themesflat Addons For Elementor
Plugin Slug:
themesflat-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Upload Fields for WPForms

Plugin:
Upload Fields for WPForms
Plugin Slug:
upload-fields-for-wpforms
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uploadcare File Uploader and Adaptive Delivery (beta)

Plugin:
Uploadcare File Uploader and Adaptive Delivery (beta)
Plugin Slug:
uploadcare
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Claudio Sanches

Plugin:
Claudio Sanches
Plugin Slug:
woocommerce-checkout-cielo
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Back Button

Plugin:
WP Back Button
Plugin Slug:
wp-back-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-DB-Table-Editor

Plugin:
WP-DB-Table-Editor
Plugin Slug:
wp-db-table-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Translate

Plugin:
WP Translate
Plugin Slug:
wp-translate
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPUpper Share Buttons

Plugin:
WPUpper Share Buttons
Plugin Slug:
wpupper-share-buttons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yumpu ePaper publishing

Plugin:
Yumpu ePaper publishing
Plugin Slug:
yumpu-epaper-publishing
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.33.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.33.0.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.32.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.7.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.10.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.0.

Post SMTP – WP SMTP Plugin with Email Logs & Mobile App for Failure Alerts – Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
SQL Injection
Patched in Version:
2.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.4.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.5.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.976
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.976.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
200,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.0.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.43.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.108
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.108.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.94.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.91
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.91.

Download Monitor

Plugin Slug:
download-monitor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.14.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.6.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.8.1.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.44.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.44.

Ninja Tables – Easiest Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.10.

Site Reviews

Plugin Slug:
site-reviews
Installations
60,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
7.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.0.

WordPress Infinite Scroll – Ajax Load More

Plugin Slug:
ajax-load-more
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
20,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.1.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.4.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

LifterLMS – WordPress LMS for eLearning

Plugin Slug:
lifterlms
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
7.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.3.

Elements For Elementor

Plugin Slug:
nd-elements
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Simple Like Page Plugin

Plugin Slug:
simple-facebook-plugin
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.

Five Star Restaurant Menu and Food Ordering

Plugin Slug:
food-and-drink-menu
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.17.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.7.
Plugin Slug:
integrate-google-drive
Installations
6,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.3.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.94.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.0.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
responsive-owl-carousel-elementor
Installations
4,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Mollie Forms

Plugin Slug:
mollie-forms
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.14.

Preferred Languages

Plugin Slug:
preferred-languages
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Simple Ajax Chat – Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20240412
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20240412.

Site Favicon

Plugin Slug:
site-favicon
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.0.

Emergency Password Reset

Plugin Slug:
emergency-password-reset
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
gamipress-link
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Safety Exit

Plugin Slug:
safety-exit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

WP Flow Plus

Plugin Slug:
wp-imageflow2
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.3.

MelaPress Login Security

Plugin Slug:
melapress-login-security
Installations
600+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin Slug:
attire-blocks
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Just Writing Statistics

Plugin Slug:
just-writing-statistics
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.

Advanced Custom Fields PRO

Plugin:
Advanced Custom Fields PRO
Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.
Plugin:
Boostify Header Footer Builder for Elementor
Plugin Slug:
boostify-header-footer-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Contact Form Manager

Plugin:
Contact Form Manager
Plugin Slug:
contact-form-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

GP Premium

Plugin:
GP Premium
Plugin Slug:
gp-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

The Plus Addons for Elementor Pro

Plugin:
The Plus Addons for Elementor Pro
Plugin Slug:
theplus_elementor_addon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.5.

Checkout Field Editor for WooCommerce (Pro)

Plugin:
Checkout Field Editor for WooCommerce (Pro)
Plugin Slug:
woocommerce-checkout-field-editor-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.3.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.3.9.

WPvivid Backup for MainWP

Plugin:
WPvivid Backup for MainWP
Plugin Slug:
wpvivid-backup-mainw
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.33.

WordPress Themes — 1 Patched / 0 Unpatched

Responsive

Theme Slug:
responsive
Downloads
4,502,287
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security