In this report, 182 vulnerabilities have been publicly disclosed. Security patches for 137 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 45 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.7 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Don’t install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 2 on a test server and site.
WordPress Plugins — 135 Patched / 42 Unpatched
Soumettre.fr
- Plugin:
- Soumettre.fr
- Plugin Slug:
- soumettre-fr
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8675
Loggedin – Limit Active Logins
- Plugin:
- Loggedin – Limit Active Logins
- Plugin Slug:
- loggedin
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9228
BuddyPress Docs
- Plugin:
- BuddyPress Docs
- Plugin Slug:
- buddypress-docs
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9207
DK PDF
Copyscape Premium
- Plugin:
- Copyscape Premium
- Plugin Slug:
- copyscape-premium
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-47644
Keap Official Opt-in Forms
- Plugin:
- Keap Official Opt-in Forms
- Plugin Slug:
- infusionsoft-official-opt-in-forms
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-47642
Online Booking & Scheduling Calendar for WordPress by vcita
- Plugin Slug:
- meeting-scheduler-by-vcita
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-47638
Include Fussball.de Widgets
- Plugin:
- Include Fussball.de Widgets
- Plugin Slug:
- include-fussball-de-widgets
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-47643
LH Copy Media File
- Plugin:
- LH Copy Media File
- Plugin Slug:
- lh-copy-media-file
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9220
Payflex Payment Gateway
- Plugin:
- Payflex Payment Gateway
- Plugin Slug:
- payflex-payment-gateway
- Installations
- 1,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-47646
RumbleTalk Live Group Chat – HTML5
- Plugin Slug:
- rumbletalk-chat-a-chat-with-themes
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8720
VdoCipher: Secure Video Player and Hosting
- Plugin Slug:
- vdocipher
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-47639
Hello World
- Plugin:
- Hello World
- Plugin Slug:
- hello-world
- Installations
- 900+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9224
123.chat
- Plugin:
- 123.chat
- Plugin Slug:
- 123-chat-videochat
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-7869
Aggregator Advanced Settings
- Plugin:
- Aggregator Advanced Settings
- Plugin Slug:
- aggregator-advanced-settings
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9368
Auto Featured Image from Title
- Plugin:
- Auto Featured Image from Title
- Plugin Slug:
- auto-featured-image-from-title
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8786
Captcha Bank
- Plugin:
- Captcha Bank
- Plugin Slug:
- captcha-bank
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9375
Confetti Fall Animation
- Plugin:
- Confetti Fall Animation
- Plugin Slug:
- confetti-fall-animation
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-47641
Custom Banners
- Plugin:
- Custom Banners
- Plugin Slug:
- custom-banners
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8799
Display Medium Posts
- Plugin:
- Display Medium Posts
- Plugin Slug:
- display-medium-posts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9445
Easy Load More
- Plugin:
- Easy Load More
- Plugin Slug:
- easy-load-more
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8728
Elastik Page Builder
- Plugin:
- Elastik Page Builder
- Plugin Slug:
- elastik-page-builder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9274
Gravity Forms Toolbar
- Plugin:
- Gravity Forms Toolbar
- Plugin Slug:
- gravity-forms-toolbar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8718
Guten Post Layout
- Plugin:
- Guten Post Layout
- Plugin Slug:
- guten-post-layout
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8288
Iconize
- Plugin:
- Iconize
- Plugin Slug:
- iconize
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-47649
KB Support
- Plugin:
- KB Support
- Plugin Slug:
- kb-support
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8632
KB Support
- Plugin:
- KB Support
- Plugin Slug:
- kb-support
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8548
LocateAndFilter
- Plugin:
- LocateAndFilter
- Plugin Slug:
- locateandfilter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9304
Login Logout Shortcode
- Plugin:
- Login Logout Shortcode
- Plugin Slug:
- login-logout-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9421
Optin Hound
- Plugin:
- Optin Hound
- Plugin Slug:
- opt-in-hound
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9267
PDF Image Generator
- Plugin:
- PDF Image Generator
- Plugin Slug:
- pdf-image-generator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9241
R Animated Icon
- Plugin:
- R Animated Icon
- Plugin Slug:
- r-animated-icon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9272
Relogo
- Plugin:
- Relogo
- Plugin Slug:
- relogo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9269
Spice Starter Sites
- Plugin:
- Spice Starter Sites
- Plugin Slug:
- spice-starter-sites
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8430
SVG Complete
- Plugin:
- SVG Complete
- Plugin Slug:
- svg-complete
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9119
Wechat Social login
- Plugin:
- Wechat Social login
- Plugin Slug:
- wechat-social-login
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-9108
Wechat Social login
- Plugin:
- Wechat Social login
- Plugin Slug:
- wechat-social-login
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-9106
WooCommerce – Store Exporter
- Plugin:
- WooCommerce – Store Exporter
- Plugin Slug:
- woocommerce-exporter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-8793
WP Blocks Hub
- Plugin:
- WP Blocks Hub
- Plugin Slug:
- wp-blocks-hub
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9372
WP Cleanup and Basic Functions
- Plugin:
- WP Cleanup and Basic Functions
- Plugin Slug:
- wp-cleanup-and-basic-functions
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9455
WP Easy Gallery
- Plugin:
- WP Easy Gallery
- Plugin Slug:
- wp-easy-gallery
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9018
XO Slider
- Plugin:
- XO Slider
- Plugin Slug:
- xo-liteslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8324
LiteSpeed Cache
- Plugin:
- LiteSpeed Cache
- Plugin Slug:
- litespeed-cache
- Installations
- 6,000,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-47637
LiteSpeed Cache
- Plugin:
- LiteSpeed Cache
- Plugin Slug:
- litespeed-cache
- Installations
- 6,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- Medium
- CVE:
- 2024-47373
LiteSpeed Cache
- Plugin:
- LiteSpeed Cache
- Plugin Slug:
- litespeed-cache
- Installations
- 6,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-47374
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
- Plugin Slug:
- seo-by-rank-math
- Installations
- 3,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.229
- Severity Score:
- Medium
- CVE:
- 2024-9161
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
- Plugin Slug:
- seo-by-rank-math
- Installations
- 3,000,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.0.229
- Severity Score:
- High
- CVE:
- 2024-9314
Advanced Custom Fields (ACF)
- Plugin:
- Advanced Custom Fields (ACF)
- Plugin Slug:
- advanced-custom-fields
- Installations
- 2,000,000+
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 6.3.6.1
- Severity Score:
- Medium
- CVE:
- 2024-9529
Advanced Custom Fields (ACF)
- Plugin:
- Advanced Custom Fields (ACF)
- Plugin Slug:
- advanced-custom-fields
- Installations
- 2,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20866
Advanced Custom Fields (ACF)
- Plugin:
- Advanced Custom Fields (ACF)
- Plugin Slug:
- advanced-custom-fields
- Installations
- 2,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20865
Advanced Custom Fields (ACF)
- Plugin:
- Advanced Custom Fields (ACF)
- Plugin Slug:
- advanced-custom-fields
- Installations
- 2,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20867
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
- Plugin:
- Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder
- Plugin Slug:
- popup-maker
- Installations
- 700,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.20.0
- Severity Score:
- Medium
- CVE:
- 2024-47358
Broken Link Checker
- Plugin:
- Broken Link Checker
- Plugin Slug:
- broken-link-checker
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.1
- Severity Score:
- High
- CVE:
- 2024-8981
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Plugin Slug:
- fluentform
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.20
- Severity Score:
- Medium
- CVE:
- 2024-9528
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.12.1
- Severity Score:
- Medium
- CVE:
- 2024-47357
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.987
- Severity Score:
- Medium
- CVE:
- 2024-8482
Checkout Field Editor (Checkout Manager) for WooCommerce
- Plugin Slug:
- woo-checkout-field-editor-pro
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.4
- Severity Score:
- High
- CVE:
- 2024-8499
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.122
- Severity Score:
- High
- CVE:
- 2024-45454
SEOPress – On-site SEO
- Plugin:
- SEOPress – On-site SEO
- Plugin Slug:
- wp-seopress
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.2
- Severity Score:
- High
- CVE:
- 2024-9225
Jeg Elementor Kit
- Plugin:
- Jeg Elementor Kit
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.9
- Severity Score:
- Medium
- CVE:
- 2024-47390
TinyPNG – JPEG, PNG & WebP image compression
- Plugin Slug:
- tiny-compress-images
- Installations
- 200,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.4.4
- Severity Score:
- Medium
- CVE:
- 2024-47635
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.8.7
- Severity Score:
- Medium
- CVE:
- 2024-8520
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.7
- Severity Score:
- Medium
- CVE:
- 2024-8519
Smart Custom 404 Error Page
- Plugin:
- Smart Custom 404 Error Page
- Plugin Slug:
- 404page
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 11.4.8
- Severity Score:
- High
- CVE:
- 2024-9204
Elementor Addon Elements
- Plugin:
- Elementor Addon Elements
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.7
- Severity Score:
- Medium
- CVE:
- 2024-47366
Elementor Addon Elements
- Plugin:
- Elementor Addon Elements
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.13.7
- Severity Score:
- Medium
- CVE:
- 2024-47361
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.16.4
- Severity Score:
- Medium
- CVE:
- 2024-8486
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.7.6
- Severity Score:
- Medium
- CVE:
- 2024-47392
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel
- Plugin Slug:
- depicter
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.0
- Severity Score:
- Medium
- CVE:
- 2024-47381
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel
- Plugin Slug:
- depicter
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.0
- Severity Score:
- Medium
- CVE:
- 2024-47359
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
- Plugin Slug:
- essential-blocks
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.0
- Severity Score:
- Medium
- CVE:
- 2024-47385
Strong Testimonials
- Plugin:
- Strong Testimonials
- Plugin Slug:
- strong-testimonials
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.1.17
- Severity Score:
- Medium
- CVE:
- 2024-47362
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
- Plugin Slug:
- the-post-grid
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3635
WooCommerce Multilingual & Multicurrency with WPML
- Plugin Slug:
- woocommerce-multilingual
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.8
- Severity Score:
- High
- CVE:
- 2024-8629
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce
- Plugin Slug:
- email-subscribers
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.7.35
- Severity Score:
- Medium
- CVE:
- 2024-8254
WP Bulk Delete
- Plugin:
- WP Bulk Delete
- Plugin Slug:
- wp-bulk-delete
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.2
- Severity Score:
- High
- CVE:
- 2024-47352
WordPress Infinite Scroll – Ajax Load More
- Plugin Slug:
- ajax-load-more
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.1.3
- Severity Score:
- Medium
- CVE:
- 2024-8505
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.1
- Severity Score:
- Medium
- CVE:
- 2024-47391
WP Booking Calendar
- Plugin:
- WP Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.1
- Severity Score:
- Medium
- CVE:
- 2024-9306
Photo Gallery, Images, Slider in Rbs Image Gallery
- Plugin Slug:
- robo-gallery
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.22
- Severity Score:
- Medium
- CVE:
- 2024-8431
Ultimate Blocks – WordPress Blocks Plugin
- Plugin Slug:
- ultimate-blocks
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.2
- Severity Score:
- Medium
- CVE:
- 2024-8536
Visual CSS Style Editor
- Plugin:
- Visual CSS Style Editor
- Plugin Slug:
- yellow-pencil-visual-theme-customizer
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6.5
- Severity Score:
- High
- CVE:
- 2024-47348
DethemeKit For Elementor
- Plugin:
- DethemeKit For Elementor
- Plugin Slug:
- dethemekit-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.8
- Severity Score:
- Medium
- CVE:
- 2024-47632
Page-list
- Plugin:
- Page-list
- Plugin Slug:
- page-list
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.7
- Severity Score:
- Medium
- CVE:
- 2024-47382
Starbox – the Author Box for Humans
- Plugin Slug:
- starbox
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.3
- Severity Score:
- Medium
- CVE:
- 2024-8239
YITH WooCommerce Ajax Search
- Plugin:
- YITH WooCommerce Ajax Search
- Plugin Slug:
- yith-woocommerce-ajax-search
- Installations
- 40,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.8.1
- Severity Score:
- Critical
- CVE:
- 2024-47350
Cost Calculator Builder
- Plugin:
- Cost Calculator Builder
- Plugin Slug:
- cost-calculator-builder
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.2.29
- Severity Score:
- High
- CVE:
- 2024-8379
Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress
- Plugin Slug:
- file-manager
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 6.5.8
- Severity Score:
- Medium
- CVE:
- 2024-8743
Ibtana – WordPress Website Builder
- Plugin Slug:
- ibtana-visual-editor
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.4.5
- Severity Score:
- Medium
- CVE:
- 2024-8282
RomethemeKit For Elementor
- Plugin:
- RomethemeKit For Elementor
- Plugin Slug:
- rometheme-for-elementor
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2024-47626
Code Embed
- Plugin:
- Code Embed
- Plugin Slug:
- simple-embed-code
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5
- Severity Score:
- Medium
- CVE:
- 2024-8804
Simple Membership After Login Redirection
- Plugin Slug:
- simple-membership-after-login-redirection
- Installations
- 20,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 1.7
- Severity Score:
- Medium
- CVE:
- 2024-47354
Slider by 10Web – Responsive Image Slider
- Plugin Slug:
- slider-wd
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.59
- Severity Score:
- Medium
- CVE:
- 2024-8283
Advanced Woo Labels – Product Labels for WooCommerce
- Plugin Slug:
- advanced-woo-labels
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.02
- Severity Score:
- Medium
- CVE:
- 2024-47622
Auto Amazon Links – Amazon Associates Affiliate Plugin
- Plugin Slug:
- amazon-auto-links
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.4.3
- Severity Score:
- High
- CVE:
- 2024-9349
BA Book Everything
- Plugin:
- BA Book Everything
- Plugin Slug:
- ba-book-everything
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.21
- Severity Score:
- High
- CVE:
- 2024-47360
Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed
- Plugin Slug:
- blockspare
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.5
- Severity Score:
- Medium
- CVE:
- 2024-47363
Demo Importer Plus
- Plugin:
- Demo Importer Plus
- Plugin Slug:
- demo-importer-plus
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.2
- Severity Score:
- Medium
- CVE:
- 2024-9172
Gallery Lightbox
- Plugin:
- Gallery Lightbox
- Plugin Slug:
- gallery-lightbox-slider
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.0.41
- Severity Score:
- Medium
- CVE:
- 2024-47623
FAQ / Accordion / Docs – Helpie WordPress FAQ Accordion plugin
- Plugin Slug:
- helpie-faq
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.28
- Severity Score:
- Medium
- CVE:
- 2024-47647
LA-Studio Element Kit for Elementor
- Plugin Slug:
- lastudio-element-kit
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.9.7
- Severity Score:
- Medium
- CVE:
- 2024-47628
MC4WP: Mailchimp Top Bar
- Plugin:
- MC4WP: Mailchimp Top Bar
- Plugin Slug:
- mailchimp-top-bar
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.1
- Severity Score:
- High
- CVE:
- 2024-9210
NEX-Forms – Ultimate Form Builder – Contact forms and much more
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.7.4
- Severity Score:
- High
- CVE:
- 2024-47389
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.12.9
- Severity Score:
- High
- CVE:
- 2024-9222
Popularis Extra
- Plugin:
- Popularis Extra
- Plugin Slug:
- popularis-extra
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.7
- Severity Score:
- High
- CVE:
- 2024-9353
CartBounty – Save and recover abandoned carts for WooCommerce
- Plugin Slug:
- woo-save-abandoned-carts
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 8.2.1
- Severity Score:
- Medium
- CVE:
- 2024-47634
YITH WooCommerce Product Add-Ons
- Plugin:
- YITH WooCommerce Product Add-Ons
- Plugin Slug:
- yith-woocommerce-product-add-ons
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.13.1
- Severity Score:
- High
- CVE:
- 2024-47367
YML for Yandex Market
- Plugin:
- YML for Yandex Market
- Plugin Slug:
- yml-for-yandex-market
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.3
- Severity Score:
- High
- CVE:
- 2024-9378
Form plugin for WordPress – Zoho Forms
- Plugin Slug:
- zoho-forms
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.1
- Severity Score:
- Medium
- CVE:
- 2024-47633
MaxSlider
- Plugin:
- MaxSlider
- Plugin Slug:
- maxslider
- Installations
- 9,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.4
- Severity Score:
- High
- CVE:
- 2024-47351
Affiliate Program Suite — SliceWP Affiliates
- Plugin Slug:
- slicewp
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.19
- Severity Score:
- High
- CVE:
- 2024-47388
Slideshow Gallery LITE
- Plugin:
- Slideshow Gallery LITE
- Plugin Slug:
- slideshow-gallery
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.4
- Severity Score:
- Medium
- CVE:
- 2024-47376
WP Hotel Booking
- Plugin:
- WP Hotel Booking
- Plugin Slug:
- wp-hotel-booking
- Installations
- 8,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.1.3
- Severity Score:
- Critical
- CVE:
- 2024-7855
Themify Builder
- Plugin:
- Themify Builder
- Plugin Slug:
- themify-builder
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6.3
- Severity Score:
- High
- CVE:
- 2024-9385
WP Compress – Instant Performance & Speed Optimization
- Plugin Slug:
- wp-compress-image-optimizer
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.21.01
- Severity Score:
- High
- CVE:
- 2024-47384
Author Avatars List/Block
- Plugin:
- Author Avatars List/Block
- Plugin Slug:
- author-avatars
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.22
- Severity Score:
- Medium
- CVE:
- 2024-47370
Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library
- Plugin Slug:
- cozy-addons
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.12
- Severity Score:
- Medium
- CVE:
- 2024-47355
Survey Maker
- Plugin:
- Survey Maker
- Plugin Slug:
- survey-maker
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.6
- Severity Score:
- Medium
- CVE:
- 2024-8488
ElementsReady Addons for Elementor
- Plugin Slug:
- element-ready-lite
- Installations
- 5,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 6.4.3
- Severity Score:
- Medium
- CVE:
- 2024-47353
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.8
- Severity Score:
- Medium
- CVE:
- 2024-47630
Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid
- Plugin Slug:
- magazine-blocks
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.15
- Severity Score:
- High
- CVE:
- 2024-9218
Easy Mega Menu Plugin for WordPress – ThemeHunk
- Plugin Slug:
- themehunk-megamenu-plus
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-8433
WPMobile.App — Android and iOS Mobile Application
- Plugin Slug:
- wpappninja
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 11.51
- Severity Score:
- High
- CVE:
- 2024-47349
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 4,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 4.0.4.6
- Severity Score:
- Medium
- CVE:
- 2024-47648
Geo Mashup
- Plugin:
- Geo Mashup
- Plugin Slug:
- geo-mashup
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.14
- Severity Score:
- Medium
- CVE:
- 2024-8990
Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress
- Plugin Slug:
- quillforms
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.0
- Severity Score:
- Medium
- CVE:
- 2024-47393
RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more
- Plugin Slug:
- rabbit-loader
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.21.1
- Severity Score:
- High
- CVE:
- 2024-8800
AVIF Uploader
- Plugin:
- AVIF Uploader
- Plugin Slug:
- avif-support
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
- 2024-9060
Move Addons for Elementor
- Plugin:
- Move Addons for Elementor
- Plugin Slug:
- move-addons
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-47364
Robokassa payment gateway for Woocommerce
- Plugin Slug:
- robokassa
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.2
- Severity Score:
- High
- CVE:
- 2024-47395
WP-Lister Lite for eBay
- Plugin:
- WP-Lister Lite for eBay
- Plugin Slug:
- wp-lister-for-ebay
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.5
- Severity Score:
- High
- CVE:
- 2024-47380
Automatically Hierarchic Categories in Menu
- Plugin Slug:
- automatically-hierarchic-categories-in-menu
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.6
- Severity Score:
- Medium
- CVE:
- 2024-47365
BSK Forms Blacklist
- Plugin:
- BSK Forms Blacklist
- Plugin Slug:
- bsk-gravityforms-blacklist
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9
- Severity Score:
- High
- CVE:
- 2024-47624
Hash Form – Drag & Drop Form Builder
- Plugin Slug:
- hash-form
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
- 2024-9417
PWA — easy way to Progressive Web App
- Plugin Slug:
- iworks-pwa
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.4
- Severity Score:
- Medium
- CVE:
- 2024-8967
Premium Blocks – Gutenberg Blocks for WordPress
- Plugin Slug:
- premium-blocks-for-gutenberg
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.34
- Severity Score:
- Medium
- CVE:
- 2024-47368
Search Analytics for WP
- Plugin:
- Search Analytics for WP
- Plugin Slug:
- search-analytics
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.11
- Severity Score:
- High
- CVE:
- 2024-9209
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials
- Plugin:
- Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials
- Plugin Slug:
- stars-testimonials-with-slider-and-masonry-grid
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.2
- Severity Score:
- Medium
- CVE:
- 2024-8989
The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)
- Plugin Slug:
- the-pack-addon
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
- CVE:
- 2024-47383
WP-WebAuthn
- Plugin:
- WP-WebAuthn
- Plugin Slug:
- wp-webauthn
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2024-47650
WPCOM Member
- Plugin:
- WPCOM Member
- Plugin Slug:
- wpcom-member
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.4.1
- Severity Score:
- High
- CVE:
- 2024-47378
XLTab – Accordions and Tabs for Elementor Page Builder
- Plugin Slug:
- xl-tab
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4
- Severity Score:
- Medium
- CVE:
- 2024-47375
Zotpress
- Plugin:
- Zotpress
- Plugin Slug:
- zotpress
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.3.11
- Severity Score:
- Medium
- CVE:
- 2024-47621
Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)
- Plugin Slug:
- buddyforms
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.13
- Severity Score:
- Medium
- CVE:
- 2024-47377
Enter Addons – Ultimate Template Builder for Elementor
- Plugin Slug:
- enteraddons
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.9
- Severity Score:
- Medium
- CVE:
- 2024-47625
Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate
- Plugin Slug:
- fish-and-ships
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2024-9237
Memberful – Membership Plugin
- Plugin:
- Memberful – Membership Plugin
- Plugin Slug:
- memberful-wp
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.73.8
- Severity Score:
- Medium
- CVE:
- 2024-9242
Search Atlas SEO – Best SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
- Plugin Slug:
- metasync
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.3
- Severity Score:
- Medium
- CVE:
- 2024-47387
TNC PDF viewer
- Plugin:
- TNC PDF viewer
- Plugin Slug:
- pdf-viewer-by-themencode
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
- 2024-47372
Product Delivery Date for WooCommerce – Lite
- Plugin Slug:
- product-delivery-date-for-woocommerce-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.4
- Severity Score:
- High
- CVE:
- 2024-9345
Logo Carousel – Clients logo carousel for WP
- Plugin Slug:
- responsive-client-logo-carousel-slider
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2024-47631
BerqWP – Automated All-In-One PageSpeed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
- Plugin Slug:
- searchpro
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.2
- Severity Score:
- High
- CVE:
- 2024-9344
Image Optimizer, Resizer and CDN – Sirv
- Plugin Slug:
- sirv
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.3.0
- Severity Score:
- Medium
- CVE:
- 2024-8964
Social Web Suite – Social Media Auto Post, Social Media Auto Publish
- Plugin Slug:
- social-web-suite
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 4.1.12
- Severity Score:
- High
- CVE:
- 2024-8352
Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider
- Plugin Slug:
- ultimate-store-kit
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.6
- Severity Score:
- Medium
- CVE:
- 2024-47629
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce
- Plugin Slug:
- wholesale-pricing-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.1
- Severity Score:
- High
- CVE:
- 2024-9384
WP MyLinks
- Plugin:
- WP MyLinks
- Plugin Slug:
- wp-mylinks
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2024-47371
WP Travel Gutenberg Blocks
- Plugin:
- WP Travel Gutenberg Blocks
- Plugin Slug:
- wp-travel-blocks
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.0
- Severity Score:
- Medium
- CVE:
- 2024-47627
The Ultimate WordPress Toolkit – WP Extended
- Plugin Slug:
- wpextended
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.9
- Severity Score:
- High
- CVE:
- 2024-47386
ShiftController Employee Shift Scheduling
- Plugin Slug:
- shiftcontroller
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.67
- Severity Score:
- High
- CVE:
- 2024-9435
QS Dark Mode Plugin
- Plugin:
- QS Dark Mode Plugin
- Plugin Slug:
- qs-dark-mode
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0
- Severity Score:
- Medium
- CVE:
- 2024-9118
Web Directory Free
- Plugin:
- Web Directory Free
- Plugin Slug:
- web-directory-free
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.4
- Severity Score:
- High
- CVE:
- 2024-47379
Limit Login Attempts (Spam Protection)
- Plugin Slug:
- wp-limit-failed-login-attempts
- Installations
- 200+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 5.4
- Severity Score:
- Medium
- CVE:
- 2022-4534
Top Bar – PopUps – by WPOptin
- Plugin:
- Top Bar – PopUps – by WPOptin
- Plugin Slug:
- wpoptin
- Installations
- 90+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.0.2
- Severity Score:
- High
- CVE:
- 2024-47645
Easy Demo Importer – A Modern One-Click Demo Import Solution
- Plugin Slug:
- easy-demo-importer
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.3
- Severity Score:
- Medium
- CVE:
- 2024-9071
Advanced Custom Fields PRO
- Plugin:
- Advanced Custom Fields PRO
- Plugin Slug:
- advanced-custom-fields-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20866
Advanced Custom Fields PRO
- Plugin:
- Advanced Custom Fields PRO
- Plugin Slug:
- advanced-custom-fields-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20865
Advanced Custom Fields PRO
- Plugin:
- Advanced Custom Fields PRO
- Plugin Slug:
- advanced-custom-fields-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.11
- Severity Score:
- Medium
- CVE:
- 2021-20867
LatePoint
- Plugin:
- LatePoint
- Plugin Slug:
- latepoint
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 5.0.13
- Severity Score:
- Critical
- CVE:
- 2024-8943
LatePoint
- Plugin:
- LatePoint
- Plugin Slug:
- latepoint
- Vulnerability:
- SQL Injection
- Patched in Version:
- 5.0.12
- Severity Score:
- Critical
- CVE:
- 2024-8911
Slider Revolution
- Plugin:
- Slider Revolution
- Plugin Slug:
- revslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.7.19
- Severity Score:
- Medium
- CVE:
- 2024-8107
Re:WP
Echo RSS Feed Post Generator Plugin for WordPress
- Plugin:
- Echo RSS Feed Post Generator Plugin for WordPress
- Plugin Slug:
- rss-feed-post-generator-echo
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 5.4.7
- Severity Score:
- Critical
- CVE:
- 2024-9265
Social Auto Poster
- Plugin:
- Social Auto Poster
- Plugin Slug:
- social-auto-poster
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.16
- Severity Score:
- High
- CVE:
- 2024-47369
JobSearch
- Plugin:
- JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.6.1
- Severity Score:
- Critical
- CVE:
- 2024-47636
JobSearch
- Plugin:
- JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.1
- Severity Score:
- High
- CVE:
- 2024-47394
Affiliate Pro – Affiliate Program for WooCommerce & WordPress
- Plugin:
- Affiliate Pro – Affiliate Program for WooCommerce & WordPress
- Plugin Slug:
- wp-wc-affiliate-program
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 8.5.0
- Severity Score:
- Critical
- CVE:
- 2024-9289
WordPress Themes — 2 Patched / 3 Unpatched
Empowerment
- Theme:
- Empowerment
- Theme Slug:
- empowerment
- Downloads
- 3,400
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-7433
UltraPress
- Theme:
- UltraPress
- Theme Slug:
- ultrapress
- Downloads
- 15,922
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-7434
Unseen Blog
- Theme:
- Unseen Blog
- Theme Slug:
- unseen-blog
- Downloads
- 2,338
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-7432
Create
- Theme:
- Create
- Theme Slug:
- create
- Downloads
- 64,027
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
- 2024-47356
Full Frame
- Theme:
- Full Frame
- Theme Slug:
- full-frame
- Downloads
- 199,864
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.3
- Severity Score:
- Medium
- CVE:
- 2024-44010
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
