WordPress Vulnerability Report

WordPress Vulnerability Report — May 1, 2024

Since last week, 359 new vulnerabilities emerged in the WordPress ecosystem, including 28 in themes and 331 in plugins. 90 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 269 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 90 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 248 Patched / 21 Unpatched

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
70,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FameTheme Demo Importer

Plugin Slug:
famethemes-demo-importer
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AGCA – Custom Dashboard & Login Page

Plugin Slug:
ag-custom-admin
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Serious Slider

Plugin Slug:
cryout-serious-slider
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xserver Migrator

Plugin Slug:
xserver-migrator
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Annual Archive

Plugin Slug:
anual-archive
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Democracy Poll

Plugin Slug:
democracy-poll
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meks ThemeForest Smart Widget

Plugin Slug:
meks-themeforest-smart-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print-O-Matic

Plugin Slug:
print-o-matic
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Recent Posts Widget

Plugin Slug:
smart-recent-posts-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Customify Site Library

Plugin Slug:
customify-sites
Installations
6,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Ad Widget

Plugin Slug:
ad-widget
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PopupAlly

Plugin:
PopupAlly
Plugin Slug:
popupally
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pretty Google Calendar

Plugin Slug:
pretty-google-calendar
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fan Page Widget by ThemeNcode

Plugin Slug:
facebook-fan-page-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Filterable Portfolio

Plugin Slug:
filterable-portfolio
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Share This Image

Plugin Slug:
share-this-image
Installations
2,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Maintenance Mode

Plugin Slug:
smart-maintenance-mode
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Advanced Search
Plugin Slug:
advance-search
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Most Recent Posts Mod

Plugin:
Advanced Most Recent Posts Mod
Plugin Slug:
advanced-most-recent-posts-mod
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post List

Plugin:
Advanced Post List
Plugin Slug:
advanced-post-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AJAX Login and Registration modal popup + inline form

Plugin:
AJAX Login and Registration modal popup + inline form
Plugin Slug:
ajax-login-and-registration-modal-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:
Element Pack Pro
Plugin Slug:
bdthemes-element-pack
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CF7 File Download – File Download for CF7

Plugin:
CF7 File Download – File Download for CF7
Plugin Slug:
cf7-file-download
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Client Dash

Plugin:
Client Dash
Plugin Slug:
client-dash
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Extension For Mailchimp

Plugin:
Contact Form 7 Extension For Mailchimp
Plugin Slug:
contact-form-7-mailchimp-extension
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPO Companion

Plugin:
CPO Companion
Plugin Slug:
cpo-companion
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:
Crelly Slider
Plugin Slug:
crelly-slider
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Set Favicon

Plugin:
Easy Set Favicon
Plugin Slug:
easy-set-favicon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Fonts

Plugin:
Embed Google Fonts
Plugin Slug:
embed-google-fonts
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Giphypress

Plugin:
Giphypress
Plugin Slug:
giphypress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GWP-Histats

Plugin:
GWP-Histats
Plugin Slug:
gwp-histats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JW Player for WordPress

Plugin:
JW Player for WordPress
Plugin Slug:
jw-player-7-for-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:
MF Gig Calendar
Plugin Slug:
mf-gig-calendar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mini Loops

Plugin:
Mini Loops
Plugin Slug:
mini-loops
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opal Widgets For Elementor

Plugin:
Opal Widgets For Elementor
Plugin Slug:
opal-widgets-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Plugin:
CodeBard’s Patron Button and Widgets for Patreon
Plugin Slug:
patron-button-and-widgets-by-codebard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PB MailCrypt

Plugin:
PB MailCrypt
Plugin Slug:
pb-mailcrypt-antispam-email-encryption
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:
Piotnet Addons For Elementor Pro
Plugin Slug:
piotnet-addons-for-elementor-pro
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:
Piotnet Addons For Elementor Pro
Plugin Slug:
piotnet-addons-for-elementor-pro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:
Piotnet Addons For Elementor Pro
Plugin Slug:
piotnet-addons-for-elementor-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:
Piotnet Addons For Elementor Pro
Plugin Slug:
piotnet-addons-for-elementor-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:
Piotnet Addons For Elementor Pro
Plugin Slug:
piotnet-addons-for-elementor-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Progressive WordPress (PWA)

Plugin:
Progressive WordPress (PWA)
Plugin Slug:
progressive-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:
Realtyna Organic IDX plugin
Plugin Slug:
real-estate-listing-realtyna-wpl
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Recencio Book Reviews

Plugin:
Recencio Book Reviews
Plugin Slug:
recencio-book-reviews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Regenerate post permalink

Plugin:
Regenerate post permalink
Plugin Slug:
regenerate-post-permalinks
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management Pro

Plugin:
School Management Pro
Plugin Slug:
school-management-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:
Shortcode Addons
Plugin Slug:
shortcode-addons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sliding Widgets

Plugin:
Sliding Widgets
Plugin Slug:
sliding-widgets
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons by Supsystic

Plugin:
Social Share Buttons by Supsystic
Plugin Slug:
social-share-buttons-by-supsystic
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Solid Affiliate

Plugin:
Solid Affiliate
Plugin Slug:
solid-affiliate
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Anything

Plugin:
Sticky Anything
Plugin Slug:
toast-stick-anything
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:
WidgetKit
Plugin Slug:
widgetkit-for-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP GDPR Compliance

Plugin:
WP GDPR Compliance
Plugin Slug:
wp-gdpr-compliance
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Masquerade

Plugin:
WP Masquerade
Plugin Slug:
wp-masquerade
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Page Post Widget Clone

Plugin:
WP Page Post Widget Clone
Plugin Slug:
wp-page-post-widget-clone
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WTI Like Post

Plugin:
WTI Like Post
Plugin Slug:
wti-like-post
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

XforWooCommerce

Plugin:
XforWooCommerce
Plugin Slug:
xforwoocommerce
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.217
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.217.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.29.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.26.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
700,000+
Vulnerability:
Path Traversal
Patched in Version:
2.12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.7.

Contact Form 7 Database Addon – CFDB7

Plugin Slug:
contact-form-cfdb7
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.7.

Duplicate Post

Plugin Slug:
copy-delete-posts
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.972
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.972.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
300,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3.95
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.95.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.5.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.21.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

YITH WooCommerce Compare

Plugin Slug:
yith-woocommerce-compare
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.38.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.38.0.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.4.

BackUpWordPress

Plugin Slug:
backupwordpress
Installations
100,000+
Vulnerability:
Directory Traversal
Patched in Version:
3.14
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.14.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.264
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.264.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.274
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.274.

FileOrganizer – Manage WordPress and Website Files

Plugin Slug:
fileorganizer
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.61.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.30.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.12.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.7.

WP Chat App

Plugin Slug:
wp-whatsapp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.

VK Block Patterns

Plugin Slug:
vk-block-patterns
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.31.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.1.1.

Backup Migration

Plugin Slug:
backup-backup
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.26.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.3.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports
Installations
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

WP SMTP

Plugin:
WP SMTP
Plugin Slug:
wp-smtp
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

WP ULike – Most Advanced WordPress Marketing Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

WP ULike – Most Advanced WordPress Marketing Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.16.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Media Cleaner: Clean your WordPress!

Plugin Slug:
media-cleaner
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce
Installations
70,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.4.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.5.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.9.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.4.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.4.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.5.

Collapse-O-Matic

Plugin Slug:
jquery-collapse-o-matic
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.5.6.
Plugin Slug:
quick-featured-images
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
13.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.7.1.

Simple Membership

Plugin Slug:
simple-membership
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.4.
Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.

Simply Static

Plugin Slug:
simply-static
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.4.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.0.

AGCA – Custom Dashboard & Login Page

Plugin Slug:
ag-custom-admin
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.2.

Popup Box – Best WordPress Popup Plugin

Plugin Slug:
ays-popup-box
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.7.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.5.45.7212
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.45.7212.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.12.

Social Sharing Plugin – Social Warfare

Plugin Slug:
social-warfare
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.2.

VOD Infomaniak

Plugin Slug:
vod-infomaniak
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.7.

WP Google Review Slider

Plugin Slug:
wp-google-places-review-slider
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.6.

Hide Dashboard Notifications

Plugin Slug:
wp-hide-backed-notices
Installations
30,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Appointment Hour Booking – WordPress Booking Plugin

Plugin Slug:
appointment-hour-booking
Installations
20,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.4.57
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.57.

Payment Gateway Based Fees and Discounts for WooCommerce

Plugin Slug:
checkout-fees-for-woocommerce
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.12.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.2.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.32.
Plugin Slug:
gt3-photo-video-gallery
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.22.

Pricing Table by Supsystic

Plugin Slug:
pricing-table-by-supsystic
Installations
20,000+
Vulnerability:
Content Injection
Patched in Version:
1.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.13.

Rate My Post – Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api
Installations
20,000+
Vulnerability:
Open Redirection
Patched in Version:
4.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.5.

Product Addons & Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
32.0.19
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 32.0.19.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription
Installations
20,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
4.0.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.18.

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin Slug:
wpzoom-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.36.

Advanced Floating Content Lite

Plugin Slug:
advanced-floating-content-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.19.
Plugin Slug:
elespare
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

SSL Mixed Content Fix

Plugin Slug:
http-https-remover
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

List Custom Taxonomy Widget

Plugin Slug:
list-custom-taxonomy-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.39.

Pop-up

Plugin:
Pop-up
Plugin Slug:
pop-up-pop-up
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Send PDF for Contact Form 7

Plugin Slug:
send-pdf-for-contact-form-7
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.4.

Ultimate Posts Widget

Plugin Slug:
ultimate-posts-widget
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Easy Accept Payments via PayPal

Plugin Slug:
wordpress-easy-paypal-payment-or-donation-accept-plugin
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.

WP Datepicker

Plugin Slug:
wp-datepicker
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.1.

Arconix FAQ

Plugin Slug:
arconix-faq
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

FG Joomla to WordPress

Plugin Slug:
fg-joomla-to-wordpress
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.21.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.21.0.

RomethemeForm For Elementor

Plugin Slug:
romethemeform
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

WP LinkedIn Auto Publish

Plugin Slug:
wp-linkedin-auto-publish
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.12.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.

Maintenance Mode

Plugin Slug:
hkdev-maintenance-mode
Installations
8,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.0.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.0.2.

WPC Composite Products for WooCommerce

Plugin Slug:
wpc-composite-products
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.8.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.0.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.3.

ProfileGrid – User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.0.

The Plus Blocks for Block Editor | Gutenberg

Plugin Slug:
the-plus-addons-for-block-editor
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.6.

Better Elementor Addons

Plugin Slug:
better-elementor-addons
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Easy Property Listings

Plugin Slug:
easy-property-listings
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Image Slider

Plugin Slug:
image-slider-widget
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.127
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.127.
Plugin Slug:
integrate-google-drive
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.91
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.91.
Plugin Slug:
integrate-google-drive
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.91
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.91.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.11.

Assistant – Every Day Productivity Apps

Plugin Slug:
assistant
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.2.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.15.

Salon booking system

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.6.6.

Salon booking system

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.6.6.

Salon booking system

Plugin Slug:
salon-booking-system
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.6.6.

Ultimate 410 Gone Status Code

Plugin Slug:
ultimate-410
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Embed Google Photos album

Plugin Slug:
embed-google-photos-album-easily
Installations
4,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Tickera – WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system
Installations
4,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.5.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.5.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Coupon & Discount Code Reveal Button

Plugin Slug:
coupon-reveal-button
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.9.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.6.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.6.

PropertyHive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.13.

Vision – Image Map Builder

Plugin Slug:
vision
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Widget Post Slider

Plugin Slug:
widget-post-slider
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
3,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.6.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.0.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
16.26.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 16.26.6.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
16.26.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 16.26.6.

Accessibility Widget

Plugin Slug:
accessibility-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.
Plugin Slug:
advanced-testimonial-carousel-for-elementor
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

All-in-one Like Widget

Plugin Slug:
all-in-one-facebook-like-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

Custom field finder

Plugin Slug:
custom-field-finder
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.4.

RSS Redirect & Feedburner Alternative

Plugin Slug:
feedburner-alternative-and-rss-redirect
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.0.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.0.25.

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

SuperFaktura WooCommerce

Plugin Slug:
woocommerce-superfaktura
Installations
2,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.40.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.40.4.

ActiveDEMAND

Plugin Slug:
activedemand
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.2.42
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.2.42.

Admin Bar Editor – Hide Toolbar by User Roles

Plugin Slug:
admin-bar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.1.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.13.

ChatBot Conversational Forms

Plugin Slug:
conversational-forms
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Culqi

Plugin:
Culqi
Plugin Slug:
culqi-checkout
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.15.

EPROLO Dropshipping

Plugin Slug:
eprolo-dropshipping
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

USPS Shipping for WooCommerce – Live Rates

Plugin Slug:
flexible-shipping-usps
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.0.

Headline Analyzer

Plugin Slug:
headline-analyzer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

KB Support – WordPress Help Desk and Knowledge Base

Plugin Slug:
kb-support
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.94
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.94.

Reviews Plus

Plugin Slug:
reviews-plus
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.
Plugin Slug:
seers-cookie-consent-banner-privacy-policy
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.1.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
7.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.3.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Poll | Vote | Contest – Best Poll Plugin for WordPress

Plugin Slug:
totalpoll-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.0.

Vitepos – Point of sale (POS) plugin for WooCommerce

Plugin Slug:
vitepos-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.2.

WP Club Manager – WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

WP GoToWebinar

Plugin Slug:
wp-gotowebinar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
15.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.1.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.1.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.07
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.07.

WPCal.io – Easy Meeting Scheduler

Plugin Slug:
wpcal
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.5.9.

WPPizza – A Restaurant Plugin

Plugin Slug:
wppizza
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.18.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.18.11.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

Leaky Paywall

Plugin Slug:
leaky-paywall
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
4.20.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.20.9.

Olive One Click Demo Import

Plugin Slug:
olive-one-click-demo-import
Installations
900+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Installations
800+
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.4.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.4.

Slash Admin

Plugin Slug:
slash-admin
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.2.

Car Dealer (Dealership) and Vehicle sales

Plugin Slug:
cardealer
Installations
700+
Vulnerability:
Content Injection
Patched in Version:
4.16
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.16.

ShortPixel Critical CSS

Plugin Slug:
shortpixel-critical-css
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.3.

Admin and Customer Messages After Order for WooCommerce: OrderConvo

Plugin Slug:
admin-and-client-message-after-order-for-woocommerce
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
12.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 12.5.

Better Comments

Plugin Slug:
better-comments
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Better Comments

Plugin Slug:
better-comments
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.
Plugin:
Header Footer Code Manager Pro
Plugin Slug:
99robots-header-footer-code-manager-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.17.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
SQL Injection
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Settings Change
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Settings Change
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Arbitrary File Deletion
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:
ARForms
Plugin Slug:
arforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

ARForms Form Builder

Plugin:
ARForms Form Builder
Plugin Slug:
arforms-form-builder
Vulnerability:
Broken Access Control
Patched in Version:
1.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.5.

Digital Publications by Supsystic

Plugin:
Digital Publications by Supsystic
Plugin Slug:
digital-publications-by-supsystic
Vulnerability:
Broken Access Control
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Local File Inclusion
Patched in Version:
3.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.1.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.8.

Interactive World Maps

Plugin:
Interactive World Maps
Plugin Slug:
interactive-world-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.

Max Addons Pro for Bricks

Plugin:
Max Addons Pro for Bricks
Plugin Slug:
max-addons-pro-bricks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

Max Addons Pro for Bricks

Plugin:
Max Addons Pro for Bricks
Plugin Slug:
max-addons-pro-bricks
Vulnerability:
Settings Change
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

WooCommerce Shipping Label

Plugin:
WooCommerce Shipping Label
Plugin Slug:
shipping-labels-for-woo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.9.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Broken Access Control
Patched in Version:
29.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 29.8.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
29.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 29.8.

WP Media Category Management

Plugin:
WP Media Category Management
Plugin Slug:
wp-media-category-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.0.

Wp Staging Pro

Plugin:
Wp Staging Pro
Plugin Slug:
wp-staging-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.0.

WordPress Themes — 21 Patched / 7 Unpatched

UDesign

Theme:
UDesign
Theme Slug:
u-design
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

XStore

Theme:
XStore
Theme Slug:
xstore
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Accountra

Theme Slug:
accountra
Downloads
20,885
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Althea WP

Theme Slug:
althea-wp
Downloads
52,642
Vulnerability:
Broken Access Control
Patched in Version:
1.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.16.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,113,676
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.40
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.40.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,113,676
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.34.

Brite

Theme:
Brite
Theme Slug:
brite
Downloads
125,207
Vulnerability:
Broken Access Control
Patched in Version:
1.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.15.

Colibri WP

Theme Slug:
colibri-wp
Downloads
1,271,195
Vulnerability:
Broken Access Control
Patched in Version:
1.0.99
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.99.

ColorNews

Theme Slug:
colornews
Downloads
266,626
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Elevate WP

Theme Slug:
elevate-wp
Downloads
70,130
Vulnerability:
Broken Access Control
Patched in Version:
1.0.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.17.

Financio

Theme:
Financio
Theme Slug:
financio
Downloads
17,197
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Hugo WP

Theme:
Hugo WP
Theme Slug:
hugo-wp
Downloads
59,334
Vulnerability:
Broken Access Control
Patched in Version:
1.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.10.

Intrace

Theme:
Intrace
Theme Slug:
intrace
Downloads
84,888
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Pathway

Theme:
Pathway
Theme Slug:
pathway
Downloads
57,050
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.16.

Photology

Theme Slug:
photology
Downloads
17,339
Vulnerability:
Broken Access Control
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit
Downloads
461,793
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.117
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.117.

Startupzy

Theme Slug:
startupzy
Downloads
66,824
Vulnerability:
Broken Access Control
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Teluro

Theme:
Teluro
Theme Slug:
teluro
Downloads
188,771
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.36.

Travey

Theme:
Travey
Theme Slug:
travey
Downloads
17,666
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

Vertice

Theme:
Vertice
Theme Slug:
vertice
Downloads
47,531
Vulnerability:
Broken Access Control
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Virtue

Theme:
Virtue
Theme Slug:
virtue
Downloads
2,473,892
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.

WP Portfolio

Theme Slug:
wp-portfolio
Downloads
82,208
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.

Zeever

Theme:
Zeever
Theme Slug:
zeever
Downloads
208,788
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security