WordPress Vulnerability Report

WordPress Vulnerability Report — September 25, 2024

Since last week, 72 new vulnerabilities emerged in the WordPress ecosystem including 66 plugins and 6 themes. 24 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 72 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 24 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.2 is available! This minor release includes 15 bug fixes in Core and 11 in the Block Editor, addressing issues like unexpected CSS specificity changes in certain themes.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 20 Unpatched

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WCFM Marketplace – Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IMPress for IDX Broker

Plugin Slug:
idx-broker-platinum
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woo-product-carousel-slider-and-grid-ultimate
Installations
9,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spice Starter Sites

Plugin Slug:
spice-starter-sites
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks – Unlimited blocks For Gutenberg

Plugin Slug:
unlimited-blocks
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Team Showcase

Plugin Slug:
team
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Accordion Image Menu

Plugin:
Accordion Image Menu
Plugin Slug:
accordion-image-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Thanh Toán Quét Mã QR Code T? ??ng

Plugin:
Thanh Toán Quét Mã QR Code T? ??ng
Plugin Slug:
bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:
Kodex Posts likes
Plugin Slug:
kodex-posts-likes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Limit Login Attempts Plus

Plugin:
Limit Login Attempts Plus
Plugin Slug:
limit-login-attempts-plus
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Logo Manager For Enamad

Plugin:
Logo Manager For Enamad
Plugin Slug:
logo-manager-for-enamad
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Posts reminder

Plugin:
Posts reminder
Plugin Slug:
posts-reminder
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Multiple Free Gift

Plugin:
WooCommerce Multiple Free Gift
Plugin Slug:
woocommerce-multiple-free-gift
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Category Dropdown

Plugin:
WP Category Dropdown
Plugin Slug:
wp-category-dropdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Custom Fields Search
Plugin Slug:
wp-custom-fields-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Easy Gallery
Plugin Slug:
wp-easy-gallery
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Easy Gallery
Plugin Slug:
wp-easy-gallery
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.17.

W3 Total Cache

Plugin Slug:
w3-total-cache
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.6
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.7.6.

Backuply – Backup, Restore, Migrate and Clone

Plugin Slug:
backuply
Installations
200,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.28.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.7.

FOX – Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.2.

Pixel Cat – Conversion Pixel Manager

Plugin Slug:
facebook-conversion-pixel
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.6.

Koko Analytics

Plugin Slug:
koko-analytics
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.13.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.3.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.4.

Themify – WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

WP Hardening (discontinued)

Plugin Slug:
wp-security-hardening
Installations
20,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.21.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.21.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Maintenance Redirect

Plugin Slug:
jf3-maintenance-mode
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.1.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.1.0.

WP Booking System – Booking Calendar

Plugin Slug:
wp-booking-system
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.19.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.19.9.

WP Datepicker

Plugin Slug:
wp-datepicker
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Affiliate Program Suite — SliceWP Affiliates

Plugin Slug:
slicewp
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.21.

Seriously Simple Stats

Plugin Slug:
seriously-simple-stats
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.0.

Garden Gnome Package

Plugin Slug:
garden-gnome-package
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Geo Mashup

Plugin:
Geo Mashup
Plugin Slug:
geo-mashup
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.13.

Waitlist Woocommerce ( Back in stock notifier )

Plugin Slug:
waitlist-woocommerce
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.6.

PropertyHive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.20.

Simple Spoiler

Plugin Slug:
simple-spoiler
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.16.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.16.8.

IdeaPush

Plugin:
IdeaPush
Plugin Slug:
ideapush
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.69
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.69.

Login with phone number

Plugin Slug:
login-with-phone-number
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.7.50
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.50.

Share This Image

Plugin Slug:
share-this-image
Installations
1,000+
Vulnerability:
Open Redirection
Patched in Version:
2.04
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.04.

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.65
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.65.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.4.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.4.

XT Ajax Add To Cart for WooCommerce

Plugin Slug:
xt-woo-ajax-add-to-cart
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

Webo-facto

Plugin:
Webo-facto
Plugin Slug:
webo-facto-connector
Installations
900+
Vulnerability:
Privilege Escalation
Patched in Version:
1.41
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.41.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.0.

Houzez Login Register

Plugin:
Houzez Login Register
Plugin Slug:
houzez-login-register
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.0.

WooEvents

Plugin:
WooEvents
Plugin Slug:
woo-events
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.3.

WordPress Themes — 2 Patched / 4 Unpatched

Blogvi

Theme:
Blogvi
Theme Slug:
blogvi
Downloads
25,426
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Roseta

Theme:
Roseta
Theme Slug:
roseta
Downloads
97,031
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Septera

Theme:
Septera
Theme Slug:
septera
Downloads
126,076
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Verbosa

Theme:
Verbosa
Theme Slug:
verbosa
Downloads
108,792
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Bricks Builder

Theme:
Bricks Builder
Theme Slug:
bricks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.2.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security