Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 28, 2024

In this report, 73 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 25 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

WordPress Plugins � 46 Patched / 25 Unpatched

Addon Library

Plugin:

Addon Library

Plugin Slug:
addon-library

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin side data storage for Contact Form 7

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Adsmonetizer

Plugin:

Adsmonetizer

Plugin Slug:
adsensei-b30

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BeePress

Plugin:

BeePress

Plugin Slug:
beepress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Configure SMTP

Plugin:

Configure SMTP

Plugin Slug:
configure-smtp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Download Media

Plugin:

Download Media

Plugin Slug:
download-media

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Duitku Payment Gateway

Plugin:

Duitku Payment Gateway

Plugin Slug:
duitku-social-payment-gateway

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fontific | Google Fonts

Plugin:

Fontific | Google Fonts

Plugin Slug:
fontific

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gestpay for WooCommerce

Plugin:

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketo Forms and Tracking

Plugin:

Marketo Forms and Tracking

Plugin Slug:
marketo-forms-and-tracking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Media Alt Renamer

Plugin:

Media Alt Renamer

Plugin Slug:
media-alt-renamer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin:

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin Slug:
myshopkit-popup-smartbar-slidein

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PayU India

Plugin:

PayU India

Plugin Slug:
payu-india

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Play.ht

Plugin:

Play.ht

Plugin Slug:
play-ht

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

postMash � custom post order

Plugin:

postMash � custom post order

Plugin Slug:
postmash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rolo Slider

Plugin:

Rolo Slider

Plugin Slug:
rolo-slider

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slivery Extender

Plugin:

Slivery Extender

Plugin Slug:
slivery-extender

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SoundCloud Shortcode

Plugin:

SoundCloud Shortcode

Plugin Slug:
soundcloud-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tabs Shortcode and Widget

Plugin:

Tabs Shortcode and Widget

Plugin Slug:
tabs-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Shortcodes Plus

Plugin:

User Shortcodes Plus

Plugin Slug:
user-shortcodes-plus

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Watermark RELOADED

Plugin:

Watermark RELOADED

Plugin Slug:
watermark-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.7.0.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.7.0.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.19.

BackWPup � WordPress Backup Plugin

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.3

Severity Score:
Low


The vulnerability has been patched, so you should update to version 4.0.3.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.32.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.31.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.13.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.260.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.260.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Directory Traversal

Patched in Version:
2.4.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.41.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.41.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.41

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.41.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.41.

Event Tickets and Registration

Plugin Slug:
event-tickets

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.2.

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.4.

Maintenance Page

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

Maintenance Page

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

SMS Alert Order Notifications � WooCommerce

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.9.

Archivist � Custom Archive Templates

Plugin Slug:
archivist-custom-archive-templates

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.6.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.

Comments Extra Fields For Post,Pages and CPT

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.

KODO Qiniu

Plugin Slug:
kodo-qiniu

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Backup

Plugin:

Backup

Plugin Slug:
backup2

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.9.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.9.9.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.19.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.3.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.4.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Authentication

Patched in Version:
2.3.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.3.4.

WP Social Widget

Plugin:

WP Social Widget

Plugin Slug:
wp-social-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.6.

WordPress Themes � 2 Patched /0 Unpatched

Colibri WP

Theme Slug:
colibri-wp

Downloads
1,232,050

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.101

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.101.

Socialdriver

Theme:

Socialdriver

Theme Slug:
socialdriver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024

Severity Score:
High


The vulnerability has been patched, so you should update to version 2024.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…