Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 1, 2024

In this report, 359 vulnerabilities have been publicly disclosed. Security patches for 269 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 90 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.2 was released on April 9, 2024, as a short-cycle security and maintenance release. This release features 2 bug fixes on Core, 12 bug fixes for the Block editor, and 1 security fix. Because this is a security release, it is recommended that you update your sites immediately.

The next major release will be version 6.6 planned for July 16, 2024.

WordPress Plugins � 248 Patched / 21 Unpatched

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FameTheme Demo Importer

Plugin Slug:
famethemes-demo-importer

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AGCA � Custom Dashboard & Login Page

Plugin Slug:
ag-custom-admin

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Serious Slider

Plugin Slug:
cryout-serious-slider

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xserver Migrator

Plugin Slug:
xserver-migrator

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Annual Archive

Plugin Slug:
anual-archive

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Democracy Poll

Plugin Slug:
democracy-poll

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meks ThemeForest Smart Widget

Plugin Slug:
meks-themeforest-smart-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Print-O-Matic

Plugin Slug:
print-o-matic

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Recent Posts Widget

Plugin Slug:
smart-recent-posts-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Customify Site Library

Plugin Slug:
customify-sites

Installations
6,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Ad Widget

Plugin Slug:
ad-widget

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PopupAlly

Plugin Slug:
popupally

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pretty Google Calendar

Plugin Slug:
pretty-google-calendar

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fan Page Widget by ThemeNcode

Plugin Slug:
facebook-fan-page-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Filterable Portfolio

Plugin Slug:
filterable-portfolio

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Share This Image

Plugin Slug:
share-this-image

Installations
2,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Maintenance Mode

Plugin Slug:
smart-maintenance-mode

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ENL Newsletter

Plugin Slug:
enl-newsletter

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Advanced Search

Plugin Slug:
advance-search

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Most Recent Posts Mod

Plugin:

Advanced Most Recent Posts Mod

Plugin Slug:
advanced-most-recent-posts-mod

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Post List

Plugin:

Advanced Post List

Plugin Slug:
advanced-post-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AJAX Login and Registration modal popup + inline form

Plugin:

AJAX Login and Registration modal popup + inline form

Plugin Slug:
ajax-login-and-registration-modal-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Element Pack Pro

Plugin:

Element Pack Pro

Plugin Slug:
bdthemes-element-pack

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CF7 File Download � File Download for CF7

Plugin:

CF7 File Download � File Download for CF7

Plugin Slug:
cf7-file-download

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Client Dash

Plugin:

Client Dash

Plugin Slug:
client-dash

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Extension For Mailchimp

Plugin:

Contact Form 7 Extension For Mailchimp

Plugin Slug:
contact-form-7-mailchimp-extension

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CPO Companion

Plugin:

CPO Companion

Plugin Slug:
cpo-companion

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:

Crelly Slider

Plugin Slug:
crelly-slider

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Set Favicon

Plugin:

Easy Set Favicon

Plugin Slug:
easy-set-favicon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Fonts

Plugin:

Embed Google Fonts

Plugin Slug:
embed-google-fonts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

XStore Core

Plugin:

XStore Core

Plugin Slug:
et-core-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Giphypress

Plugin:

Giphypress

Plugin Slug:
giphypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GWP-Histats

Plugin:

GWP-Histats

Plugin Slug:
gwp-histats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JW Player for WordPress

Plugin:

JW Player for WordPress

Plugin Slug:
jw-player-7-for-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:

MF Gig Calendar

Plugin Slug:
mf-gig-calendar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mini Loops

Plugin:

Mini Loops

Plugin Slug:
mini-loops

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Opal Widgets For Elementor

Plugin:

Opal Widgets For Elementor

Plugin Slug:
opal-widgets-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Plugin:

CodeBard’s Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PB MailCrypt

Plugin:

PB MailCrypt

Plugin Slug:
pb-mailcrypt-antispam-email-encryption

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor Pro

Plugin:

Piotnet Addons For Elementor Pro

Plugin Slug:
piotnet-addons-for-elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Progressive WordPress (PWA)

Plugin:

Progressive WordPress (PWA)

Plugin Slug:
progressive-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:

Realtyna Organic IDX plugin

Plugin Slug:
real-estate-listing-realtyna-wpl

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Recencio Book Reviews

Plugin:

Recencio Book Reviews

Plugin Slug:
recencio-book-reviews

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Regenerate post permalink

Plugin:

Regenerate post permalink

Plugin Slug:
regenerate-post-permalinks

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management Pro

Plugin:

School Management Pro

Plugin Slug:
school-management-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sliding Widgets

Plugin:

Sliding Widgets

Plugin Slug:
sliding-widgets

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons by Supsystic

Plugin:

Social Share Buttons by Supsystic

Plugin Slug:
social-share-buttons-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Solid Affiliate

Plugin:

Solid Affiliate

Plugin Slug:
solid-affiliate

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Anything

Plugin:

Sticky Anything

Plugin Slug:
toast-stick-anything

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit

Plugin:

WidgetKit

Plugin Slug:
widgetkit-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:

WZone

Plugin Slug:
woozone

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP GDPR Compliance

Plugin:

WP GDPR Compliance

Plugin Slug:
wp-gdpr-compliance

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Masquerade

Plugin:

WP Masquerade

Plugin Slug:
wp-masquerade

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Page Post Widget Clone

Plugin:

WP Page Post Widget Clone

Plugin Slug:
wp-page-post-widget-clone

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WTI Like Post

Plugin:

WTI Like Post

Plugin Slug:
wti-like-post

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

XforWooCommerce

Plugin:

XforWooCommerce

Plugin Slug:
xforwoocommerce

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.217

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.217.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.29.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.26.

Spectra � WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
700,000+

Vulnerability:
Path Traversal

Patched in Version:
2.12.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.7.

Contact Form 7 Database Addon � CFDB7

Plugin Slug:
contact-form-cfdb7

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.7.

Duplicate Post

Plugin Slug:
copy-delete-posts

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.5.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.972

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.972.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3.95

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.95.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.5.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

YITH WooCommerce Compare

Plugin Slug:
yith-woocommerce-compare

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.38.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.38.0.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.4.

BackUpWordPress

Plugin Slug:
backupwordpress

Installations
100,000+

Vulnerability:
Directory Traversal

Patched in Version:
3.14

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.14.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.264

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.264.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.274

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.274.

FileOrganizer � Manage WordPress and Website Files

Plugin Slug:
fileorganizer

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

Social Sharing Plugin � Sassy Social Share

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.61.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.30.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.12.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.7.

WP Chat App

Plugin Slug:
wp-whatsapp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.4.

VK Block Patterns

Plugin Slug:
vk-block-patterns

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.31.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.1.1.

Backup Migration

Plugin Slug:
backup-backup

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.26.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.3.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

WP SMTP

Plugin:

WP SMTP

Plugin Slug:
wp-smtp

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
1.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.7.

Comments � wpDiscuz

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.16.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.9.

Media Cleaner: Clean your WordPress!

Plugin Slug:
media-cleaner

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.3.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
70,000+

Vulnerability:
Deserialization of untrusted data

Patched in Version:
2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.4.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.4.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.5.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.9.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.4.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.4.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.5.

Collapse-O-Matic

Plugin Slug:
jquery-collapse-o-matic

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.5.6.
Plugin Slug:
quick-featured-images

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
13.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.7.1.

Simple Membership

Plugin Slug:
simple-membership

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.4.
Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.

Simply Static

Plugin Slug:
simply-static

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.4.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.0.

AGCA � Custom Dashboard & Login Page

Plugin Slug:
ag-custom-admin

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.2.

Popup Box � Best WordPress Popup Plugin

Plugin Slug:
ays-popup-box

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.7.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.5.45.7212

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.45.7212.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.12.

Social Sharing Plugin � Social Warfare

Plugin Slug:
social-warfare

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.6.2.

VOD Infomaniak

Plugin Slug:
vod-infomaniak

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.7.

WP Google Review Slider

Plugin Slug:
wp-google-places-review-slider

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.6.

Hide Dashboard Notifications

Plugin Slug:
wp-hide-backed-notices

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Appointment Hour Booking � WordPress Booking Plugin

Plugin Slug:
appointment-hour-booking

Installations
20,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.4.57

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.57.

Payment Gateway Based Fees and Discounts for WooCommerce

Plugin Slug:
checkout-fees-for-woocommerce

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.12.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.2.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.32.

Pricing Table by Supsystic

Plugin Slug:
pricing-table-by-supsystic

Installations
20,000+

Vulnerability:
Content Injection

Patched in Version:
1.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.13.

Rate My Post � Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post

Installations
20,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.5.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.2.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api

Installations
20,000+

Vulnerability:
Open Redirection

Patched in Version:
4.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.5.

Product Addons & Fields for WooCommerce

Plugin Slug:
woocommerce-product-addon

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
32.0.19

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 32.0.19.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription

Installations
20,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
4.0.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.18.

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin Slug:
wpzoom-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.36.

Advanced Floating Content Lite

Plugin Slug:
advanced-floating-content-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.19.
Plugin Slug:
elespare

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

SSL Mixed Content Fix

Plugin Slug:
http-https-remover

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.7.

List Custom Taxonomy Widget

Plugin Slug:
list-custom-taxonomy-widget

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.39

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.39.

Pop-up

Plugin:

Pop-up

Plugin Slug:
pop-up-pop-up

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Send PDF for Contact Form 7

Plugin Slug:
send-pdf-for-contact-form-7

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.4.

Ultimate Posts Widget

Plugin Slug:
ultimate-posts-widget

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Easy Accept Payments via PayPal

Plugin Slug:
wordpress-easy-paypal-payment-or-donation-accept-plugin

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.1.

Arconix FAQ

Plugin Slug:
arconix-faq

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.4.

FG Joomla to WordPress

Plugin Slug:
fg-joomla-to-wordpress

Installations
9,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.21.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.21.0.

RomethemeForm For Elementor

Plugin Slug:
romethemeform

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

WP LinkedIn Auto Publish

Plugin Slug:
wp-linkedin-auto-publish

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.12.

WordPress Backup & Migration

Plugin Slug:
wp-migration-duplicator

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.9.

Maintenance Mode

Plugin Slug:
hkdev-maintenance-mode

Installations
8,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.0.2

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.0.2.

WPC Composite Products for WooCommerce

Plugin Slug:
wpc-composite-products

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.8.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.0.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.0.

The Plus Blocks for Block Editor | Gutenberg

Plugin Slug:
the-plus-addons-for-block-editor

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.6.

Better Elementor Addons

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

Image Slider

Plugin Slug:
image-slider-widget

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.127

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.127.
Plugin Slug:
integrate-google-drive

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.91.
Plugin Slug:
integrate-google-drive

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.91

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.91.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.11.

Assistant � Every Day Productivity Apps

Plugin Slug:
assistant

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.9.2.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.15.

Salon booking system

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.6.6.

Salon booking system

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.6.6.

Salon booking system

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.6.6.

Ultimate 410 Gone Status Code

Plugin Slug:
ultimate-410

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Advanced Local Pickup for WooCommerce

Plugin Slug:
advanced-local-pickup-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

Embed Google Photos album

Plugin Slug:
embed-google-photos-album-easily

Installations
4,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

Tickera � WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system

Installations
4,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.5.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

Coupon & Discount Code Reveal Button

Plugin Slug:
coupon-reveal-button

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

Debug Log Manager

Plugin Slug:
debug-log-manager

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.2.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.9.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.9.6.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.6.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.13.

Vision � Image Map Builder

Plugin Slug:
vision

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

Widget Post Slider

Plugin Slug:
widget-post-slider

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.6.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.6.0.

Accessibility Widget

Plugin Slug:
accessibility-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.
Plugin Slug:
advanced-testimonial-carousel-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

All-in-one Like Widget

Plugin Slug:
all-in-one-facebook-like-widget

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

Custom field finder

Plugin Slug:
custom-field-finder

Installations
2,000+

Vulnerability:
PHP Object Injection

Patched in Version:
0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.4.

RSS Redirect & Feedburner Alternative

Plugin Slug:
feedburner-alternative-and-rss-redirect

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.0.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.0.25.

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

SuperFaktura WooCommerce

Plugin Slug:
woocommerce-superfaktura

Installations
2,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.40.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.40.4.

ActiveDEMAND

Plugin Slug:
activedemand

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.2.42

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.2.42.

Admin Bar Editor � Hide Toolbar by User Roles

Plugin Slug:
admin-bar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.1.

ChatBot Conversational Forms

Plugin Slug:
conversational-forms

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

Culqi

Plugin:

Culqi

Plugin Slug:
culqi-checkout

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.15.

EPROLO Dropshipping

Plugin Slug:
eprolo-dropshipping

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.2.

USPS Shipping for WooCommerce � Live Rates

Plugin Slug:
flexible-shipping-usps

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.10.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.0.

Headline Analyzer

Plugin Slug:
headline-analyzer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.94

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.94.

Reviews Plus

Plugin Slug:
reviews-plus

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.
Plugin Slug:
seers-cookie-consent-banner-privacy-policy

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.1.

Image Optimizer, Resizer and CDN � Sirv

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
7.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.3.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

WP Club Manager � WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.12.

WP GoToWebinar

Plugin Slug:
wp-gotowebinar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
15.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 15.1.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.1.

WP Time Slots Booking Form

Plugin Slug:
wp-time-slots-booking-form

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.07

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.07.

WPCal.io � Easy Meeting Scheduler

Plugin Slug:
wpcal

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
0.9.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.5.9.

WPPizza � A Restaurant Plugin

Plugin Slug:
wppizza

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.18.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.18.11.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.4.

Leaky Paywall

Plugin Slug:
leaky-paywall

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
4.20.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.20.9.

Olive One Click Demo Import

Plugin Slug:
olive-one-click-demo-import

Installations
900+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

Barcode Scanner and Inventory manager. POS (Point of Sale) � scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.4.

Slash Admin

Plugin Slug:
slash-admin

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.2.

Car Dealer (Dealership) and Vehicle sales

Plugin Slug:
cardealer

Installations
700+

Vulnerability:
Content Injection

Patched in Version:
4.16

Severity Score:
Low


The vulnerability has been patched, so you should update to version 4.16.

ShortPixel Critical CSS

Plugin Slug:
shortpixel-critical-css

Installations
700+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.3.

Better Comments

Plugin Slug:
better-comments

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Better Comments

Plugin Slug:
better-comments

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.
Plugin:

Header Footer Code Manager Pro

Plugin Slug:
99robots-header-footer-code-manager-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.17.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
SQL Injection

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Arbitrary File Deletion

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.1.

ARForms Form Builder

Plugin:

ARForms Form Builder

Plugin Slug:
arforms-form-builder

Vulnerability:
Broken Access Control

Patched in Version:
1.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.5.

Digital Publications by Supsystic

Plugin:

Digital Publications by Supsystic

Plugin Slug:
digital-publications-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Local File Inclusion

Patched in Version:
3.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.1.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.8.

Interactive World Maps

Plugin:

Interactive World Maps

Plugin Slug:
interactive-world-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.

Max Addons Pro for Bricks

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

Max Addons Pro for Bricks

Plugin:

Max Addons Pro for Bricks

Plugin Slug:
max-addons-pro-bricks

Vulnerability:
Settings Change

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

WooCommerce Shipping Label

Plugin:

WooCommerce Shipping Label

Plugin Slug:
shipping-labels-for-woo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.9.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Broken Access Control

Patched in Version:
29.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 29.8.

WooCommerce Customers Manager

Plugin:

WooCommerce Customers Manager

Plugin Slug:
woocommerce-customers-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
29.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 29.8.

WP Media Category Management

Plugin:

WP Media Category Management

Plugin Slug:
wp-media-category-management

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.0.

Wp Staging Pro

Plugin:

Wp Staging Pro

Plugin Slug:
wp-staging-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.0.

WordPress Themes � 21 Patched / 7 Unpatched

UDesign

Theme:

UDesign

Theme Slug:
u-design

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

XStore

Theme:

XStore

Theme Slug:
xstore

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Accountra

Theme Slug:
accountra

Downloads
20,885

Vulnerability:
Broken Access Control

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Althea WP

Theme Slug:
althea-wp

Downloads
52,642

Vulnerability:
Broken Access Control

Patched in Version:
1.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.16.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,113,676

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.40

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.40.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,113,676

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.34.

Brite

Theme:

Brite

Theme Slug:
brite

Downloads
125,207

Vulnerability:
Broken Access Control

Patched in Version:
1.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.15.

Colibri WP

Theme Slug:
colibri-wp

Downloads
1,271,195

Vulnerability:
Broken Access Control

Patched in Version:
1.0.99

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.99.

ColorNews

Theme Slug:
colornews

Downloads
266,626

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Elevate WP

Theme Slug:
elevate-wp

Downloads
70,130

Vulnerability:
Broken Access Control

Patched in Version:
1.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.17.

Financio

Theme Slug:
financio

Downloads
17,197

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

Hugo WP

Theme:

Hugo WP

Theme Slug:
hugo-wp

Downloads
59,334

Vulnerability:
Broken Access Control

Patched in Version:
1.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.10.

Intrace

Theme:

Intrace

Theme Slug:
intrace

Downloads
84,888

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

Pathway

Theme:

Pathway

Theme Slug:
pathway

Downloads
57,050

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.16.

Photology

Theme Slug:
photology

Downloads
17,339

Vulnerability:
Broken Access Control

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit

Downloads
461,793

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.117

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.117.

Startupzy

Theme Slug:
startupzy

Downloads
66,824

Vulnerability:
Broken Access Control

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Teluro

Theme:

Teluro

Theme Slug:
teluro

Downloads
188,771

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.36.

Travey

Theme:

Travey

Theme Slug:
travey

Downloads
17,666

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

Vertice

Theme:

Vertice

Theme Slug:
vertice

Downloads
47,531

Vulnerability:
Broken Access Control

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

Virtue

Theme:

Virtue

Theme Slug:
virtue

Downloads
2,473,892

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.

WP Portfolio

Theme Slug:
wp-portfolio

Downloads
82,208

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.

Zeever

Theme:

Zeever

Theme Slug:
zeever

Downloads
208,788

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…