WordPress Security

WordPress Vulnerability Report — October 18, 2023

Since last week, 151 new vulnerabilities emerged in the WordPress ecosystem, including 7 in WordPress core, 2 in themes, and 142 in plugins. More than half of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Dan Knauss

Since our last report, 151 new vulnerabilities have been publicly disclosed1, including 7 in WordPress core patched in the WordPress 6.3.2 update. Security patches for 66 plugins and 2 themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 76 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

Vulnerability:
Other Vulnerability Type
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Broken Access Control
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Core

Vulnerability:
Denial of Service Attack
Patched in Version:
6.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.2.

WordPress Plugin Vulnerabilities — 66 Patched / 76 Unpatched

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. Our weekly WordPress Vulnerability Report powered by Patchstack covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and 40% of the web — more secure.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations:
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP ULike – Most Advanced WordPress Marketing Toolkit

Plugin Slug:
wp-ulike
Installations:
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2
Installations:
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print, PDF, Email by PrintFriendly

Plugin Slug:
printfriendly
Installations:
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lazy Load for Videos

Plugin Slug:
lazy-load-for-videos
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wp Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Maps

Plugin:
HTML5 Maps
Plugin Slug:
html5-maps
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Proofreading

Plugin Slug:
proofreading
Installations:
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Protección de Datos RGPD

Plugin Slug:
click-datos-lopd
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comments Ratings

Plugin Slug:
comments-ratings
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ApplyOnline – Application Form Builder and Manager

Plugin Slug:
apply-online
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ApplyOnline – Application Form Builder and Manager

Plugin Slug:
apply-online
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact Forms by MailMunch

Plugin Slug:
constant-contact-forms-by-mailmunch
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple File List

Plugin Slug:
simple-file-list
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Attachments

Plugin Slug:
wp-attachments
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ashe Extra

Plugin:
Ashe Extra
Plugin Slug:
ashe-extra
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
buddypress-global-search
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom post types, Custom Fields & more

Plugin Slug:
custom-post-types
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DX Delete Attached Media

Plugin Slug:
dx-delete-attached-media
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Minimum Purchase for WooCommerce

Plugin Slug:
minimum-purchase-for-woocommerce
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rocket Font

Plugin Slug:
rocket-font
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

which template file

Plugin Slug:
which-template-file
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder, Contact Widget

Plugin Slug:
contact-forms-builder
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PDF Block

Plugin:
PDF Block
Plugin Slug:
pdf-block
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpiderVPlayer

Plugin Slug:
player
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FreshMail For WordPress

Plugin Slug:
freshmail-integration
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting
Installations:
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Column Widgets

Plugin Slug:
responsive-column-widgets
Installations:
2,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Gallery

Plugin Slug:
simple-post-gallery
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tweeple

Plugin:
Tweeple
Plugin Slug:
tweeple
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AMP WP – Google AMP For WordPress

Plugin Slug:
amp-wp
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form With Captcha

Plugin Slug:
contact-form-with-captcha
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Copy or Move Comments

Plugin Slug:
copy-or-move-comments
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Testimonial Slider and Form

Plugin Slug:
easy-testimonial-rotator
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Store

Plugin Slug:
ebook-store
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EG-Attachments

Plugin Slug:
eg-attachments
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fast WP Speed

Plugin Slug:
fast-wp-speed
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-album
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-album
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-album
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Icons Font Loader

Plugin Slug:
icons-font-loader
Installations:
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lava Directory Manager

Plugin Slug:
lava-directory-manager
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LeadSquared Suite

Plugin Slug:
leadsquared-suite
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sendle Shipping Plugin

Plugin Slug:
official-sendle-shipping-method
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Remote Content Shortcode

Plugin Slug:
remote-content-shortcode
Installations:
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RumbleTalk Live Group Chat – HTML5

Plugin Slug:
rumbletalk-chat-a-chat-with-themes
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video Playlist For YouTube

Plugin Slug:
video-playlist-for-youtube
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Next Page

Plugin:
Next Page
Plugin Slug:
next-page
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scroll post excerpt

Plugin Slug:
scroll-post-excerpt
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Tweet

Plugin Slug:
simple-tweet
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Awesome Feed – Custom Feed

Plugin Slug:
wp-facebook-feed
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

QR Twitter Widget

Plugin Slug:
qr-twitter-widget
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Taxonomy Manager

Plugin Slug:
ultimate-taxonomy-manager
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Taxonomy Manager

Plugin Slug:
ultimate-taxonomy-manager
Installations:
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Snap Pixel

Plugin:
Snap Pixel
Plugin Slug:
snap-pixel
Installations:
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Caret Country Access Limit

Plugin Slug:
caret-country-access-limit
Installations:
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPT Shortcode Generator

Plugin Slug:
cpt-shortcode
Installations:
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPT Shortcode Generator

Plugin Slug:
cpt-shortcode
Installations:
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Report Post

Plugin:
WP Report Post
Plugin Slug:
wp-report-post
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IMPress Listings

Plugin:
IMPress Listings
Plugin Slug:
wp-listings
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Feed Statistics

Plugin:
Feed Statistics
Plugin Slug:
wordpress-feed-statistics
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Who Hit The Page – Hit Counter

Plugin:
Who Hit The Page – Hit Counter
Plugin Slug:
who-hit-the-page-hit-counter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slick Contact Forms

Plugin:
Slick Contact Forms
Plugin Slug:
slick-contact-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Online ADA

Plugin:
Accessibility Suite by Online ADA
Plugin Slug:
online-accessibility
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mediabay

Plugin:
Mediabay
Plugin Slug:
mediabay-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magee Shortcodes

Plugin:
Magee Shortcodes
Plugin Slug:
magee-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AGP Font Awesome Collection

Plugin:
AGP Font Awesome Collection
Plugin Slug:
agp-font-awesome-collection
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Shortcodes Actions And Filters

Plugin:
Add Shortcodes Actions And Filters
Plugin Slug:
add-actions-and-filters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.

Gutenberg

Plugin:
Gutenberg
Plugin Slug:
gutenberg
Installations:
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.8.1.

Migration, Backup, Staging – WPvivid

Plugin Slug:
wpvivid-backuprestore
Installations:
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.9.92
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.9.92.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.7.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations:
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.79
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.79.
Plugin Slug:
wordpress-popular-posts
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.3.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.6.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.6.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.4.

WordPress Online Booking and Scheduling Plugin – Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool
Installations:
70,000+
Vulnerability:
SQL Injection
Patched in Version:
22.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 22.4.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Booking Calendar

Plugin Slug:
booking
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.7.3.1.

File Manager Pro – Filester

Plugin Slug:
filester
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

File Manager Pro – Filester

Plugin Slug:
filester
Installations:
50,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Master Addons for Elementor

Plugin Slug:
master-addons
Installations:
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations:
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.0.12.

Appointment Hour Booking – WordPress Booking Plugin

Plugin Slug:
appointment-hour-booking
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.24.

Embed Calendly

Plugin Slug:
embed-calendly-scheduling
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support
Installations:
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator
Installations:
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Responsive Tabs

Plugin Slug:
responsive-tabs
Installations:
7,000+
Vulnerability:
Content Injection
Patched in Version:
4.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.6.

Etsy Shop

Plugin:
Etsy Shop
Plugin Slug:
etsy-shop
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

GEO my WordPress

Plugin Slug:
geo-my-wp
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

Active Directory Integration / LDAP Integration

Plugin Slug:
ldap-login-for-intranet-sites
Installations:
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.10.

Poll Maker – Best WordPress Poll Plugin

Plugin Slug:
poll-maker
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.2.
Plugin Slug:
broken-link-finder
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Path Traversal
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.1.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.7.

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.
Plugin Slug:
smart-cookie-kit
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

DoLogin Security

Plugin Slug:
dologin
Installations:
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

Amministrazione Trasparente

Plugin Slug:
amministrazione-trasparente
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.0.5.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.6.

Get Custom Field Values

Plugin Slug:
get-custom-field-values
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.

WP Open Street Map

Plugin Slug:
wp-open-street-map
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.30.

School Management System – WPSchoolPress

Plugin Slug:
wpschoolpress
Installations:
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

Ajax Archive Calendar

Plugin Slug:
ajax-archive-calendar
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.

Eupago Gateway For Woocommerce

Plugin Slug:
eupago-gateway-for-woocommerce
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.10.

Sort SearchResult By Title

Plugin Slug:
sort-searchresult-by-title
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.0.

WP GoToWebinar

Plugin Slug:
wp-gotowebinar
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.46.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Nexter Extension

Plugin Slug:
nexter-extension
Installations:
900+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.0.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.4.

Nexter Extension

Plugin Slug:
nexter-extension
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Fattura24

Plugin:
Fattura24
Plugin Slug:
fattura24
Installations:
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.8.

Campaign Monitor Forms by Optin Cat

Plugin Slug:
campaign-monitor-wp
Installations:
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.6.

Peter’s Custom Anti-Spam

Plugin Slug:
peters-custom-anti-spam-image
Installations:
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.3.

Maileon for WordPress

Plugin Slug:
xqueue-maileon
Installations:
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.1.

File Uploader

Plugin:
File Uploader
Plugin Slug:
wp-file-uploader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.23.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.3.

WooCommerce Ninja Forms Product Add-ons

Plugin:
WooCommerce Ninja Forms Product Add-ons
Plugin Slug:
woocommerce-ninjaforms-product-addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

PixFields

Plugin:
PixFields
Plugin Slug:
pixfields
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.1.

cits-support-svg-webp-media-upload

Plugin:
cits-support-svg-webp-media-upload
Plugin Slug:
cits-support-svg-webp-media-upload
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

WordPress Theme Vulnerabilities

Nexter

Theme:
Nexter
Theme Slug:
nexter
Downloads:
11,281
Vulnerability:
Broken Access Control
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Nexter

Theme:
Nexter
Theme Slug:
nexter
Downloads:
11,281
Vulnerability:
SQL Injection
Patched in Version:
2.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.4.

Notes

  1. This report comes out on Wednesdays and covers the last seven days of public disclosures in the Patchstack vulnerability database from the beginning of the previous week to the beginning of the current week — from last Monday to this Monday. This excludes any vulnerabilities added to the database in the last 48 hours. However, that up-to-the-minute vulnerability data powers Solid Security Pro for our customers who have purchased Solid Suite. Solid Security Pro automatically protects WordPress sites from active exploits aimed at unpatched vulnerabilities. ↩︎

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: