In this report, 323 vulnerabilities have been publicly disclosed. Security patches for 95 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 228 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.7, code-named “Rollins,” is out now, paying tribute to the legendary jazz saxophonist Sonny Rollins. WordPress 6.7 debuts the modern Twenty Twenty-Five theme, offering design flexibility for blogs.
WordPress Plugins — 92 Patched / 226 Unpatched
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations
- Plugin Slug:
- master-addons
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52387
Classified Listing – Classified ads & Business Directory Plugin
- Plugin Slug:
- classified-listing
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52386
Team Member – Multi Language Supported Team Plugin
- Plugin Slug:
- team-showcase-supreme
- Installations
- 8,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52385
Post From Frontend
- Plugin:
- Post From Frontend
- Plugin Slug:
- post-from-frontend
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9689
AA Audio Player
- Plugin:
- AA Audio Player
- Plugin Slug:
- aa-audio-player
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52348
Bing Search API Integration
- Plugin:
- Bing Search API Integration
- Plugin Slug:
- abbs-bing-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51692
AchillesTheme-shortcodes
- Plugin:
- AchillesTheme-shortcodes
- Plugin Slug:
- achilles-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51878
Add Ribbon Shortcode
- Plugin:
- Add Ribbon Shortcode
- Plugin Slug:
- add-ribbon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51823
Advanced Video Player with Analytics
- Plugin:
- Advanced Video Player with Analytics
- Plugin Slug:
- advanced-video-player-with-analytics
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51824
Adventure Bucket List
- Plugin:
- Adventure Bucket List
- Plugin Slug:
- adventure-bucket-list
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51908
AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress
- Plugin:
- AgendaPress – Easily Publish Meeting Agendas and Programs on WordPress
- Plugin Slug:
- agendapress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51807
Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation
- Plugin:
- Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation
- Plugin Slug:
- ai-content-generator
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52384
Instant Image Generator
- Plugin:
- Instant Image Generator
- Plugin Slug:
- ai-image
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52377
Ajax Content Filter
- Plugin:
- Ajax Content Filter
- Plugin Slug:
- ajax-content-filter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51717
Alert Me!
- Plugin:
- Alert Me!
- Plugin Slug:
- alert-me
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51825
EleForms
- Plugin:
- EleForms
- Plugin Slug:
- all-contact-form-integration-for-elementor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-6626
Assist24 Help Desk
- Plugin:
- Assist24 Help Desk
- Plugin Slug:
- assist24it
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51910
Audio Record
- Plugin:
- Audio Record
- Plugin Slug:
- audio-record
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-51792
audioCase
- Plugin:
- audioCase
- Plugin Slug:
- audiocase
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51909
Awesome Fitness Testimonials
- Plugin:
- Awesome Fitness Testimonials
- Plugin Slug:
- awesome-fitness-testimonials
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51806
Awesome Tool Tip
- Plugin:
- Awesome Tool Tip
- Plugin Slug:
- awesome-tool-tip
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52349
AzonBox
- Plugin:
- AzonBox
- Plugin Slug:
- azonbox
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51931
Bamboo Enquiries
- Plugin:
- Bamboo Enquiries
- Plugin Slug:
- bamboo-enquiries
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51859
Banner System
- Plugin:
- Banner System
- Plugin Slug:
- banner-system
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51816
Be Shortcodes
- Plugin:
- Be Shortcodes
- Plugin Slug:
- be-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51881
Beacon For Help Scout
- Plugin:
- Beacon For Help Scout
- Plugin Slug:
- beacon-for-helpscout
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51828
BeBetter Social Icons
- Plugin:
- BeBetter Social Icons
- Plugin Slug:
- bebetter-social-icons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51880
best bootstrap widgets for elementor
- Plugin:
- best bootstrap widgets for elementor
- Plugin Slug:
- best-bootstrap-widgets-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51851
Bg Patriarchia BU
- Plugin:
- Bg Patriarchia BU
- Plugin Slug:
- bg-patriarchia-bu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51799
Bitcoin Payments
- Plugin:
- Bitcoin Payments
- Plugin Slug:
- bitcoin-payments
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51826
Blocks Post Grid
- Plugin:
- Blocks Post Grid
- Plugin Slug:
- blocks-post-grid
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51928
Boat Rental Plugin for WordPress
- Plugin:
- Boat Rental Plugin for WordPress
- Plugin Slug:
- boat-rental-system
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52376
Boombox Shortcode
- Plugin:
- Boombox Shortcode
- Plugin Slug:
- boombox-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51827
Brand my Footer
- Plugin:
- Brand my Footer
- Plugin Slug:
- brand-my-footer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51801
Bread & Butter
- Plugin:
- Bread & Butter
- Plugin Slug:
- bread-butter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51802
Browsing History
- Plugin:
- Browsing History
- Plugin Slug:
- browsing-history
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51885
BU Slideshow
- Plugin:
- BU Slideshow
- Plugin Slug:
- bu-slideshow
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52351
Buooy Sticky Header
- Plugin:
- Buooy Sticky Header
- Plugin Slug:
- buooy-sticky-header
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51699
CE21 Suite
- Plugin:
- CE21 Suite
- Plugin Slug:
- ce21-suite
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-10294
CE21 Suite
- Plugin:
- CE21 Suite
- Plugin Slug:
- ce21-suite
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-10285
CF7 WOW Styler
- Plugin:
- CF7 WOW Styler
- Plugin Slug:
- cf7-styler
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51689
Charity Addon for Elementor
- Plugin:
- Charity Addon for Elementor
- Plugin Slug:
- charity-addon-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51938
codeSnips
- Plugin:
- codeSnips
- Plugin Slug:
- codesnips
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51808
Smooth Maps
- Plugin:
- Smooth Maps
- Plugin Slug:
- colour-smooth-maps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51901
Combo WP Rewrite Slugs
- Plugin:
- Combo WP Rewrite Slugs
- Plugin Slug:
- combo-wp-rewrite-slugs
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51817
Community Yard Sale
- Plugin:
- Community Yard Sale
- Plugin Slug:
- community-yard-sale
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51846
Computer Repair Shop
- Plugin:
- Computer Repair Shop
- Plugin Slug:
- computer-repair-shop
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-51793
WP Virtual Room Configurator
- Plugin:
- WP Virtual Room Configurator
- Plugin Slug:
- configure-conference-room
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51907
Content Syndication Toolkit Reader
- Plugin:
- Content Syndication Toolkit Reader
- Plugin Slug:
- content-syndication-toolkit-reader
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51696
Conversion Helper
- Plugin:
- Conversion Helper
- Plugin Slug:
- conversion-helper
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-10676
Cowidgets – Elementor Addons
- Plugin:
- Cowidgets – Elementor Addons
- Plugin Slug:
- cowidgets-elementor-addons
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-10779
Cowidgets – Elementor Addons
- Plugin:
- Cowidgets – Elementor Addons
- Plugin Slug:
- cowidgets-elementor-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8960
Custom Dashboard Widget
- Plugin:
- Custom Dashboard Widget
- Plugin Slug:
- create-custom-dashboard-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51860
Creative Blocks
- Plugin:
- Creative Blocks
- Plugin Slug:
- creative-blocks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51822
CRM 2go
- Plugin:
- CRM 2go
- Plugin Slug:
- crm2go
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52350
Custom URL Shortener
- Plugin:
- Custom URL Shortener
- Plugin Slug:
- custom-url-shorter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51930
Daily Image
- Plugin:
- Daily Image
- Plugin Slug:
- daily-image
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51776
Dashing Memberships
- Plugin:
- Dashing Memberships
- Plugin Slug:
- dashing-memberships
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51760
Datasets Manager by Arttia Creative
- Plugin:
- Datasets Manager by Arttia Creative
- Plugin Slug:
- datasets-manager-by-arttia-creative
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52375
Debug Tool
- Plugin:
- Debug Tool
- Plugin Slug:
- debug-tool
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-10586
Devexhub Gallery
- Plugin:
- Devexhub Gallery
- Plugin Slug:
- devexhub-gallery
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52373
DigiPass
- Plugin:
- DigiPass
- Plugin Slug:
- digipass
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-52378
Do That Task
- Plugin:
- Do That Task
- Plugin Slug:
- do-that-task
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52374
Don’t Break The Code
- Plugin:
- Don’t Break The Code
- Plugin Slug:
- dont-break-the-code
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51779
Doofinder
- Plugin:
- Doofinder
- Plugin Slug:
- doofinder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51697
drop in image slideshow gallery
- Plugin:
- drop in image slideshow gallery
- Plugin Slug:
- drop-in-image-slideshow-gallery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51914
DuoGeek Blocks
- Plugin:
- DuoGeek Blocks
- Plugin Slug:
- duogeek-blocks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51868
Easy CSV Importer BETA
- Plugin:
- Easy CSV Importer BETA
- Plugin Slug:
- easy-csv-importer
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52372
Easy Social Sharebar
- Plugin:
- Easy Social Sharebar
- Plugin Slug:
- easy-social-sharebar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51833
eewee admin custom
- Plugin:
- eewee admin custom
- Plugin Slug:
- eewee-admincustom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51780
Ekiline Block Collection
- Plugin:
- Ekiline Block Collection
- Plugin Slug:
- ekiline-block-collection
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51934
Embed documents shortcode
- Plugin:
- Embed documents shortcode
- Plugin Slug:
- embed-documents-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51904
ESB Testimonials
- Plugin:
- ESB Testimonials
- Plugin Slug:
- esb-testimonials
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51936
Fabrica Synced Pattern Instances
- Plugin:
- Fabrica Synced Pattern Instances
- Plugin Slug:
- fabrica-reusable-block-instances
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51695
Faltu Testimonial Rotator
- Plugin:
- Faltu Testimonial Rotator
- Plugin Slug:
- faltu-testimonial-rotator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51853
Fancy User List
- Plugin:
- Fancy User List
- Plugin Slug:
- fancy-user-listing
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51889
Fast Video and Image Display
- Plugin:
- Fast Video and Image Display
- Plugin Slug:
- fast-video-and-image-display
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51935
Featured product by category name
- Plugin:
- Featured product by category name
- Plugin Slug:
- featured-product-by-category-name
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51911
File Select Control For Elementor
- Plugin:
- File Select Control For Elementor
- Plugin Slug:
- file-select-control-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51841
Firework Shoppable Live Video
- Plugin:
- Firework Shoppable Live Video
- Plugin Slug:
- firework-videos
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51781
Forms: 3rd-Party Post Again
- Plugin:
- Forms: 3rd-Party Post Again
- Plugin Slug:
- forms-3rdparty-post-again
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51783
FriendStore for WooCommerce
- Plugin:
- FriendStore for WooCommerce
- Plugin Slug:
- friendstore-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51784
Horsemanager
- Plugin:
- Horsemanager
- Plugin Slug:
- fruitcake-horsemanager
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51843
Gboy Custom Google Map
- Plugin:
- Gboy Custom Google Map
- Plugin Slug:
- gboy-custom-google-map
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51882
Geoportail Shortcode
- Plugin:
- Geoportail Shortcode
- Plugin Slug:
- geoportail-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51890
Geotagged Media
- Plugin:
- Geotagged Media
- Plugin Slug:
- geotagged-media
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51694
Global Gateway e4 | Payeezy Gateway |
- Plugin:
- Global Gateway e4 | Payeezy Gateway |
- Plugin Slug:
- globe-gateway-e4
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-52371
Google Visualization Charts
- Plugin:
- Google Visualization Charts
- Plugin Slug:
- google-visualization-charts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51862
GreenCon
- Plugin:
- GreenCon
- Plugin Slug:
- greencon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51926
WoW Guild Armory Roster
- Plugin:
- WoW Guild Armory Roster
- Plugin Slug:
- guild-armory-roster
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51850
Gutenium Blocks
- Plugin:
- Gutenium Blocks
- Plugin Slug:
- gutenium
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51869
Satisfaction Reports from Help Scout
- Plugin:
- Satisfaction Reports from Help Scout
- Plugin Slug:
- happiness-reports-for-help-scout
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51778
HB AUDIO GALLERY
- Plugin:
- HB AUDIO GALLERY
- Plugin Slug:
- hb-audio-gallery
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-51790
Hola Free Video Player
- Plugin:
- Hola Free Video Player
- Plugin Slug:
- hola-free-video-player
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51854
HQ60 Fidelity Card
- Plugin:
- HQ60 Fidelity Card
- Plugin Slug:
- hq60-fidelity-card
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51713
I Plant A Tree
- Plugin:
- I Plant A Tree
- Plugin Slug:
- i-plant-a-tree
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51883
IA Map Analytics Basic
- Plugin:
- IA Map Analytics Basic
- Plugin Slug:
- ia-map-analytics-basic
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51937
Icon Widget
- Plugin:
- Icon Widget
- Plugin Slug:
- icon-widget-with-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51929
Image Carousel Shortcode
- Plugin:
- Image Carousel Shortcode
- Plugin Slug:
- image-carousel-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51842
Image Classify
- Plugin:
- Image Classify
- Plugin Slug:
- image-classify
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-51789
Inline Click To Tweet
- Plugin:
- Inline Click To Tweet
- Plugin Slug:
- inline-click-to-tweet
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51803
IntelliWidget Elements
- Plugin:
- IntelliWidget Elements
- Plugin Slug:
- intelliwidget-elements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51912
Jigoshop – Store Toolkit
- Plugin:
- Jigoshop – Store Toolkit
- Plugin Slug:
- jigoshop-store-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51712
KBucket
- Plugin:
- KBucket
- Plugin Slug:
- kbucket
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52369
Keymaster Chord Notation Free
- Plugin:
- Keymaster Chord Notation Free
- Plugin Slug:
- keymaster-chord-notation-free
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51809
Kings Tab Slider
- Plugin:
- Kings Tab Slider
- Plugin Slug:
- kings-tab-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51932
L Squared Hub WP
- Plugin:
- L Squared Hub WP
- Plugin Slug:
- l-squared-hub-wp-virtual-device
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51820
Lenxel Core for Lenxel(LNX) LMS
- Plugin:
- Lenxel Core for Lenxel(LNX) LMS
- Plugin Slug:
- lenxel-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9270
Location Click Map
- Plugin:
- Location Click Map
- Plugin Slug:
- location-click-map
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51844
Loginplus
- Plugin:
- Loginplus
- Plugin Slug:
- loginplus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51782
Luzuk Slider
- Plugin:
- Luzuk Slider
- Plugin Slug:
- luzuk-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51834
Luzuk Team
- Plugin:
- Luzuk Team
- Plugin Slug:
- luzuk-team
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51871
Luzuk Testimonials
- Plugin:
- Luzuk Testimonials
- Plugin Slug:
- luzuk-testimonials
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51872
Mage Front End Forms
- Plugin:
- Mage Front End Forms
- Plugin Slug:
- mage-forms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52339
Magic Slider
- Plugin:
- Magic Slider
- Plugin Slug:
- magic-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51896
Map Store Locator
- Plugin:
- Map Store Locator
- Plugin Slug:
- map-store-location
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51920
Mapme
- Plugin:
- Mapme
- Plugin Slug:
- mapme
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51913
Master Bar
- Plugin:
- Master Bar
- Plugin Slug:
- master-bar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51698
MDC YouTube Downloader
- Plugin:
- MDC YouTube Downloader
- Plugin Slug:
- mdc-youtube-downloader
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51875
Matix Popup Builder
- Plugin:
- Matix Popup Builder
- Plugin Slug:
- medma-matix
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52382
mFolio Lite
- Plugin:
- mFolio Lite
- Plugin Slug:
- mfolio-lite
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-9307
MG Post Contributors
- Plugin:
- MG Post Contributors
- Plugin Slug:
- mg-post-contributors
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51701
Minical Hotel Booking Plugin
- Plugin:
- Minical Hotel Booking Plugin
- Plugin Slug:
- minical
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51895
Mobile Kiosk
- Plugin:
- Mobile Kiosk
- Plugin Slug:
- mobile-kiosk
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51829
Moka Get Posts Shortcode
- Plugin:
- Moka Get Posts Shortcode
- Plugin Slug:
- moka-get-posts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51804
Moose Elementor Kit
- Plugin:
- Moose Elementor Kit
- Plugin Slug:
- moose-elementor-kit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51856
Multi-day Booking Calendar
- Plugin:
- Multi-day Booking Calendar
- Plugin Slug:
- multi-day-booking-calendar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51873
Multifox Plus
- Plugin:
- Multifox Plus
- Plugin Slug:
- multifox-plus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51916
Multiple Votes in one page
- Plugin:
- Multiple Votes in one page
- Plugin Slug:
- multiple-votes-in-one-page
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51917
My Restaurant Menu
- Plugin:
- My Restaurant Menu
- Plugin Slug:
- my-restaurant-menu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51849
WP Responsive Video
- Plugin:
- WP Responsive Video
- Plugin Slug:
- my-wp-responsive-video
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51940
Narnoo Commerce Manager
- Plugin:
- Narnoo Commerce Manager
- Plugin Slug:
- narnoo-commerce-manager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51708
News Articles
- Plugin:
- News Articles
- Plugin Slug:
- news-articles
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51897
News Ticker
- Plugin:
- News Ticker
- Plugin Slug:
- newsticker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51830
The Novel Design Store Directory
- Plugin:
- The Novel Design Store Directory
- Plugin Slug:
- noveldesign-store-directory
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-51788
NV Slider
- Plugin:
- NV Slider
- Plugin Slug:
- nv-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51887
Official SalesWizard CRM Plugin
- Plugin:
- Official SalesWizard CRM Plugin
- Plugin Slug:
- official-saleswizard-crm
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51891
Olympus Shortcodes
- Plugin:
- Olympus Shortcodes
- Plugin Slug:
- olympus-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51857
OpenCart Product Display
- Plugin:
- OpenCart Product Display
- Plugin Slug:
- opencart-product-display
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51835
OS BXSlider
- Plugin:
- OS BXSlider
- Plugin Slug:
- os-bxslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52342
OS Our Team
- Plugin:
- OS Our Team
- Plugin Slug:
- os-our-team
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52341
OS Pricing Tables
- Plugin:
- OS Pricing Tables
- Plugin Slug:
- os-pricing-tables
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52343
Parallaxer
- Plugin:
- Parallaxer
- Plugin Slug:
- parallaxer-lite-parallax-effects-on-images
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51848
ParOne Feeds
- Plugin:
- ParOne Feeds
- Plugin Slug:
- parone
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51874
Pay With Stripe
- Plugin:
- Pay With Stripe
- Plugin Slug:
- payments-stripe-gateway
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51918
Pdf Embedder Fay
- Plugin:
- Pdf Embedder Fay
- Plugin Slug:
- pdf-embedder-fay
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51795
Persian Nested Show/Hide Text
- Plugin:
- Persian Nested Show/Hide Text
- Plugin Slug:
- persian-nested-showhide-text
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51831
PF Timer
- Plugin:
- PF Timer
- Plugin Slug:
- pf-timer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51863
Photographer Connections
- Plugin:
- Photographer Connections
- Plugin Slug:
- photographer-connections
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52340
Picsmize
- Plugin:
- Picsmize
- Plugin Slug:
- picsmize
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-52380
Plenigo
- Plugin:
- Plenigo
- Plugin Slug:
- plenigo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51832
Popup Image
- Plugin:
- Popup Image
- Plugin Slug:
- popup-image
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51811
Postcasa Shortcode
- Plugin:
- Postcasa Shortcode
- Plugin Slug:
- postcasa
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52352
Postify: Post Layout For Elementor
- Plugin:
- Postify: Post Layout For Elementor
- Plugin Slug:
- postify-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51893
Posts Filter
- Plugin:
- Posts Filter
- Plugin Slug:
- posts-filter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51886
Posts Search
- Plugin:
- Posts Search
- Plugin Slug:
- posts-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51884
PropertyShift
- Plugin:
- PropertyShift
- Plugin Slug:
- propertyshift
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51762
Provide Forex Signals
- Plugin:
- Provide Forex Signals
- Plugin Slug:
- provide-forex-signals
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52344
Pull This
- Plugin:
- Pull This
- Plugin Slug:
- pull-this
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51838
ra_qrcode
- Plugin:
- ra_qrcode
- Plugin Slug:
- ra-qrcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52345
Relais 2FA
- Plugin:
- Relais 2FA
- Plugin Slug:
- relais-2fa
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-10245
Responsive Data Table
- Plugin:
- Responsive Data Table
- Plugin Slug:
- responsive-data-table
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51710
Share Buttons – Social Media
- Plugin:
- Share Buttons – Social Media
- Plugin Slug:
- rich-web-share-button
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51845
Rig Elements For Elementor
- Plugin:
- Rig Elements For Elementor
- Plugin Slug:
- rig-elements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51927
RSV 360 View
- Plugin:
- RSV 360 View
- Plugin Slug:
- rsv-360-view
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51906
RSV PDF Preview
- Plugin:
- RSV PDF Preview
- Plugin Slug:
- rsv-pdf-preview
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51905
Saragna
- Plugin:
- Saragna
- Plugin Slug:
- saragna-social-stream
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51711
scrollup
- Plugin:
- scrollup
- Plugin Slug:
- scrollup
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51921
Search order by product SKU for WooCommerce
- Plugin:
- Search order by product SKU for WooCommerce
- Plugin Slug:
- search-order-by-product-sku-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51693
Sell Media File with Stripe
- Plugin:
- Sell Media File with Stripe
- Plugin Slug:
- sell-media-file
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51892
Semantic Shortcode
- Plugin:
- Semantic Shortcode
- Plugin Slug:
- semantic-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51898
Lewe Bootstrap Visuals
- Plugin:
- Lewe Bootstrap Visuals
- Plugin Slug:
- shortcode-bootstrap-visuals
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51810
Shortcode Collection
- Plugin:
- Shortcode Collection
- Plugin Slug:
- shortcode-collection
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51864
Redirecter
- Plugin:
- Redirecter
- Plugin Slug:
- shortcode-for-redirection
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51855
Simple Pricing Table
- Plugin:
- Simple Pricing Table
- Plugin Slug:
- simple-pricing-table
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51899
Simple Social Share Block
- Plugin:
- Simple Social Share Block
- Plugin Slug:
- simple-social-share-block
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51865
SimpleGMaps
- Plugin:
- SimpleGMaps
- Plugin Slug:
- simplegmaps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52346
Simple Modal
- Plugin:
- Simple Modal
- Plugin Slug:
- simplemodal
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51718
Simplistic SEO
- Plugin:
- Simplistic SEO
- Plugin Slug:
- simplistic-seo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51719
Simpul Events by Esotech
- Plugin:
- Simpul Events by Esotech
- Plugin Slug:
- simpul-events-by-esotech
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51867
Social button
- Plugin:
- Social button
- Plugin Slug:
- social-button
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51866
Social Locker
- Plugin:
- Social Locker
- Plugin Slug:
- social-locker-content
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51858
Stylish Internal Links
- Plugin:
- Stylish Internal Links
- Plugin Slug:
- stylish-internal-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51939
Surbma | Font Awesome
- Plugin:
- Surbma | Font Awesome
- Plugin Slug:
- surbma-font-awesome
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51798
SV Forms
- Plugin:
- SV Forms
- Plugin Slug:
- sv-forms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51877
SVT Simple
- Plugin:
- SVT Simple
- Plugin Slug:
- svt-simple
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51759
Table of Contents Plus
- Plugin:
- Table of Contents Plus
- Plugin Slug:
- table-of-contents-plus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5578
Team Showcase and Slider – Team Members Builder
- Plugin:
- Team Showcase and Slider – Team Members Builder
- Plugin Slug:
- team-showcase-ultimate
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51763
TeleAdmin
- Plugin:
- TeleAdmin
- Plugin Slug:
- teleadmin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51709
Testimonial Slider Shortcode
- Plugin:
- Testimonial Slider Shortcode
- Plugin Slug:
- testimonial-slider-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51925
Text Advertisements
- Plugin:
- Text Advertisements
- Plugin Slug:
- text-advertisements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51879
Tigris Flexplatform
- Plugin:
- Tigris Flexplatform
- Plugin Slug:
- tigris-flexplatform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51819
TinyCode
- Plugin:
- TinyCode
- Plugin Slug:
- tinycode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51902
Topbar ID for Elementor
- Plugin:
- Topbar ID for Elementor
- Plugin Slug:
- topbar-id-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51894
Trendy Restaurant Menu
- Plugin:
- Trendy Restaurant Menu
- Plugin Slug:
- trendy-restaurant-menu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51796
SrcSet Responsive Images for WordPress
- Plugin:
- SrcSet Responsive Images for WordPress
- Plugin Slug:
- truenorth-srcset
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51702
Twitter real time search scrolling
- Plugin:
- Twitter real time search scrolling
- Plugin Slug:
- twitter-real-time-search-scrolling
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51716
Ultimate Accordion
- Plugin:
- Ultimate Accordion
- Plugin Slug:
- ultimate-accordion
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51797
User Meta
- Plugin:
- User Meta
- Plugin Slug:
- user-meta
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9262
User Password Reset
- Plugin:
- User Password Reset
- Plugin Slug:
- user-password-reset
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51714
Utech Spinning Earth
- Plugin:
- Utech Spinning Earth
- Plugin Slug:
- utech-spinning-earth
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51839
UW Freelancer
- Plugin:
- UW Freelancer
- Plugin Slug:
- uw-freelancer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51706
VP Sitemap
- Plugin:
- VP Sitemap
- Plugin Slug:
- vp-sitemap
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51922
Wd-image-magnifier-xoss
- Plugin:
- Wd-image-magnifier-xoss
- Plugin Slug:
- wd-image-magnifier-xoss
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51840
WE – Client Logo Carousel
- Plugin:
- WE – Client Logo Carousel
- Plugin Slug:
- we-client-logo-carousel
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51821
Websand Subscription Form
- Plugin:
- Websand Subscription Form
- Plugin Slug:
- websand-subscription-form
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51923
Wezido
- Plugin:
- Wezido
- Plugin Slug:
- wezido-elementor-addon-based-on-easy-digital-downloads
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51836
WP Agenda
- Plugin:
- WP Agenda
- Plugin Slug:
- wp-agenda
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51924
wp_automatic_widget
- Plugin:
- wp_automatic_widget
- Plugin Slug:
- wp-automatic-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51876
WP-Basics
- Plugin:
- WP-Basics
- Plugin Slug:
- wp-basics
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51703
WP Contest
- Plugin:
- WP Contest
- Plugin Slug:
- wp-contest
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51837
EventPress
- Plugin:
- EventPress
- Plugin Slug:
- wp-eventpress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51861
Wp-ImageZoom
- Plugin:
- Wp-ImageZoom
- Plugin Slug:
- wp-imagezoom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9934
imPress
- Plugin:
- imPress
- Plugin Slug:
- wp-js-impress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51704
WP Listings Pro
- Plugin:
- WP Listings Pro
- Plugin Slug:
- wp-listings-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51903
WP MMenu Lite
- Plugin:
- WP MMenu Lite
- Plugin Slug:
- wp-mmenu-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51705
WP PagSeguro Payments
- Plugin:
- WP PagSeguro Payments
- Plugin Slug:
- wp-pagseguro-payments
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51847
Wp Slide Categorywise
- Plugin:
- Wp Slide Categorywise
- Plugin Slug:
- wp-slide-categorywise
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51690
WP Visual Adverts
- Plugin:
- WP Visual Adverts
- Plugin Slug:
- wp-visual-adverts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51707
Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera
- Plugin:
- Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera
- Plugin Slug:
- wp-website-creator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-52347
WPHelpful
- Plugin:
- WPHelpful
- Plugin Slug:
- wphelpful
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51761
Admin Amplify
- Plugin:
- Admin Amplify
- Plugin Slug:
- wpr-admin-amplify
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-51691
yPHPlista
- Plugin:
- yPHPlista
- Plugin Slug:
- yphplista
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51805
????????
- Plugin:
- ????????
- Plugin Slug:
- yr-activity-link
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51814
Cookie Nonsense for YT
- Plugin:
- Cookie Nonsense for YT
- Plugin Slug:
- yt-cookie-nonsense
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51933
ZIJ KART
- Plugin:
- ZIJ KART
- Plugin Slug:
- zij-kart
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-52381
Elementor Header & Footer Builder
- Plugin Slug:
- header-footer-elementor
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.46
- Severity Score:
- Medium
- CVE:
- 2024-10325
Loginizer
- Plugin:
- Loginizer
- Plugin Slug:
- loginizer
- Installations
- 1,000,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.9.3
- Severity Score:
- High
- CVE:
- 2024-10097
Safe SVG
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.12.6
- Severity Score:
- Medium
- CVE:
- 2024-10538
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
- Plugin Slug:
- photo-gallery
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.31
- Severity Score:
- Medium
- CVE:
- 2024-9878
Admin and Site Enhancements (ASE)
- Plugin Slug:
- admin-site-enhancements
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.5.2
- Severity Score:
- Medium
- CVE:
- 2024-10790
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.3
- Severity Score:
- Medium
- CVE:
- 2024-9657
Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)
- Plugin Slug:
- bdthemes-prime-slider-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.15.19
- Severity Score:
- Medium
- CVE:
- 2024-8442
Contact Form 7 – Dynamic Text Extension
- Plugin Slug:
- contact-form-7-dynamic-text-extension
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.5.1
- Severity Score:
- Medium
- CVE:
- 2024-10084
Pods – Custom Content Types and Fields
- Plugin Slug:
- pods
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.7.1
- Severity Score:
- Medium
- CVE:
- 2024-9883
WP ULike – All-in-One Engagement Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.5
- Severity Score:
- Medium
- CVE:
- 2024-7879
WP Booking Calendar
- Plugin:
- WP Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.3
- Severity Score:
- Medium
- CVE:
- 2024-10027
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.31
- Severity Score:
- High
- CVE:
- 2024-10265
MapPress Maps for WordPress
- Plugin:
- MapPress Maps for WordPress
- Plugin Slug:
- mappress-google-maps-for-wordpress
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.94.2
- Severity Score:
- Medium
- CVE:
- 2024-10715
Easy SVG Support
- Plugin:
- Easy SVG Support
- Plugin Slug:
- easy-svg
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8
- Severity Score:
- Medium
- CVE:
- 2024-10269
Envo Extra
- Plugin:
- Envo Extra
- Plugin Slug:
- envo-extra
- Installations
- 30,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.9.4
- Severity Score:
- Medium
- CVE:
- 2024-10770
Seriously Simple Podcasting
- Plugin:
- Seriously Simple Podcasting
- Plugin Slug:
- seriously-simple-podcasting
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.0
- Severity Score:
- High
- CVE:
- 2024-9667
Social Share, Social Login and Social Comments Plugin – Super Socializer
- Plugin Slug:
- super-socializer
- Installations
- 30,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 7.14
- Severity Score:
- High
- CVE:
- 2024-9946
Futurio Extra
- Plugin:
- Futurio Extra
- Plugin Slug:
- futurio-extra
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.14
- Severity Score:
- Medium
- CVE:
- 2024-10695
Code Embed
- Plugin:
- Code Embed
- Plugin Slug:
- simple-embed-code
- Installations
- 20,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.5.1
- Severity Score:
- Medium
- CVE:
- 2024-10814
140+ Widgets | Xpro Addons For Elementor – FREE
- Plugin Slug:
- xpro-elementor-addons
- Installations
- 20,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.4.6.1
- Severity Score:
- Medium
- CVE:
- 2024-10319
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
- Plugin Slug:
- charitable
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.3.1
- Severity Score:
- High
- CVE:
- 2024-10876
Contact Form 7 – PayPal & Stripe Add-on
- Plugin Slug:
- contact-form-7-paypal-add-on
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.2
- Severity Score:
- High
- CVE:
- 2024-10683
SysBasics Customize My Account for WooCommerce
- Plugin Slug:
- customize-my-account-for-woocommerce
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.30
- Severity Score:
- High
- CVE:
- 2024-10837
Pricing Tables WordPress Plugin – Easy Pricing Tables
- Plugin Slug:
- easy-pricing-tables
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.7
- Severity Score:
- Medium
- CVE:
- 2024-8323
JetWidgets For Elementor
- Plugin:
- JetWidgets For Elementor
- Plugin Slug:
- jetwidgets-for-elementor
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.19
- Severity Score:
- Medium
- CVE:
- 2024-10323
myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification
- Plugin Slug:
- mycred
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.5
- Severity Score:
- Medium
- CVE:
- 2024-10187
OSM – OpenStreetMap
- Plugin:
- OSM – OpenStreetMap
- Plugin Slug:
- osm
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.1.3
- Severity Score:
- Medium
- CVE:
- 2024-52355
Registrations for the Events Calendar – Event Registration Plugin
- Plugin Slug:
- registrations-for-the-events-calendar
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.12.4
- Severity Score:
- High
- CVE:
- 2024-7982
WP Photo Album Plus
- Plugin:
- WP Photo Album Plus
- Plugin Slug:
- wp-photo-album-plus
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.9.01.001
- Severity Score:
- Medium
- CVE:
- 2024-10958
Algori PDF Viewer
- Plugin:
- Algori PDF Viewer
- Plugin Slug:
- algori-pdf-viewer
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.8
- Severity Score:
- Medium
- CVE:
- 2018-5158
WS Form LITE – Drag & Drop Contact Form Builder for WordPress
- Plugin Slug:
- ws-form
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.245
- Severity Score:
- High
- CVE:
- 2024-10647
Contact Form 7 Redirect & Thank You Page
- Plugin Slug:
- cf7-redirect-thank-you-page
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- High
- CVE:
- 2024-10685
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
- Plugin Slug:
- poll-maker
- Installations
- 7,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 5.4.7
- Severity Score:
- High
- CVE:
- 2024-9874
Ultimate Bootstrap Elements for Elementor
- Plugin Slug:
- ultimate-bootstrap-elements-for-elementor
- Installations
- 7,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.4.7
- Severity Score:
- Medium
- CVE:
- 2024-10329
XT Floating Cart for WooCommerce
- Plugin:
- XT Floating Cart for WooCommerce
- Plugin Slug:
- woo-floating-cart-lite
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.3
- Severity Score:
- Medium
- CVE:
- 2024-9178
WP Job Portal – A Complete Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-52389
WOLF – WordPress Posts Bulk Editor and Manager Professional
- Plugin Slug:
- bulk-editor
- Installations
- 5,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 1.0.8.4
- Severity Score:
- Medium
- CVE:
- 2024-52396
ElementsReady Addons for Elementor
- Plugin Slug:
- element-ready-lite
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.4
- Severity Score:
- Medium
- CVE:
- 2024-51787
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
- Plugin Slug:
- magical-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
- 2024-10352
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 5,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 4.1.17
- Severity Score:
- Critical
- CVE:
- 2024-52393
Simple Shortcode for Google Maps
- Plugin:
- Simple Shortcode for Google Maps
- Plugin Slug:
- simple-google-maps-short-code
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6
- Severity Score:
- Medium
- CVE:
- 2024-10621
Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin
- Plugin Slug:
- everest-backup
- Installations
- 4,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.2.14
- Severity Score:
- High
- CVE:
- 2024-10028
LIQUID BLOCKS – Slider, Carousel, Accordion
- Plugin Slug:
- liquid-blocks
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2024-52357
Content Slider Block
- Plugin:
- Content Slider Block
- Plugin Slug:
- content-slider-block
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1.6
- Severity Score:
- Medium
- CVE:
- 2024-10667
Multiple Page Generator Plugin – MPG
- Plugin Slug:
- multiple-pages-generator-by-porthas
- Installations
- 3,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 4.0.3
- Severity Score:
- Low
- CVE:
- 2024-10672
Tickera – WordPress Event Ticketing
- Plugin Slug:
- tickera-event-ticketing-system
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.4.6
- Severity Score:
- Medium
- CVE:
- 2024-10263
Active Products Tables for WooCommerce. Use constructor to create tables
- Plugin Slug:
- profit-products-tables-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.6.5
- Severity Score:
- Medium
- CVE:
- 2024-10168
Responsive Filterable Portfolio
- Plugin:
- Responsive Filterable Portfolio
- Plugin Slug:
- responsive-filterable-portfolio
- Installations
- 2,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.0.23
- Severity Score:
- Medium
- CVE:
- 2024-51785
Slickstream: Engagement and Conversions
- Plugin Slug:
- slick-engagement
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.0
- Severity Score:
- Medium
- CVE:
- 2024-10179
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)
- Plugin Slug:
- the-pack-addon
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.1
- Severity Score:
- Medium
- CVE:
- 2024-52356
Zotpress
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 24.0.4
- Severity Score:
- Critical
- CVE:
- 2024-10687
Countdown Timer block – Display the event’s date into a timer.
- Plugin Slug:
- countdown-time
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.2.5
- Severity Score:
- Medium
- CVE:
- 2024-10669
Event post
- Plugin:
- Event post
- Plugin Slug:
- event-post
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.7
- Severity Score:
- Medium
- CVE:
- 2024-10186
Event post
- Plugin:
- Event post
- Plugin Slug:
- event-post
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.7
- Severity Score:
- Medium
- CVE:
- 2024-10186
Heateor Social Login WordPress
- Plugin:
- Heateor Social Login WordPress
- Plugin Slug:
- heateor-social-login
- Installations
- 1,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.1.36
- Severity Score:
- High
- CVE:
- 2024-10020
WooCommerce Report
- Plugin:
- WooCommerce Report
- Plugin Slug:
- ithemelandco-woo-report
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.5.2
- Severity Score:
- High
- CVE:
- 2024-10711
Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages
- Plugin Slug:
- landing-page-cat
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.7
- Severity Score:
- High
- CVE:
- 2024-9226
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates
- Plugin Slug:
- responsive-addons-for-elementor
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.0
- Severity Score:
- Medium
- CVE:
- 2024-52358
Web Stories Widgets For Elementor
- Plugin Slug:
- shortcodes-for-amp-web-stories-and-elementor-widget
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-52354
SKT Addons for Elementor
- Plugin:
- SKT Addons for Elementor
- Plugin Slug:
- skt-addons-for-elementor
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.4
- Severity Score:
- Medium
- CVE:
- 2024-10693
Tumult Hype Animations
- Plugin:
- Tumult Hype Animations
- Plugin Slug:
- tumult-hype-animations
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.15
- Severity Score:
- Medium
- CVE:
- 2024-10543
Video Gallery for WooCommerce
- Plugin:
- Video Gallery for WooCommerce
- Plugin Slug:
- video-wc-gallery
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.32
- Severity Score:
- Medium
- CVE:
- 2024-10535
W3SPEEDSTER
- Plugin:
- W3SPEEDSTER
- Plugin Slug:
- w3speedster-wp
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 7.27
- Severity Score:
- Medium
- CVE:
- 2024-52392
xili-tidy-tags
- Plugin:
- xili-tidy-tags
- Plugin Slug:
- xili-tidy-tags
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.12.05
- Severity Score:
- High
- CVE:
- 2024-9357
Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One
- Plugin Slug:
- ai-auto-tool
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.3
- Severity Score:
- High
- CVE:
- 2024-52383
CYAN Backup
- Plugin:
- CYAN Backup
- Plugin Slug:
- cyan-backup
- Installations
- 500+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 2.5.4
- Severity Score:
- Medium
- CVE:
- 2024-52390
Shortcodes Blocks Creator Ultimate
- Plugin Slug:
- ultimate-shortcodes-creator
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.0
- Severity Score:
- Medium
- CVE:
- 2024-10340
Basticom Framework
- Plugin:
- Basticom Framework
- Plugin Slug:
- basticom-framework
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-9443
Forms
- Plugin:
- Forms
- Plugin Slug:
- forms-by-made-it
- Installations
- 100+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.8.1
- Severity Score:
- Critical
- CVE:
- 2024-51791
Pro Addons For Elementor
- Plugin:
- Pro Addons For Elementor
- Plugin Slug:
- pro-addons-for-elementor
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.0
- Severity Score:
- Medium
- CVE:
- 2024-51812
Print PDF Generator and Publisher
- Plugin Slug:
- nopeamedia
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
- 2024-52394
Anant Addons for Elementor
- Plugin:
- Anant Addons for Elementor
- Plugin Slug:
- anant-addons-for-elementor
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2024-51813
Realty by BestWebSoft
- Plugin:
- Realty by BestWebSoft
- Plugin Slug:
- realty
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2024-51786
Christian Science Bible Lesson Subjects
- Plugin Slug:
- christian-science-bible-lesson-subjects
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1
- Severity Score:
- Medium
- CVE:
- 2024-52353
Hebrew Dates
- Plugin:
- Hebrew Dates
- Plugin Slug:
- hebrewdates
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.3.0
- Severity Score:
- High
- CVE:
- 2024-52388
Floating Buttons for WooCommerce
- Plugin:
- Floating Buttons for WooCommerce
- Plugin Slug:
- shop-assistant-for-woocommerce-jarvis
- Installations
- 10+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
- 2024-52395
Ultimate Flipbox Addon for Elementor
- Plugin Slug:
- ultimate-flipbox-addon-for-elementor
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.5
- Severity Score:
- Medium
- CVE:
- 2024-51870
Dynamic Post Grid Elementor Addon
- Plugin Slug:
- dynamic-post-grid-elementor-addon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2024-51852
Hive Support – WordPress Help Desk
- Plugin:
- Hive Support – WordPress Help Desk
- Plugin Slug:
- hive-support
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.2
- Severity Score:
- Critical
- CVE:
- 2024-52370
kineticPay for WooCommerce
- Plugin:
- kineticPay for WooCommerce
- Plugin Slug:
- kineticpay-for-woocommerce
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.0
- Severity Score:
- Critical
- CVE:
- 2024-52379
Loginizer Security
- Plugin:
- Loginizer Security
- Plugin Slug:
- loginizer-security
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.9.3
- Severity Score:
- High
- CVE:
- 2024-10097
Pie Register Premium
- Plugin:
- Pie Register Premium
- Plugin Slug:
- pie-register-premium
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.8.3.3
- Severity Score:
- Medium
- CVE:
- 2024-52391
Quform
- Plugin:
- Quform
- Plugin Slug:
- quform
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.21.0
- Severity Score:
- Medium
- CVE:
- 2024-8756
WooCommerce Social Login
- Plugin:
- WooCommerce Social Login
- Plugin Slug:
- woo-social-login
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.7.8
- Severity Score:
- High
- CVE:
- 2024-10114
WooCommerce Support Ticket System
- Plugin:
- WooCommerce Support Ticket System
- Plugin Slug:
- woocommerce-support-ticket-system
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 17.8
- Severity Score:
- Critical
- CVE:
- 2024-10627
WooCommerce Support Ticket System
- Plugin:
- WooCommerce Support Ticket System
- Plugin Slug:
- woocommerce-support-ticket-system
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 17.8
- Severity Score:
- High
- CVE:
- 2024-10625
JobSearch
- Plugin:
- JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.6.8
- Severity Score:
- Critical
- CVE:
- 2024-8614
JobSearch
- Plugin:
- JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.6.8
- Severity Score:
- Critical
- CVE:
- 2024-8615
WP Membership
- Plugin:
- WP Membership
- Plugin Slug:
- wp-membership
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.6.3
- Severity Score:
- Critical
- CVE:
- 2024-10547
User Extra Fields
- Plugin:
- User Extra Fields
- Plugin Slug:
- wp-user-extra-fields
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 16.6
- Severity Score:
- Critical
- CVE:
- 2024-10801
WordPress Themes — 3 Patched / 2 Unpatched
Storely
- Theme:
- Storely
- Theme Slug:
- storely
- Downloads
- 435,857
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-51794
Anih
- Theme:
- Anih
- Theme Slug:
- anih
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9775
Th Shop Mania
- Theme:
- Th Shop Mania
- Theme Slug:
- th-shop-mania
- Downloads
- 35,161
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
- 2024-10674
Top Store
- Theme:
- Top Store
- Theme Slug:
- top-store
- Downloads
- 198,806
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 1.5.5
- Severity Score:
- Medium
- CVE:
- 2024-10673
WPLMS
- Theme:
- WPLMS
- Theme Slug:
- wplms
- Vulnerability:
- Path Traversal
- Patched in Version:
- 4.963
- Severity Score:
- Critical
- CVE:
- 2024-10470
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
