Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � April 24, 2024

In this report, 358 vulnerabilities have been publicly disclosed. Security patches for 312 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 46 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

WordPress Plugins � 310 Patched / 45 Unpatched

What’s New Generator

Plugin Slug:
whats-new-genarator

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zero Spam for WordPress

Plugin Slug:
zero-spam

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Textillate

Plugin Slug:
easy-textillate

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoga Schedule Momoyoga

Plugin Slug:
momoyoga-integration

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QR Code Composer � Automatic QR code Generator

Plugin Slug:
qr-code-composer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Buttons Creator

Plugin Slug:
simple-buttons-creator

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Access Category Password

Plugin:

Access Category Password

Plugin Slug:
access-category-password

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Advanced Search

Plugin Slug:
advance-search

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post Block – Post Grid for WordPress block editor

Plugin:

Advanced Post Block – Post Grid for WordPress block editor

Plugin Slug:
advanced-post-block

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes and extra features for Phlox theme

Plugin:

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Block Converter

Plugin:

Bulk Block Converter

Plugin Slug:
bulk-block-converter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Canva � Design beautiful blog graphics

Plugin:

Canva � Design beautiful blog graphics

Plugin Slug:
canva

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Order Statuses for WooCommerce

Plugin:

Custom Order Statuses for WooCommerce

Plugin Slug:
custom-order-statuses-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Delete Custom Fields

Plugin:

Delete Custom Fields

Plugin Slug:
delete-custom-fields

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy CountDowner

Plugin:

Easy CountDowner

Plugin Slug:
easy-countdowner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flash Video Player

Plugin:

Flash Video Player

Plugin Slug:
flash-video-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Knight Lab Timeline

Plugin:

Knight Lab Timeline

Plugin Slug:
knight-lab-timelinejs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LoginPress Pro

Plugin:

LoginPress Pro

Plugin Slug:
loginpress-pro

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LoginPress Pro

Plugin:

LoginPress Pro

Plugin Slug:
loginpress-pro

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Related Posts for WordPress

Plugin Slug:
microkids-related-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:

MJ Update History

Plugin Slug:
mj-update-history

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ovic Responsive WPBakery

Plugin:

Ovic Responsive WPBakery

Plugin Slug:
ovic-vc-addon

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PeproDev CF7 Database

Plugin:

PeproDev CF7 Database

Plugin Slug:
pepro-cf7-database

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Code Insert Manager (Q2W3 Inc Manager)

Plugin:

Code Insert Manager (Q2W3 Inc Manager)

Plugin Slug:
q2w3-inc-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shopkeeper Extender

Plugin:

Shopkeeper Extender

Plugin Slug:
shopkeeper-extender

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Testimonials Showcase

Plugin:

Simple Testimonials Showcase

Plugin Slug:
simple-testimonials-showcase

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Superfly Menu

Plugin:

Superfly Menu

Plugin Slug:
superfly-menu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:

Tax Rate Upload

Plugin Slug:
tax-rate-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:

Mega Addons For Elementor

Plugin Slug:
ultimate-addons-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:

WidgetKit

Plugin Slug:
widgetkit-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

2Checkout Payment Gateway for WooCommerce

Plugin:

2Checkout Payment Gateway for WooCommerce

Plugin Slug:
woocommerce-2checkout-payment

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Registration for WooCommerce

Plugin:

Simple Registration for WooCommerce

Plugin Slug:
woocommerce-simple-registration

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP-Cufon

Plugin:

WP-Cufon

Plugin Slug:
wp-cufon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP File Download Light

Plugin:

WP File Download Light

Plugin Slug:
wp-file-download-light

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP TradingView

Plugin:

WP TradingView

Plugin Slug:
wp-tradingview

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP User Profile Avatar

Plugin:

WP User Profile Avatar

Plugin Slug:
wp-user-profile-avatar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:

Z Y N I T H

Plugin Slug:
zynith-seo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Really Simple SSL

Plugin Slug:
really-simple-ssl

Installations
5,000,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.0.0.

WooCommerce

Plugin Slug:
woocommerce

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.217

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.217.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.7.

Smart Slider 3

Plugin Slug:
smart-slider-3

Installations
900,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.1.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.23.

Meta Box � WordPress Custom Fields Framework

Plugin Slug:
meta-box

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.4.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.26.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.5.

Click to Chat � HoliThemes

Plugin Slug:
click-to-chat-for-whatsapp

Installations
500,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.6.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.10.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.5.

Migration, Backup, Staging � WPvivid

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
PHP Object Injection

Patched in Version:
0.9.100

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.100.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.972

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.972.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3.95

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.95.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.95

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.95.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.

YITH WooCommerce Compare

Plugin Slug:
yith-woocommerce-compare

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.38.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.38.0.

Ivory Search � WordPress Search Plugin

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.6.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.264

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.264.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.274

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.274.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.9.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.
Plugin Slug:
intelly-related-posts

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.30.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.9.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
5.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.4.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.3.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.3.

Enhanced Media Library

Plugin Slug:
enhanced-media-library

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.10.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.5.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
90,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.9.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.7.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.9.

VK Block Patterns

Plugin Slug:
vk-block-patterns

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.31.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.1.1.

WP Show Posts

Plugin Slug:
wp-show-posts

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

Backup Migration

Plugin Slug:
backup-backup

Installations
80,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.26.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.3.

WPZOOM Social Feed Widget & Block

Plugin Slug:
instagram-widget-by-wpzoom

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.14.

Real Media Library: Media Library Folder & File Manager

Plugin Slug:
real-media-library-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.22.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.22.12.

Theme My Login

Plugin Slug:
theme-my-login

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.7.

Comments � wpDiscuz

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.16.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
70,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.4.

Cornerstone

Plugin Slug:
cornerstone

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.8.1.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.48.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.48.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.47.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.47.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.47.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.47.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.4.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.5.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.3.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

WP 2FA � Two-factor authentication for WordPress

Plugin Slug:
wp-2fa

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.3.

hCaptcha for WordPress

Plugin Slug:
hcaptcha-for-forms-and-more

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.
Plugin Slug:
quick-featured-images

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
13.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.7.1.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.10.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.32.

Simply Static

Plugin Slug:
simply-static

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.4.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.5.

Gutenberg Block Editor Toolkit � EditorsKit

Plugin Slug:
block-options

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.40.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.40.5.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.5.45.7212

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.45.7212.

Slider by 10Web � Responsive Image Slider

Plugin Slug:
slider-wd

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.55

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.55.

Social Sharing Plugin � Social Warfare

Plugin Slug:
social-warfare

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.6.2.

Testimonial Slider

Plugin Slug:
testimonial-slider-and-showcase

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.8.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews

Installations
30,000+

Vulnerability:
Unvalidated Redirects and Forwards

Patched in Version:
3.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.1.

Appointment Hour Booking � WordPress Booking Plugin

Plugin Slug:
appointment-hour-booking

Installations
20,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.4.57

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.57.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.32.

Envo Extra

Plugin Slug:
envo-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.12.

Pricing Table by Supsystic

Plugin Slug:
pricing-table-by-supsystic

Installations
20,000+

Vulnerability:
Content Injection

Patched in Version:
1.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.13.

Rate My Post � Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.5.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

Top Bar

Plugin:

Top Bar

Plugin Slug:
top-bar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.5.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription

Installations
20,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
4.0.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.18.

WP Meta SEO

Plugin Slug:
wp-meta-seo

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.5.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.13.

WP Meta SEO

Plugin Slug:
wp-meta-seo

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.13.

Advanced Floating Content Lite

Plugin Slug:
advanced-floating-content-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.9.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.9.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.19.

Language Translate Widget for WordPress � ConveyThis

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
224

Severity Score:
High


The vulnerability has been patched, so you should update to version 224.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
4.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.3.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.3.

Easy Custom Auto Excerpt

Plugin Slug:
easy-custom-auto-excerpt

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

eCommerce Product Catalog Plugin for WordPress

Plugin Slug:
ecommerce-product-catalog

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.33

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.33.
Plugin Slug:
elespare

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

eRoom � Zoom Meetings & Webinars

Plugin Slug:
eroom-zoom-meetings-webinar

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.19.

List Custom Taxonomy Widget

Plugin Slug:
list-custom-taxonomy-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.

Mega Elements � Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

WPC Frequently Bought Together for WooCommerce

Plugin Slug:
woo-bought-together

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.4.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review

Installations
10,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element

Installations
9,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.19.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.19.5.

Elements Plus!

Plugin Slug:
elements-plus

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.16.4.

FG Joomla to WordPress

Plugin Slug:
fg-joomla-to-wordpress

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.21.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.21.0.
Plugin Slug:
gdpr-cookie-consent

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.

Media Library Folders

Plugin Slug:
media-library-plus

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.2.1.

RomethemeForm For Elementor

Plugin Slug:
romethemeform

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

WP LinkedIn Auto Publish

Plugin Slug:
wp-linkedin-auto-publish

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.12.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.9.

WP Social Comments

Plugin Slug:
gs-facebook-comments

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.4.

Maintenance Mode

Plugin Slug:
hkdev-maintenance-mode

Installations
8,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.0.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.0.2.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.8.

Icon Widget

Plugin Slug:
icon-widget

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.0.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.0.

Country State City Dropdown CF7

Plugin Slug:
country-state-city-auto-dropdown

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.2.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Env�aloSimple: Email Marketing y Newsletters

Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.

Image Slider

Plugin Slug:
image-slider-widget

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.127

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.127.

Poll Maker � Best WordPress Poll Plugin

Plugin Slug:
poll-maker

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.9.

Poll Maker � Best WordPress Poll Plugin

Plugin Slug:
poll-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.9.

Responsive Tabs

Plugin Slug:
responsive-tabs

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.7.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.15.

Salon booking system

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.6.3.

TrackShip for WooCommerce

Plugin Slug:
trackship-for-woocommerce

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.6.

Ultimate 410 Gone Status Code

Plugin Slug:
ultimate-410

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
5.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.4.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

Embed Google Photos album

Plugin Slug:
embed-google-photos-album-easily

Installations
4,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

RSS Feed Widget

Plugin Slug:
rss-feed-widget

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.8.

Tickera � WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system

Installations
4,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.5.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator

Installations
4,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
3.3.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.0.

WPC Grouped Product for WooCommerce

Plugin Slug:
wpc-grouped-product

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.3.

Coupon & Discount Code Reveal Button

Plugin Slug:
coupon-reveal-button

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

Debug Log Manager

Plugin Slug:
debug-log-manager

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.2.

WP-FormAssembly

Plugin Slug:
formassembly-web-forms

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

HelloAsso

Plugin Slug:
helloasso

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

MaxGalleria

Plugin Slug:
maxgalleria

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.3.

Navigation menu as Dropdown Widget

Plugin Slug:
navigation-menu-as-dropdown-widget

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.9.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.9.6.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.6.

Vision � Image Map Builder

Plugin Slug:
vision

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

Widget Post Slider

Plugin Slug:
widget-post-slider

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.6.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.0.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.0.

WP-Recall � Registration, Profile, Commerce & More

Plugin Slug:
wp-recall

Installations
3,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
16.26.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 16.26.6.

WP Stripe Checkout

Plugin Slug:
wp-stripe-checkout

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2.42

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.42.

Accessibility Widget

Plugin Slug:
accessibility-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.
Plugin Slug:
advanced-testimonial-carousel-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

All-in-one Like Widget

Plugin Slug:
all-in-one-facebook-like-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.0.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.0.25.

Kattene

Plugin:

Kattene

Plugin Slug:
kattene

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.23.

Mortgage Calculators WP

Plugin Slug:
mortgage-calculators-wp

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.60

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.60.

SuperFaktura WooCommerce

Plugin Slug:
woocommerce-superfaktura

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.40.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.40.4.

WP Helper Premium

Plugin Slug:
wp-helper-lite

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.0.

ActiveDEMAND

Plugin Slug:
activedemand

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.2.42

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.2.42.

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.1.

Attesa Extra

Plugin Slug:
attesa-extra

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.0.

Backend Designer

Plugin Slug:
backend-designer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Import Content in WordPress & WooCommerce with Excel

Plugin Slug:
content-excel-importer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.

Culqi

Plugin:

Culqi

Plugin Slug:
culqi-checkout

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.15.

DSGVO Youtube

Plugin Slug:
dsgvo-youtube

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.6.

USPS Shipping for WooCommerce � Live Rates

Plugin Slug:
flexible-shipping-usps

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.0.

Headline Analyzer

Plugin Slug:
headline-analyzer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.8.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.94

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.94.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.17.

Netgsm

Plugin:

Netgsm

Plugin Slug:
netgsm

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.

Reviews Plus

Plugin Slug:
reviews-plus

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.
Plugin Slug:
seers-cookie-consent-banner-privacy-policy

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.1.

WooCommerce Shipping Label

Plugin Slug:
shipping-labels-for-woo

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.9.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

Void Elementor WHMCS Elements For Elementor Page Builder

Plugin Slug:
void-elementor-whmcs-elements

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

Multi Currency For WooCommerce

Plugin Slug:
wc-multi-currency

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Order Limit for WooCommerce

Plugin Slug:
wc-order-limit-lite

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP Club Manager � WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.

WP Club Manager � WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.

WP Dynamic Keywords Injector

Plugin Slug:
wp-dynamic-keywords-injector

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.22.

WP GoToWebinar

Plugin Slug:
wp-gotowebinar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
15.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.1.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.1.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.

WP Smart Import : Import any XML File to WordPress

Plugin Slug:
wp-smart-import

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

WPCal.io � Easy Meeting Scheduler

Plugin Slug:
wpcal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.5.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.4.

Olive One Click Demo Import

Plugin Slug:
olive-one-click-demo-import

Installations
900+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Language Switcher for Transposh

Plugin Slug:
language-switcher-for-transposh

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.0.

BMI Adult & Kid Calculator

Plugin Slug:
bmi-adultkid-calculator

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

ShortPixel Critical CSS

Plugin Slug:
shortpixel-critical-css

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.3.

Fixed HTML Toolbar

Plugin Slug:
fixed-html-toolbar

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

NPS computy

Plugin Slug:
nps-computy

Installations
90+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.6.

NPS computy

Plugin Slug:
nps-computy

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.6.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
SQL Injection

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Arbitrary File Deletion

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

Barcode Scanner with Inventory & Order Manager

Plugin:

Barcode Scanner with Inventory & Order Manager

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.

CBX Bookmark & Favorite

Plugin:

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.22.

Chauffeur Taxi Booking System for WordPress

Plugin:

Chauffeur Taxi Booking System for WordPress

Plugin Slug:
chauffeur-booking-system

Vulnerability:
Broken Authentication

Patched in Version:
7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.

Conversational Forms for ChatBot

Plugin:

Conversational Forms for ChatBot

Plugin Slug:
conversational-forms

Vulnerability:
Arbitrary File Download

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

Essential Addons for Elementor Pro

Plugin:

Essential Addons for Elementor Pro

Plugin Slug:
essential-addons-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.12.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.81.

Integrate Google Drive

Plugin:

Integrate Google Drive

Plugin Slug:
integrate-google-drive

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.91.

Integrate Google Drive

Plugin:

Integrate Google Drive

Plugin Slug:
integrate-google-drive

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.91.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

Max Addons Pro for Bricks

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

Max Addons Pro for Bricks

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Settings Change

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
SQL Injection

Patched in Version:
29.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 29.7.

Automatic

Plugin:

Automatic

Plugin Slug:
wp-automatic

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.93.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.93.0.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.1.76

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.1.76.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
Broken Access Control

Patched in Version:
10.1.77

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.1.77.

WP Media Category Management

Plugin:

WP Media Category Management

Plugin Slug:
wp-media-category-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.0.

Wp Staging Pro

Plugin:

Wp Staging Pro

Plugin Slug:
wp-staging-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.0.

WordPress Themes � 2 Patched / 1 Unpatched

GuCherry Blog

Theme Slug:
gucherry-blog

Downloads
137,149

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit

Downloads
457,475

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.117

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.117.

Tainacan Interface

Theme Slug:
tainacan-interface

Downloads
16,620

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.2.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…