WordPress Security

WordPress Vulnerability Report — November 29, 2023

This week, 138 new vulnerabilities have emerged, potentially impacting 10 million WordPress sites. 89 vulnerable plugins remain unpatched.

Dan Knauss

Since our last report, 138 new vulnerabilities have been publicly disclosed. Security patches for 49 plugins and one theme are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 89 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.1 was released on November 8 as a short-cycle maintenance release to address several bugs, including loss of backward compatibility with a dependency, cURL 7.29 or earlier. This broke the WordPress internal update facility on servers running very old, insecure cURL versions.

WordPress 6.4 was released on November 7 as the third major release of 2023. Following a major release, you should not update live sites without taking backups and testing the update in a non-production environment first.

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugins — 49 Patched / # Unpatched

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations:
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Theme Editor

Plugin Slug:
theme-editor
Installations:
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Captcha Code

Plugin Slug:
captcha-code-authentication
Installations:
30,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mail Bank – #1 Mail SMTP Plugin for WordPress

Plugin Slug:
wp-mail-bank
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Maspik – Spam Blacklist

Plugin Slug:
contact-forms-anti-spam
Installations:
20,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Restricted Site Access

Plugin Slug:
restricted-site-access
Installations:
20,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Child Theme Generator

Plugin Slug:
wp-child-theme-generator
Installations:
10,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SoundCloud Shortcode

Plugin Slug:
soundcloud-shortcode
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simply Exclude

Plugin Slug:
simply-exclude
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Forms Puzzle Captcha

Plugin Slug:
wp-forms-puzzle-captcha
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Forms Puzzle Captcha

Plugin Slug:
wp-forms-puzzle-captcha
Installations:
7,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Campaign Monitor for WordPress

Plugin Slug:
forms-for-campaign-monitor
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Parallax Image

Plugin Slug:
parallax-image
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpiderVPlayer

Plugin Slug:
player
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Comment Remove

Plugin Slug:
bulk-comment-remove
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form to Any API

Plugin Slug:
contact-form-to-any-api
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

League Table

Plugin Slug:
league-table-lite
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Availability Calendar

Plugin Slug:
availability-calendar
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
broken-link-checker-for-youtube
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Shortcodes Ultimate

Plugin Slug:
bs-shortcode-ultimate
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations:
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Delete Post Revisions In WordPress

Plugin Slug:
delete-post-revisions-on-single-click
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontier Post

Plugin Slug:
frontier-post
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Seraphinite Post .DOCX Source

Plugin Slug:
seraphinite-post-docx-source
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Testimonials Showcase

Plugin Slug:
simple-testimonials-showcase
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Taxonomy filter

Plugin Slug:
taxonomy-filter
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TriPay Payment Gateway

Plugin Slug:
tripay-payment-gateway
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Display Custom Post

Plugin Slug:
display-custom-post
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TextMe SMS

Plugin:
TextMe SMS
Plugin Slug:
textme-sms-integration
Installations:
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Long Form

Plugin Slug:
simple-long-form
Installations:
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fast Custom Social Share by CodeBard

Plugin Slug:
fast-custom-social-share-by-codebard
Installations:
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Githuber MD

Plugin:
WP Githuber MD
Plugin Slug:
wp-githuber-md
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Video PopUp

Plugin:
Video PopUp
Plugin Slug:
video-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Grab & Save

Plugin:
Grab & Save
Plugin Slug:
save-grab
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grab & Save

Plugin:
Grab & Save
Plugin Slug:
save-grab
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayTR Taksit Tablosu

Plugin:
PayTR Taksit Tablosu
Plugin Slug:
paytr-taksit-tablosu-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide login page

Plugin:
Hide login page
Plugin Slug:
hide-login-page
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Consensu.io

Plugin:
Consensu.io
Plugin Slug:
consensu-io
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CataBlog

Plugin:
CataBlog
Plugin Slug:
catablog
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CataBlog

Plugin:
CataBlog
Plugin Slug:
catablog
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Audio Merchant

Plugin:
Audio Merchant
Plugin Slug:
audio-merchant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Audio Merchant

Plugin:
Audio Merchant
Plugin Slug:
audio-merchant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin:
Yoast SEO
Plugin Slug:
wordpress-seo
Installations:
5,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
21.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 21.1.

Antispam Bee

Plugin Slug:
antispam-bee
Installations:
700,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.11.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.4.

BackWPup – WordPress Backup Plugin

Plugin Slug:
backwpup
Installations:
600,000+
Vulnerability:
Path Traversal
Patched in Version:
4.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations:
600,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
7.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.0.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations:
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.0.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations:
300,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.1.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.89
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.89.

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce
Installations:
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.3.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.3.12.

HUSKY – Products Filter for WooCommerce Professional

Plugin Slug:
woocommerce-products-filter
Installations:
100,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.4.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.4.3.

HUSKY – Products Filter for WooCommerce Professional

Plugin Slug:
woocommerce-products-filter
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.3.

Events Manager

Plugin Slug:
events-manager
Installations:
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.6.

Export any WordPress data to XML/CSV

Plugin Slug:
wp-all-export
Installations:
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.1.

Export any WordPress data to XML/CSV

Plugin Slug:
wp-all-export
Installations:
90,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.0.

Export any WordPress data to XML/CSV

Plugin Slug:
wp-all-export
Installations:
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.1.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations:
60,000+
Vulnerability:
Content Injection
Patched in Version:
7.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.3.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations:
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Super Progressive Web Apps

Plugin Slug:
super-progressive-web-apps
Installations:
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.22.

BlossomThemes Email Newsletter

Plugin Slug:
blossomthemes-email-newsletter
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Easy Social Icons

Plugin Slug:
easy-social-icons
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.
Plugin Slug:
link-whisper
Installations:
30,000+
Vulnerability:
SQL Injection
Patched in Version:
0.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.6.6.

Accept Stripe Payments

Plugin Slug:
stripe-payments
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.80
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.80.

Accept Stripe Payments

Plugin Slug:
stripe-payments
Installations:
30,000+
Vulnerability:
Content Injection
Patched in Version:
2.0.80
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.80.

Maspik – Spam Blacklist

Plugin Slug:
contact-forms-anti-spam
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.3.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

wpForo Forum

Plugin Slug:
wpforo
Installations:
20,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

YASR – Yet Another Star Rating Plugin for WordPress

Plugin Slug:
yet-another-stars-rating
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.5.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.5.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations:
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.42.

Decorator – WooCommerce Email Customizer

Plugin Slug:
decorator-woocommerce-email-customizer
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Participants Database

Plugin Slug:
participants-database
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

Qode Essential Addons

Plugin Slug:
qode-essential-addons
Installations:
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.5.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.3.

Quttera Web Malware Scanner

Plugin Slug:
quttera-web-malware-scanner
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.1.

Quttera Web Malware Scanner

Plugin Slug:
quttera-web-malware-scanner
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.4.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.1.

WP Mail Log

Plugin Slug:
wp-mail-log
Installations:
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

Drop Shadow Boxes

Plugin Slug:
drop-shadow-boxes
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.14.

Event Single Page Builder For The Event Calendar

Plugin Slug:
event-page-templates-addon-for-the-events-calendar
Installations:
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.2.8.1.

License Manager for WooCommerce

Plugin Slug:
license-manager-for-woocommerce
Installations:
6,000+
Vulnerability:
SQL Injection
Patched in Version:
2.2.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.11.

Salon booking system

Plugin Slug:
salon-booking-system
Installations:
6,000+
Vulnerability:
Privilege Escalation
Patched in Version:
8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.

Void Elementor Post Grid Addon for Elementor Page builder

Plugin Slug:
void-elementor-post-grid-addon-for-elementor-page-builder
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
5,000+
Vulnerability:
SQL Injection
Patched in Version:
4.7.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.9.
Plugin Slug:
wp-auto-affiliate-links
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.6.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.3.

Autocomplete Location field Contact Form 7

Plugin Slug:
autocomplete-location-field-contact-form-7
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

Import Spreadsheets from Microsoft Excel

Plugin Slug:
import-spreadsheets-from-microsoft-excel
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.1.4.

Preloader for Website

Plugin Slug:
preloader-for-website
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.20.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.20.5.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations:
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.14.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.25.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager
Installations:
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

WordPress Job Board and Recruitment Plugin – JobWP

Plugin Slug:
jobwp
Installations:
400+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

WP Roadmap – Product Feedback Board

Plugin Slug:
wp-roadmap
Installations:
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.6.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.8.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.6.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.6.

WCFM Marketplace

Plugin:
WCFM Marketplace
Plugin Slug:
wc-multivendor-marketplace
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Broken Authentication
Patched in Version:
5.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Broken Access Control
Patched in Version:
5.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.5.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Broken Authentication
Patched in Version:
5.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Privilege Escalation
Patched in Version:
5.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.5.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.1.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Broken Access Control
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.1.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.2.

Theme My Login 2FA

Plugin:
Theme My Login 2FA
Plugin Slug:
tml-2fa
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Salient Core

Plugin:
Salient Core
Plugin Slug:
salient-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.3.

Salient Core

Plugin:
Salient Core
Plugin Slug:
salient-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

Porto Theme – Functionality

Plugin:
Porto Theme – Functionality
Plugin Slug:
porto-functionality
Vulnerability:
SQL Injection
Patched in Version:
2.12.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.12.1.

Porto Theme – Functionality

Plugin:
Porto Theme – Functionality
Plugin Slug:
porto-functionality
Vulnerability:
Broken Access Control
Patched in Version:
2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.1.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Broken Access Control
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.7.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

collectchat

Plugin:
collectchat
Plugin Slug:
collectchat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

WordPress Themes — 1 Patched / 0 Unpatched

Enfold

Theme:
Enfold
Theme Slug:
enfold
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.5.

Did you like this article? Spread the word: