WordPress Vulnerability Report

WordPress Vulnerability Report — September 4, 2024

Since last week, 167 new vulnerabilities emerged in the WordPress ecosystem including 143 plugins and 24 themes. 69 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 167 vulnerabilities have been publicly disclosed. Security patches for 98 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 69 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 92 Patched / 51 Unpatched

Plugin Slug:
yet-another-related-posts-plugin
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium SEO Pack – WP SEO Plugin

Plugin Slug:
premium-seo-pack
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Like Button Rating ? LikeBtn

Plugin Slug:
likebtn-like-button
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Maintenance & Coming Soon Redirect Animation

Plugin Slug:
maintenance-coming-soon-redirect-animation
Installations
5,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

EU/UK VAT Manager for WooCommerce

Plugin Slug:
eu-vat-for-woocommerce
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Testimonials

Plugin Slug:
super-testimonial
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Classic Addons – WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Query Blocks

Plugin Slug:
post-type-archive-mapping
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendGrid for WordPress

Plugin Slug:
wp-sendgrid-mailer
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Animated Number Counters

Plugin:
Animated Number Counters
Plugin Slug:
animated-number-counters
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

azurecurve Toggle Show/Hide

Plugin:
azurecurve Toggle Show/Hide
Plugin Slug:
azurecurve-toggle-showhide
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog Introduction

Plugin:
Blog Introduction
Plugin Slug:
blogintroduction-wordpress-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brickscore

Plugin:
Brickscore
Plugin Slug:
brickscore
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DN Popup

Plugin:
DN Popup
Plugin Slug:
dn-popup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Enhanced Search Box
Plugin Slug:
extended-search-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GHActivity

Plugin:
GHActivity
Plugin Slug:
ghactivity
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gixaw Chat

Plugin:
Gixaw Chat
Plugin Slug:
gixaw-chat
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ILC Thickbox

Plugin:
ILC Thickbox
Plugin Slug:
ilc-thickbox
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
infolinks Ad Wrap
Plugin Slug:
infolinks-ad-wrap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Justified Image Grid

Plugin:
Justified Image Grid
Plugin Slug:
justified-image-grid
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LatePoint

Plugin:
LatePoint
Plugin Slug:
latepoint
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin:
LWS Affiliation
Plugin Slug:
lws-affiliation
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Memberpress

Plugin:
Memberpress
Plugin Slug:
memberpress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Paypal

Plugin:
Misiek Paypal
Plugin Slug:
misiek-paypal
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:
Misiek Photo Album
Plugin Slug:
misiek-photo-album
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:
Misiek Photo Album
Plugin Slug:
misiek-photo-album
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:
Music Request Manager
Plugin Slug:
music-request-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Propovoice Pro

Plugin:
Propovoice Pro
Plugin Slug:
propovoice-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Review Ratings

Plugin:
Review Ratings
Plugin Slug:
ratings-shorttags
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Headline Rotator

Plugin:
Simple Headline Rotator
Plugin Slug:
simple-headline-rotator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Special Feed Items

Plugin:
Special Feed Items
Plugin Slug:
special-feed-items
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Vikinghammer Tweet

Plugin:
Vikinghammer Tweet
Plugin Slug:
vikinghammer-tweet
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Viral Signup

Plugin:
Viral Signup
Plugin Slug:
viral-signup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Visual Sound (old)

Plugin:
Visual Sound (old)
Plugin Slug:
visual-sound-widget-for-soundcloud-and-artistplugme-visualdreams
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:
WP Testimonial Widget
Plugin Slug:
wp-testimonial-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:
WP Testimonial Widget
Plugin Slug:
wp-testimonial-widget
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:
Z Y N I T H
Plugin Slug:
zynith-seo
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:
Z Y N I T H
Plugin Slug:
zynith-seo
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Forms – The Contact Form Builder That Grows With You

Plugin Slug:
ninja-forms
Installations
800,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.11.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.13.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.985
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.985.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
responsive-lightbox
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.6.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.3.4.

Email Address Encoder

Plugin Slug:
email-address-encoder
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.24.

EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

Plugin Slug:
embedpress
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.9.
Plugin Slug:
envira-gallery-lite
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.15.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.16.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.16.0.

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce
Installations
100,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
7.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.0.

Ninja Tables – Easiest Data Table Builder

Plugin Slug:
ninja-tables
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.13.
Plugin Slug:
permalink-manager
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.1.

Theme Editor

Plugin Slug:
theme-editor
Installations
60,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.

WP Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.5.1.

Visual CSS Style Editor

Plugin Slug:
yellow-pencil-visual-theme-customizer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.4.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Events Manager

Plugin Slug:
wp-events-manager
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.0.

WPZOOM Portfolio Lite – Filterable Portfolio Plugin

Plugin Slug:
wpzoom-portfolio
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.5.

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.4.

Generate Images – Magic Post Thumbnail

Plugin Slug:
magic-post-thumbnail
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.10.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.4.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
8.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.3.

WP Accessibility Helper (WAH)

Plugin Slug:
wp-accessibility-helper
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.2.9.

Clean Login

Plugin Slug:
clean-login
Installations
8,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.14.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.14.6.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.14
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.14.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.14.

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.49
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.49.
Plugin Slug:
relevanssi-live-ajax-search
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations
4,000+
Vulnerability:
Settings Change
Patched in Version:
2.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.11.

Collapsing Archives

Plugin Slug:
collapsing-archives
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.6.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.29.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.29.1.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
4.9.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.13.

Share This Image

Plugin Slug:
share-this-image
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.02
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.02.

Front End Users

Plugin Slug:
front-end-only-users
Installations
700+
Vulnerability:
SQL Injection
Patched in Version:
3.2.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.29.

Front End Users

Plugin Slug:
front-end-only-users
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.29.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
600+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.3.

Favicon Generator (CLOSED)

Plugin Slug:
favicon-generator
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.

Login As Users

Plugin Slug:
login-as-users
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Web Application Firewall – website security

Plugin Slug:
web-application-firewall
Installations
300+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Two-factor authentication (formerly IP Vault)

Plugin Slug:
ip-vault-wp-firewall
Installations
20+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Local File Inclusion
Patched in Version:
3.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.8.

The Events Calendar PRO

Plugin:
The Events Calendar PRO
Plugin Slug:
events-calendar-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
7.0.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.2.1.

Funnel Kit Funnel Builder PRO

Plugin:
Funnel Kit Funnel Builder PRO
Plugin Slug:
funnel-builder-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.0.

Greenshift Query and Meta Addon

Plugin:
Greenshift Query and Meta Addon
Plugin Slug:
greenshiftquery
Vulnerability:
SQL Injection
Patched in Version:
3.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.2.

Greenshift Woocommerce Addon

Plugin:
Greenshift Woocommerce Addon
Plugin Slug:
greenshiftwoo
Vulnerability:
SQL Injection
Patched in Version:
1.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.8.

Memberpress

Plugin:
Memberpress
Plugin Slug:
memberpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.11.30.

Newspack

Plugin:
Newspack
Plugin Slug:
newspack-plugin
Vulnerability:
Broken Access Control
Patched in Version:
3.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.7.

Oxygen Builder

Plugin:
Oxygen Builder
Plugin Slug:
oxygenbuilder
Vulnerability:
Broken Access Control
Patched in Version:
4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
SQL Injection
Patched in Version:
6.9.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.9.8.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
SQL Injection
Patched in Version:
6.9.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.9.8.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.9.8.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.3.

WP Armour Extended

Plugin:
WP Armour Extended
Plugin Slug:
wp-armour-extended
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.32.

WP Armour Extended

Plugin:
WP Armour Extended
Plugin Slug:
wp-armour-extended
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.32.

WP Cerber Security

Plugin:
WP Cerber Security
Plugin Slug:
wp-cerber
Vulnerability:
Bypass Vulnerability
Patched in Version:
9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.5.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
PHP Object Injection
Patched in Version:
2.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Access Control
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

WordPress Themes — 6 Patched / 18 Unpatched

Esotera

Theme:
Esotera
Theme Slug:
esotera
Downloads
59,473
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Fluida

Theme:
Fluida
Theme Slug:
fluida
Downloads
486,615
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hotel Galaxy

Theme Slug:
hotel-galaxy
Downloads
247,851
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

IntoTheDark

Theme Slug:
intothedark
Downloads
2,035
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kahuna

Theme:
Kahuna
Theme Slug:
kahuna
Downloads
170,236
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Liquido

Theme:
Liquido
Theme Slug:
liquido
Downloads
32,519
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Mantra

Theme:
Mantra
Theme Slug:
mantra
Downloads
1,152,946
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Mystique

Theme:
Mystique
Theme Slug:
mystique
Downloads
705,708
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Nirvana

Theme:
Nirvana
Theme Slug:
nirvana
Downloads
752,479
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Parabola

Theme:
Parabola
Theme Slug:
parabola
Downloads
635,288
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Posterity

Theme Slug:
posterity
Downloads
96,548
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Sliding Door

Theme Slug:
sliding-door
Downloads
537,528
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Tempera

Theme:
Tempera
Theme Slug:
tempera
Downloads
703,523
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Enfold

Theme:
Enfold
Theme Slug:
enfold
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Filmix

Theme:
Filmix
Theme Slug:
filmix
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Opor Ayam

Theme:
Opor Ayam
Theme Slug:
opor-ayam
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Attire

Theme:
Attire
Theme Slug:
attire
Downloads
72,378
Vulnerability:
PHP Object Injection
Patched in Version:
2.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.7.

Blockbooster

Theme Slug:
blockbooster
Downloads
8,463
Vulnerability:
Broken Access Control
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Blogpoet

Theme:
Blogpoet
Theme Slug:
blogpoet
Downloads
4,865
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

FotaWP

Theme:
FotaWP
Theme Slug:
fotawp
Downloads
146,783
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

ReviveNews

Theme Slug:
revivenews
Downloads
7,963
Vulnerability:
Broken Access Control
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Masterstudy LMS Starter

Theme:
Masterstudy LMS Starter
Theme Slug:
ms-lms-starter-theme
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security