WordPress Vulnerability Report

WordPress Vulnerability Report — March 13, 2024

Since last week, 70 new vulnerabilities emerged in the WordPress ecosystem, including 2 in themes and 68 in plugins. 13 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 70 vulnerabilities have been publicly disclosed. Security patches for 57 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 13 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 55 Patched / 13 Unpatched

HT Easy GA4 – Google Analytics WordPress Plugin

Plugin Slug:
ht-easy-google-analytics
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Refresh Single Page

Plugin:
Auto Refresh Single Page
Plugin Slug:
auto-refresh-single-page
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blue Triad EZAnalytics

Plugin:
Blue Triad EZAnalytics
Plugin Slug:
blue-triad-ezanalytics
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Change Memory Limit

Plugin:
Change Memory Limit
Plugin Slug:
change-memory-limit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Build & Control Block Patterns

Plugin:
Build & Control Block Patterns
Plugin Slug:
control-block-patterns
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Droit Elementor Addons

Plugin:
Droit Elementor Addons
Plugin Slug:
droit-elementor-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FeedWordPress

Plugin:
FeedWordPress
Plugin Slug:
feedwordpress
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Maintenance Mode by helderk

Plugin:
Maintenance Mode by helderk
Plugin Slug:
hkdev-maintenance-mode
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:
Master Slider
Plugin Slug:
master-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:
Master Slider
Plugin Slug:
master-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich – Front-End Page Builder

Plugin:
Page Builder Sandwich – Front-End Page Builder
Plugin Slug:
page-builder-sandwich
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich – Front-End Page Builder

Plugin:
Page Builder Sandwich – Front-End Page Builder
Plugin Slug:
page-builder-sandwich
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Vimeography: Vimeo Video Gallery WordPress Plugin
Plugin Slug:
vimeography
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Manager

Plugin Slug:
wp-file-manager
Installations
1,000,000+
Vulnerability:
Path Traversal
Patched in Version:
7.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.2.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.4.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.4.

Metform Elementor Contact Form Builder

Plugin Slug:
metform
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.4.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.92
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.92.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.4.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.33.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.263
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.263.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.59.

The Plus Addons for Elementor

Plugin Slug:
the-plus-addons-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.1.

WP Chat App

Plugin Slug:
wp-whatsapp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.11.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.11.

Event Tickets and Registration

Plugin Slug:
event-tickets
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.1.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.2.

Simple Membership

Plugin Slug:
simple-membership
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.3.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.8.

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.18.
Plugin Slug:
woo-product-carousel-slider-and-grid-ultimate
Installations
9,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.8.

JM Twitter Cards

Plugin Slug:
jm-twitter-cards
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.
Plugin Slug:
wp-auto-affiliate-links
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.3.1.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.

Profile Box Shortcode And Widget

Plugin Slug:
facebook-likebox-widget-and-shortcode
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Password Protected Store for WooCommerce

Plugin Slug:
password-protected-woo-store
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

WooCommerce Add to Cart Custom Redirect

Plugin Slug:
woocommerce-add-to-cart-custom-redirect
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.14.

affiliate-toolkit – WordPress Affiliate Plugin

Plugin Slug:
affiliate-toolkit-starter
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.5.

affiliate-toolkit – WordPress Affiliate Plugin

Plugin Slug:
affiliate-toolkit-starter
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.5.

Simple Restrict

Plugin Slug:
simple-restrict
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Easy!Appointments

Plugin Slug:
easyappointments
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Booster Elite for WooCommerce

Plugin:
Booster Elite for WooCommerce
Plugin Slug:
booster-elite-for-woocommerce
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.1.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.1.8.

BuddyForms

Plugin:
BuddyForms
Plugin Slug:
buddyforms
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.8.

BuddyForms

Plugin:
BuddyForms
Plugin Slug:
buddyforms
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

BuddyForms

Plugin:
BuddyForms
Plugin Slug:
buddyforms
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.8.

Digits

Plugin:
Digits
Plugin Slug:
digits
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.2.

Events Tickets Plus

Plugin:
Events Tickets Plus
Plugin Slug:
event-tickets-plus
Vulnerability:
Broken Access Control
Patched in Version:
5.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.1.

Events Tickets Plus

Plugin:
Events Tickets Plus
Plugin Slug:
event-tickets-plus
Vulnerability:
Broken Access Control
Patched in Version:
5.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.1.

Mollie Forms

Plugin:
Mollie Forms
Plugin Slug:
mollie-forms
Vulnerability:
Broken Access Control
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Mollie Forms

Plugin:
Mollie Forms
Plugin Slug:
mollie-forms
Vulnerability:
Broken Access Control
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Restaurant Reservations

Plugin:
Restaurant Reservations
Plugin Slug:
nd-restaurant-reservations
Vulnerability:
Local File Inclusion
Patched in Version:
2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.

Otter Blocks PRO

Plugin:
Otter Blocks PRO
Plugin Slug:
otter-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Otter Blocks PRO

Plugin:
Otter Blocks PRO
Plugin Slug:
otter-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.4.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

File Manager Pro

Plugin:
File Manager Pro
Plugin Slug:
wp-file-manager-pro
Vulnerability:
Path Traversal
Patched in Version:
8.3.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.3.5.

WordPress Themes — 2 Patched / 0 Unpatched

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
2,918,819
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.27.

Total

Theme:
Total
Theme Slug:
total
Downloads
1,067,594
Vulnerability:
Broken Access Control
Patched in Version:
2.1.60
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.60.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: