Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � March 27, 2024

In this report, 209 vulnerabilities have been publicly disclosed. Security patches for 190 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 19 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

WordPress Plugins � 182 Patched / 18 Unpatched

Create by Mediavine

Plugin Slug:
mediavine-create

Installations
8,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Coming Soon & Maintenance Mode by Colorlib

Plugin Slug:
colorlib-coming-soon-maintenance

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Travelpayouts: All Travel Brands in One Place

Plugin Slug:
travelpayouts

Installations
7,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Social Feeds Widget & Shortcode

Plugin:

Advanced Social Feeds Widget & Shortcode

Plugin Slug:
advanced-facebook-twitter-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Animated Headline

Plugin:

Animated Headline

Plugin Slug:
animated-headline

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Maintenance Mode

Plugin:

Easy Maintenance Mode

Plugin Slug:
easy-maintenance-mode-coming-soon

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enjoy Social Feed plugin for WordPress website

Plugin:

Enjoy Social Feed plugin for WordPress website

Plugin Slug:
enjoy-instagram-instagram-responsive-images-gallery-and-carousel

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Enjoy Social Feed plugin for WordPress website

Plugin:

Enjoy Social Feed plugin for WordPress website

Plugin Slug:
enjoy-instagram-instagram-responsive-images-gallery-and-carousel

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Innovs HR

Plugin:

Innovs HR

Plugin Slug:
innovs-hr-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Network Summary

Plugin:

Network Summary

Plugin Slug:
network-summary

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Scalable Vector Graphics (SVG)

Plugin:

Scalable Vector Graphics (SVG)

Plugin Slug:
scalable-vector-graphics-svg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Media Share Buttons

Plugin:

Social Media Share Buttons

Plugin Slug:
social-media-builder

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Standout Color Boxes and Buttons

Plugin:

Standout Color Boxes and Buttons

Plugin Slug:
standout-color-boxes-and-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UX Flat

Plugin:

UX Flat

Plugin Slug:
ux-flat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Website Article Monetization By MageNet

Plugin:

Website Article Monetization By MageNet

Plugin Slug:
website-article-monetization-by-magenet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Management App for WooCommerce

Plugin:

Management App for WooCommerce

Plugin Slug:
wemanage-app-worker

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:

Live Sales Notification for Woocommerce – Woomotiv

Plugin Slug:
woomotiv

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Youzify Buddypress Moderation

Plugin:

Youzify Buddypress Moderation

Plugin Slug:
youzify-moderation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO with AI SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.215

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.215.

File Manager

Plugin Slug:
wp-file-manager

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.5.

Popup Maker � Popup for opt-ins, lead gen, & more

Plugin Slug:
popup-maker

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.18.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.18.3.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.29.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.29.7.

Page Builder Gutenberg Blocks � CoBlocks

Plugin Slug:
coblocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.30

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.30.

Breeze � WordPress Cache Plugin

Plugin Slug:
breeze

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

PDF Embedder

Plugin Slug:
pdf-embedder

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.1.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.32.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

Check & Log Email

Plugin Slug:
check-email

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.10.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.8.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.3.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 12.3.17.

Tracking Code Manager

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.97.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.97.0.0.

Widget for Social Page Feeds

Plugin Slug:
facebook-pagelike-widget

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.
Plugin Slug:
permalink-manager

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.3.2.
Plugin Slug:
permalink-manager

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.3.2.
Plugin Slug:
permalink-manager

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.3.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.4.3.2.

Real Media Library: Media Library Folder & File Manager

Plugin Slug:
real-media-library-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.22.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.8.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
SQL Injection

Patched in Version:
3.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.14.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

Translate WordPress and go Multilingual � Weglot

Plugin Slug:
weglot

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.7.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.55

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.55.

Image Hover Effects � Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

Smart Custom Fields

Plugin Slug:
smart-custom-fields

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.0.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.1.8.

WPFront Notification Bar

Plugin Slug:
wpfront-notification-bar

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.
Plugin Slug:
gallery-by-supsystic

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.17.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.26.

Simply Static

Plugin Slug:
simply-static

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.
Plugin Slug:
sina-extension-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.10.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.
Plugin Slug:
portfolio-filter-gallery

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.7.

Stratum � Elementor Widgets

Plugin Slug:
stratum

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.16.

Team Members

Plugin Slug:
team-members

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.2.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.11.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.6.

WPBakery Page Builder Addons by Livemesh

Plugin Slug:
addons-for-visual-composer

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.

FlatPM � Ad Manager, AdSense and Custom Code

Plugin Slug:
flatpm-wp

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.05

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.05.

JetWidgets For Elementor

Plugin Slug:
jetwidgets-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.17.

Jobs for WordPress

Plugin Slug:
job-postings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.

Lightweight Accordion

Plugin Slug:
lightweight-accordion

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.17.

Modal Window � create popup modal window

Plugin Slug:
modal-window

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.9.

WP Coder � Powerful HTML, CSS, JS and PHP Injection

Plugin Slug:
wp-coder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.1.

RevivePress � Keep your Old Content Evergreen

Plugin Slug:
wp-auto-republish

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.1.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

WooCommerce POS � Point of Sale (POS)

Plugin Slug:
woocommerce-pos

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.12.

WP Compress � Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.11.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.11.11.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
SQL Injection

Patched in Version:
3.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.3.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.10.

Woo Viet � WooCommerce for Vietnam

Plugin Slug:
woo-viet

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

WP Change Email Sender

Plugin Slug:
wp-change-email-sender

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Doneren met Mollie

Plugin Slug:
doneren-met-mollie

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.10.3.

Error Log Viewer by BestWebSoft

Plugin Slug:
error-log-viewer

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.3.

Podlove Web Player

Plugin Slug:
podlove-web-player

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

Survey Maker � Best WordPress Survey Plugin

Plugin Slug:
survey-maker

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.7.

Fancy Comments WordPress

Plugin Slug:
fancy-facebook-comments

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.15.

Slider Hero with Animation, Video Background

Plugin Slug:
slider-hero

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.7.0.

Premium Packages � Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8.3.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Advanced Classifieds & Directory Pro

Plugin Slug:
advanced-classifieds-and-directory-pro

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.0.

Hot Random Image

Plugin Slug:
hot-random-image

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.2.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Order Tip for WooCommerce

Plugin Slug:
order-tip-woo

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.9.

Simple Ajax Chat � Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20240223

Severity Score:
High


The vulnerability has been patched, so you should update to version 20240223.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

affiliate-toolkit � WordPress Affiliate Plugin

Plugin Slug:
affiliate-toolkit-starter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.6.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.83

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.83.

Cards for Beaver Builder

Plugin Slug:
bb-bootstrap-cards

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Crypto Converter ? Widget

Plugin Slug:
crypto-converter-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.0.

Grid Shortcodes

Plugin Slug:
grid-shortcodes

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.8.

Aparat for WordPress

Plugin Slug:
wp-aparat

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

360 Javascript Viewer

Plugin Slug:
360deg-javascript-viewer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.13.

Advanced Sermons

Plugin Slug:
advanced-sermons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.10.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.27.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.18.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.5.72.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.73

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.5.73.

Dropdown multisite selector

Plugin Slug:
dropdown-multisite-selector

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.2.1.

Exchange Rates Widget

Plugin Slug:
exchange-rates-widget

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

Football Pool

Plugin Slug:
football-pool

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.4.

Fullscreen Galleria

Plugin Slug:
fullscreen-galleria

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.12.
Plugin Slug:
fulltext-search

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.60.213

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.60.213.
Plugin Slug:
gallery-photo-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.5.3.

GamiPress � Button

Plugin Slug:
gamipress-button

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program

Plugin Slug:
gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.5.

iCalendrier

Plugin Slug:
icalendrier

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.81.

Web Icons

Plugin Slug:
icon

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.0.11.

Locatoraid Store Locator

Plugin Slug:
locatoraid

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.31.

MyCurator Content Curation

Plugin Slug:
mycurator

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.77

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.77.

Off-Canvas Sidebars & Menus (Slidebars)

Plugin Slug:
off-canvas-sidebars

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.5.8.2.

Passwordless Login

Plugin Slug:
passwordless-login

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

PDF Builder for WPForms

Plugin Slug:
pdf-builder-for-wpforms

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.89

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.89.

ReDi Restaurant Reservation

Plugin Slug:
redi-restaurant-reservation

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
24.0303

Severity Score:
High


The vulnerability has been patched, so you should update to version 24.0303.
Plugin Slug:
seo-backlink-monitor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.0.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.6.

Travelers’ Map

Plugin Slug:
travelers-map

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

WC Builder � WooCommerce Page Builder for WPBakery

Plugin Slug:
wc-builder

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.19.

Shipping with Venipak for WooCommerce

Plugin Slug:
wc-venipak-shipping

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.19.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.19.6.

WishSuite � Wishlist for WooCommerce

Plugin Slug:
wishsuite

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

WooCommerce Clover Payment Gateway

Plugin Slug:
woo-clover-gateway-by-zaytech

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.
Plugin Slug:
woocommerce-cloak-affiliate-links

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.34

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.34.

WP-Lister Lite for Amazon

Plugin Slug:
wp-lister-for-amazon

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.9.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.1.

WP Post Disclaimer

Plugin Slug:
wp-post-disclaimer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Backup Bolt

Plugin Slug:
backup-bolt

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

System Dashboard

Plugin Slug:
system-dashboard

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.10.

CM Download Manager � Document and File Management

Plugin Slug:
cm-download-manager

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.1.

CM Download Manager � Document and File Management

Plugin Slug:
cm-download-manager

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

CM Download Manager � Document and File Management

Plugin Slug:
cm-download-manager

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

Contests by Rewards Fuel

Plugin Slug:
contests-from-rewards-fuel

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.65

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.65.

Contests by Rewards Fuel

Plugin Slug:
contests-from-rewards-fuel

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.63

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.63.

MJM Clinic

Plugin Slug:
mjm-clinic

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.23.

BuddyForms

Plugin:

BuddyForms

Plugin Slug:
buddyforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.6.

Easy Social Share Buttons

Plugin:

Easy Social Share Buttons

Plugin Slug:
easy-social-share-buttons3

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.5.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
SQL Injection

Patched in Version:
6.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.5.

Invitation Code Content Restriction Plugin from CreativeMinds

Plugin:

Invitation Code Content Restriction Plugin from CreativeMinds

Plugin Slug:
invitation-code-content-access

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.5.

Memberpress

Plugin:

Memberpress

Plugin Slug:
memberpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.11.27

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.11.27.

New RoyalSlider

Plugin:

New RoyalSlider

Plugin Slug:
new-royalslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.3.

Olive One Click Demo Import

Plugin:

Olive One Click Demo Import

Plugin Slug:
olive-one-click-demo-import

Vulnerability:
Broken Access Control

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.
Plugin:

Permalink Manager Pro

Plugin Slug:
permalink-manager-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.3.2.

Schema Pro

Plugin:

Schema Pro

Plugin Slug:
wp-schema-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.7.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.16.

WordPress Importer

Plugin:

WordPress Importer

Plugin Slug:
wp-smart-import

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.5.

WordPress Themes � 8 Patched / 1 Unpatched

Graphene

Theme Slug:
graphene

Downloads
1,515,731

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Astra

Theme:

Astra

Theme Slug:
astra

Downloads
11,885,431

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.9.

Astra

Theme:

Astra

Theme Slug:
astra

Downloads
11,885,431

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.5.

ColorMag

Theme Slug:
colormag

Downloads
3,868,842

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

Newsmatic

Theme Slug:
newsmatic

Downloads
185,361

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.11.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.11.7.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
SQL Injection

Patched in Version:
7.11.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.11.7.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.11.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.11.7.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.11.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.11.7.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…