WordPress Vulnerability Report � January 24, 2024

In this report, 88 new vulnerabilities have been publicly disclosed. Security patches for 29 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 59 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Free Online Training Event! TODAY! Register Now!

TODAY! January 24, 2024 @ 1:00 PM – 2:00 PM (CST)

Not all WordPress threats and vulnerabilities are �created equal.� Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.

This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.

Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

WordPress Plugins � 28 Patched / 59 Unpatched

Ninja Tables � Best Data Table Plugin for WordPress

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer & 3D PDF Flipbook � DearPDF

Plugin Slug:
dearpdf-lite

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Browser Theme Color

Plugin Slug:
browser-theme-color

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FreshMail For WordPress

Plugin Slug:
freshmail-integration

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Albo Pretorio On line

Plugin Slug:
albo-pretorio-on-line

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Albo Pretorio On line

Plugin Slug:
albo-pretorio-on-line

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BA Plus

Plugin:

BA Plus

Plugin Slug:
ba-plus-before-after-image-slider-free

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Better Anchor Links

Plugin Slug:
better-anchor-links

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CformsII

Plugin:

CformsII

Plugin Slug:
cforms2

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Dashboard Widgets

Plugin:

Custom Dashboard Widgets

Plugin Slug:
custom-dashboard-widgets

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Delhivery Logistics Courier

Plugin:

Delhivery Logistics Courier

Plugin Slug:
delhivery-logistics-courier

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Frontpage Manager

Plugin:

Frontpage Manager

Plugin Slug:
frontpage-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Tag Manager

Plugin:

Image Tag Manager

Plugin Slug:
image-tag-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

lasTunes

Plugin:

lasTunes

Plugin Slug:
lastunes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post views Stats

Plugin:

Post views Stats

Plugin Slug:
post-views-stats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SimpleMap Store Locator

Plugin:

SimpleMap Store Locator

Plugin Slug:
simplemap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Splashscreen

Plugin:

Splashscreen

Plugin Slug:
splashscreen

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Addons for WPBakery Page Builder

Plugin:

Unlimited Addons for WPBakery Page Builder

Plugin Slug:
unlimited-addons-for-wpbakery-page-builder

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Smart Editor

Plugin:

WP Smart Editor

Plugin Slug:
wp-smart-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.2.5.

Migration, Backup, Staging � WPvivid

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.9.95

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.95.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.6.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.28.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.

Product Import Export for WooCommerce

Plugin Slug:
product-import-export-for-woo

Installations
90,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.8.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.24.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.24.7.

VK Block Patterns

Plugin Slug:
vk-block-patterns

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.31.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.2.0.
Plugin Slug:
advanced-woo-search

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.97

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.97.

Booking for Appointments and Events Calendar � Amelia

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.94

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.94.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.18.

Simple Membership

Plugin Slug:
simple-membership

Installations
50,000+

Vulnerability:
Open Redirection

Patched in Version:
4.4.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 4.4.2.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Path Traversal

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.1.

IP2Location Country Blocker

Plugin Slug:
ip2location-country-blocker

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.33.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.33.4.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.0.

Cryptocurrency Widgets � Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.6.

Stripe Payment Plugin for WooCommerce

Plugin Slug:
payment-gateway-stripe-and-woocommerce-integration

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.0.
Plugin Slug:
portfolio-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.
Plugin Slug:
bp-profile-search

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.

HD Quiz

Plugin:

HD Quiz

Plugin Slug:
hd-quiz

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.12.

ChatBot with AI

Plugin Slug:
chatbot

Installations
5,000+

Vulnerability:
PHP Object Injection

Patched in Version:
5.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.1.

Slider by Supsystic

Plugin Slug:
slider-by-supsystic

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.

FastDup � Fastest WordPress Migration & Duplicator

Plugin Slug:
fastdup

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.2.0.

Formzu WP

Plugin Slug:
formzu-wp

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.8.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.8.

WP Spell Check

Plugin Slug:
wp-spell-check

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.18.

WPZOOM Shortcodes

Plugin Slug:
wpzoom-shortcodes

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.2.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
0.1.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.9.

Stock Locations for WooCommerce

Plugin Slug:
stock-locations-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.2.5.

GeneratePress Premium

Plugin:

GeneratePress Premium

Plugin Slug:
generatepress-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

PeepSo Core: Photos

Plugin:

PeepSo Core: Photos

Plugin Slug:
peepso-photos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.1.0.

SalesKing

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Privilege Escalation

Patched in Version:
1.6.30

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.30.

SalesKing

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Settings Change

Patched in Version:
1.6.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.30.

SalesKing

Plugin:

SalesKing

Plugin Slug:
salesking

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.30

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.30.

WooCommerce Subscriptions

Plugin:

WooCommerce Subscriptions

Plugin Slug:
woocommerce-subscriptions

Vulnerability:
Broken Access Control

Patched in Version:
5.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.0.

WPForms Pro

Plugin:

WPForms Pro

Plugin Slug:
wpforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.4.

WordPress Themes � 1 Patched / 0 Unpatched

ColorMag

Theme Slug:
colormag

Downloads
3,787,317

Vulnerability:
Broken Access Control

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…