WordPress Vulnerability Report

WordPress Vulnerability Report — October 16, 2024

Since last week, 176 new vulnerabilities emerged in the WordPress ecosystem including 173 plugins and 3 themes. 89 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 176 vulnerabilities have been publicly disclosed. Security patches for 87 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 89 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Don’t install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 2 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 87 Patched / 86 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Docs

Plugin Slug:
buddypress-docs
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
linkz-ai
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
linkz-ai
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

2D Tag Cloud

Plugin:
2D Tag Cloud
Plugin Slug:
2d-tag-cloud-widget-by-sujin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AB Categories Search Widget

Plugin:
AB Categories Search Widget
Plugin Slug:
ab-categories-search-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACF Images Search And Insert

Plugin:
ACF Images Search And Insert
Plugin Slug:
acf-images-search-and-insert
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Add Categories Post Footer

Plugin:
Add Categories Post Footer
Plugin Slug:
add-categories-post-footer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ADIF Log Search Widget

Plugin:
ADIF Log Search Widget
Plugin Slug:
adif-log-search-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Blocks Pro

Plugin:
Advanced Blocks Pro
Plugin Slug:
advanced-blocks-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ahime Image Printer

Plugin:
Ahime Image Printer
Plugin Slug:
ahime-image-printer
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ahmeti Wp Timeline

Plugin:
Ahmeti Wp Timeline
Plugin Slug:
ahmeti-wp-timeline
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ajax Custom CSS/JS

Plugin:
Ajax Custom CSS/JS
Plugin Slug:
ajax-awesome-css
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ajax-extend

Plugin:
ajax-extend
Plugin Slug:
ajax-extend
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ajax Rating with Custom Login

Plugin:
Ajax Rating with Custom Login
Plugin Slug:
ajax-rating-with-custom-login
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Analyse Uploads

Plugin:
Analyse Uploads
Plugin Slug:
analyse-uploads
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Arkhe Blocks

Plugin:
Arkhe Blocks
Plugin Slug:
arkhe-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Azz Anonim Posting

Plugin:
Azz Anonim Posting
Plugin Slug:
azz-anonim-posting
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Better Author Bio

Plugin:
Better Author Bio
Plugin Slug:
better-author-bio
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Better Registration

Plugin:
BuddyPress Better Registration
Plugin Slug:
better-bp-registration
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Booking.com Banner Creator

Plugin:
Booking.com Banner Creator
Plugin Slug:
bookingcom-banner-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bot for Telegram on WooCommerce

Plugin:
Bot for Telegram on WooCommerce
Plugin Slug:
bot-for-telegram-on-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bVerse Convert

Plugin:
bVerse Convert
Plugin Slug:
bverse-convert
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CJ Change Howdy

Plugin:
CJ Change Howdy
Plugin Slug:
cj-change-howdy
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Cookie Scanner
Plugin Slug:
cookie-scanner
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Country Flags for Elementor

Plugin:
Country Flags for Elementor
Plugin Slug:
country-flags-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crazy Call To Action Box

Plugin:
Crazy Call To Action Box
Plugin Slug:
crazy-call-to-action-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Creates 3D Flipbook, PDF Flipbook

Plugin:
Creates 3D Flipbook, PDF Flipbook
Plugin Slug:
create-flipbook-from-pdf
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

cSlider

Plugin:
cSlider
Plugin Slug:
cslider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Builder

Plugin:
WP Builder
Plugin Slug:
cssjockey-add-ons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV Product Import Export for WooCommerce

Plugin:
CSV Product Import Export for WooCommerce
Plugin Slug:
csv-wc-product-import-export
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Curator.io

Plugin:
Curator.io
Plugin Slug:
curatorio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Digital Lottery

Plugin:
Digital Lottery
Plugin Slug:
digital-lottery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Disc Golf Manager

Plugin:
Disc Golf Manager
Plugin Slug:
disc-golf-manager
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Elementor Addons

Plugin:
Dynamic Elementor Addons
Plugin Slug:
dynamic-elementor-addons
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Social Share Buttons

Plugin:
Easy Social Share Buttons
Plugin Slug:
easy-social-share-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Events Addon for Elementor

Plugin:
Events Addon for Elementor
Plugin Slug:
events-addon-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
External featured image from bing
Plugin Slug:
external-featured-image-from-bing
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Posts with Multiple Custom Groups (FPMCG)
Plugin Slug:
featured-posts-with-multiple-custom-groups-fpmcg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Featured Posts with Multiple Custom Groups (FPMCG)
Plugin Slug:
featured-posts-with-multiple-custom-groups-fpmcg
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Feed Comments Number

Plugin:
Feed Comments Number
Plugin Slug:
feed-comments-number
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Free Stock Photos Foter

Plugin:
Free Stock Photos Foter
Plugin Slug:
free-stock-photos-foter
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GDPR-Extensions-com

Plugin:
GDPR-Extensions-com
Plugin Slug:
gdpr-consent-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Inline SVG

Plugin:
Elementor Inline SVG
Plugin Slug:
inline-svg-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IP Loc8

Plugin:
IP Loc8
Plugin Slug:
ip-loc8
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Keep Backup Daily

Plugin:
Keep Backup Daily
Plugin Slug:
keep-backup-daily
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WordPress Gallery Plugin – Limb Image Gallery
Plugin Slug:
limb-gallery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WordPress Gallery Plugin – Limb Image Gallery
Plugin Slug:
limb-gallery
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Linked Variation for WooCommerce

Plugin:
Linked Variation for WooCommerce
Plugin Slug:
linked-variation-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Forms, Live Support, CRM, Video Messages

Plugin:
Contact Forms, Live Support, CRM, Video Messages
Plugin Slug:
live-support-tickets
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Maan Addons For Elementor

Plugin:
Maan Addons For Elementor
Plugin Slug:
maan-elementor-addons
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Forms for Mailchimp by Optin Cat

Plugin:
Forms for Mailchimp by Optin Cat
Plugin Slug:
mailchimp-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketing and SEO Booster

Plugin:
Marketing and SEO Booster
Plugin Slug:
marketing-and-seo-booster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MAS Elementor

Plugin:
MAS Elementor
Plugin Slug:
mas-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

El mejor Cluster

Plugin:
El mejor Cluster
Plugin Slug:
mejorcluster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mighty Builder

Plugin:
Mighty Builder
Plugin Slug:
mighty-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mitm Bug Tracker

Plugin:
Mitm Bug Tracker
Plugin Slug:
mitm-bug-tracker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Favorites

Plugin:
My Favorites
Plugin Slug:
my-favorites
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mynx Page Builder

Plugin:
Mynx Page Builder
Plugin Slug:
mynx-page-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy PayPal Gift Certificate

Plugin:
Easy PayPal Gift Certificate
Plugin Slug:
paypal-gift-certificate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pedalo Connector

Plugin:
Pedalo Connector
Plugin Slug:
pedalo-connector
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Plexx Elementor Extension

Plugin:
Plexx Elementor Extension
Plugin Slug:
plexx-elementor-extension
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QA Analytics

Plugin:
QA Analytics
Plugin Slug:
qa-heatmap-analytics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Read more By Adam

Plugin:
Read more By Adam
Plugin Slug:
read-more
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recently

Plugin:
Recently
Plugin Slug:
recently-viewed-most-viewed-and-sold-products-for-woocommerce
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Restaurant Reservations Widget

Plugin:
Restaurant Reservations Widget
Plugin Slug:
restaurantconnect-reswidget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RS-Members

Plugin:
RS-Members
Plugin Slug:
rs-members
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode For Elementor Templates

Plugin:
Shortcode For Elementor Templates
Plugin Slug:
shortcode-support-for-elementor-templates
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes AnyWhere

Plugin:
Shortcodes AnyWhere
Plugin Slug:
shortcodes-anywhere
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Baseball Scoreboard

Plugin:
Simple Baseball Scoreboard
Plugin Slug:
simple-baseball-scoreboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Plus

Plugin:
Table of Contents Plus
Plugin Slug:
table-of-contents-plus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TAKETIN To WP Membership

Plugin:
TAKETIN To WP Membership
Plugin Slug:
taketin-to-wp-membership
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Talkback

Plugin:
Talkback
Plugin Slug:
talkback-secure-linkback-protocol
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Telecash Ricaricaweb

Plugin:
Telecash Ricaricaweb
Plugin Slug:
telecash-ricaricaweb
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Tito

Plugin:
Tito
Plugin Slug:
tito
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Addon For Elementor

Plugin:
Unlimited Addon For Elementor
Plugin Slug:
unlimited-addon-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Adding drop down roles in registration

Plugin:
Adding drop down roles in registration
Plugin Slug:
user-drop-down-roles-in-registration
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:
UserPlus
Plugin Slug:
userplus
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Video

Plugin:
WordPress Video
Plugin Slug:
wordpress-video
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Spreadplugin

Plugin:
WP-Spreadplugin
Plugin Slug:
wp-spreadplugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Users Masquerade

Plugin:
WP Users Masquerade
Plugin Slug:
wp-users-masquerade
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wpPricing Builder

Plugin:
wpPricing Builder
Plugin Slug:
wppricing-builder-lite-responsive-pricing-table-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wsify Widget

Plugin:
Wsify Widget
Plugin Slug:
wsify-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Content Injection
Patched in Version:
9.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.0.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack
Installations
4,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
13.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.9.1.

Secure Custom Fields

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
6.3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.6.1.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.3.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.12.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.4.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.987
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.987.

Ad Inserter – Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.38
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.38.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.5.122
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.122.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.28.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.13.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.9.

Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.23.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.1.

Stackable – Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.7.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.8.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.7.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.22.

Download Plugins and Themes in ZIP from Dashboard

Plugin Slug:
download-plugins-dashboard
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.2.

WPIDE – File Manager & Code Editor

Plugin Slug:
wpide
Installations
40,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

FULL – Cliente

Plugin Slug:
full-customer
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.23.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.9.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.9.19.

VOD Infomaniak

Plugin Slug:
vod-infomaniak
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Embed PDF Viewer

Plugin Slug:
embed-pdf-viewer
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More

Plugin Slug:
post-carousel
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

WordPress File Upload

Plugin Slug:
wp-file-upload
Installations
20,000+
Vulnerability:
Path Traversal
Patched in Version:
4.24.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.24.12.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
1.22.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.22.22.

Contact Form 7 – PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.1.

Hunk Companion

Plugin Slug:
hunk-companion
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.5.

WP Post Author – Boost Your Blog’s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.2.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.29.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic
Installations
9,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.7.29
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.29.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.11.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.9.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.9.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.3.1.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.6.

Auto iFrame

Plugin Slug:
auto-iframe
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Easy Mega Menu Plugin for WordPress – ThemeHunk

Plugin Slug:
themehunk-megamenu-plus
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

WP Ultimate Post Grid

Plugin Slug:
wp-ultimate-post-grid
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.16.

Social Sharing (by Danny)

Plugin Slug:
dvk-social-sharing
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Category Icon

Plugin Slug:
category-icon
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce
Installations
3,000+
Vulnerability:
Directory Traversal
Patched in Version:
2.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.9.

Products, Order & Customers Export for WooCommerce

Plugin Slug:
export-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.0.

Notification for Telegram

Plugin Slug:
notification-for-telegram
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

Embed videos and respect privacy

Plugin Slug:
video-embed-privacy
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

BlockMeister – Block Pattern Builder

Plugin Slug:
blockmeister
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.11.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations
2,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
3.31.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.31.7.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Smart Blocks

Plugin Slug:
smart-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

IdeaPush

Plugin:
IdeaPush
Plugin Slug:
ideapush
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.71
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.71.

Increase upload file size & Maximum Execution Time limit

Plugin Slug:
increase-upload-file-size-maximum-execution-time-limit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.

Language Switcher

Plugin Slug:
language-switcher
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

Maximum Products per User for WooCommerce

Plugin Slug:
maximum-products-per-user-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.9.

Order Attachments for WooCommerce

Plugin Slug:
order-attachments-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.0.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.21.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.21.11.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
0.21.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.21.9.

wp-Monalisa

Plugin Slug:
wp-monalisa
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.
Plugin Slug:
wp-advanced-search
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
3.3.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.9.2.

AADMY – Add Auto Date Month Year Into Posts

Plugin Slug:
auto-date-year-month
Installations
300+
Vulnerability:
Content Injection
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Da Reactions

Plugin Slug:
da-reactions
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.0.

Limit Login Attempts (Spam Protection)

Plugin Slug:
wp-limit-failed-login-attempts
Installations
200+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.
Plugin Slug:
image-gallery
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.
Plugin Slug:
image-gallery
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.
Plugin Slug:
image-gallery
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

pretix widget

Plugin Slug:
pretix-widget
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.6.

WP 2FA with Telegram

Plugin Slug:
two-factor-login-telegram
Installations
100+
Vulnerability:
Broken Authentication
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

WP 2FA with Telegram

Plugin Slug:
two-factor-login-telegram
Installations
100+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.

SB Random Posts Widget

Plugin Slug:
sb-random-posts-widget
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro
Vulnerability:
Arbitrary Code Execution
Patched in Version:
6.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.8.

Bridge Core

Plugin:
Bridge Core
Plugin Slug:
bridge-core
Vulnerability:
Broken Access Control
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

CMSMasters Content Composer

Plugin:
CMSMasters Content Composer
Plugin Slug:
cmsmasters-content-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.0.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Broken Authentication
Patched in Version:
5.0.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.13.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
SQL Injection
Patched in Version:
5.0.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.12.

Social Auto Poster

Plugin:
Social Auto Poster
Plugin Slug:
social-auto-poster
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.16.

WordPress Themes — 0 Patched / 3 Unpatched

disconnected

Theme:
disconnected
Theme Slug:
disconnected
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

my flatonica

Theme:
my flatonica
Theme Slug:
my-flatonica
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

my wooden under construction

Theme:
my wooden under construction
Theme Slug:
my-wooden-under-construction
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security