WordPress Security

WordPress Vulnerability Report — November 15, 2023

There have been 109 new WordPress plugin and theme vulnerabilities disclosed since our last report.

Dan Knauss

Since our last report, 109 new vulnerabilities have been publicly disclosed. Security patches for 57 plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there is one theme and 52 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are protected by the Solid Security firewall with virtual patches from Patchstack.

Coupled with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.1 was released on November 8 as a short-cycle maintenance release to address several bugs, including loss of backward compatibility with a dependency, cURL 7.29 or earlier. This broke the WordPress internal update facility on servers running very old, insecure cURL versions.

WordPress 6.4 was released on November 7 as the third major release of 2023. Following a major release, you should not update live sites without taking backups and testing the update in a non-production environment first.

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugins — # Patched / # Unpatched

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-logo-showcase-responsive-slider-slider
Installations:
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Maintenance

Plugin Slug:
wp-maintenance
Installations:
40,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Responsive Recent Post Slider/Carousel

Plugin Slug:
wp-responsive-recent-post-slider
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-slick-slider-and-image-carousel
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms – Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP News and Scrolling Widgets

Plugin Slug:
sp-news-and-widget
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Welcome Email Editor

Plugin Slug:
welcome-email-editor
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Blog and Widgets

Plugin Slug:
wp-blog-and-widgets
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
footer-putter
Installations:
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Podlove Web Player

Plugin Slug:
podlove-web-player
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP responsive FAQ with category plugin

Plugin Slug:
sp-faq
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyAzon – Amazon Associates Affiliate Plugin

Plugin Slug:
easyazon
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Animator – Scroll Triggered Animations

Plugin Slug:
scroll-triggered-animations
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Finder

Plugin Slug:
shortcodes-finder
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Korea SNS

Plugin:
Korea SNS
Plugin Slug:
korea-sns
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
permalinks-customizer
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Featured Post Creative

Plugin Slug:
featured-post-creative
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Foyer – Digital Signage for WordPress

Plugin Slug:
foyer
Installations:
2,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Enquiry for WooCommerce

Plugin Slug:
gm-woocommerce-quote-popup
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard's Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plainview Protect Passwords

Plugin Slug:
plainview-protect-passwords
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Plainview Protect Passwords

Plugin Slug:
plainview-protect-passwords
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Team Members Showcase

Plugin Slug:
dazzlersoft-teams
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive World Map

Plugin Slug:
interactive-world-map
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Preloader Matrix

Plugin Slug:
matrix-pre-loader
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Pay Counter

Plugin Slug:
post-pay-counter
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woo Custom and Sequential Order Number

Plugin Slug:
woo-custom-and-sequential-order-number
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Product Enquiry

Plugin Slug:
woo-product-enquiry
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Youtube SpeedLoad

Plugin Slug:
youtube-speedload
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mini Cart Drawer For WooCommerce

Plugin Slug:
woo-mini-cart-drawer
Installations:
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simply Excerpts

Plugin Slug:
simply-excerpts
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Not Login Hide

Plugin:
WP Not Login Hide
Plugin Slug:
wp-not-login-hide-wpnlh
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Full Stripe Free

Plugin:
WP Full Stripe Free
Plugin Slug:
wp-full-stripe-free
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Featured Content and Slider
Plugin Slug:
wp-featured-content-and-slide
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Category Post List Widget

Plugin:
WP Category Post List Widget
Plugin Slug:
wp-category-posts-list
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Vertical scroll recent post

Plugin:
Vertical scroll recent post
Plugin Slug:
vertical-scroll-recent-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WooCommerce Product Carousel Slider
Plugin Slug:
product-carousel-slider-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Plugin:
LuckyWP Scripts Control
Plugin Slug:
luckywp-scripts-contro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Plugin:
Leadster
Plugin Slug:
leadster-marketing-conversaciona
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyRotator

Plugin:
EasyRotator
Plugin Slug:
easyrotator-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BSK Contact Form 7 Blacklist

Plugin:
BSK Contact Form 7 Blacklist
Plugin Slug:
bsk-contact-form-7-blacklist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AMP+ Plus

Plugin:
AMP+ Plus
Plugin Slug:
amp-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EWWW Image Optimizer

Plugin Slug:
ewww-image-optimizer
Installations:
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

WP Fastest Cache

Plugin Slug:
wp-fastest-cache
Installations:
1,000,000+
Vulnerability:
SQL Injection
Patched in Version:
1.2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.2.

Code Snippets

Plugin Slug:
code-snippets
Installations:
800,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
simple-301-redirects
Installations:
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations:
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

Checkout Field Manager (Checkout Manager) for WooCommerce

Plugin Slug:
woocommerce-checkout-manager
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.1.

Brizy – Page Builder

Plugin Slug:
brizy
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.30.

Big File Uploads – Increase Maximum File Upload Size

Plugin Slug:
tuxedo-big-file-uploads
Installations:
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.12.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.8.

Solid Central – Site Management, Backups, Security, and Reporting

Plugin Slug:
ithemes-sync
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.25.

Ultimate Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.7.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.32.

Delete Duplicate Posts

Plugin Slug:
delete-duplicate-posts
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

Ecwid Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.12.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.4.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations:
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.5.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.26.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.8.

Japanized For WooCommerce

Plugin Slug:
woocommerce-for-japan
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.5.

YOP Poll

Plugin:
YOP Poll
Plugin Slug:
yop-poll
Installations:
10,000+
Vulnerability:
Race Condition
Patched in Version:
6.5.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.27.

Gift Up Gift Cards for WordPress and WooCommerce

Plugin Slug:
gift-up
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.20.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.2.

Hreflang Manager

Plugin Slug:
hreflang-manager-lite
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

avalex – Automatisch sichere Rechtstexte

Plugin Slug:
avalex
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

Arigato Autoresponder and Newsletter

Plugin Slug:
bft-autoresponder
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.3.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations:
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
22.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 22.6.

Website Optimization – Plerdy

Plugin Slug:
plerdy-heatmap
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Post Status Notifier Lite

Plugin Slug:
post-status-notifier-lite
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.11.1.

Product Catalog Simple

Plugin Slug:
post-type-x
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.6.

Bus Ticket Booking with Seat Reservation

Plugin Slug:
bus-ticket-booking-with-seat-reservation
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.6.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.2.

Image Compressor & Optimizer – iLoveIMG

Plugin Slug:
iloveimg
Installations:
100+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

WooCommerce Canada Post Shipping

Plugin:
WooCommerce Canada Post Shipping
Plugin Slug:
woocommerce-shipping-canada-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

WooCommerce Bookings

Plugin:
WooCommerce Bookings
Plugin Slug:
woocommerce-bookings
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Star CloudPRNT for WooCommerce

Plugin:
Star CloudPRNT for WooCommerce
Plugin Slug:
star-cloudprnt-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.15.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Arbitrary File Upload
Patched in Version:
6.6.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.16.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.7.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.7.10.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.10.

Essential Grid

Plugin:
Essential Grid
Plugin Slug:
essential-grid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.1.

Essential Grid

Plugin:
Essential Grid
Plugin Slug:
essential-grid
Vulnerability:
Broken Access Control
Patched in Version:
3.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.19.

WordPress Themes — # Patched / # Unpatched

Themify Ultra

Theme:
Themify Ultra
Theme Slug:
themify-ultra
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: