Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 22, 2024

In this report, 153 vulnerabilities have been publicly disclosed. Security patches for 119 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 34 plugin and themes vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

WordPress Plugins � 109 Patched / 33 Unpatched

Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds

Plugin Slug:
tagembed-widget

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

reCAPTCHA Jetpack

Plugin Slug:
recaptcha-jetpack

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

reCAPTCHA Jetpack

Plugin Slug:
recaptcha-jetpack

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UnGallery

Plugin Slug:
ungallery

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add Custom CSS and JS

Plugin Slug:
add-custom-css-and-js

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Stacker

Plugin Slug:
wp-stacker

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AdFoxly � Ad Manager, AdSense Ads & Ads.txt

Plugin:

AdFoxly � Ad Manager, AdSense Ads & Ads.txt

Plugin Slug:
adfoxly

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Crafthemes Demo Import

Plugin:

Crafthemes Demo Import

Plugin Slug:
crafthemes-demo-import

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dextaz Ping

Plugin:

Dextaz Ping

Plugin Slug:
dextaz-ping

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Elegant Blocks

Plugin:

Elegant Blocks

Plugin Slug:
elegant-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fast Custom Social Share by CodeBard

Plugin:

Fast Custom Social Share by CodeBard

Plugin Slug:
fast-custom-social-share-by-codebard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:

HL Twitter

Plugin Slug:
hl-twitter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:

HL Twitter

Plugin Slug:
hl-twitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LetterPress

Plugin:

LetterPress

Plugin Slug:
letterpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Popup4Phone

Plugin:

Popup4Phone

Plugin Slug:
popup4phone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Popup4Phone

Plugin:

Popup4Phone

Plugin Slug:
popup4phone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PopupAlly

Plugin:

PopupAlly

Plugin Slug:
popupally

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Praison SEO WordPress

Plugin:

Praison SEO WordPress

Plugin Slug:
seo-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Popup Manager

Plugin:

Simple Popup Manager

Plugin Slug:
simple-popup-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Directory Traversal

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Backpack

Plugin:

WP Backpack

Plugin Slug:
wp-backpack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Next Post Navi

Plugin:

WP Next Post Navi

Plugin Slug:
wp-next-post-navi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:

WP Prayer

Plugin Slug:
wp-prayer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPB Elementor Addons

Plugin:

WPB Elementor Addons

Plugin Slug:
wpb-elementor-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin Slug:
wordpress-seo

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
22.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 22.7.

Jetpack � WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.4.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.219-beta

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.219-beta.
Plugin Slug:
header-footer-elementor

Installations
1,000,000+

Vulnerability:
Content Injection

Patched in Version:
1.6.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.27.
Plugin Slug:
header-footer-elementor

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.29.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.29.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.29.16.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.0.1.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.6.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.2.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.9.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.8.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.975

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.975.

Menu Icons by ThemeIsle

Plugin Slug:
menu-icons

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.13.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.13.14.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.0.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

iframe

Plugin:

iframe

Plugin Slug:
iframe

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.

Master Slider � Responsive Touch Slider

Plugin Slug:
master-slider

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.10.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.7.

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.32.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.1.

Visual Portfolio, Photo Gallery & Post Grid

Plugin Slug:
visual-portfolio

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.7.

WP Table Builder � WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.15.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.28.
Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.0.

Envo Extra

Plugin Slug:
envo-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.17.

Post Grid Elementor Addon

Plugin Slug:
post-grid-elementor-addon

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.17.

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin Slug:
wpzoom-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.37.

Mega Elements � Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
20240511

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20240511.

140+ Widgets | Best Addons For Elementor � FREE

Plugin Slug:
xpro-elementor-addons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.3.1.

YITH WooCommerce Gift Cards

Plugin Slug:
yith-woocommerce-gift-cards

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.13.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.13.0.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
8,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.8.

WP Compress � Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.20.02

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.20.02.

WP Compress � Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Open Redirection

Patched in Version:
6.20.02

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.20.02.

JCH Optimize

Plugin Slug:
jch-optimize

Installations
6,000+

Vulnerability:
Path Traversal

Patched in Version:
4.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.1.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Debug Log � Manger Tool

Plugin Slug:
debug-log-config-tool

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

FundEngine � Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.0.

Kognetiks Chatbot for WordPress

Plugin Slug:
chatbot-chatgpt

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.0.1.

Copymatic � AI Content Writer & Generator

Plugin Slug:
copymatic

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.

Custom Post Type Attachment

Plugin Slug:
custom-post-type-pdf-attachment

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.6.

Fastly

Plugin:

Fastly

Plugin Slug:
fastly

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.26.

Fastly

Plugin:

Fastly

Plugin Slug:
fastly

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.26.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.9.58

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.58.

Popup Builder

Plugin Slug:
easy-notify-lite

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.30.

Popup � Popup More Popups

Plugin Slug:
popup-more

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.3.

Bulk Posts Editing For WordPress

Plugin Slug:
ithemeland-bulk-posts-editing-lite

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.4.

Bulk Posts Editing For WordPress

Plugin Slug:
ithemeland-bulk-posts-editing-lite

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.4.

month name translation benaceur

Plugin Slug:
month-name-translation-benaceur

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.8.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Arbitrary Code Execution

Patched in Version:
6.2.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.2.10.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Local File Inclusion

Patched in Version:
6.2.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.2.10.

ConvertPlus

Plugin:

ConvertPlus

Plugin Slug:
convertplug

Vulnerability:
PHP Object Injection

Patched in Version:
3.5.26.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.26.1.

Cost Calculator Builder Pro

Plugin:

Cost Calculator Builder Pro

Plugin Slug:
cost-calculator-builder-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.73

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.73.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.2.

Penci Soledad Data Migrator

Plugin:

Penci Soledad Data Migrator

Plugin Slug:
penci-data-migrator

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.1.

Swift Framework Page Builder

Plugin:

Swift Framework Page Builder

Plugin Slug:
socialdriver-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2024.0.0.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

Uber Menu

Plugin:

Uber Menu

Plugin Slug:
ubermenu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.3.

Automatic

Plugin:

Automatic

Plugin Slug:
wp-automatic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.95.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.95.0.

WordPress Themes � 10 Patched / 1 Unpatched

ImageMagick Sharpen Resized Images

Theme:

ImageMagick Sharpen Resized Images

Theme Slug:
imagemagick-sharpen-resized-images

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,200,500

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.47

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.47.

ChaosTheory

Theme Slug:
chaostheory

Downloads
441,334

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Consus

Theme:

Consus

Theme Slug:
consus

Downloads
16,413

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

EmpowerWP

Theme Slug:
empowerwp

Downloads
219,617

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.22.

Ketos

Theme:

Ketos

Theme Slug:
ketos

Downloads
28,821

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Mindscape

Theme Slug:
mindscape

Downloads
42,404

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

Niveau

Theme:

Niveau

Theme Slug:
niveau

Downloads
16,949

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

Oasis

Theme:

Oasis

Theme Slug:
oasis

Downloads
69,561

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.13.

Skyline WP

Theme Slug:
skyline-wp

Downloads
169,826

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

Zeka

Theme:

Zeka

Theme Slug:
zeka

Downloads
20,361

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.10.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…