WordPress Vulnerability Report

WordPress Vulnerability Report – October 4, 2023

Since last week, 97 new vulnerabilities have emerged in public disclosures. They may affect over two million WordPress sites. This includes 50 plugin vulnerabilities with security patches, so run those updates! Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors' intentions and progress toward a security release.

Dan Knauss

Since last week, 97 new vulnerabilities have emerged in public disclosures. They may affect over two million WordPress sites. This includes 50 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress toward a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme or plugin repositories, you should consider deactivation and removal in favor of alternative solutions.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Table of Contents Plus

Product image for Table of Contents Plus.
Plugin Slug
table-of-contents-plus
Installations
300,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2309
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2309.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.
Plugin Slug
foogallery
Installations
100,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.3.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

iframe

Product image for iframe.
Plugin
iframe
Plugin Slug
iframe
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.7.

Advanced Custom Fields: Extended

Product image for Advanced Custom Fields: Extended.
Plugin Slug
acf-extended
Installations
80,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.8.9.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 0.8.9.4.

Astra Bulk Edit

Product image for Astra Bulk Edit.
Plugin Slug
astra-bulk-edit
Installations
70,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Simple Membership

Product image for Simple Membership.
Plugin Slug
simple-membership
Installations
50,000+
Vulnerability
Privilege Escalation
Patched in Version
4.3.5
Severity Score
High
The vulnerability has been patched, so you should update to version 4.3.5.

Simple Membership

Product image for Simple Membership.
Plugin Slug
simple-membership
Installations
50,000+
Vulnerability
Privilege Escalation
Patched in Version
4.3.5
Severity Score
High
The vulnerability has been patched, so you should update to version 4.3.5.

Abandoned Cart Lite for WooCommerce

Product image for Abandoned Cart Lite for WooCommerce.
Plugin Slug
woocommerce-abandoned-cart
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.16.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 5.16.0.

flowpaper

Product image for flowpaper.
Plugin
flowpaper
Plugin Slug
flowpaper-lite-pdf-flipbook
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Simple Cloudflare Turnstile

Product image for Simple Cloudflare Turnstile – CAPTCHA Alternative.
Plugin Slug
simple-cloudflare-turnstile
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.23.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.23.2.

Inactive Logout

Product image for Inactive Logout.
Plugin Slug
inactive-logout
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
3.2.3
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Modal Window

Product image for Modal Window – create popup modal window.
Plugin Slug
modal-window
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.3.6
Severity Score
Medium
The vulnerability has been patched, so you should update to version 5.3.6.

Options for Twenty Seventeen

Product image for Options for Twenty Seventeen.
Plugin Slug
options-for-twenty-seventeen
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

bbp style pack

Product image for bbp style pack.
Plugin Slug
bbp-style-pack
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.6.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 5.6.8.

Brands for WooCommerce

Product image for Brands for WooCommerce.
Plugin Slug
brands-for-woocommerce
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
3.8.2.3
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.8.2.3.

Active Directory Integration / LDAP Integration

Product image for Active Directory Integration / LDAP Integration.
Plugin Slug
ldap-login-for-intranet-sites
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
4.2
Severity Score
Low
The vulnerability has been patched, so you should update to version 4.2.

AI ChatBot

Product image for AI ChatBot.
Plugin Slug
chatbot
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.7.9
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.7.9.

ActivityPub for WordPress

Product image for ActivityPub.
Plugin Slug
activitypub
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.
Plugin Slug
activitypub
Installations
3,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
1.0.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.
Plugin Slug
activitypub
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.
Plugin Slug
activitypub
Installations
3,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
1.0.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

Checkfront Online Booking System

Product image for Checkfront Online Booking System.
Plugin Slug
checkfront-wp-booking
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.7
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.7.

DoLogin Security

Plugin Slug
dologin
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.7
Severity Score
High
The vulnerability has been patched, so you should update to version 3.7.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.
Plugin Slug
import-xml-feed
Installations
3,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
2.1.5
Severity Score
Critical
The vulnerability has been patched, so you should update to version 2.1.5.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.
Plugin Slug
import-xml-feed
Installations
3,000+
Vulnerability
Arbitrary File Upload
Patched in Version
2.1.4
Severity Score
Critical
The vulnerability has been patched, so you should update to version 2.1.4.

Track The Click

Product image for Track The Click.
Plugin Slug
track-the-click
Installations
3,000+
Vulnerability
SQL Injection
Patched in Version
0.3.12
Severity Score
High
The vulnerability has been patched, so you should update to version 0.3.12.

Anchor Episodes Index (Spotify for Podcasters)

Product image for Anchor Episodes Index (Spotify for Podcasters).
Plugin Slug
anchor-episodes-index
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

Comment Blacklist Updater

Product image for Comment Blacklist Updater.
Plugin Slug
comment-blacklist-updater
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Instant CSS

Product image for Instant CSS.
Plugin Slug
instant-css
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.2.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Pretty Google Calendar

Plugin Slug
pretty-google-calendar
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

OpenHook

Product image for OpenHook.
Plugin
OpenHook
Plugin Slug
thesis-openhook
Installations
2,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
4.3.1
Severity Score
Critical
The vulnerability has been patched, so you should update to version 4.3.1.

BuddyMeet

Product image for BuddyMeet.
Plugin
BuddyMeet
Plugin Slug
buddymeet
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Pre-Publish Checklist

Product image for Pre-Publish Checklist.
Plugin Slug
pre-publish-checklist
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
1.1.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

User Avatar – Reloaded

Product image for User Avatar – Reloaded.
Plugin Slug
user-avatar-reloaded
Installations
800+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Payment gateway per Product for WooCommerce

Product image for Payment gateway per Product for WooCommerce.
Plugin Slug
woocommerce-product-payments
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.2.8
Severity Score
High
The vulnerability has been patched, so you should update to version 3.2.8.

Staff / Employee Business Directory for Active Directory

Product image for Staff / Employee Business Directory for Active Directory.
Plugin Slug
ldap-ad-staff-employee-directory-search
Installations
10+
Vulnerability
Broken Access Control
Patched in Version
1.3
Severity Score
Low
The vulnerability has been patched, so you should update to version 1.3.

Modern Events Calendar lite

Plugin
Modern Events Calendar Lite
Plugin Slug
modern-events-calendar-lite
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.1.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 7.1.0.

User Activity Log Pro

Plugin
User Activity Log Pro
Plugin Slug
user-activity-log-pro
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.4
Severity Score
High
The vulnerability has been patched, so you should update to version 2.3.4.

User Activity Log Pro

Plugin
User Activity Log Pro
Plugin Slug
user-activity-log-pro
Vulnerability
Bypass Vulnerability
Patched in Version
2.3.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Unyson

Product image for Unyson.
Plugin
Unyson
Plugin Slug
unyson
Installations
200,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media Library Assistant

Product image for Media Library Assistant.
Plugin Slug
media-library-assistant
Installations
70,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Timthumb Vulnerability Scanner

Plugin Slug
timthumb-vulnerability-scanner
Installations
40,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mang Board WP

Product image for Mang Board WP.
Plugin Slug
mangboard
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mediavine Control Panel

Plugin Slug
mediavine-control-panel
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Schema App Structured Data

Product image for Schema App Structured Data.
Plugin Slug
schema-app-structured-data-for-schemaorg
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Block Plugin Update

Product image for Block Plugin Update.
Plugin Slug
block-specific-plugin-updates
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple File List

Plugin Slug
simple-file-list
Installations
5,000+
Vulnerability
Arbitrary File Deletion
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Product image for WP Job Portal – A Complete Job Board.
Plugin Slug
wp-job-portal
Installations
3,000+
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Blocks

Product image for Blocks.
Plugin
Blocks
Plugin Slug
blocks
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form

Product image for Contact Form.
Plugin Slug
contact-form-ready
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Timely Booking Button

Product image for Timely Booking Button.
Plugin Slug
timely-booking-button
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tiny Carousel Horizontal Slider

Product image for Tiny Carousel Horizontal Slider.
Plugin Slug
tiny-carousel-horizontal-slider
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce ESTO

Plugin Slug
woo-esto
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Pages

Plugin Slug
wp-hide-pages
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.
Plugin Slug
popup-contact-form
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.
Plugin Slug
popup-contact-form
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Metrics

Plugin Slug
social-metrics
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Awesome Feed – Custom Feed

Product image for The Awesome Feed – Custom Feed.
Plugin Slug
wp-facebook-feed
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Onclick Show Popup

Product image for Onclick show popup.
Plugin Slug
onclick-show-popup
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slideshow, Image Slider by 2J

Plugin
Images Slideshow by 2J
Plugin Slug
2j-slideshow
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Add Shortcodes Actions And Filters

Plugin
Add Shortcodes Actions And Filters
Plugin Slug
add-actions-and-filters
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contractor Contact Form Website to Workflow Tool

Plugin
Contractor Contact Form Website to Workflow Tool
Plugin Slug
contractor-contact-form-website-to-workflow-tool
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cooked

Plugin
Cooked
Plugin Slug
cooked
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CopyRightPro

Plugin
CopyRightPro
Plugin Slug
copyrightpro
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Comments by Startbit

Plugin
Comments by Startbit
Plugin Slug
facebook-comment-by-vivacity
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome Integration

Plugin
Font Awesome Integration
Plugin Slug
font-awesome-integration
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome More Icons

Plugin
Font Awesome More Icons
Plugin Slug
font-awesome-more-icons
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form Form For All

Plugin
Contact form Form For All
Plugin Slug
formforall
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Keap Landing Pages

Plugin
Keap Landing Pages
Plugin Slug
infusionsoft-landing-pages
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Backend Localization

Plugin
Backend Localization
Plugin Slug
kau-boys-backend-localization
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Kv TinyMCE Editor Add Fonts

Plugin
Kv TinyMCE Editor Add Fonts
Plugin Slug
kv-tinymce-editor-fonts
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Magic Action Box

Plugin
Magic Action Box
Plugin Slug
magic-action-box
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Remove slug from custom post type

Plugin
Remove slug from custom post type
Plugin Slug
remove-slug-from-custom-post-type
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Responsive header image slider

Plugin
WP Responsive header image slide
Plugin Slug
responsive-header-image-slider
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Events Rich Snippets for Google

Plugin
Events Rich Snippets for Google
Plugin Slug
rich-snippets-vevents
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Shockingly Simple Favicon

Plugin
Shockingly Simple Favicon
Plugin Slug
shockingly-simple-favicon
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

TM WooCommerce Compare & Wishlist

Plugin
TM WooCommerce Compare & Wishlist
Plugin Slug
tm-woocommerce-compare-wishlist
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Vrm 360 3D Model Viewer

Plugin
Vrm 360 3D Model Viewer
Plugin Slug
vrm360
Vulnerability
Sensitive Data Exposure
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

Plugin
WP Captcha
Plugin Slug
wp-captcha
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

Plugin
WP Captcha
Plugin Slug
wp-captcha
Vulnerability
Bypass Vulnerability
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP GPX Maps

Plugin
WP GPX Map
Plugin Slug
wp-gpx-maps
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Jump Menu

Plugin
WP Jump Menu
Plugin Slug
wp-jump-menu
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Site Protector

Plugin
WP Site Protector
Plugin Slug
wp-site-protector
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WWM Social Share On Image Hover

Plugin
WWM Social Share On Image Hover
Plugin Slug
wwm-social-share-on-image-hover
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

  • No new WordPress theme vulnerabilities were disclosed this week.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.


Did you like this article? Spread the word: