WordPress Security

WordPress Vulnerability Report — October 25, 2023

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. Our weekly WordPress Vulnerability Report powered by Patchstack covers the latest WordPress plugin, theme, and core vulnerabilities to emerge.

Dan Knauss

Since our last report, 125 new vulnerabilities have been publicly disclosed.1 Security patches for 61 plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 64 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall with virtual patches from Patchstack. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our weekly WordPress Vulnerability Report covers the latest WordPress plugin, theme, and core vulnerabilities to emerge. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.3.2 is a Maintenance and Security release issued on October 12. It features 19 bug fixes on Core, 22 bug fixes for the Block Editor, and 8 security fixes.

Because this is a security release, it is recommended that you apply it and update your sites to WordPress 6.3.2 as soon as possible. Backports are also available for older supported major WordPress releases from version 4.1 onward.

The next major release will be version 6.4, expected on 7 November 2023.

No new WordPress core vulnerabilities were disclosed this week.

WordPress Plugins — 61 Patched / 64 Unpatched

Simple Calendar – Google Calendar Plugin

Plugin Slug:
google-calendar-events
Installations:
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web Push Notifications – Webpushr

Plugin Slug:
webpushr-web-push-notifications
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Motors – Car Dealer, Classifieds & Listing

Plugin Slug:
motors-car-dealership-classified-listings
Installations:
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Motors – Car Dealer, Classifieds & Listing

Plugin Slug:
motors-car-dealership-classified-listings
Installations:
9,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Protección de Datos RGPD

Plugin Slug:
click-datos-lopd
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus – Unlimited grid layout

Plugin Slug:
grid-plus
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WC Captcha

Plugin:
WC Captcha
Plugin Slug:
wc-captcha
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ApplyOnline – Application Form Builder and Manager

Plugin Slug:
apply-online
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce
Installations:
4,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ashe Extra

Plugin:
Ashe Extra
Plugin Slug:
ashe-extra
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom post types, Custom Fields & more

Plugin Slug:
custom-post-types
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DX Delete Attached Media

Plugin Slug:
dx-delete-attached-media
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Minimum Purchase for WooCommerce

Plugin Slug:
minimum-purchase-for-woocommerce
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rocket Font

Plugin Slug:
rocket-font
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder, Contact Widget

Plugin Slug:
contact-forms-builder
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Duplicate Theme

Plugin Slug:
duplicate-theme
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
internal-link-building-plugin
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
internal-link-building-plugin
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Login New User After Registration

Plugin Slug:
auto-login-new-user-after-registration
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Login New User After Registration

Plugin Slug:
auto-login-new-user-after-registration
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FreshMail For WordPress

Plugin Slug:
freshmail-integration
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Open Graph Metabox

Plugin Slug:
open-graph-metabox
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Userback

Plugin:
Userback
Plugin Slug:
userback
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointment Calendar

Plugin Slug:
appointment-calendar
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Archivist – Custom Archive Templates

Plugin Slug:
archivist-custom-archive-templates
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category SEO Meta Tags

Plugin Slug:
category-seo-meta-tags
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EG-Attachments

Plugin Slug:
eg-attachments
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Eonet Manual User Approve

Plugin Slug:
eonet-manual-user-approve
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Headline Analyzer

Plugin Slug:
headline-analyzer
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Icons Font Loader

Plugin Slug:
icons-font-loader
Installations:
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Just Custom Fields

Plugin Slug:
just-custom-fields
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lava Directory Manager

Plugin Slug:
lava-directory-manager
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Novo-Map : your WP posts on custom google maps

Plugin Slug:
novo-map
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SALESmanago

Plugin Slug:
salesmanago
Installations:
1,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart App Banner

Plugin Slug:
smart-app-banner
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
smooth-scrolling-links-ssl
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WDSocialWidgets

Plugin Slug:
spider-facebook
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Webmaster Tools

Plugin Slug:
webmaster-tools
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Webmaster Tools

Plugin Slug:
webmaster-tools
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Awesome Feed – Custom Feed

Plugin Slug:
wp-facebook-feed
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Triberr

Plugin:
Triberr
Plugin Slug:
triberr-wordpress-plugin
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Soisy Pagamento Rateale

Plugin Slug:
soisy-pagamento-rateale
Installations:
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Columns

Plugin:
WP Post Columns
Plugin Slug:
wp-post-columns
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Full Stripe Free

Plugin:
WP Full Stripe Free
Plugin Slug:
wp-full-stripe-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Who Hit The Page – Hit Counter

Plugin:
Who Hit The Page – Hit Counter
Plugin Slug:
who-hit-the-page-hit-counter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WhatsApp Share Button

Plugin:
WhatsApp Share Button
Plugin Slug:
whatsapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Blvd Shortcodes

Plugin:
Theme Blvd Shortcodes
Plugin Slug:
theme-blvd-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TCD Google Maps

Plugin:
TCD Google Maps
Plugin Slug:
tcd-google-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Skype Legacy Buttons

Plugin:
Skype Legacy Buttons
Plugin Slug:
skype-online-status
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Table Manager

Plugin:
WP Simple Table Manager
Plugin Slug:
simple-table-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Tree

Plugin:
Product Category Tree
Plugin Slug:
product-category-tree
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MpOperationLogs

Plugin:
MpOperationLogs
Plugin Slug:
mpoperationlogs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mediabay

Plugin:
Mediabay
Plugin Slug:
mediabay-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magee Shortcodes

Plugin:
Magee Shortcodes
Plugin Slug:
magee-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CPO Shortcodes

Plugin:
CPO Shortcodes
Plugin Slug:
cpo-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Custom Body Class

Plugin:
Add Custom Body Class
Plugin Slug:
add-custom-body-class
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Shortcodes Actions And Filters

Plugin:
Add Shortcodes Actions And Filters
Plugin Slug:
add-actions-and-filters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Stripe Payment Gateway

Plugin Slug:
woocommerce-gateway-stripe
Installations:
900,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.1.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.
Plugin Slug:
nextgen-gallery
Installations:
500,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.39.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations:
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.9.1.

MW WP Form

Plugin:
MW WP Form
Plugin Slug:
mw-wp-form
Installations:
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations:
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.7.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.6.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.6.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
7.6.4
Severity Score:
Low
The vulnerability has been patched, so you should update to version 7.6.4.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Content Injection
Patched in Version:
7.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.11.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations:
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.11.

WordPress Online Booking and Scheduling Plugin – Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool
Installations:
70,000+
Vulnerability:
SQL Injection
Patched in Version:
22.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 22.4.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Booking Calendar

Plugin Slug:
booking
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.7.3.1.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.3.

File Manager Pro – Filester

Plugin Slug:
filester
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

File Manager Pro – Filester

Plugin Slug:
filester
Installations:
50,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations:
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.0.12.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.51.
Plugin Slug:
betterlinks
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

E2Pdf – Export To Pdf Tool for WordPress

Plugin Slug:
e2pdf
Installations:
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.20.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.20.19.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.4.

Popup by Supsystic

Plugin Slug:
popup-by-supsystic
Installations:
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.10.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.20.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support
Installations:
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.

WP EXtra

Plugin:
WP EXtra
Plugin Slug:
wp-extra
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.

Freesoul Deactivate Plugins – Plugin manager and cleanup

Plugin Slug:
freesoul-deactivate-plugins
Installations:
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

iPanorama 360 – WordPress Virtual Tour Builder

Plugin Slug:
ipanorama-360-virtual-tour-builder-lite
Installations:
7,000+
Vulnerability:
SQL Injection
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Modern Footnotes

Plugin Slug:
modern-footnotes
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.17.

WOLF – WordPress Posts Bulk Editor and Manager Professional

Plugin Slug:
bulk-editor
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.2.

Active Directory Integration / LDAP Integration

Plugin Slug:
ldap-login-for-intranet-sites
Installations:
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.10.
Plugin Slug:
broken-link-finder
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Directory Traversal
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

AI ChatBot

Plugin:
AI ChatBot
Plugin Slug:
chatbot
Installations:
4,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.9.1.

EventON

Plugin:
EventON
Plugin Slug:
eventon-lite
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.7.

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Team Showcase

Plugin Slug:
team-showcase
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.

DoLogin Security

Plugin Slug:
dologin
Installations:
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

Tab Ultimate

Plugin Slug:
tabs-pro
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

School Management System – WPSchoolPress

Plugin Slug:
wpschoolpress
Installations:
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

Ajax Archive Calendar

Plugin Slug:
ajax-archive-calendar
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.

Social proof testimonials and reviews by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.00
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.00.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

History Log by click5

Plugin Slug:
history-log-by-click5
Installations:
800+
Vulnerability:
SQL Injection
Patched in Version:
1.0.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.13.

Maileon for WordPress

Plugin Slug:
xqueue-maileon
Installations:
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.16.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.16.1.

Delete Usermetas

Plugin Slug:
delete-usermetas
Installations:
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

File Uploader

Plugin:
File Uploader
Plugin Slug:
wp-file-uploader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.23.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.3.

WooCommerce Ninja Forms Product Add-ons

Plugin:
WooCommerce Ninja Forms Product Add-ons
Plugin Slug:
woocommerce-ninjaforms-product-addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.15.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Local File Inclusion
Patched in Version:
3.19.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.19.15.

Super Testimonial Pro

Plugin:
Super Testimonial Pro
Plugin Slug:
super-testimonial-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

WordPress Themes

No new WordPress theme vulnerabilities were disclosed this week.

Notes

  1. This report comes out on Wednesdays and covers the last seven days of public disclosures in the Patchstack vulnerability database from the beginning of the previous week to the beginning of the current week — from last Monday to this Monday. This period intentionally excludes any vulnerabilities added to the database in the last 48 hours. However, that up-to-the-minute vulnerability data powers Solid Security Pro for our customers who have purchased Solid Suite. Solid Security Pro automatically protects WordPress sites from active exploits aimed at unpatched vulnerabilities. ↩︎

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: