WordPress Vulnerability Report

WordPress Vulnerability Report — May 8, 2024

Since last week, 219 new vulnerabilities emerged in the WordPress ecosystem including 8 in themes, and 211 in plugins. 84 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah Ulmer

In this report, 219 vulnerabilities have been publicly disclosed. Security patches for 135 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 84 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 129 Patched / 82 Unpatched

Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xserver Migrator

Plugin Slug:
xserver-migrator
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Booster Extension

Plugin Slug:
booster-extension
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Democracy Poll

Plugin Slug:
democracy-poll
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print-O-Matic

Plugin Slug:
print-o-matic
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author – Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eleblog – Elementor Blog And Magazine Addons

Plugin Slug:
ele-blog
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Share This Image

Plugin Slug:
share-this-image
Installations
2,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Image Popup

Plugin Slug:
simple-image-popup
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Page Spider

Plugin Slug:
admin-page-spider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Viet Nam Affiliate

Plugin Slug:
viet-nam-affiliate
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

5280 Bootstrap Modal Contact Form

Plugin:
5280 Bootstrap Modal Contact Form
Plugin Slug:
5280-bootstrap-modal-contact-form
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print Barcode Labels for your WooCommerce products/orders

Plugin:
Print Barcode Labels for your WooCommerce products/orders
Plugin Slug:
a4-barcode-generator
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print Barcode Labels for your WooCommerce products/orders

Plugin:
Print Barcode Labels for your WooCommerce products/orders
Plugin Slug:
a4-barcode-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AA Cash Calculator

Plugin:
AA Cash Calculator
Plugin Slug:
aa-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACF Front End Editor

Plugin:
ACF Front End Editor
Plugin Slug:
acf-front-end-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACF On-The-Go

Plugin:
ACF On-The-Go
Plugin Slug:
acf-on-the-go
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AJAX Login and Registration modal popup + inline form

Plugin:
AJAX Login and Registration modal popup + inline form
Plugin Slug:
ajax-login-and-registration-modal-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AnnounceKit

Plugin:
AnnounceKit
Plugin Slug:
announcekit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Archives Calendar Widget

Plugin:
Archives Calendar Widget
Plugin Slug:
archives-calendar-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AWSOM News Announcement

Plugin:
AWSOM News Announcement
Plugin Slug:
awsom-news-announcement
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlogLentor

Plugin:
BlogLentor
Plugin Slug:
bloglentor-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brozzme Scroll Top

Plugin:
Brozzme Scroll Top
Plugin Slug:
brozzme-scroll-top
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Calendar

Plugin:
Calendar
Plugin Slug:
calendar
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

canvasio3D Light

Plugin:
canvasio3D Light
Plugin Slug:
canvasio3d-light
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Configure Login Timeout

Plugin:
Configure Login Timeout
Plugin Slug:
configure-login-timeout
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Corona Virus (COVID-19) Banner & Live Data

Plugin:
Corona Virus (COVID-19) Banner & Live Data
Plugin Slug:
corona-virus-covid-19-banner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPO Companion

Plugin:
CPO Companion
Plugin Slug:
cpo-companion
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:
Crelly Slider
Plugin Slug:
crelly-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Different Menu in Different Pages

Plugin:
Different Menu in Different Pages
Plugin Slug:
different-menus-in-different-pages
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Restaurant Table Booking

Plugin:
Easy Restaurant Table Booking
Plugin Slug:
easy-table-booking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Event Management Tickets Booking

Plugin:
Event Management Tickets Booking
Plugin Slug:
event-monster
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fancy Elementor Flipbox

Plugin:
Fancy Elementor Flipbox
Plugin Slug:
fancy-elementor-flipbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elementor ImageBox

Plugin:
Elementor ImageBox
Plugin Slug:
fd-elementor-imagebox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Content Gallery
Plugin Slug:
featured-content-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forty Four – 404 Plugin for WordPress

Plugin:
Forty Four – 404 Plugin for WordPress
Plugin Slug:
forty-four
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Front User Submit / Front Editor

Plugin:
WP Front User Submit / Front Editor
Plugin Slug:
front-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GDPR Compliance

Plugin:
GDPR Compliance
Plugin Slug:
gdpr-compliance
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Giphypress

Plugin:
Giphypress
Plugin Slug:
giphypress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Document Embedder

Plugin:
Google Document Embedder
Plugin Slug:
google-document-embedder
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Typography

Plugin:
Google Typography
Plugin Slug:
google-typography
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Comments Evolved for WordPress

Plugin:
Comments Evolved for WordPress
Plugin Slug:
gplus-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GWP-Histats

Plugin:
GWP-Histats
Plugin Slug:
gwp-histats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inline Google Spreadsheet Viewer

Plugin:
Inline Google Spreadsheet Viewer
Plugin Slug:
inline-google-spreadsheet-viewer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:
MF Gig Calendar
Plugin Slug:
mf-gig-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Min and Max Purchase for WooCommerce

Plugin:
Min and Max Purchase for WooCommerce
Plugin Slug:
min-and-max-purchase-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mini Loops

Plugin:
Mini Loops
Plugin Slug:
mini-loops
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Grid Gallery
Plugin Slug:
new-grid-gallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Photo Gallery – Responsive Photo Gallery
Plugin Slug:
new-photo-gallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Plugin:
CodeBard’s Patron Button and Widgets for Patreon
Plugin Slug:
patron-button-and-widgets-by-codebard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PB MailCrypt

Plugin:
PB MailCrypt
Plugin Slug:
pb-mailcrypt-antispam-email-encryption
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Perfect Pullquotes

Plugin:
Perfect Pullquotes
Plugin Slug:
perfect-pullquotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pk Favicon Manager

Plugin:
Pk Favicon Manager
Plugin Slug:
phpsword-favicon-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Progressive WordPress (PWA)

Plugin:
Progressive WordPress (PWA)
Plugin Slug:
progressive-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QuickieBar

Plugin:
QuickieBar
Plugin Slug:
quickiebar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:
Realtyna Organic IDX plugin
Plugin Slug:
real-estate-listing-realtyna-wpl
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management Pro

Plugin:
School Management Pro
Plugin Slug:
school-management-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sliding Widgets

Plugin:
Sliding Widgets
Plugin Slug:
sliding-widgets
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons by Supsystic

Plugin:
Social Share Buttons by Supsystic
Plugin Slug:
social-share-buttons-by-supsystic
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Subway – Private Site Option

Plugin:
Subway – Private Site Option
Plugin Slug:
subway
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:
SVS Pricing Tables
Plugin Slug:
svs-pricing-tables
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:
SVS Pricing Tables
Plugin Slug:
svs-pricing-tables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Swift Framework

Plugin:
Swift Framework
Plugin Slug:
swift-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Swift Framework

Plugin:
Swift Framework
Plugin Slug:
swift-framework
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TT Custom Post Type Creator

Plugin:
TT Custom Post Type Creator
Plugin Slug:
tt-custom-post-type-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TweetScroll Widget

Plugin:
TweetScroll Widget
Plugin Slug:
tweetscroll-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Viet Affiliate Link
Plugin Slug:
viet-affiliate-link
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woo Total Sales

Plugin:
Woo Total Sales
Plugin Slug:
woo-total-sales
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP etracker

Plugin:
WP etracker
Plugin Slug:
wp-etracker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Favorite Posts

Plugin:
WP Favorite Posts
Plugin Slug:
wp-favorite-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WPCS ( WordPress Custom Search )
Plugin Slug:
wpcs-wp-custom-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WTI Like Post

Plugin:
WTI Like Post
Plugin Slug:
wti-like-post
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ZD YouTube FLV Player

Plugin:
ZD YouTube FLV Player
Plugin Slug:
zd-youtube-flv-player
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin:
Yoast SEO
Plugin Slug:
wordpress-seo
Installations
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
22.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 22.6.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.218
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.218.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.31.

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
700,000+
Vulnerability:
Path Traversal
Patched in Version:
2.12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.7.

Contact Form 7 Database Addon – CFDB7

Plugin Slug:
contact-form-cfdb7
Installations
600,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.3.

SEOPress – On-site SEO

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.5.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.4.

BackUpWordPress

Plugin Slug:
backupwordpress
Installations
100,000+
Vulnerability:
Directory Traversal
Patched in Version:
3.14
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.14.

BuddyPress

Plugin:
BuddyPress
Plugin Slug:
buddypress
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.4.1.

MailerLite – Signup forms (official)

Plugin Slug:
official-mailerlite-sign-up-forms
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.7.

MailerLite – Signup forms (official)

Plugin Slug:
official-mailerlite-sign-up-forms
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.7.

Sydney Toolbox

Plugin Slug:
sydney-toolbox
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

WP ULike – Most Advanced WordPress Marketing Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

WP ULike – Most Advanced WordPress Marketing Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

3D FlipBook – PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.15.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.15.5.

Media Cleaner: Clean your WordPress!

Plugin Slug:
media-cleaner
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.3.

Drag and Drop Multiple File Upload – Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.8.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.2.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Image Hover Effects – Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.19.

Simple Membership

Plugin Slug:
simple-membership
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.

Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms

Plugin Slug:
stop-spammer-registrations-plugin
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2024.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2024.5.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.9.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.4.0.
Plugin Slug:
sina-extension-for-elementor
Installations
40,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.2.

WP Video Lightbox

Plugin Slug:
wp-video-lightbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.11.

Popup Box – Best WordPress Popup Plugin

Plugin Slug:
ays-popup-box
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.3.

Float menu – awesome floating side menu

Plugin Slug:
float-menu
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.1.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.12.

LeadConnector

Plugin Slug:
leadconnector
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.

LeadConnector

Plugin Slug:
leadconnector
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.0.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.6.

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Plugin Slug:
leaflet-maps-marker
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.9.

Modal Window – create popup modal window

Plugin Slug:
modal-window
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.10.

WordPress Header Builder Plugin – Pearl

Plugin Slug:
pearl-header-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20240502
Severity Score:
High
The vulnerability has been patched, so you should update to version 20240502.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Web Push Notifications – Webpushr

Plugin Slug:
webpushr-web-push-notifications
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.36.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.36.0.

Embed Google Fonts

Plugin Slug:
embed-google-fonts
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

WordPress Affiliates Plugin — SliceWP Affiliates

Plugin Slug:
slicewp
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

WPC Composite Products for WooCommerce

Plugin Slug:
wpc-composite-products
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.8.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce
Installations
7,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

iPanorama 360 – WordPress Virtual Tour Builder

Plugin Slug:
ipanorama-360-virtual-tour-builder-lite
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.2.

Sticky Buttons – floating buttons builder

Plugin Slug:
sticky-buttons
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Button Generator – easily Button Builder

Plugin Slug:
button-generation
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Side Menu Lite – add sticky fixed buttons

Plugin Slug:
side-menu-lite
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.1.

Edwiser Bridge – WordPress Moodle LMS Integration

Plugin Slug:
edwiser-bridge
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.0.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.6.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.0.

Testimonial Slider

Plugin Slug:
testimonial-slider
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

WPify Woo Czech

Plugin Slug:
wpify-woo
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.11.

Popup Box – new WordPress popup plugin

Plugin Slug:
popup-box
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets
Installations
4,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.7.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.14.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets
Installations
4,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.14
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.14.
Plugin Slug:
wp-auto-affiliate-links
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
6.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.4.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

Mihdan: Yandex Turbo Feed

Plugin Slug:
mihdan-yandex-turbo-feed
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Herd Effects – fake notifications and social proof plugin

Plugin Slug:
mwp-herd-effect
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.7.

PropertyHive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

JW Player for WordPress

Plugin Slug:
jw-player-7-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

Ultimate Under Construction

Plugin Slug:
ultimate-under-construction
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

Where Did You Hear About Us Checkout Field for WooCommerce

Plugin Slug:
wc-customer-source
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Follow Us Badges

Plugin Slug:
wpsite-follow-us-badges
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.11.

Admin Bar Editor – Hide Toolbar by User Roles

Plugin Slug:
admin-bar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.8.

ChatBot Conversational Forms

Plugin Slug:
conversational-forms
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.20.

Mooberry Book Manager

Plugin Slug:
mooberry-book-manager
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.15.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.15.13.

SimpleShop

Plugin:
SimpleShop
Plugin Slug:
simpleshop-cz
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.3.

SimpleShop

Plugin:
SimpleShop
Plugin Slug:
simpleshop-cz
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.1.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
1.3.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.3.

Wow Skype Buttons

Plugin Slug:
mwp-skype
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.

Last Viewed Posts by WPBeginner

Plugin Slug:
last-viewed-posts
Installations
600+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.1.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.4.

Tabellen von faustball.com

Plugin Slug:
docollipics-faustball-de
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Breakdance

Plugin:
Breakdance
Plugin Slug:
breakdance
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

ConvertPlus

Plugin:
ConvertPlus
Plugin Slug:
convertplug
Vulnerability:
Broken Access Control
Patched in Version:
3.5.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.26.

ConvertPlus

Plugin:
ConvertPlus
Plugin Slug:
convertplug
Vulnerability:
PHP Object Injection
Patched in Version:
3.5.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.26.

Cost Calculator Builder Pro

Plugin:
Cost Calculator Builder Pro
Plugin Slug:
cost-calculator-builder-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.68
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.68.

Digital Publications by Supsystic

Plugin:
Digital Publications by Supsystic
Plugin Slug:
digital-publications-by-supsystic
Vulnerability:
Broken Access Control
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.21.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.2.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.81.

Gravity Forms Unique ID

Plugin:
Gravity Forms Unique ID
Plugin Slug:
gp-unique-id
Vulnerability:
Content Spoofing
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Mhr Post Ticker

Plugin Slug:
mhr-post-ticker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.8.

WooCommerce AWeber Newsletter Subscription

Plugin:
WooCommerce AWeber Newsletter Subscription
Plugin Slug:
woocommerce-aweber-newsletter-subscription
Vulnerability:
Settings Change
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

WordPress Themes — 6 Patched / 2 Unpatched

Adventure Journal

Theme:
Adventure Journal
Theme Slug:
adventure-journal
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Unique

Theme:
Unique
Theme Slug:
unique
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
3,141,362
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.43.

Edge

Theme:
Edge
Theme Slug:
edge
Downloads
336,008
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Freesia Empire

Theme Slug:
freesia-empire
Downloads
203,860
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Pliska

Theme:
Pliska
Theme Slug:
pliska
Downloads
47,512
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.6.

raindrops

Theme Slug:
raindrops
Downloads
716,582
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.700
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.700.

Restaurant and Cafe

Theme Slug:
restaurant-and-cafe
Downloads
126,841
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security