WordPress Vulnerability Report

WordPress Vulnerability Report — May 15, 2024

Since last week, 192 new vulnerabilities emerged in the WordPress ecosystem, including 16 in themes and 176 in plugins. 47 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 192 vulnerabilities have been publicly disclosed. Security patches for 145 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 129 Patched / 47 Unpatched

Flo Forms – Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

140+ Widgets | Best Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JCH Optimize

Plugin Slug:
jch-optimize
Installations
6,000+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kognetiks Chatbot for WordPress

Plugin Slug:
chatbot-chatgpt
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gsearch-plus
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
sticky-social-link
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DS Site Message

Plugin Slug:
ds-site-message
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viet Nam Affiliate

Plugin Slug:
viet-nam-affiliate
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AWSOM News Announcement

Plugin:
AWSOM News Announcement
Plugin Slug:
awsom-news-announcement
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlogLentor

Plugin:
BlogLentor
Plugin Slug:
bloglentor-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brozzme Scroll Top

Plugin:
Brozzme Scroll Top
Plugin Slug:
brozzme-scroll-top
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

canvasio3D Light

Plugin:
canvasio3D Light
Plugin Slug:
canvasio3d-light
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Configure Login Timeout

Plugin:
Configure Login Timeout
Plugin Slug:
configure-login-timeout
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Corona Virus (COVID-19) Banner & Live Data

Plugin:
Corona Virus (COVID-19) Banner & Live Data
Plugin Slug:
corona-virus-covid-19-banner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:
Crelly Slider
Plugin Slug:
crelly-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Debug Info

Plugin:
Debug Info
Plugin Slug:
debug-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyEvent

Plugin:
EasyEvent
Plugin Slug:
easyevent
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enter Addons

Plugin:
Enter Addons
Plugin Slug:
enteraddons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fancy Elementor Flipbox

Plugin:
Fancy Elementor Flipbox
Plugin Slug:
fancy-elementor-flipbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fast Custom Social Share by CodeBard

Plugin:
Fast Custom Social Share by CodeBard
Plugin Slug:
fast-custom-social-share-by-codebard
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Content Gallery
Plugin Slug:
featured-content-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forty Four – 404 Plugin for WordPress

Plugin:
Forty Four – 404 Plugin for WordPress
Plugin Slug:
forty-four
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GDPR Compliance

Plugin:
GDPR Compliance
Plugin Slug:
gdpr-compliance
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comments Evolved for WordPress

Plugin:
Comments Evolved for WordPress
Plugin Slug:
gplus-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LetterPress

Plugin:
LetterPress
Plugin Slug:
letterpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:
MF Gig Calendar
Plugin Slug:
mf-gig-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pk Favicon Manager

Plugin:
Pk Favicon Manager
Plugin Slug:
phpsword-favicon-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Pootle Pagebuilder – WordPress Page builder

Plugin:
Pootle Pagebuilder – WordPress Page builder
Plugin Slug:
pootle-page-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pure Chat

Plugin:
Pure Chat
Plugin Slug:
pure-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QuickieBar

Plugin:
QuickieBar
Plugin Slug:
quickiebar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Connect

Plugin:
Social Connect
Plugin Slug:
social-connect
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Swift Performance Lite

Plugin:
Swift Performance Lite
Plugin Slug:
swift-performance-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Table Maker

Plugin:
Table Maker
Plugin Slug:
table-maker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TT Custom Post Type Creator

Plugin:
TT Custom Post Type Creator
Plugin Slug:
tt-custom-post-type-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Viet Affiliate Link
Plugin Slug:
viet-affiliate-link
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP etracker

Plugin:
WP etracker
Plugin Slug:
wp-etracker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Favorite Posts

Plugin:
WP Favorite Posts
Plugin Slug:
wp-favorite-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WPCS ( WordPress Custom Search )
Plugin Slug:
wpcs-wp-custom-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin:
Yoast SEO
Plugin Slug:
wordpress-seo
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
22.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 22.6.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations
4,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.4.

One Click Demo Import

Plugin Slug:
one-click-demo-import
Installations
1,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

Translate Multilingual sites – TranslatePress

Plugin Slug:
translatepress-multilingual
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

Blocksy Companion

Plugin Slug:
blocksy-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.46.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor
Installations
200,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.5.103
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.103.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.103
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.103.

White Label CMS

Plugin Slug:
white-label-cms
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.52.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.52.2.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.52.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.52.2.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.1.3.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.1.2.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.1.

WP Job Manager

Plugin Slug:
wp-job-manager
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

XML Sitemap & Google News

Plugin Slug:
xml-sitemap-feed
Installations
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.9.

EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor

Plugin Slug:
embedpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.17.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
SQL Injection
Patched in Version:
4.2.6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.6.6.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.2.6.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.6.6.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.26.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.6.

Mesmerize Companion

Plugin Slug:
mesmerize-companion
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.149
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.149.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.32.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
70,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.2.70
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.70.

Custom Field Suite

Plugin Slug:
custom-field-suite
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.6.

Image Hover Effects – Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.39
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.39.

Timber

Plugin:
Timber
Plugin Slug:
timber-library
Installations
40,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
1.23.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.23.1.
Plugin Slug:
visual-footer-credit-remover
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Social Sharing Plugin – Social Warfare

Plugin Slug:
social-warfare
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.

Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro

Plugin Slug:
back-in-stock-notifier-for-woocommerce
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.2.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.
Plugin Slug:
easy-affiliate-links
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.3.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.10.

HTML5 Audio Player- Best WordPress Audio Player Plugin

Plugin Slug:
html5-audio-player
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.22.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.
Plugin Slug:
meow-gallery
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

Hotel Booking Lite

Plugin Slug:
motopress-hotel-booking-lite
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.11.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.11.2.

Shared Counts – Social Media Share Buttons

Plugin Slug:
shared-counts
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
20240511
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20240511.

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.21.

Themify Shortcodes

Plugin Slug:
themify-shortcodes
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.1.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

Orders Tracking for WooCommerce

Plugin Slug:
woo-orders-tracking
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.11.

WP Latest Posts

Plugin Slug:
wp-latest-posts
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.8.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus
Installations
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.7.01.002
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.7.01.002.

YITH WooCommerce Gift Cards

Plugin Slug:
yith-woocommerce-gift-cards
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.13.0.

If-So Dynamic Content Personalization

Plugin Slug:
if-so
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.1.

WordPress Affiliates Plugin — SliceWP Affiliates

Plugin Slug:
slicewp
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.20.02
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.20.02.

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer
Installations
7,000+
Vulnerability:
Open Redirection
Patched in Version:
6.20.02
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.20.02.

Better Elementor Addons

Plugin Slug:
better-elementor-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

Edwiser Bridge – WordPress Moodle LMS Integration

Plugin Slug:
edwiser-bridge
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.0.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.6.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.5.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets
Installations
4,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.7.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.14.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets
Installations
4,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.14
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.14.
Plugin Slug:
wp-auto-affiliate-links
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
6.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.4.

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.16.

Mihdan: Yandex Turbo Feed

Plugin Slug:
mihdan-yandex-turbo-feed
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Move Addons for Elementor

Plugin Slug:
move-addons
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

ShopBuilder – Elementor WooCommerce Builder Addons

Plugin Slug:
shopbuilder
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

Zotpress

Plugin:
Zotpress
Plugin Slug:
zotpress
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.10.

Arigato Autoresponder and Newsletter

Plugin Slug:
bft-autoresponder
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.4.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Falang multilanguage for WordPress

Plugin Slug:
falang
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.50
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.50.

Ghost

Plugin:
Ghost
Plugin Slug:
ghost
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Gold Addons for Elementor

Plugin Slug:
gold-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Dynamics 365 Integration

Plugin Slug:
integration-dynamics
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.18.

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

SKT Addons for Elementor

Plugin Slug:
skt-addons-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.4.8.

WP Discourse

Plugin Slug:
wp-discourse
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

WPCal.io – Easy Meeting Scheduler

Plugin Slug:
wpcal
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.5.9.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Installations
800+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.5.

Sticky banner

Plugin Slug:
sticky-banner
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Joli FAQ SEO – WordPress FAQ Plugin

Plugin Slug:
joli-faq-seo
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Soccer Engine – Soccer Plugin for WordPress

Plugin Slug:
soccer-engine-lite
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.4.

ADFO – Custom data in admin dashboard

Plugin Slug:
admin-form
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

ADFO – Custom data in admin dashboard

Plugin Slug:
admin-form
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

Z-Downloads

Plugin Slug:
z-downloads
Installations
60+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.11.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.11.4.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Broken Access Control
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

Divi Builder

Plugin:
Divi Builder
Plugin Slug:
divi-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.25.1.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.81.

Porto Theme – Functionality

Plugin:
Porto Theme – Functionality
Plugin Slug:
porto-functionality
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

Spectra Pro

Plugin:
Spectra Pro
Plugin Slug:
spectra-pro
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.6.

Stockholm Core

Plugin:
Stockholm Core
Plugin Slug:
stockholm-core
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.2.

Stockholm Core

Plugin:
Stockholm Core
Plugin Slug:
stockholm-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.2.

Unyson

Plugin:
Unyson
Plugin Slug:
unyson
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.31.

WordPress Themes — 16 Patched

Consus

Theme:
Consus
Theme Slug:
consus
Downloads
16,364
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

EmpowerWP

Theme Slug:
empowerwp
Downloads
219,376
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.22.

Himalayas

Theme Slug:
himalayas
Downloads
332,940
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Ketos

Theme:
Ketos
Theme Slug:
ketos
Downloads
28,703
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Mindscape

Theme Slug:
mindscape
Downloads
41,737
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

Niveau

Theme:
Niveau
Theme Slug:
niveau
Downloads
16,831
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

Oasis

Theme:
Oasis
Theme Slug:
oasis
Downloads
69,511
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.13.

raindrops

Theme Slug:
raindrops
Downloads
716,615
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.700
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.700.

Skyline WP

Theme Slug:
skyline-wp
Downloads
169,635
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Zeka

Theme:
Zeka
Theme Slug:
zeka
Downloads
20,249
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.10.

Divi

Theme:
Divi
Theme Slug:
divi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.25.1.

Extra

Theme:
Extra
Theme Slug:
extra
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.25.1.

Porto

Theme:
Porto
Theme Slug:
porto
Vulnerability:
Local File Inclusion
Patched in Version:
7.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.1.

Porto

Theme:
Porto
Theme Slug:
porto
Vulnerability:
Local File Inclusion
Patched in Version:
7.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.1.

Stockholm

Theme:
Stockholm
Theme Slug:
stockholm
Vulnerability:
Local File Inclusion
Patched in Version:
9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.7.

Stockholm

Theme:
Stockholm
Theme Slug:
stockholm
Vulnerability:
Local File Inclusion
Patched in Version:
9.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security