WordPress Vulnerability Report

WordPress Vulnerability Report — March 20, 2024

Since last week, 201 new vulnerabilities emerged in the WordPress ecosystem, including 2 in themes and 199 in plugins. 16 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 201 vulnerabilities have been publicly disclosed. Security patches for 185 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 183 Patched / 16 Unpatched

HT Easy GA4 – Google Analytics WordPress Plugin

Plugin Slug:
ht-easy-google-analytics
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Social Feeds Widget & Shortcode

Plugin:
Advanced Social Feeds Widget & Shortcode
Plugin Slug:
advanced-facebook-twitter-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:
ArtiBot
Plugin Slug:
artibot
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enjoy Social Feed plugin for WordPress website

Plugin:
Enjoy Social Feed plugin for WordPress website
Plugin Slug:
enjoy-instagram-instagram-responsive-images-gallery-and-carousel
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enjoy Social Feed plugin for WordPress website

Plugin:
Enjoy Social Feed plugin for WordPress website
Plugin Slug:
enjoy-instagram-instagram-responsive-images-gallery-and-carousel
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

f(x) Private Site

Plugin:
f(x) Private Site
Plugin Slug:
fx-private-site
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Innovs HR

Plugin:
Innovs HR
Plugin Slug:
innovs-hr-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LadiApp

Plugin:
LadiApp
Plugin Slug:
ladipage
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LadiApp

Plugin:
LadiApp
Plugin Slug:
ladipage
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Malware Scanner

Plugin:
Malware Scanner
Plugin Slug:
miniorange-malware-protection
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter2Go

Plugin:
Newsletter2Go
Plugin Slug:
newsletter2go
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Play.ht

Plugin:
Play.ht
Plugin Slug:
play-ht
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Play.ht

Plugin:
Play.ht
Plugin Slug:
play-ht
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scalable Vector Graphics (SVG)

Plugin:
Scalable Vector Graphics (SVG)
Plugin Slug:
scalable-vector-graphics-svg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web Application Firewall – website security

Plugin:
Web Application Firewall – website security
Plugin Slug:
web-application-firewall
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7

Plugin Slug:
contact-form-7
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.2.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.
Plugin Slug:
header-footer-elementor
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.25.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.17.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.24.

WP Statistics

Plugin Slug:
wp-statistics
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 14.5.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.2.

Gutenberg Blocks by Kadence Blocks – Page Builder Features

Plugin Slug:
kadence-blocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.24.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.33.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.0.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.0.33.

PDF Embedder

Plugin Slug:
pdf-embedder
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.1.

Backuply – Backup, Restore, Migrate and Clone

Plugin Slug:
backuply
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Anti-Malware Security and Brute-Force Firewall

Plugin Slug:
gotmls
Installations
200,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.23.56
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.23.56.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.12.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.11.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.5.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.263
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.263.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.85
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.85.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.0.

WP Armour – Honeypot Anti Spam

Plugin Slug:
honeypot
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.14.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Directory Traversal
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.8.

Tracking Code Manager

Plugin Slug:
tracking-code-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.2.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.3.

Widget for Social Page Feeds

Plugin Slug:
facebook-pagelike-widget
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.
Plugin Slug:
permalink-manager
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.3.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.4.3.2.
Plugin Slug:
permalink-manager
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.3.1.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
2.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.2.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Site Reviews

Plugin Slug:
site-reviews
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.11.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.11.7.

Site Reviews

Plugin Slug:
site-reviews
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.11.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.11.7.

Easy Accordion – Best Accordion FAQ Plugin for WordPress

Plugin Slug:
easy-accordion-free
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.11.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.10.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.11.

Shariff Wrapper

Plugin Slug:
shariff
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.10.
Plugin Slug:
woo-permalink-manager
Installations
50,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.11.

Super Page Cache for Cloudflare

Plugin Slug:
wp-cloudflare-page-cache
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.6.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.3.0.

Starbox – the Author Box for Humans

Plugin Slug:
starbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Crisp – Live Chat and Chatbot

Plugin Slug:
crisp
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.45.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.5.44.7212
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.44.7212.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.6.9.

Seriously Simple Podcasting

Plugin Slug:
seriously-simple-podcasting
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Team Members

Plugin Slug:
team-members
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.2.

Visualizer: Tables and Charts Manager for WordPress

Plugin Slug:
visualizer
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.6.

WP Popups – WordPress Popup builder

Plugin Slug:
wp-popups-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.6.

Accordion

Plugin:
Accordion
Plugin Slug:
accordions
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.97
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.97.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.11.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.
Plugin Slug:
related-posts-for-wp
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Simple Job Board

Plugin Slug:
simple-job-board
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.11.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.11.1.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.5.

404 Solution

Plugin Slug:
404-solution
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.35.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.35.8.

WPBakery Page Builder Addons by Livemesh

Plugin Slug:
addons-for-visual-composer
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.3.

Contact Form 7 – PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

Cryptocurrency Widgets – Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

JetWidgets For Elementor

Plugin Slug:
jetwidgets-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.16.

Jobs for WordPress

Plugin Slug:
job-postings
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.5.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.1.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.7.

Ultimate Posts Widget

Plugin Slug:
ultimate-posts-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

WP Coder – Powerful HTML, CSS, JS and PHP Injection

Plugin Slug:
wp-coder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.0.

Zippy

Plugin:
Zippy
Plugin Slug:
zippy
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.6.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.10.

Elements Plus!

Plugin Slug:
elements-plus
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.3.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.1.

Tablesome – Responsive Table, Email Log, Form Automation – Contact Form 7, Elementor, WPForms, Gravity Forms, Fluent, Forminator

Plugin Slug:
tablesome
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.28
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.28.

Better Search – Relevant search results for WordPress

Plugin Slug:
better-search
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.1.

Database for Contact Form 7

Plugin Slug:
cf7-database
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.7.

Restaurant Menu and Food Ordering

Plugin Slug:
food-and-drink-menu
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

HT Easy GA4 – Google Analytics WordPress Plugin

Plugin Slug:
ht-easy-google-analytics
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

AntiSpam for Contact Form 7

Plugin Slug:
cf7-antispam
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.6.1.

Free Downloads WooCommerce

Plugin Slug:
download-now-for-woocommerce
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.8.3.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

Survey Maker – Best WordPress Survey Plugin

Plugin Slug:
survey-maker
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.6.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

News Announcement Scroll

Plugin Slug:
news-announcement-scroll
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.0.

Coupon Affiliates – WooCommerce Affiliate Plugin

Plugin Slug:
woo-coupon-usage
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.12.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.12.8.
Plugin Slug:
wp-auto-affiliate-links
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.3.1.

WP Calameo

Plugin:
WP Calameo
Plugin Slug:
wp-calameo
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Email Subscription Popup

Plugin Slug:
email-subscribe
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.21.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.4.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.

Profile Box Shortcode And Widget

Plugin Slug:
facebook-likebox-widget-and-shortcode
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Multiple Page Generator Plugin – MPG

Plugin Slug:
multiple-pages-generator-by-porthas
Installations
3,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.1.

oik

Plugin:
oik
Plugin Slug:
oik
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.2.

Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction

Plugin Slug:
pie-register
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.8.3.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.3.3.

PropertyHive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.10.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

CWW Companion

Plugin Slug:
cww-companion
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

WP Responsive Tabs horizontal vertical and accordion Tabs

Plugin Slug:
responsive-horizontal-vertical-and-accordion-tabs
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.18.

Sitekit

Plugin:
Sitekit
Plugin Slug:
sitekit
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

The Moneytizer

Plugin Slug:
the-moneytizer
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.6.1.

Advanced Sermons

Plugin Slug:
advanced-sermons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.

Bulgarisation for WooCommerce

Plugin Slug:
bulgarisation-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.15.

Bulgarisation for WooCommerce

Plugin Slug:
bulgarisation-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.15.

Knight Lab Timeline

Plugin Slug:
knight-lab-timelinejs
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.4.

MyCurator Content Curation

Plugin Slug:
mycurator
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.77
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.77.

Passwordless Login

Plugin Slug:
passwordless-login
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs)

Plugin Slug:
sky-elementor-addons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

WEN Responsive Columns

Plugin Slug:
wen-responsive-columns
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

wp-mpdf

Plugin:
wp-mpdf
Plugin Slug:
wp-mpdf
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

WP SendFox

Plugin:
WP SendFox
Plugin Slug:
wp-sendfox
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Backup Bolt

Plugin Slug:
backup-bolt
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Team Circle Image Slider With Lightbox

Plugin Slug:
circle-image-slider-with-lightbox
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

MJM Clinic

Plugin:
MJM Clinic
Plugin Slug:
mjm-clinic
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.23.

MJM Clinic

Plugin:
MJM Clinic
Plugin Slug:
mjm-clinic
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.23.

Barcode Scanner with Inventory & Order Manager

Plugin:
Barcode Scanner with Inventory & Order Manager
Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

Calendarista Basic Edition

Plugin:
Calendarista Basic Edition
Plugin Slug:
calendarista-basic-edition
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.3.

Contact Forms by Cimatti

Plugin:
Contact Forms by Cimatti
Plugin Slug:
contact-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Digits

Plugin:
Digits
Plugin Slug:
digits
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.2.

Evergreen Content Poster

Plugin:
Evergreen Content Poster
Plugin Slug:
evergreen-content-poster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
SQL Injection
Patched in Version:
6.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.5.

Formidable Registration

Plugin:
Formidable Registration
Plugin Slug:
formidable-registration
Vulnerability:
Broken Authentication
Patched in Version:
2.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.12.

WooCommerce License Manager

Plugin:
WooCommerce License Manager
Plugin Slug:
fs-license-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.2.

WooThumbs for WooCommerce by Iconic

Plugin:
WooThumbs for WooCommerce by Iconic
Plugin Slug:
iconic-woothumbs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.5.4.

Mollie Forms

Plugin:
Mollie Forms
Plugin Slug:
mollie-forms
Vulnerability:
Broken Access Control
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

Mollie Forms

Plugin:
Mollie Forms
Plugin Slug:
mollie-forms
Vulnerability:
Broken Access Control
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.

OxyExtras

Plugin:
OxyExtras
Plugin Slug:
oxyextras
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

Scrollsequence

Plugin:
Scrollsequence
Plugin Slug:
scrollsequence
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Tourfic

Plugin:
Tourfic
Plugin Slug:
tourfic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.8.

Tourfic

Plugin:
Tourfic
Plugin Slug:
tourfic
Vulnerability:
PHP Object Injection
Patched in Version:
2.11.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.19.

Tourfic

Plugin:
Tourfic
Plugin Slug:
tourfic
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.11.16
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.11.16.

Tourfic

Plugin:
Tourfic
Plugin Slug:
tourfic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.9.

User profile

Plugin:
User profile
Plugin Slug:
user-profile
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.21.

Builder for WooCommerce reviews shortcodes – ReviewShort

Plugin:
Builder for WooCommerce reviews shortcodes – ReviewShort
Plugin Slug:
woo-product-reviews-shortcode
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.01.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.01.4.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
SQL Injection
Patched in Version:
3.92.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.92.1.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.92.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.92.1.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
Arbitrary File Download
Patched in Version:
3.92.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.92.1.

WordPress Themes — 2 Patched / 0 Unpatched

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
2,949,629
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.27.

Blossom Spa

Theme Slug:
blossom-spa
Downloads
191,726
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: