Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 21, 2024

In this report, 96 vulnerabilities have been publicly disclosed. Security patches for 76 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 20 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

WordPress Plugins � 75 Patched / 20 Unpatched

Plugin Slug:
featured-image-from-url

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Malware Scanner

Plugin Slug:
miniorange-malware-protection

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comments Like Dislike

Plugin Slug:
comments-like-dislike

Installations
9,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PJ News Ticker

Plugin Slug:
pj-news-ticker

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE and TinyMCE Advanced Professsional Formats and Styles

Plugin Slug:
tinymce-and-tinymce-advanced-professsional-formats-and-styles

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyWaze

Plugin:

MyWaze

Plugin Slug:
my-waze

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PB oEmbed HTML5 Audio � with Cache Support

Plugin Slug:
pb-oembed-html5-audio-with-cache-support

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

GigPress

Plugin:

GigPress

Plugin Slug:
gigpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Denial of Service Attack

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Oliver POS

Plugin:

Oliver POS

Plugin Slug:
oliver-pos

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

postMash � custom post order

Plugin:

postMash � custom post order

Plugin Slug:
postmash

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Sitepact’s Contact Form 7 Extension For Klaviyo

Plugin:

Sitepact’s Contact Form 7 Extension For Klaviyo

Plugin Slug:
sitepact-klaviyo-contact-form-7

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widgets Controller

Plugin:

Widgets Controller

Plugin Slug:
widgets-controller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pexels: Free Stock Photos

Plugin:

Pexels: Free Stock Photos

Plugin Slug:
wp-pexels-free-stock-photos

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Forms for Mailchimp

Plugin:

Easy Forms for Mailchimp

Plugin Slug:
yikes-inc-easy-mailchimp-extender

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.19.
Plugin Slug:
broken-link-checker

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.58.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.58.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.58.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.58.4.

WP Activity Log

Plugin Slug:
wp-security-audit-log

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.2.
Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.9.

Login Lockdown � Protect Login Form

Plugin Slug:
login-lockdown

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.09

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.09.

Page scroll to id

Plugin Slug:
page-scroll-to-id

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.9.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.27.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.27.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.1.

Simple Share Buttons Adder

Plugin Slug:
simple-share-buttons-adder

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.4.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.12.

Microsoft Clarity

Plugin Slug:
microsoft-clarity

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.9.4.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.88.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.88.16.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.88.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.88.15.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.7.

WP Maintenance

Plugin Slug:
wp-maintenance

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.7.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

WP Editor

Plugin Slug:
wp-editor

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Maspik � Spam Blacklist

Plugin Slug:
contact-forms-anti-spam

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.10.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.10.7.

My Private Site

Plugin Slug:
jonradio-private-site

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

My Calendar

Plugin Slug:
my-calendar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.24.
Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.1.

Coming Soon Maintenance Mode

Plugin Slug:
coming-soon-maintenance-mode

Installations
6,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

WP Testimonials

Plugin Slug:
testimonial-widgets

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

Piraeus Bank WooCommerce Payment Gateway

Plugin Slug:
woo-payment-gateway-for-piraeus-bank

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
1.7.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.0.

WPify Woo Czech

Plugin Slug:
wpify-woo

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.9.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.3.

SKT Page Builder

Plugin Slug:
skt-builder

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.
Plugin Slug:
doofinder-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.9.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
0.1.0.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.1.0.9.

SMTP Mail

Plugin Slug:
smtp-mail

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.21.

GD Rating System

Plugin Slug:
gd-rating-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.1.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
22.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 22.8.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

Peach Payments Gateway

Plugin Slug:
wc-peach-payments-gateway

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

Ultimate Reviews

Plugin Slug:
ultimate-reviews

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.9.

Action Network

Plugin Slug:
wp-action-network

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

Web3 � Crypto wallet Login & NFT token gating

Plugin Slug:
web3-authentication

Installations
200+

Vulnerability:
Broken Authentication

Patched in Version:
3.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.0.

Cwicly

Plugin:

Cwicly

Plugin Slug:
cwicly

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.4.0.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.0.3.

WooCommerce Easy Checkout Field Editor, Fees & Discounts

Plugin:

WooCommerce Easy Checkout Field Editor, Fees & Discounts

Plugin Slug:
phppoet-checkout-fields

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.5.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.5.13.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.7.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Settings Change

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Settings Change

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

WP Setup Wizard

Plugin:

WP Setup Wizard

Plugin Slug:
wp-setup-wizard

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.2.

WordPress Themes � 1 Patched / 0 Unpatched

Bricks Builder

Theme:

Bricks Builder

Theme Slug:
bricks

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.9.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.6.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…