A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange �bug�, a triangle with an explanation point in the middle and a gray gear.

WordPress Vulnerability Report – February 16, 2022

Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities, and what to do if you run one of the vulnerable plugins or themes on your website.

Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. New in this report: vulnerabilities are now listed in order by the number of active installs, rather than the date of the disclosure.

Please share this post with your friends to help get the word out and make WordPress safer for everyone!

WordPress 5.9: Core Major Version Update Now Available

The latest version of WordPress core is WordPress 5.9. Be sure to update to WordPress 5.9 as soon as possible!

WordPress Plugin Vulnerabilities

In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

Premium Plugin Vulnerabilities

In this section, the latest vulnerabilities for premium plugins have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

WordPress Plugin Vulnerabilities – No Known Fix

Good news! No plugins with no known fix were disclosed this week.

WordPress Theme Vulnerabilities

In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, and the severity rating.

WordPress Theme Vulnerabilities – No Known Fix

This section covers vulnerabilities in themes with no known fix. Until a patch is available, deactivate and uninstall the theme.

Colorway

Product image for ColorWay.

Theme
ColorWay
Downloads
1,313,341
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Wallstreet

Product image for Wallstreet.

Theme
Wallstreet
Downloads
718,444
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Quality

Product image for Quality.

Theme
Quality
Downloads
495,739
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

StartKit

Product image for StartKit.

Theme
StartKit
Downloads
459,051
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Busiprof

Product image for Busiprof.

Theme
Busiprof
Downloads
458,162
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Rambo

Product image for Rambo.

Theme
Rambo
Downloads
371,342
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Spasalon

Product image for Spasalon.

Theme
Spasalon
Downloads
334,726
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

HoneyPress

Product image for HoneyPress.

Theme
HoneyPress
Downloads
226,695
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Fifteen

Product image for Fifteen.

Theme
Fifteen
Downloads
212,109
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

ElitePress

Product image for ElitePress.

Theme
ElitePress
Downloads
148,007
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Envo Business

Product image for Envo Business.

Theme
Envo Business
Downloads
111,185
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

CloudPress

Product image for CloudPress.

Theme
CloudPress
Downloads
102,458
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Shopbiz Lite

Product image for Shopbiz Lite.

Theme
Shopbiz Lite
Downloads
83,149
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

ConsultEra

Product image for ConsultEra.

Theme
ConsultEra
Downloads
82,730
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

EventPress

Product image for EventPress.

Theme
EventPress
Downloads
70,771
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Blain

Product image for Blain.

Theme
Blain
Downloads
50,841
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Robolist Lite

Product image for Robolist Lite.

Theme
Robolist Lite
Downloads
48,328
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Short

Product image for Short.

Theme
Short
Downloads
46,868
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

BusiCare

Product image for BusiCare.

Theme
BusiCare
Downloads
42,606
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Spice Software

Product image for Spice Software.

Theme
Spice Software
Downloads
40,528
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

WP Real Estate

Product image for WP Real Estate.

Theme
WP Real Estate
Downloads
38,280
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Jewelry Store

Product image for Jewelry Store.

Theme
Jewelry Store
Downloads
31,042
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

IH Business Pro

Product image for IH Business Pro.

Theme
IH Business Pro
Downloads
25,480
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Spiko

Product image for Spiko.

Theme
Spiko
Downloads
20,289
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Mediciti LIte

Product image for Mediciti Lite.

Theme
Mediciti Lite
Downloads
20,137
Vulnerability
XSS
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Auto Car

Product image for Auto Car.

Theme
Auto Car
Downloads
10,972
Vulnerability
XSS
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Hasten Lite

Product image for Hasten Lite.

Theme
Hasten Lite
Downloads
10,364
Vulnerability
XSS
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

lawyerpress lite

Product image for lawyerpress lite.

Theme
lawyerpress lite
Downloads
9,576
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Spawp

Product image for Spawp.

Theme
Spawp
Downloads
8,864
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Businesswp

Product image for Businesswp.

Theme
Businesswp
Downloads
6,371
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

NGO Charity Lite

Theme
NGO Charity Lite
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

AStore

Theme
AStore
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

Cactus

Theme
Cactus
Vulnerability
Reflected Cross-Site Scripting via Customizer Notify
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the theme.

How to Protect Your WordPress Website From Vulnerable Plugins and Themes

As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.

Get iThemes Security Pro with 24/7 Website Security Monitoring

iThemes Security Pro, our WordPress security plugin, offers 50+ ways to secure and protect your website from common WordPress security vulnerabilities. With WordPress, two-factor authentication, brute force protection, strong password enforcement, and more, you can add extra layers of security to your website.

Get iThemes Security Pro

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…