WordPress Vulnerability Report

WordPress Vulnerability Report — November 27, 2024

This last week, 277 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 121 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 277 vulnerabilities have been publicly disclosed. Security patches for 156 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 121 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7, code-named “Rollins,” is out now, paying tribute to the legendary jazz saxophonist Sonny Rollins. WordPress 6.7 debuts the modern Twenty Twenty-Five theme, offering design flexibility for blogs.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 153 Patched / 115 Unpatched

Dynamic “To Top” Plugin

Plugin Slug:
dynamic-to-top
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meteor Slides

Plugin Slug:
meteor-slides
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weather Atlas Widget

Plugin Slug:
weather-atlas
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Announcement & Notification Banner – Bulletin

Plugin Slug:
bulletin-announcements
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yaad Sarig Payment Gateway For WC

Plugin Slug:
yaad-sarig-payment-gateway-for-wc
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Extensions for Elementor

Plugin Slug:
extensions-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Absolute Addons For Elementor

Plugin Slug:
absolute-addons
Installations
700+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Library Bookshelves

Plugin Slug:
library-bookshelves
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SuevaFree Essential Kit

Plugin Slug:
suevafree-essential-kit
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Team Rosters

Plugin Slug:
team-rosters
Installations
300+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Buying Buddy IDX CRM

Plugin Slug:
buying-buddy-idx-crm
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post By Email

Plugin Slug:
post-by-email
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ai-responsive-gallery-album
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

amr shortcodes

Plugin Slug:
amr-shortcodes
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lazy load videos and sticky control

Plugin Slug:
lazy-load-videos-and-sticky-control
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LeadBoxer

Plugin:
LeadBoxer
Plugin Slug:
leadboxer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LGPD Framework By Data443

Plugin Slug:
lgpd-framework
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SP Blog Designer

Plugin Slug:
sp-blog-designer
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tailored Tools

Plugin Slug:
tailored-tools
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TM Islamic Helper

Plugin Slug:
tm-islamic-helper
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Portfolio Builder

Plugin Slug:
portfolio-builder-elementor
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AI Quiz | Quiz Maker

Plugin Slug:
ai-quiz
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Open edX LMS and WordPress integrator (LITE)

Plugin Slug:
edunext-openedx-integrator
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Geolocator

Plugin:
Geolocator
Plugin Slug:
geolocator
Installations
50+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Infinite Slider

Plugin Slug:
infinite-slider
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Price Alert

Plugin Slug:
price-alert-woocommerce
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

QRMenu Restaurant QR Menu Lite

Plugin Slug:
qrmenu-lite
Installations
50+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP e-Commerce Style Email

Plugin Slug:
wp-e-commerce-style-email
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Office Locator

Plugin Slug:
office-locator
Installations
40+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Event Manager

Plugin Slug:
advanced-event-manager
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

de:branding

Plugin Slug:
debranding
Installations
30+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fintelligence Calculator

Plugin Slug:
fintelligence-calculator
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ITERAS

Plugin:
ITERAS
Plugin Slug:
iteras
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Studio

Plugin Slug:
awesome-studio
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Lyrics Karaoke Player

Plugin Slug:
html5-lyrics-karaoke-player
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

nBlocks – Responsive Gutenberg News Blocks

Plugin Slug:
nblocks
Installations
20+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Ideas

Plugin:
Post Ideas
Plugin Slug:
post-ideas
Installations
20+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
20+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AtaraPay WooCommerce Payment Gateway

Plugin Slug:
atarapay-woocommerce
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chameleoni Jobs

Plugin Slug:
chameleon-jobs
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Explara Events

Plugin Slug:
explara-events
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GoQMieruca

Plugin:
GoQMieruca
Plugin Slug:
goqmieruca
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GoQSmile

Plugin:
GoQSmile
Plugin Slug:
goqsmile
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pathomation

Plugin Slug:
pathomation
Installations
10+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Pricing table addon for elementor

Plugin Slug:
pricing-table-addon-for-elementor
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xpresslane Fast Checkout

Plugin Slug:
xpresslane-integration-for-woocommerce
Installations
10+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ahmeti Wp Güzel Sözler

Plugin:
Ahmeti Wp Güzel Sözler
Plugin Slug:
ahmeti-wp-guzel-sozler
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alphabetical List

Plugin:
Alphabetical List
Plugin Slug:
alphabetical-list
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

April’s Call Posts

Plugin:
April’s Call Posts
Plugin Slug:
aprils-call-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Banner System

Plugin:
Banner System
Plugin Slug:
banner-system
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Email Add on

Plugin:
Contact Form 7 Email Add on
Plugin Slug:
cf7-email-add-on
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Page With Google Map

Plugin:
Contact Page With Google Map
Plugin Slug:
contact-page-with-google-map
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Continue Shopping From Cart

Plugin:
Continue Shopping From Cart
Plugin Slug:
continue-shopping-from-cart-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Control horas

Plugin:
Control horas
Plugin Slug:
control-horas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Shortcode Sidebars

Plugin:
Custom Shortcode Sidebars
Plugin Slug:
custom-shortcode-sidebars
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic URL SEO

Plugin:
Dynamic URL SEO
Plugin Slug:
dynamic-url-seo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Twitter Feed

Plugin:
Easy Twitter Feed
Plugin Slug:
easy-twitter-feeds
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

F4 Improvements

Plugin:
F4 Improvements
Plugin Slug:
f4-improvements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Favicon My Blog

Plugin:
Favicon My Blog
Plugin Slug:
favicon-my-blog
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fence URL

Plugin:
Fence URL
Plugin Slug:
fence-url
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Footer Flyout Widget
Plugin Slug:
footer-flyout-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Plus Share and +1 Button

Plugin:
Google Plus Share and +1 Button
Plugin Slug:
google-plus-share-and-plusone-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grey Owl Lightbox

Plugin:
Grey Owl Lightbox
Plugin Slug:
grey-owl-lightbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Grid View Gallery
Plugin Slug:
grid-view-gallery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Brute Force Protection – Stop Brute Force Attacks

Plugin:
WordPress Brute Force Protection – Stop Brute Force Attacks
Plugin Slug:
guardgiant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hotlink2Watermark

Plugin:
Hotlink2Watermark
Plugin Slug:
hotlink2watermark
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IceStats

Plugin:
IceStats
Plugin Slug:
icestats
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Idealien Category Enhancements

Plugin:
Idealien Category Enhancements
Plugin Slug:
idealien-category-enhancements
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image horizontal reel scroll slideshow

Plugin:
Image horizontal reel scroll slideshow
Plugin Slug:
image-horizontal-reel-scroll-slideshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ImbaChat

Plugin:
ImbaChat
Plugin Slug:
imbachat-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iPhone Webclip Manager

Plugin:
iPhone Webclip Manager
Plugin Slug:
iphone-webclip-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kevin’s

Plugin:
Kevin’s
Plugin Slug:
kevins-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LeanPress

Plugin:
LeanPress
Plugin Slug:
leanpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LinkLaunder SEO

Plugin:
LinkLaunder SEO
Plugin Slug:
linklaunder-seo-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lock User Account

Plugin:
Lock User Account
Plugin Slug:
lock-user-account
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Feed Reader

Plugin:
Multi Feed Reader
Plugin Slug:
multi-feed-reader
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Login

Plugin:
Social Login
Plugin Slug:
oa-social-login
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Community by PeepSo

Plugin:
Community by PeepSo
Plugin Slug:
peepso-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Designer

Plugin:
Product Designer
Plugin Slug:
product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Protect Your Content

Plugin:
Protect Your Content
Plugin Slug:
protect-your-content
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pure CSS Circle Progress Bar

Plugin:
Pure CSS Circle Progress Bar
Plugin Slug:
pure-css-circle-progress-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Learn

Plugin Slug:
quick-learn
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Quotes llama

Plugin:
Quotes llama
Plugin Slug:
quotes-llama
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RealtyCandy IDX Broker Extended

Plugin:
RealtyCandy IDX Broker Extended
Plugin Slug:
realtycandy-idx-broker-extended
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RecipePress Reloaded

Plugin:
RecipePress Reloaded
Plugin Slug:
recipepress-reloaded
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

salavat counter

Plugin:
salavat counter
Plugin Slug:
salavat-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Crypto and DeFi Widgets

Plugin:
Crypto and DeFi Widgets
Plugin Slug:
security-force
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shine PDF Embeder

Plugin:
Shine PDF Embeder
Plugin Slug:
shine-pdf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Travel Map

Plugin:
Simple Travel Map
Plugin Slug:
simple-travel-map
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slick Sitemap

Plugin:
Slick Sitemap
Plugin Slug:
slick-sitemap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Silverlight Video Player

Plugin:
Silverlight Video Player
Plugin Slug:
smooth-streaming-player
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Social Icons

Plugin:
Sticky Social Icons
Plugin Slug:
sticky-social-icons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LSX Tour Operator

Plugin:
LSX Tour Operator
Plugin Slug:
tour-operator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tribute Testimonials

Plugin:
Tribute Testimonials
Plugin Slug:
tribute-testimonial-gridslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin:
Ultimate YouTube Video & Shorts Player With Vimeo
Plugin Slug:
ultimate-youtube-video-player
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin:
Ultimate YouTube Video & Shorts Player With Vimeo
Plugin Slug:
ultimate-youtube-video-player
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UltraAddons Elementor Lite

Plugin:
UltraAddons Elementor Lite
Plugin Slug:
ultraaddons-elementor-lite
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:
UserPlus
Plugin Slug:
userplus
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPBakery Visual Composer WHMCS Elements

Plugin:
WPBakery Visual Composer WHMCS Elements
Plugin Slug:
void-visual-whmcs-element
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wc Recently viewed products

Plugin:
Wc Recently viewed products
Plugin Slug:
wc-recently-viewed-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wp auto top

Plugin:
wp auto top
Plugin Slug:
wp-auto-top
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-ISPConfig 3

Plugin:
WP-ISPConfig 3
Plugin Slug:
wp-ispconfig3
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPDash Notes

Plugin:
WPDash Notes
Plugin Slug:
wpdash-notes
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Youneeq Recommendations

Plugin:
Youneeq Recommendations
Plugin Slug:
youneeq-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

yPHPlista

Plugin:
yPHPlista
Plugin Slug:
yphplista
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zajax – Ajax Navigation

Plugin:
Zajax – Ajax Navigation
Plugin Slug:
zajax-ajax-navigation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
3,000,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.0.232
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.232.

Google for WooCommerce

Plugin Slug:
google-listings-and-ads
Installations
900,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.7.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1002
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1002.

Activity Log – Monitor & Record User Changes

Plugin Slug:
aryo-activity-log
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.2.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect
Installations
200,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.45
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.45.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect
Installations
200,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.44
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.44.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.10.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.10.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.3.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.3.21.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.6.4.

Parsi Date

Plugin:
Parsi Date
Plugin Slug:
wp-parsidate
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
SQL Injection
Patched in Version:
2.7.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.7.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.62.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.62.0.

Clone

Plugin:
Clone
Plugin Slug:
wp-clone-by-wp-academy
Installations
70,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

Increase Maximum Upload File Size | Increase Execution Time

Plugin Slug:
wp-maximum-upload-file-size
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.13.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations
60,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
1.4.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.3.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.4.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.4.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.47
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.47.

Simple Membership

Plugin Slug:
simple-membership
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.6.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
2.145.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.145.1.

Stratum – Elementor Widgets

Plugin Slug:
stratum
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.4.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.22.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.22.22.

404 Solution

Plugin Slug:
404-solution
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.35.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.35.20.

CM Pop-Up Banners for WordPress

Plugin Slug:
cm-pop-up-banners
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.6.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

Restaurant Menu – Food Ordering System – Table Reservation

Plugin Slug:
menu-ordering-reservations
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.3.

Simple Side Tab

Plugin Slug:
simple-side-tab
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.7.

WP User Manager – User Profile Builder & Membership

Plugin Slug:
wp-user-manager
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.12.

WP User Manager – User Profile Builder & Membership

Plugin Slug:
wp-user-manager
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.12.

Category Ajax Filter

Plugin Slug:
category-ajax-filter
Installations
8,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.3.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.12.

GD bbPress Attachments

Plugin Slug:
gd-bbpress-attachments
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.3.

If-So Dynamic Content Personalization

Plugin Slug:
if-so
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.2.

MailMunch – Grow your Email List

Plugin Slug:
mailmunch
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.0.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.3.7.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce
Installations
6,000+
Vulnerability:
Path Traversal
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.8.

GEO my WP

Plugin:
GEO my WP
Plugin Slug:
geo-my-wp
Installations
5,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.5.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.16.

CM WordPress Search And Replace Plugin

Plugin Slug:
cm-on-demand-search-and-replace
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

Sp*tify Play Button for WordPress

Plugin Slug:
spotify-play-button-for-wordpress
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.4.

Add Chat App Button

Plugin Slug:
add-whatsapp-button
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Parallax Image

Plugin Slug:
parallax-image
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.22.

affiliate-toolkit – WP Affiliate Plugin with Amazon

Plugin Slug:
affiliate-toolkit-starter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.8.

Email Subscription Popup

Plugin Slug:
email-subscribe
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.23.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.3.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.2.

SVG Block

Plugin:
SVG Block
Plugin Slug:
svg-block
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.25.

Theme Builder For Elementor

Plugin Slug:
theme-builder-for-elementor
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Checkout with Cash App on WooCommerce

Plugin Slug:
wc-cashapp
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.0.3.

What Would Seth Godin Do

Plugin Slug:
what-would-seth-godin-do
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Anonymous Restricted Content

Plugin Slug:
anonymous-restricted-content
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.4.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.4.7.

Attesa Extra

Plugin Slug:
attesa-extra
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.
Plugin Slug:
bne-gallery-extended
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Name: CM E-Mail Registration Blacklist

Plugin Slug:
cm-email-blacklist
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.
Plugin Slug:
cm-header-footer-script-loader
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.77
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.5.77.

Friendly Functions for Welcart

Plugin Slug:
friendly-functions-for-welcart
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.5.

GD Rating System

Plugin Slug:
gd-rating-system
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.
Plugin Slug:
inpost-gallery
Installations
1,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.3.

JobBoardWP – Job Board Listings and Submissions

Plugin Slug:
jobboardwp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

NiceJob

Plugin:
NiceJob
Plugin Slug:
nicejob
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

????? ?? ???? – ???? ?? ????

Plugin Slug:
pgall-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.0.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.1.

Bard Extra

Plugin:
Bard Extra
Plugin Slug:
bard-extra
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Include Mastodon Feed

Plugin Slug:
include-mastodon-feed
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.6.

System Dashboard

Plugin Slug:
system-dashboard
Installations
800+
Vulnerability:
Path Traversal
Patched in Version:
2.8.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.15.

System Dashboard

Plugin Slug:
system-dashboard
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.15.

StreamWeasels Online Status Bar

Plugin Slug:
stream-status-for-twitch
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.10.

Theater for WordPress

Plugin Slug:
theatre
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.18.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.18.7.

Block Editor Bootstrap Blocks

Plugin Slug:
block-editor-bootstrap-blocks
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.6.2.

Memberlite Shortcodes

Plugin Slug:
memberlite-shortcodes
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

???? ???

Plugin:
???? ???
Plugin Slug:
mshop-naver-talktalk
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

WP Mailster

Plugin Slug:
wp-mailster
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.17.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.17.0.

CM Table Of Contents – WordPress TOC Plugin

Plugin Slug:
cm-table-of-content
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.4.

CM Table Of Contents – WordPress TOC Plugin

Plugin Slug:
cm-table-of-content
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

???? ?????

Plugin:
???? ?????
Plugin Slug:
mshop-npay
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.0.

Custom CSS, JS & PHP

Plugin Slug:
custom-css
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.0.

FireCask’s Twitter Follow Button

Plugin Slug:
twitter-follow
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.

Easy Liveblogs

Plugin Slug:
easy-liveblogs
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.

Opal Woo Custom Product Variation

Plugin Slug:
opal-woo-custom-product-variation
Installations
200+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.4.

Slotti Ajanvaraus

Plugin Slug:
slotti-ajanvaraus
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

WIP Incoming Lite

Plugin Slug:
wip-incoming-lite
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

WP-Orphanage Extended

Plugin Slug:
wp-orphanage-extended
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.

Chessgame Shizzle

Plugin Slug:
chessgame-shizzle
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

My Contador lesr

Plugin Slug:
my-contador-wp
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Skt NURCaptcha

Plugin Slug:
skt-nurcaptcha
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.0.

Ortto

Plugin:
Ortto
Plugin Slug:
autopilot
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.21.

AutoListicle: Automatically Update Numbered List Articles

Plugin Slug:
autolisticle-automatically-update-numbered-list-articles
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Video Lessons Manager – WordPress LMS Plugin

Plugin Slug:
cm-video-lesson-manager
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.3.

PDF Invoices & Packing Slips Generator for WooCommerce

Plugin Slug:
pdf-invoicing-for-woocommerce
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

Page Parts

Plugin:
Page Parts
Plugin Slug:
page-parts
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Fediverse Embeds

Plugin Slug:
fediverse-embeds
Installations
40+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.4.

WordPress Bootscraper

Plugin Slug:
wp-bootscraper
Installations
40+
Vulnerability:
Local File Inclusion
Patched in Version:
4.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.0.

???????? ??????? ????????? ??????

Plugin Slug:
express-pay
Installations
20+
Vulnerability:
SQL Injection
Patched in Version:
1.1.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.9.

Document & Data Automation

Plugin:
Document & Data Automation
Plugin Slug:
document-data-automation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

MP3 Sticky Player

Plugin:
MP3 Sticky Player
Plugin Slug:
fwdmsp
Vulnerability:
Path Traversal
Patched in Version:
8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Broken Access Control
Patched in Version:
67.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 67.2.0.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
67.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 67.2.0.

Leopard – WordPress offload media

Plugin:
Leopard – WordPress offload media
Plugin Slug:
leopard-wordpress-offload-media
Vulnerability:
Broken Access Control
Patched in Version:
3.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.2.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
92.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 92.0.0.

Wishlist for WooCommerce Pro

Plugin:
Wishlist for WooCommerce Pro
Plugin Slug:
wish-list-for-woocommerce-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.3.

Booking & Appointment Plugin for WooCommerce

Plugin:
Booking & Appointment Plugin for WooCommerce
Plugin Slug:
woocommerce-booking
Vulnerability:
Broken Access Control
Patched in Version:
6.10.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.10.0.

WordPress GDPR & CCPA

Plugin:
WordPress GDPR & CCPA
Plugin Slug:
wordpress-gdpr
Vulnerability:
Broken Access Control
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

WordPress GDPR & CCPA

Plugin:
WordPress GDPR & CCPA
Plugin Slug:
wordpress-gdpr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.3.

WordPress Themes — 3 Patched / 6 Unpatched

Grip

Theme:
Grip
Theme Slug:
grip
Downloads
27,482
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

AccessPress Staple

Theme:
AccessPress Staple
Theme Slug:
accesspress-staple
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:
Jobify – Job Board WordPress Theme
Theme Slug:
jobify
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:
Jobify – Job Board WordPress Theme
Theme Slug:
jobify
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:
Jobify – Job Board WordPress Theme
Theme Slug:
jobify
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:
Jobify – Job Board WordPress Theme
Theme Slug:
jobify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Ashe

Theme:
Ashe
Theme Slug:
ashe
Downloads
2,043,009
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.244
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.244.

Bard

Theme:
Bard
Theme Slug:
bard
Downloads
939,343
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.217
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.217.

ForumEngine

Theme:
ForumEngine
Theme Slug:
forumengine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security