WordPress Vulnerability Report

WordPress Vulnerability Report — March 6, 2024

Since last week, 126 new vulnerabilities emerged in the WordPress ecosystem, including 5 in themes and 121 in plugins. 49 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 126 vulnerabilities have been publicly disclosed. Security patches for 77 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 73 Patched / 48 Unpatched

Slivery Extender

Plugin Slug:
slivery-extender
Installations
2,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IDonate – blood request management system

Plugin Slug:
idonate
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Adsmonetizer

Plugin:
Adsmonetizer
Plugin Slug:
adsensei-b30
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ArtiBot

Plugin:
ArtiBot
Plugin Slug:
artibot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Refresh Single Page

Plugin:
Auto Refresh Single Page
Plugin Slug:
auto-refresh-single-page
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BeePress

Plugin:
BeePress
Plugin Slug:
beepress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blue Triad EZAnalytics

Plugin:
Blue Triad EZAnalytics
Plugin Slug:
blue-triad-ezanalytics
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Change Memory Limit

Plugin:
Change Memory Limit
Plugin Slug:
change-memory-limit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Under Construction / Maintenance Mode from Acurax

Plugin:
Under Construction / Maintenance Mode from Acurax
Plugin Slug:
coming-soon-maintenance-mode-from-acurax
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Under Construction / Maintenance Mode from Acurax

Plugin:
Under Construction / Maintenance Mode from Acurax
Plugin Slug:
coming-soon-maintenance-mode-from-acurax
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Configure SMTP

Plugin:
Configure SMTP
Plugin Slug:
configure-smtp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Build & Control Block Patterns

Plugin:
Build & Control Block Patterns
Plugin Slug:
control-block-patterns
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom fields shortcode

Plugin:
Custom fields shortcode
Plugin Slug:
custom-fields-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Media

Plugin:
Download Media
Plugin Slug:
download-media
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Duitku Payment Gateway

Plugin:
Duitku Payment Gateway
Plugin Slug:
duitku-social-payment-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Plugin:
Easy!Appointments
Plugin Slug:
easyappointments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin:
Ebook Store
Plugin Slug:
ebook-store
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Conversios.io

Plugin:
Conversios.io
Plugin Slug:
enhanced-e-commerce-for-woocommerce-store
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FeedWordPress

Plugin:
FeedWordPress
Plugin Slug:
feedwordpress
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fontific | Google Fonts

Plugin:
Fontific | Google Fonts
Plugin Slug:
fontific
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gestpay for WooCommerce

Plugin:
Gestpay for WooCommerce
Plugin Slug:
gestpay-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Maintenance Mode by helderk

Plugin:
Maintenance Mode by helderk
Plugin Slug:
hkdev-maintenance-mode
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JM Twitter Cards

Plugin:
JM Twitter Cards
Plugin Slug:
jm-twitter-cards
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketing Optimizer

Plugin:
Marketing Optimizer
Plugin Slug:
marketing-optimizer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:
Master Slider
Plugin Slug:
master-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:
Master Slider
Plugin Slug:
master-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media Alt Renamer

Plugin:
Media Alt Renamer
Plugin Slug:
media-alt-renamer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin:
WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit
Plugin Slug:
myshopkit-popup-smartbar-slidein
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich – Front-End Page Builder

Plugin:
Page Builder Sandwich – Front-End Page Builder
Plugin Slug:
page-builder-sandwich
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich – Front-End Page Builder

Plugin:
Page Builder Sandwich – Front-End Page Builder
Plugin Slug:
page-builder-sandwich
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Restrict

Plugin:
Page Restrict
Plugin Slug:
pagerestrict
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Password Protected Store for WooCommerce

Plugin:
Password Protected Store for WooCommerce
Plugin Slug:
password-protected-woo-store
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayU India

Plugin:
PayU India
Plugin Slug:
payu-india
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

postMash – custom post order

Plugin:
postMash – custom post order
Plugin Slug:
postmash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Restaurant Solutions – Checklist

Plugin Slug:
restaurant-solutions-checklist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rolo Slider

Plugin:
Rolo Slider
Plugin Slug:
rolo-slider
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Tweet

Plugin:
Simple Tweet
Plugin Slug:
simple-tweet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Bootstrap Elements for Elementor

Plugin:
Ultimate Bootstrap Elements for Elementor
Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Bootstrap Elements for Elementor

Plugin:
Ultimate Bootstrap Elements for Elementor
Plugin Slug:
ultimate-bootstrap-elements-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Shortcodes Plus

Plugin:
User Shortcodes Plus
Plugin Slug:
user-shortcodes-plus
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Vimeography: Vimeo Video Gallery WordPress Plugin
Plugin Slug:
vimeography
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Watermark RELOADED

Plugin:
Watermark RELOADED
Plugin Slug:
watermark-reloaded
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Access Control

Plugin:
WordPress Access Control
Plugin Slug:
wordpress-access-control
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeMirror Blocks

Plugin:
CodeMirror Blocks
Plugin Slug:
wp-codemirror-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP eCommerce

Plugin:
WP eCommerce
Plugin Slug:
wp-e-commerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP eCommerce

Plugin:
WP eCommerce
Plugin Slug:
wp-e-commerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Page Duplicator

Plugin:
Page Duplicator
Plugin Slug:
wp-page-duplicator
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:
WP Private Content Plus
Plugin Slug:
wp-private-content-plus
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.0.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.0.1.
Plugin Slug:
complianz-gdpr
Installations
900,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.0.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.22.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.4.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.58.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.58.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.2.

Nextend Social Login and Register

Plugin Slug:
nextend-facebook-connect
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.13.

GenerateBlocks

Plugin Slug:
generateblocks
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.3.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.32.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.31.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.3.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.86
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.86.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.85
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.85.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.7.

WP Show Posts

Plugin Slug:
wp-show-posts
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2024.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.2.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.1.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.99
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.99.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.1.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.1.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.1.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.1.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.57
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.57.

Custom Field Suite

Plugin Slug:
custom-field-suite
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.5.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes
Installations
30,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations
20,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.21.

NextMove Lite – Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.18.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.18.1.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

Contact Form 7 – PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

Contact Form 7 – PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

LifterLMS – WordPress LMS Plugin for eLearning

Plugin Slug:
lifterlms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.2.

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.18.

WPvivid Backup for MainWP

Plugin Slug:
wpvivid-backup-mainwp
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.33.

Finale Lite – Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.18.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.18.0.

SoundCloud Shortcode

Plugin Slug:
soundcloud-shortcode
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.0.

Coming Soon Page & Maintenance Mode

Plugin Slug:
responsive-coming-soon
Installations
4,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.9.

Friends

Plugin:
Friends
Plugin Slug:
friends
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.6.

Oliver POS – A WooCommerce Point of Sale (POS)

Plugin Slug:
oliver-pos
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.9.

Page Restriction WordPress (WP) – Protect WP Pages/Post

Plugin Slug:
page-and-post-restriction
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.20.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.20.7.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

Backup

Plugin:
Backup
Plugin Slug:
backup2
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.9.9.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.19.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.3.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Authentication
Patched in Version:
2.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.4.

WP Social Widget

Plugin:
WP Social Widget
Plugin Slug:
wp-social-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

WordPress Themes — 4 Patched / 1 Unpatched

Atahualpa

Theme Slug:
atahualpa
Downloads
1,333,690
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Yuki

Theme:
Yuki
Theme Slug:
yuki
Downloads
133,433
Vulnerability:
Broken Access Control
Patched in Version:
1.3.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.14.

Yuki

Theme:
Yuki
Theme Slug:
yuki
Downloads
133,433
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.15.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.11.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.11.6.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.11.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.11.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: