WordPress Security

WordPress Vulnerability Report — November 22, 2023

Since our last report, 141 new vulnerabilities have been publicly disclosed, including three in Jetpack and others in WooCommerce, EWW Image Optimizer, WP Fastest Cache, and Forminator. Security patches are available for them now, along with 77 other plugins, so run those updates as soon as possible!

Dan Knauss

Since our last report, 141 new vulnerabilities have been publicly disclosed, including three in Jetpack and others in WooCommerce, EWW Image Optimizer, WP Fastest Cache, and Forminator. Security patches are available for them now, along with 77 other plugins, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 57 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.1 was released on November 8 as a short-cycle maintenance release to address several bugs, including loss of backward compatibility with a dependency, cURL 7.29 or earlier. This broke the WordPress internal update facility on servers running very old, insecure cURL versions.

WordPress 6.4 was released on November 7 as the third major release of 2023. Following a major release, you should not update live sites without taking backups and testing the update in a non-production environment first.

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugins — 84 Patched / 57 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations:
100,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio
Installations:
50,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Editor

Plugin Slug:
theme-editor
Installations:
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Welcome Email Editor

Plugin Slug:
welcome-email-editor
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Child Theme Generator

Plugin Slug:
wp-child-theme-generator
Installations:
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
footer-putter
Installations:
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Acme Fix Images

Plugin Slug:
acme-fix-images
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyAzon – Amazon Associates Affiliate Plugin

Plugin Slug:
easyazon
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Disable User Login

Plugin Slug:
disable-user-login
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Parallax Image

Plugin Slug:
parallax-image
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
permalinks-customizer
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form to Any API

Plugin Slug:
contact-form-to-any-api
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard's Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SearchIQ – The Search Solution

Plugin Slug:
searchiq
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Shortcodes Ultimate

Plugin Slug:
bs-shortcode-ultimate
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive World Map

Plugin Slug:
interactive-world-map
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theater for WordPress

Plugin Slug:
theatre
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simply Excerpts

Plugin Slug:
simply-excerpts
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpMandrill

Plugin:
wpMandrill
Plugin Slug:
wpmandrill
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Not Login Hide

Plugin:
WP Not Login Hide
Plugin Slug:
wp-not-login-hide-wpnlh
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Like Button

Plugin:
WP Like Button
Plugin Slug:
wp-like-button
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Githuber MD

Plugin:
WP Githuber MD
Plugin Slug:
wp-githuber-md
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

10WebAnalytics

Plugin:
10WebAnalytics
Plugin Slug:
wd-google-analytics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grab & Save

Plugin:
Grab & Save
Plugin Slug:
save-grab
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grab & Save

Plugin:
Grab & Save
Plugin Slug:
save-grab
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Call Button

Plugin:
Quick Call Button
Plugin Slug:
quick-call-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WooCommerce Product Carousel Slider
Plugin Slug:
product-carousel-slider-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayTR Taksit Tablosu

Plugin:
PayTR Taksit Tablosu
Plugin Slug:
paytr-taksit-tablosu-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Plugin:
LuckyWP Scripts Control
Plugin Slug:
luckywp-scripts-contro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Plugin:
Leadster
Plugin Slug:
leadster-marketing-conversaciona
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Call Now by ThikShare

Plugin:
Easy Call Now by ThikShare
Plugin Slug:
easy-call-now
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DrawIt (draw.io)

Plugin:
DrawIt (draw.io)
Plugin Slug:
drawit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live Preview for Contact Form 7

Plugin:
Live Preview for Contact Form 7
Plugin Slug:
cf7-live-preview
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Integration for Contact Form 7 and Constant Contact

Plugin:
Integration for Contact Form 7 and Constant Contact
Plugin Slug:
cf7-constant-contact
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CataBlog

Plugin:
CataBlog
Plugin Slug:
catablog
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CataBlog

Plugin:
CataBlog
Plugin Slug:
catablog
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BSK Contact Form 7 Blacklist

Plugin:
BSK Contact Form 7 Blacklist
Plugin Slug:
bsk-contact-form-7-blacklist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BP Profile Shortcodes Extra

Plugin:
BP Profile Shortcodes Extra
Plugin Slug:
bp-profile-shortcodes-extra
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BMI Calculator Plugin

Plugin:
BMI Calculator Plugin
Plugin Slug:
bmi-calculator-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better RSS Widget

Plugin:
Better RSS Widget
Plugin Slug:
better-rss-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bamboo Columns

Plugin:
Bamboo Columns
Plugin Slug:
bamboo-columns
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Phlox Shop

Plugin:
Phlox Shop
Plugin Slug:
auxin-shop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Audio Merchant

Plugin:
Audio Merchant
Plugin Slug:
audio-merchant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Audio Merchant

Plugin:
Audio Merchant
Plugin Slug:
audio-merchant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Anywhere Flash Embed

Plugin:
Anywhere Flash Embed
Plugin Slug:
anywhere-flash-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AMP+ Plus

Plugin:
AMP+ Plus
Plugin Slug:
amp-plus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ajax Domain Checker

Plugin:
Ajax Domain Checker
Plugin Slug:
ajax-domain-checker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Widgets to Page

Plugin:
Add Widgets to Page
Plugin Slug:
add-widgets-to-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations:
5,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.7.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations:
5,000,000+
Vulnerability:
Clickjacking
Patched in Version:
12.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.7.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations:
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.8-a.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.8-a.3.

WooCommerce

Plugin Slug:
woocommerce
Installations:
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.0.

EWWW Image Optimizer

Plugin Slug:
ewww-image-optimizer
Installations:
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.1.

WP Fastest Cache

Plugin Slug:
wp-fastest-cache
Installations:
1,000,000+
Vulnerability:
SQL Injection
Patched in Version:
1.2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.2.
Plugin Slug:
simple-301-redirects
Installations:
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.12.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.12.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.12.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.12.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.8.

WooCommerce Blocks

Plugin Slug:
woo-gutenberg-products-block
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.1.2.

WP Meta and Date Remover

Plugin Slug:
wp-meta-and-date-remover
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

Big File Uploads – Increase Maximum File Upload Size

Plugin Slug:
tuxedo-big-file-uploads
Installations:
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.12.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.8.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.25.

Slider – Ultimate Responsive Image Slider

Plugin Slug:
ultimate-responsive-image-slider
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.12.

WP Maintenance

Plugin Slug:
wp-maintenance
Installations:
40,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
6.1.4
Severity Score:
Low
The vulnerability has been patched, so you should update to version 6.1.4.

BlossomThemes Email Newsletter

Plugin Slug:
blossomthemes-email-newsletter
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.
Plugin Slug:
link-whisper
Installations:
30,000+
Vulnerability:
SQL Injection
Patched in Version:
0.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.6.6.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.32.

Delete Duplicate Posts

Plugin Slug:
delete-duplicate-posts
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.1.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations:
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.6.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations:
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.5.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.27.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.26.

LWS Hide Login

Plugin Slug:
lws-hide-login
Installations:
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.1.9
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.1.9.

WP EXtra

Plugin:
WP EXtra
Plugin Slug:
wp-extra
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.

WP Mail Log

Plugin Slug:
wp-mail-log
Installations:
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

YOP Poll

Plugin:
YOP Poll
Plugin Slug:
yop-poll
Installations:
10,000+
Vulnerability:
Race Condition
Patched in Version:
6.5.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.27.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor
Installations:
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

Drop Shadow Boxes

Plugin Slug:
drop-shadow-boxes
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.14.
Plugin Slug:
wp-auto-affiliate-links
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.6.

FormCraft – Contact Form Builder for WordPress

Plugin Slug:
formcraft-form-builder
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

ARI Stream Quiz – WordPress Quizzes Builder

Plugin Slug:
ari-stream-quiz
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Hreflang Manager

Plugin Slug:
hreflang-manager-lite
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Accordion

Plugin:
Accordion
Plugin Slug:
accordions-wp
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

avalex – Automatisch sichere Rechtstexte

Plugin Slug:
avalex
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

Daily Prayer Time

Plugin Slug:
daily-prayer-time-for-mosques
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2023.10.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2023.10.21.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations:
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
22.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 22.6.

Website Optimization – Plerdy

Plugin Slug:
plerdy-heatmap
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Post Status Notifier Lite

Plugin Slug:
post-status-notifier-lite
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.11.1.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager
Installations:
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.2.

Image Compressor & Optimizer – iLoveIMG

Plugin Slug:
iloveimg
Installations:
100+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

WooCommerce Canada Post Shipping

Plugin:
WooCommerce Canada Post Shipping
Plugin Slug:
woocommerce-shipping-canada-post
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

WooCommerce Bookings

Plugin:
WooCommerce Bookings
Plugin Slug:
woocommerce-bookings
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Star CloudPRNT for WooCommerce

Plugin:
Star CloudPRNT for WooCommerce
Plugin Slug:
star-cloudprnt-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.15.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Arbitrary File Upload
Patched in Version:
6.6.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.16.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Broken Access Control
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.7.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.7.10.

LayerSlider

Plugin:
LayerSlider
Plugin Slug:
layerslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.10.

Essential Grid

Plugin:
Essential Grid
Plugin Slug:
essential-grid
Vulnerability:
Broken Access Control
Patched in Version:
3.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.19.

WordPress Themes — 0 Patched / 0 Unpatched

No new WordPress theme vulnerabilities were disclosed this week.

Did you like this article? Spread the word: