WordPress Security

WordPress Vulnerability Report – October 11, 2023

Since last week, 101 new plugin vulnerabilities emerged. 42 have security patches. 59 do not. Not to worry — our firewall has you covered.

Dan Knauss

Between last Monday (October 2) and Monday this week (October 9), 101 new vulnerabilities were publicly disclosed.1 They may affect nearly two million WordPress sites. There are 42 plugin vulnerabilities with security patches, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 59 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

  1. This report comes out on Wednesdays and covers the last seven days of public disclosures in the Patchstack vulnerability database from the previous to the current Monday. It excludes any vulnerabilities added to the database in the last 48 hours. However, that up-to-the-minute vulnerability data powers Solid Security Pro. Solid Security Pro automatically protects WordPress sites from active exploits aimed at unpatched vulnerabilities. ↩︎

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugin Vulnerabilities (59 Unpatched / 42 Patched)

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Widget area

Plugin Slug:
wp-custom-widget-area
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations:
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Power Stats

Plugin Slug:
wp-power-stats
Installations:
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple SEO

Plugin:
Simple SEO
Plugin Slug:
cds-simple-seo
Installations:
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Forms Puzzle Captcha

Plugin Slug:
wp-forms-puzzle-captcha
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post View Count

Plugin Slug:
wp-simple-post-view
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Complete Open Graph

Plugin Slug:
complete-open-graph
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sp*tify Play Button for WordPress

Plugin Slug:
spotify-play-button-for-wordpress
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
permalinks-customizer
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Urvanov Syntax Highlighter

Plugin Slug:
urvanov-syntax-highlighter
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Login Redirect

Plugin Slug:
woo-login-redirect
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GoodBarber

Plugin:
GoodBarber
Plugin Slug:
goodbarber
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gumroad

Plugin:
Gumroad
Plugin Slug:
gumroad
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShortCodes UI

Plugin Slug:
shortcodes-ui
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Short URL

Plugin:
Short URL
Plugin Slug:
shorten-url
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Feed | Custom Feed for Social Media Networks

Plugin Slug:
wp-social-feed
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blog Manager Light

Plugin Slug:
blog-manager-light
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

canvasio3D Light

Plugin Slug:
canvasio3d-light
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Copy or Move Comments

Plugin Slug:
copy-or-move-comments
Installations:
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin Slug:
ebook-store
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hitsteps Web Analytics

Plugin Slug:
hitsteps-visitor-manager
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hitsteps Web Analytics

Plugin Slug:
hitsteps-visitor-manager
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Interactive World Map

Plugin Slug:
interactive-world-map
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LeadSquared Suite

Plugin Slug:
leadsquared-suite
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mailrelay

Plugin:
Mailrelay
Plugin Slug:
mailrelay
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OPcache Dashboard

Plugin Slug:
opcache
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Order auto complete for WooCommerce

Plugin Slug:
order-auto-complete-for-woocommerce
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendPulse Free Web Push

Plugin Slug:
sendpulse-web-push
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social proof testimonials and reviews by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Timely Booking Button

Plugin Slug:
timely-booking-button
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WhitePage

Plugin:
WhitePage
Plugin Slug:
white-page-publication
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sharkdropship for AliExpress Dropship and Affiliate

Plugin Slug:
wooshark-aliexpress-importer
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image vertical reel scroll slideshow

Plugin Slug:
image-vertical-reel-scroll-slideshow
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stout Google Calendar

Plugin Slug:
stout-google-calendar
Installations:
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category Meta plugin

Plugin Slug:
wp-category-meta
Installations:
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Location and IP

Plugin Slug:
user-location-and-ip
Installations:
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fotomoto

Plugin:
Fotomoto
Plugin Slug:
fotomoto
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mendeley Plugin

Plugin Slug:
mendeleyplugin
Installations:
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Publish Confirm Message

Plugin Slug:
publish-confirm-message
Installations:
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AmpedSense – AdSense Split Tester

Plugin Slug:
ampedsense-adsense-split-tester
Installations:
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Automated Editor

Plugin Slug:
automated-editor
Installations:
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dropshipping & Affiliation with Amazon

Plugin:
Dropshipping & Affiliation with Amazon
Plugin Slug:
wp-amazon-shop
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woo Custom Emails

Plugin:
Woo Custom Emails
Plugin Slug:
woo-custom-emails
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slick Contact Forms

Plugin:
Slick Contact Forms
Plugin Slug:
slick-contact-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Responsive header image slide

Plugin:
WP Responsive header image slide
Plugin Slug:
responsive-header-image-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Tree

Plugin:
Product Category Tree
Plugin Slug:
product-category-tree
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pressference Exporter

Plugin Slug:
pressference-exporter
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Instagram for WordPress

Plugin:
Instagram for WordPress
Plugin Slug:
instagram-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hotjar

Plugin:
Hotjar
Plugin Slug:
hotjar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact form Form For All

Plugin:
Contact form Form For All
Plugin Slug:
formforall
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations:
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.0.
Plugin Slug:
wordpress-popular-posts
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.3.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations:
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.36.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.36.1.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations:
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Abandoned Cart Lite for WooCommerce

Plugin Slug:
woocommerce-abandoned-cart
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.16.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.16.0.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.33.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

10Web Map Builder for Google Maps

Plugin Slug:
wd-google-maps
Installations:
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.74
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.74.

bbp style pack

Plugin Slug:
bbp-style-pack
Installations:
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.8.

Podcast Subscribe Buttons

Plugin Slug:
podcast-subscribe-buttons
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.9.

Seriously Simple Stats

Plugin Slug:
seriously-simple-stats
Installations:
6,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.

Seriously Simple Stats

Plugin Slug:
seriously-simple-stats
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.2.

GEO my WordPress

Plugin Slug:
geo-my-wp
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

Connect to external APIs – WPGetAPI

Plugin Slug:
wpgetapi
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.9.

MStore API

Plugin:
MStore API
Plugin Slug:
mstore-api
Installations:
4,000+
Vulnerability:
SQL Injection
Patched in Version:
4.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.7.
Plugin Slug:
smart-cookie-kit
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

affiliate-toolkit – WordPress Affiliate Plugin

Plugin Slug:
affiliate-toolkit-starter
Installations:
2,000+
Vulnerability:
Open Redirection
Patched in Version:
3.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.0.

Open User Map

Plugin Slug:
open-user-map
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.27.

Profile Extra Fields by BestWebSoft

Plugin Slug:
profile-extra-fields
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

WP Bing Map Pro

Plugin Slug:
api-bing-map-2018
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.

BuddyMeet

Plugin:
BuddyMeet
Plugin Slug:
buddymeet
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Geo Controller

Plugin Slug:
cf-geoplugin
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.3.

YouTube Playlist Player

Plugin Slug:
youtube-playlist-player
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.8.

Comment Reply Email

Plugin Slug:
comment-reply-email
Installations:
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

WP Mail SMTP Pro

Plugin:
WP Mail SMTP Pro
Plugin Slug:
wp-mail-smtp-pro
Vulnerability:
Broken Access Control
Patched in Version:
3.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.

Optimize Database after Deleting Revisions

Plugin:
Optimize Database after Deleting Revisions
Plugin Slug:
rvg-optimize-database
Vulnerability:
Broken Access Control
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

WordPress Theme Vulnerabilities

No new WordPress theme vulnerabilities were disclosed this week.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security