Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � April 17, 2024

In this report, 342 vulnerabilities have been publicly disclosed. Security patches for 254 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 88 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.2.

WordPress Plugins � 234 Patched / 81 Unpatched

Product Feed PRO for WooCommerce

Plugin Slug:
woo-product-feed-pro

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

What’s New Generator

Plugin Slug:
whats-new-genarator

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zero Spam for WordPress

Plugin Slug:
zero-spam

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Leadinfo

Plugin:

Leadinfo

Plugin Slug:
leadinfo

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sync Post With Other Site

Plugin Slug:
sync-post-with-other-site

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Textillate

Plugin Slug:
easy-textillate

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoga Schedule Momoyoga

Plugin Slug:
momoyoga-integration

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MM-email2image

Plugin Slug:
mm-email2image

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bannerlid

Plugin Slug:
bannerlid

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Access Category Password

Plugin:

Access Category Password

Plugin Slug:
access-category-password

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ads.txt Admin

Plugin:

Ads.txt Admin

Plugin Slug:
ads-txt-admin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Advanced Search

Plugin Slug:
advance-search

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Page Visit Counter

Plugin:

Advanced Page Visit Counter

Plugin Slug:
advanced-page-visit-counter

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post Block – Post Grid for WordPress block editor

Plugin:

Advanced Post Block – Post Grid for WordPress block editor

Plugin Slug:
advanced-post-block

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AIKit

Plugin:

AIKit

Plugin Slug:
aikit-wordpress-ai-writing-assistant-using-gpt3

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Aspose.Words Exporter

Plugin:

Aspose.Words Exporter

Plugin Slug:
aspose-doc-exporter

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Before And After

Plugin:

Before And After

Plugin Slug:
before-and-after

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

bizcalendar-web

Plugin:

bizcalendar-web

Plugin Slug:
bizcalendar-web

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Block Converter

Plugin:

Bulk Block Converter

Plugin Slug:
bulk-block-converter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Canva � Design beautiful blog graphics

Plugin:

Canva � Design beautiful blog graphics

Plugin Slug:
canva

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CBX Bookmark & Favorite

Plugin:

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Citadela Listing

Plugin:

Citadela Listing

Plugin Slug:
citadela-directory

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Citadela Listing

Plugin:

Citadela Listing

Plugin Slug:
citadela-directory

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Convert Post Types

Plugin:

Convert Post Types

Plugin Slug:
convert-post-types

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crony Cronjob Manager

Plugin:

Crony Cronjob Manager

Plugin Slug:
crony

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Order Statuses for WooCommerce

Plugin:

Custom Order Statuses for WooCommerce

Plugin Slug:
custom-order-statuses-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Customily Product Personalizer

Plugin:

Customily Product Personalizer

Plugin Slug:
customily-v2

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Delete Custom Fields

Plugin:

Delete Custom Fields

Plugin Slug:
delete-custom-fields

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Disable Comments | WPZest

Plugin:

Disable Comments | WPZest

Plugin Slug:
disable-comments-wpz

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy CountDowner

Plugin:

Easy CountDowner

Plugin Slug:
easy-countdowner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Easy Logo

Plugin Slug:
easylogo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EZ Form Calculator

Plugin:

EZ Form Calculator

Plugin Slug:
ez-form-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Filter Custom Fields & Taxonomies Light

Plugin:

Filter Custom Fields & Taxonomies Light

Plugin Slug:
filter-custom-fields-taxonomies-light

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Find Duplicates

Plugin:

Find Duplicates

Plugin Slug:
find-duplicates

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fixed HTML Toolbar

Plugin:

Fixed HTML Toolbar

Plugin Slug:
fixed-html-toolbar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flash Video Player

Plugin:

Flash Video Player

Plugin Slug:
flash-video-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:

Font Farsi

Plugin Slug:
font-farsi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook

Plugin:

Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook

Plugin Slug:
forms-to-zapier

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Freshdesk (official)

Plugin:

Freshdesk (official)

Plugin Slug:
freshdesk-support

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kimili Flash Embed

Plugin:

Kimili Flash Embed

Plugin Slug:
kimili-flash-embed

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form & Lead Form Elementor Builder

Plugin:

Contact Form & Lead Form Elementor Builder

Plugin Slug:
lead-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form & Lead Form Elementor Builder

Plugin:

Contact Form & Lead Form Elementor Builder

Plugin Slug:
lead-form-builder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin:

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Libsyn Publisher Hub

Plugin:

Libsyn Publisher Hub

Plugin Slug:
libsyn-podcasting

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Related Posts for WordPress

Plugin Slug:
microkids-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:

MJ Update History

Plugin Slug:
mj-update-history

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ovic Addon Toolkit

Plugin:

Ovic Addon Toolkit

Plugin Slug:
ovic-addon-toolkit

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin:

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Product Feed on WooCommerce for Google

Plugin:

Product Feed on WooCommerce for Google

Plugin Slug:
purple-xmls-google-product-feed-for-woocommerce

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Insert Manager (Q2W3 Inc Manager)

Plugin:

Code Insert Manager (Q2W3 Inc Manager)

Plugin Slug:
q2w3-inc-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:

Realtyna Organic IDX plugin

Plugin Slug:
real-estate-listing-realtyna-wpl

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Sangar Slider

Plugin:

Sangar Slider

Plugin Slug:
sangar-slider-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shopkeeper Extender

Plugin:

Shopkeeper Extender

Plugin Slug:
shopkeeper-extender

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Matterport Shortcode

Plugin:

WP Matterport Shortcode

Plugin Slug:
shortcode-gallery-for-matterport-showcase

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Short URL

Plugin:

Short URL

Plugin Slug:
shorten-url

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Testimonials Showcase

Plugin:

Simple Testimonials Showcase

Plugin Slug:
simple-testimonials-showcase

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:

Tax Rate Upload

Plugin Slug:
tax-rate-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Type Builder (PTB)

Plugin:

Post Type Builder (PTB)

Plugin Slug:
themify-ptb

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Type Builder (PTB)

Plugin:

Post Type Builder (PTB)

Plugin Slug:
themify-ptb

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:

Mega Addons For Elementor

Plugin Slug:
ultimate-addons-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Activity Log Pro

Plugin:

User Activity Log Pro

Plugin Slug:
user-activity-log-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Appointment Bookings for Zoom GoogleMeet and more � Wappointment

Plugin:

Appointment Bookings for Zoom GoogleMeet and more � Wappointment

Plugin Slug:
wappointment

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:

WidgetKit

Plugin Slug:
widgetkit-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

2Checkout Payment Gateway for WooCommerce

Plugin:

2Checkout Payment Gateway for WooCommerce

Plugin Slug:
woocommerce-2checkout-payment

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Registration for WooCommerce

Plugin:

Simple Registration for WooCommerce

Plugin Slug:
woocommerce-simple-registration

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP-Cufon

Plugin:

WP-Cufon

Plugin Slug:
wp-cufon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP File Download Light

Plugin:

WP File Download Light

Plugin Slug:
wp-file-download-light

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Radio � Worldwide Online Radio Stations Directory for WordPress

Plugin:

WP Radio � Worldwide Online Radio Stations Directory for WordPress

Plugin Slug:
wp-radio

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Radio � Worldwide Online Radio Stations Directory for WordPress

Plugin:

WP Radio � Worldwide Online Radio Stations Directory for WordPress

Plugin Slug:
wp-radio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Search Keyword Redirect

Plugin:

Search Keyword Redirect

Plugin Slug:
wp-search-keyword-redirect

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP TradingView

Plugin:

WP TradingView

Plugin Slug:
wp-tradingview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin:

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.7.

EWWW Image Optimizer

Plugin Slug:
ewww-image-optimizer

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.3.0.

Smart Slider 3

Plugin Slug:
smart-slider-3

Installations
900,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.1.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.23.

Meta Box � WordPress Custom Fields Framework

Plugin Slug:
meta-box

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.4.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.28.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.25.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.25.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.17.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.1.

BackWPup � WordPress Backup Plugin

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.5.
Plugin Slug:
nextgen-gallery

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.59.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.59.1.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.0.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.35.

Migration, Backup, Staging � WPvivid

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
PHP Object Injection

Patched in Version:
0.9.100

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.100.

Favicon by RealFaviconGenerator

Plugin Slug:
favicon-by-realfavicongenerator

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.30.

Gutenberg

Plugin Slug:
gutenberg

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
18.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 18.1.0.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.0.7.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.29.

Smash Balloon Social Post Feed

Plugin Slug:
custom-facebook-feed

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.

Ivory Search � WordPress Search Plugin

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.6.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.2.83

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.83.
Plugin Slug:
foogallery

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.
Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.
Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.0.
Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Import any XML or CSV File to WordPress

Plugin Slug:
wp-all-import

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.4.

Enhanced Media Library

Plugin Slug:
enhanced-media-library

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.10.
Plugin Slug:
remove-footer-credit

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.14.

WPZOOM Social Feed Widget & Block

Plugin Slug:
instagram-widget-by-wpzoom

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.14.

Real Media Library: Media Library Folder & File Manager

Plugin Slug:
real-media-library-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.22.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.12.

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.29.

Theme My Login

Plugin Slug:
theme-my-login

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.7.

Clone

Plugin:

Clone

Plugin Slug:
wp-clone-by-wp-academy

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

BoldGrid Easy SEO � Simple and Effective SEO

Plugin Slug:
boldgrid-easy-seo

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.15.

ActiveCampaign � Forms, Site Tracking, Live Chat

Plugin Slug:
activecampaign-subscription-forms

Installations
60,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.1.15.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.7.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.7.

Advanced iFrame

Plugin Slug:
advanced-iframe

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2024.3.

Booking for Appointments and Events Calendar � Amelia

Plugin Slug:
ameliabooking

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.96

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.96.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.47.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.47.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.1.

Redirection

Plugin Slug:
redirect-redirection

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

Spotlight Social Feeds [Block, Shortcode, and Widget]

Plugin Slug:
spotlight-social-photo-feeds

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.11.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

Carousel, Slider, Gallery by WP Carousel � Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.4.

Carousel, Slider, Gallery by WP Carousel � Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.9.

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.4.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.10.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Advanced Cron Manager � debug & control

Plugin Slug:
advanced-cron-manager

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
7.5.45.7212

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.45.7212.
Plugin Slug:
link-whisper

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.7.0.

Login With Ajax � Fast Logins, 2FA, Redirects

Plugin Slug:
login-with-ajax

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.

Testimonial Slider

Plugin Slug:
testimonial-slider-and-showcase

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.8.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews

Installations
30,000+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
3.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.
Plugin Slug:
beaf-before-and-after-gallery

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

Dashboard Welcome for Elementor

Plugin Slug:
dashboard-welcome-for-elementor

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Envo Extra

Plugin Slug:
envo-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.12.

Import Users from CSV

Plugin Slug:
import-users-from-csv

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

IP2Location Country Blocker

Plugin Slug:
ip2location-country-blocker

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.34.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.34.3.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

Email Marketing for WooCommerce by Omnisend

Plugin Slug:
omnisend-connect

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.14.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.14.4.

Powerkit � Supercharge your WordPress Site

Plugin Slug:
powerkit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.2.

Top Bar

Plugin:

Top Bar

Plugin Slug:
top-bar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Top Bar

Plugin:

Top Bar

Plugin Slug:
top-bar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.6.

Welcart e-Commerce

Plugin Slug:
usc-e-shop

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.0.

NextMove Lite � Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.18.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.18.2.

WP Accessibility Helper (WAH)

Plugin Slug:
wp-accessibility-helper

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.6.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.2.6.

Asgaros Forum

Plugin Slug:
asgaros-forum

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.5.

bunny.net � WordPress CDN Plugin

Plugin Slug:
bunnycdn

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Language Translate Widget for WordPress � ConveyThis

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
224

Severity Score:
High


The vulnerability has been patched, so you should update to version 224.

E2Pdf � Export To Pdf Tool for WordPress

Plugin Slug:
e2pdf

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.23.00

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.23.00.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.3.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.29.

eRoom � Zoom Meetings & Webinars

Plugin Slug:
eroom-zoom-meetings-webinar

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.19.

Jobs for WordPress

Plugin Slug:
job-postings

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.6.

LifterLMS � WordPress LMS Plugin for eLearning

Plugin Slug:
lifterlms

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.1.

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.36.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.21.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.0.

Popup by Supsystic

Plugin Slug:
popup-by-supsystic

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.28.

Membership Plugin � Restrict Content

Plugin Slug:
restrict-content

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.9.

Simple Post Notes

Plugin Slug:
simple-post-notes

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

Mail logging � WP Mail Catcher

Plugin Slug:
wp-mail-catcher

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.0.

Elements Plus!

Plugin Slug:
elements-plus

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.16.4.

WooCommerce UPS Shipping � Live Rates and Access Points

Plugin Slug:
flexible-shipping-ups

Installations
9,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5 .

Fatal Error Notify

Plugin Slug:
fatal-error-notify

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Unlimited Elementor Inner Sections By BoomDevs

Plugin Slug:
unlimited-elementor-inner-sections-by-boomdevs

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

WPvivid Backup for MainWP

Plugin Slug:
wpvivid-backup-mainwp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.34.

Finale Lite � Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.18.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.18.1.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.7.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.9.

Ultimate Product Catalog

Plugin Slug:
ultimate-product-catalogue

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.2.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.16.

WP Compress � Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.11.01

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.11.01.

Load More Anything

Plugin Slug:
ajax-load-more-anything

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.6.
Plugin Slug:
boostify-header-footer-builder

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Country State City Dropdown CF7

Plugin Slug:
country-state-city-auto-dropdown

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.2.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.
Plugin Slug:
responsive-gallery-grid

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.11.

Responsive Tabs

Plugin Slug:
responsive-tabs

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.7.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.

WP Login and Logout Redirect

Plugin Slug:
wp-login-and-logout-redirect

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

Church Content � Sermons, Events and More

Plugin Slug:
church-theme-content

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

GEO my WordPress

Plugin Slug:
geo-my-wp

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.

Intagrate Lite

Plugin Slug:
instagrate-to-wordpress

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.1.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
4.0.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.14.

WP Client Reports

Plugin Slug:
wp-client-reports

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
5.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.4.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.0.

CP Media Player � Audio Player and Video Player

Plugin Slug:
audio-and-video-player

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

Contact Form Plugin

Plugin Slug:
contact-form-lite

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.25.

Marker.io � Visual Website Feedback

Plugin Slug:
marker-io

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.9.

MultiParcels Shipping For WooCommerce

Plugin Slug:
multiparcels-shipping-for-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.16.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.16.9.

Account Engagement

Plugin Slug:
pardot

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.1.

WordPress Hosting Benchmark tool

Plugin Slug:
wpbenchmark

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

WPC Grouped Product for WooCommerce

Plugin Slug:
wpc-grouped-product

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.3.

Zoho Campaigns

Plugin Slug:
zoho-campaigns

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Zoho Campaigns

Plugin Slug:
zoho-campaigns

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Premmerce Product Filter for WooCommerce

Plugin Slug:
premmerce-woocommerce-product-filter

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.3.

SEO Booster

Plugin Slug:
seo-booster

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.10.

TOP Table Of Contents

Plugin Slug:
top-table-of-contents

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.16.

Extra Product Options Builder for WooCommerce

Plugin Slug:
additional-product-fields-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.105

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.105.

Currency per Product for WooCommerce

Plugin Slug:
currency-per-product-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.
Plugin Slug:
gallery-box

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.34.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.1.0.23

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.1.0.23.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.23.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.1.

Benchmark Email Lite

Plugin Slug:
benchmark-email-lite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.28.

TempTool [Show Current Template Info]

Plugin Slug:
current-template-name

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.13.

Dashboard To-Do List

Plugin Slug:
dashboard-to-do-list

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

USPS Shipping for WooCommerce � Live Rates

Plugin Slug:
flexible-shipping-usps

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.17.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.94

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.94.

MihanPanel � User Login , Registration and Dashboard

Plugin Slug:
mihanpanel-lite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
12.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.7.

Netgsm

Plugin:

Netgsm

Plugin Slug:
netgsm

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.

No-Bot Registration

Plugin Slug:
no-bot-registration

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

Novelist

Plugin:

Novelist

Plugin Slug:
novelist

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

POEditor

Plugin:

POEditor

Plugin Slug:
poeditor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.9.

ReDi Restaurant Reservation

Plugin Slug:
redi-restaurant-reservation

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
24.0303

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 24.0303.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

Multi Currency For WooCommerce

Plugin Slug:
wc-multi-currency

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

WP Dynamic Keywords Injector

Plugin Slug:
wp-dynamic-keywords-injector

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.22.

MWW Disclaimer Buttons

Plugin Slug:
mww-disclaimer-buttons

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.

Siteimprove

Plugin Slug:
siteimprove

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.7.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

Popup Like box � Page Plugin

Plugin Slug:
ays-facebook-popup-likebox

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.3.

F4 Improvements

Plugin Slug:
f4-improvements

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

NPS computy

Plugin Slug:
nps-computy

Installations
80+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.6.

NPS computy

Plugin Slug:
nps-computy

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.6.

Save as Image Plugin by Pdfcrowd

Plugin Slug:
save-as-image-by-pdfcrowd

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

AffiEasy

Plugin:

AffiEasy

Plugin Slug:
affieasy

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

AWP Classifieds

Plugin:

AWP Classifieds

Plugin Slug:
another-wordpress-classifieds-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.2.

BWL Advanced FAQ Manager

Plugin:

BWL Advanced FAQ Manager

Plugin Slug:
bwl-advanced-faq-manager

Vulnerability:
SQL Injection

Patched in Version:
2.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.4.

Calendarista Basic Edition

Plugin:

Calendarista Basic Edition

Plugin Slug:
calendarista-basic-edition

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

Digital Publications by Supsystic

Plugin:

Digital Publications by Supsystic

Plugin Slug:
digital-publications-by-supsystic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

Essential Grid

Plugin:

Essential Grid

Plugin Slug:
essential-grid

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.81.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

RestroPress

Plugin:

RestroPress

Plugin Slug:
restropress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.1.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.0.

Table & Contact Form 7 Database � Tablesome

Plugin:

Table & Contact Form 7 Database � Tablesome

Plugin Slug:
tablesome

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.26.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
SQL Injection

Patched in Version:
29.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 29.7.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.1.76

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.1.76.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Broken Access Control

Patched in Version:
10.1.77

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.1.77.

WP Activity Log Premium

Plugin:

WP Activity Log Premium

Plugin Slug:
wp-security-audit-log-premium

Vulnerability:
SQL Injection

Patched in Version:
4.6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.4.1.

WPB Show Core

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.

WPB Show Core

Plugin:

WPB Show Core

Plugin Slug:
wpb-show-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.

WordPress Themes � 19 Patched / 7 Unpatched

Decode

Theme:

Decode

Theme Slug:
decode

Downloads
269,521

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Gridsby

Theme:

Gridsby

Theme Slug:
gridsby

Downloads
288,716

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

GuCherry Blog

Theme Slug:
gucherry-blog

Downloads
136,966

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

HappenStance

Theme Slug:
happenstance

Downloads
134,390

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

i-excel

Theme:

i-excel

Theme Slug:
i-excel

Downloads
262,257

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

i-max

Theme:

i-max

Theme Slug:
i-max

Downloads
270,530

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Sensible WP

Theme Slug:
sensible-wp

Downloads
277,690

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,056,299

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

CityLogic

Theme Slug:
citylogic

Downloads
292,720

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.30.

Default Mag

Theme Slug:
default-mag

Downloads
93,066

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Emmet Lite

Theme Slug:
emmet-lite

Downloads
104,881

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

Lightning

Theme Slug:
lightning

Downloads
2,240,450

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
15.19.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.19.0.

Namaha

Theme:

Namaha

Theme Slug:
namaha

Downloads
63,477

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.41.

NewsXpress

Theme Slug:
newsxpress

Downloads
11,096

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Panoramic

Theme Slug:
panoramic

Downloads
614,830

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.57

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.57.

PopularFX

Theme Slug:
popularfx

Downloads
773,374

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Sarada Lite

Theme Slug:
sarada-lite

Downloads
86,466

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Shopstar!

Theme Slug:
shopstar

Downloads
286,946

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.34.

Sliding Door

Theme Slug:
sliding-door

Downloads
537,017

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.

Spa and Salon

Theme Slug:
spa-and-salon

Downloads
155,971

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Tainacan Interface

Theme Slug:
tainacan-interface

Downloads
16,543

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.2.

The Conference

Theme Slug:
the-conference

Downloads
52,521

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

X-T9

Theme:

X-T9

Theme Slug:
x-t9

Downloads
30,187

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.19.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.19.1.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.6.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Broken Access Control

Patched in Version:
8.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.6.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Broken Access Control

Patched in Version:
8.4.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.4.6.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…