WordPress Security

WordPress Vulnerability Report — November 1, 2023

This week, 136 new vulnerabilities have been publicly disclosed in WordPress plugins.

Dan Knauss

Since our last report, 136 new vulnerabilities have been publicly disclosed.1 They all affect WordPress plugins, so there are no theme vulnerabilities to report this week. Security patches for 64 plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 72 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

New Releases: Solid Security Pro 8.0.3 and Basic 9.0.2. Please update!

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.3.2 is a Maintenance and Security release issued on October 12. It features 19 bug fixes on Core, 22 bug fixes for the Block Editor, and 8 security fixes.

Because this is a security release, it is recommended that you apply it and update your sites to WordPress 6.3.2 as soon as possible. Backports are also available for older supported major WordPress releases from version 4.1 onward.

The next major release will be version 6.4, expected on 7 November 2023.

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugins — 64 Patched / 72 Unpatched

WP Word Count

Plugin Slug:
wp-word-count
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Convertful – Your Ultimate On-Site Conversion Tool

Plugin Slug:
convertful
Installations:
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Avatar

Plugin Slug:
user-avatar
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Remove Add to Cart WooCommerce

Plugin Slug:
remove-add-to-cart-woocommerce
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Export WP Page to Static HTML/CSS

Plugin Slug:
export-wp-page-to-static-html
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SAHU TikTok Pixel for E-Commerce

Plugin Slug:
sahu-tiktok-pixel
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DeepL API translation plugin

Plugin Slug:
wpdeepl
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom My Account for Woocommerce

Plugin Slug:
custom-my-account-for-woocommerce
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DoLogin Security

Plugin Slug:
dologin
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FeedFocal

Plugin:
FeedFocal
Plugin Slug:
feedfocal
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Recommendation Quiz for eCommerce

Plugin Slug:
product-recommendation-quiz-for-ecommerce
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress

Plugin Slug:
quillforms
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Group Chat & Video Chat by AtomChat

Plugin Slug:
atomchat
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category SEO Meta Tags

Plugin Slug:
category-seo-meta-tags
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Header Images

Plugin Slug:
custom-header-images
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
daext-autolinks-manager
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Generate Dummy Posts

Plugin Slug:
generate-dummy-posts
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Shortcodes

Plugin Slug:
my-shortcodes
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Listing

Plugin Slug:
simple-user-listing
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WDSocialWidgets

Plugin Slug:
spider-facebook
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Parcel Pro

Plugin:
Parcel Pro
Plugin Slug:
woo-parcel-pro
Installations:
1,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Glossary

Plugin Slug:
wp-glossary
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP iCal Availability

Plugin Slug:
wp-ical-availability
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FLOWFACT WP Connector

Plugin Slug:
flowfact-wp-connector
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Sales Report

Plugin Slug:
ni-woocommerce-sales-report
Installations:
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Galleries

Plugin:
WP Simple Galleries
Plugin Slug:
wp-simple-galleries
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Popup

Plugin:
WP Post Popup
Plugin Slug:
wp-post-modal
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Columns

Plugin:
WP Post Columns
Plugin Slug:
wp-post-columns
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Knowledgebase

Plugin:
WP Knowledgebase
Plugin Slug:
wp-knowledgebase
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Maps made Simple

Plugin:
Google Maps made Simple
Plugin Slug:
wp-gmappity-easy-google-maps
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Font Awesome

Plugin:
WP Font Awesome
Plugin Slug:
wp-font-awesome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NinjaTeam Live Chat (Messenger API)

Plugin:
NinjaTeam Live Chat (Messenger API)
Plugin Slug:
wp-facebook-messenger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magic Embeds

Plugin:
Magic Embeds
Plugin Slug:
wp-embed-facebook
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Products for WooCommerce
Plugin Slug:
woo-related-products-refresh-on-reload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WhatsApp Share Button

Plugin:
WhatsApp Share Button
Plugin Slug:
whatsapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weather Atlas Widget

Plugin:
Weather Atlas Widget
Plugin Slug:
weather-atlas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WCP OpenWeather

Plugin:
WCP OpenWeather
Plugin Slug:
wcp-openweather
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Blvd Shortcodes

Plugin:
Theme Blvd Shortcodes
Plugin Slug:
theme-blvd-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TCD Google Maps

Plugin:
TCD Google Maps
Plugin Slug:
tcd-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Shortcodes

Plugin:
Simple Shortcodes
Plugin Slug:
smpl-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Menu

Plugin:
Shortcode Menu
Plugin Slug:
shortcode-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reusable Text Blocks

Plugin:
Reusable Text Blocks
Plugin Slug:
reusable-text-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PubyDoc

Plugin:
PubyDoc
Plugin Slug:
pubydoc-data-tables-and-charts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PHP to Page

Plugin:
PHP to Page
Plugin Slug:
php-to-page
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Original texts Yandex WebMaster

Plugin:
Original texts Yandex WebMaster
Plugin Slug:
original-texts-yandex-webmaster
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mediabay

Plugin:
Mediabay
Plugin Slug:
mediabay-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

KD Coming Soon

Plugin:
KD Coming Soon
Plugin Slug:
kd-coming-soon
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live updates from Excel

Plugin:
Live updates from Excel
Plugin Slug:
ipushpull
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iframe forms

Plugin:
iframe forms
Plugin Slug:
iframe-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

idbbee

Plugin:
idbbee
Plugin Slug:
idbbee
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus

Plugin:
Grid Plus
Plugin Slug:
grid-plus
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus

Plugin:
Grid Plus
Plugin Slug:
grid-plus
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Feather Login Page

Plugin:
Feather Login Page
Plugin Slug:
feather-login-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FareHarbor for WordPress

Plugin:
FareHarbor for WordPress
Plugin Slug:
fareharbor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyRecipe

Plugin:
EasyRecipe
Plugin Slug:
easyrecipe
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CTA

Plugin:
WordPress CTA
Plugin Slug:
easy-sticky-sidebar
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Delete Me

Plugin:
Delete Me
Plugin Slug:
delete-me
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Deeper Comments

Plugin:
Deeper Comments
Plugin Slug:
deeper-comments
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Current Menu Item for Custom Post Types

Plugin:
Current Menu Item for Custom Post Types
Plugin Slug:
current-menu-item-for-custom-post-types
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPO Shortcodes

Plugin:
CPO Shortcodes
Plugin Slug:
cpo-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Form Builder

Plugin:
Form Builder
Plugin Slug:
contact-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CloudNet360

Plugin Slug:
cloudnet-sync
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Buzzsprout Podcasting

Plugin:
Buzzsprout Podcasting
Plugin Slug:
buzzsprout-podcasting
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BSK PDF Manager

Plugin:
BSK PDF Manager
Plugin Slug:
bsk-pdf-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bellows Accordion Menu

Plugin:
Bellows Accordion Menu
Plugin Slug:
bellows-accordion-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Limit Posts Reloaded

Plugin:
Auto Limit Posts Reloaded
Plugin Slug:
auto-limit-posts-reloaded
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Excerpt everywhere

Plugin:
Auto Excerpt everywhere
Plugin Slug:
auto-excerpt-everywhere
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Article analytics

Plugin Slug:
article-analytics
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Alter

Plugin:
Alter
Plugin Slug:
alter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Menu Widget

Plugin:
Advanced Menu Widget
Plugin Slug:
advanced-menu-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ads by datafeedr.com

Plugin:
Ads by datafeedr.com
Plugin Slug:
ads-by-datafeedrcom
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations:
4,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.

kk Star Ratings

Plugin Slug:
kk-star-ratings
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.6.

VK Blocks

Plugin:
VK Blocks
Plugin Slug:
vk-blocks
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.64.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.64.0.0.

News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry)

Plugin Slug:
blog-designer-pack
Installations:
30,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.4.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.2.

CallRail Phone Call Tracking

Plugin Slug:
callrail-phone-call-tracking
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.5.3.

Interactive Image Map Plugin – Draw Attention

Plugin Slug:
draw-attention
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.16.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.51.

YOP Poll

Plugin:
YOP Poll
Plugin Slug:
yop-poll
Installations:
20,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.5.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.29.

404 Solution

Plugin Slug:
404-solution
Installations:
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.34.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.34.0.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations:
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.0.

ICS Calendar

Plugin Slug:
ics-calendar
Installations:
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
10.12.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.12.0.4.

Image Regenerate & Select Crop

Plugin Slug:
image-regenerate-select-crop
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.1.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.20.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.32.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.20.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.20.29.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations:
10,000+
Vulnerability:
Open Redirection
Patched in Version:
2.20.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.29.

WP EXtra

Plugin:
WP EXtra
Plugin Slug:
wp-extra
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.

WP EXtra

Plugin:
WP EXtra
Plugin Slug:
wp-extra
Installations:
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
6.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.3.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.1.

Fathom Analytics for WP

Plugin Slug:
fathom-analytics
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Pre-Orders for WooCommerce

Plugin Slug:
pre-orders-for-woocommerce
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.14.

Image horizontal reel scroll slideshow

Plugin Slug:
image-horizontal-reel-scroll-slideshow
Installations:
5,000+
Vulnerability:
SQL Injection
Patched in Version:
13.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.3.
Plugin Slug:
vk-filter-search
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

Assistant – Every Day Productivity Apps

Plugin Slug:
assistant
Installations:
4,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Very Simple Google Maps

Plugin Slug:
very-simple-google-maps
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.

Slick Popup: Contact Form 7 Popup Plugin

Plugin Slug:
slick-popup
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.15.

Vertical marquee plugin

Plugin Slug:
vertical-marquee-plugin
Installations:
3,000+
Vulnerability:
SQL Injection
Patched in Version:
7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.
Plugin Slug:
wp-responsive-thumbnail-slider
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Accordion

Plugin:
Accordion
Plugin Slug:
accordions-wp
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.

GD Security Headers

Plugin Slug:
gd-security-headers
Installations:
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.
Plugin Slug:
imagelinks-interactive-image-builder-lite
Installations:
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.0.

Popup with fancybox

Plugin Slug:
popup-with-fancybox
Installations:
2,000+
Vulnerability:
SQL Injection
Patched in Version:
3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.

Tab Ultimate

Plugin Slug:
tabs-pro
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

TK Google Fonts GDPR Compliant

Plugin Slug:
tk-google-fonts
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

WP Helper Premium

Plugin Slug:
wp-helper-lite
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.2.

Zotpress

Plugin:
Zotpress
Plugin Slug:
zotpress
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.5.

Add to Calendar Button

Plugin Slug:
add-to-calendar-button
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

MomentoPress for Momento360

Plugin Slug:
cmyee-momentopress
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox
Installations:
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.1.

WPPizza – A Restaurant Plugin

Plugin Slug:
wppizza
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.18.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.18.3.

Image vertical reel scroll slideshow

Plugin Slug:
image-vertical-reel-scroll-slideshow
Installations:
800+
Vulnerability:
SQL Injection
Patched in Version:
9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.

Animated Counters

Plugin Slug:
animated-counters
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Jquery news ticker

Plugin Slug:
jquery-news-ticker
Installations:
700+
Vulnerability:
SQL Injection
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Medialist

Plugin:
Medialist
Plugin Slug:
media-list
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager
Installations:
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager
Installations:
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Information Reel

Plugin Slug:
information-reel
Installations:
600+
Vulnerability:
SQL Injection
Patched in Version:
10.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.1.

Message ticker

Plugin Slug:
message-ticker
Installations:
600+
Vulnerability:
SQL Injection
Patched in Version:
9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.3.

WP fade in text news

Plugin Slug:
wp-fade-in-text-news
Installations:
600+
Vulnerability:
SQL Injection
Patched in Version:
12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.1.

Wp anything slider

Plugin Slug:
wp-anything-slider
Installations:
400+
Vulnerability:
SQL Injection
Patched in Version:
9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.2.

Neon text

Plugin:
Neon text
Plugin Slug:
neon-text
Installations:
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.
Plugin Slug:
superb-slideshow-gallery
Installations:
300+
Vulnerability:
SQL Injection
Patched in Version:
13.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.2.

wp image slideshow

Plugin Slug:
wp-image-slideshow
Installations:
300+
Vulnerability:
SQL Injection
Patched in Version:
12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.1.
Plugin Slug:
left-right-image-slideshow-gallery
Installations:
100+
Vulnerability:
SQL Injection
Patched in Version:
12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.1.

Wp photo text slider 50

Plugin Slug:
wp-photo-text-slider-50
Installations:
100+
Vulnerability:
SQL Injection
Patched in Version:
8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.

Jquery accordion slideshow

Plugin Slug:
jquery-accordion-slideshow
Installations:
70+
Vulnerability:
SQL Injection
Patched in Version:
8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.
Plugin Slug:
up-down-image-slideshow-gallery
Installations:
40+
Vulnerability:
SQL Injection
Patched in Version:
12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.1.
Plugin:
HTML filter and csv-file search
Plugin Slug:
hk-filter-and-search
Vulnerability:
Local File Inclusion
Patched in Version:
2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.
Plugin:
HTML filter and csv-file search
Plugin Slug:
hk-filter-and-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.

Bonus for Woo

Plugin:
Bonus for Woo
Plugin Slug:
bonus-for-woo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.3.

Advanced Booking Calendar

Plugin:
Advanced Booking Calendar
Plugin Slug:
advanced-booking-calendar
Vulnerability:
SQL Injection
Patched in Version:
3.2.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.12.

WordPress Themes — 0 Patched / 0 Unpatched

No new WordPress theme vulnerabilities were disclosed this week.

Notes

  1. This report comes out on Wednesdays and covers the last seven days of public disclosures in the Patchstack vulnerability database from the beginning of the previous week to the beginning of the current week — from last Monday to this Monday. This period intentionally excludes any vulnerabilities added to the database in the last 48 hours. However, that up-to-the-minute Patchstack vulnerability data powers Solid Security Pro for our customers who have purchased Solid Suite or Solid Security Pro. Using Patchstack’s virtual patches, Solid Security Pro automatically protects WordPress sites from active exploits aimed at unpatched vulnerabilities. ?

Did you like this article? Spread the word: