Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 26, 2024

In this report, 194 vulnerabilities have been publicly disclosed. Security patches for 100 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 94 plugin and themes vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.5 is now available! This release features three security fixes. Because this is a security release, it is recommended that you update your sites immediately. This minor release also includes 3 bug fixes in Core.

WordPress Plugins � 85 Patched / 91 Unpatched

Custom Field Suite

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Suite

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Suite

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Favorites

Plugin Slug:
my-favorites

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Zoho Marketing Automation

Plugin Slug:
zoho-marketinghub

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accordions

Plugin:

Accordions

Plugin Slug:
accordions-or-faqs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ali2Woo Lite

Plugin:

Ali2Woo Lite

Plugin Slug:
ali2woo-lite

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bible Text

Plugin:

Bible Text

Plugin Slug:
bible-text

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blogmentor � Blog Layouts for Elementor

Plugin:

Blogmentor � Blog Layouts for Elementor

Plugin Slug:
blogmentor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blogmentor � Blog Layouts for Elementor

Plugin:

Blogmentor � Blog Layouts for Elementor

Plugin Slug:
blogmentor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scheduling Plugin � Online Booking for WordPress

Plugin:

Scheduling Plugin � Online Booking for WordPress

Plugin Slug:
calendar-booking

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CB (legacy)

Plugin:

CB (legacy)

Plugin Slug:
commons-booking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CB (legacy)

Plugin:

CB (legacy)

Plugin Slug:
commons-booking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSSable Countdown

Plugin:

CSSable Countdown

Plugin Slug:
cssable-countdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Product List Table

Plugin:

Custom Product List Table

Plugin Slug:
custom-product-list-table

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Demo Awesome

Plugin:

Demo Awesome

Plugin Slug:
demo-awesome

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Demo Awesome

Plugin:

Demo Awesome

Plugin Slug:
demo-awesome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DImage 360

Plugin:

DImage 360

Plugin Slug:
dimage-360

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DOP Shortcodes

Plugin:

DOP Shortcodes

Plugin Slug:
dop-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elegant Themes Icons

Plugin:

Elegant Themes Icons

Plugin Slug:
elegant-themes-icons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EmbedSocial

Plugin:

EmbedSocial

Plugin Slug:
embedalbum-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Empty Cart Button for WooCommerce

Plugin:

Empty Cart Button for WooCommerce

Plugin Slug:
empty-cart-button-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Export WP Page to Static HTML/CSS

Plugin:

Export WP Page to Static HTML/CSS

Plugin Slug:
export-wp-page-to-static-html

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FS Poster

Plugin:

FS Poster

Plugin Slug:
fs-poster

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Universal Slider

Plugin:

Universal Slider

Plugin Slug:
fusion-slider

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Plugin:

Kanban Boards for WordPress

Plugin Slug:
kanban

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kimili Flash Embed

Plugin:

Kimili Flash Embed

Plugin Slug:
kimili-flash-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Laybuy Payment Extension for WooCommerce

Plugin:

Laybuy Payment Extension for WooCommerce

Plugin Slug:
laybuy-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

License Manager for WooCommerce

Plugin:

License Manager for WooCommerce

Plugin Slug:
license-manager-for-woocommerce

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Lifeline Donation

Plugin:

Lifeline Donation

Plugin Slug:
lifeline-donation

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Live Composer

Plugin:

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Live Composer

Plugin:

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder: Live Composer

Plugin:

Page Builder: Live Composer

Plugin Slug:
live-composer-page-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MIMO Woocommerce Order Tracking

Plugin:

MIMO Woocommerce Order Tracking

Plugin Slug:
mimo-woocommerce-order-tracking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Restaurant Reservations

Plugin:

Restaurant Reservations

Plugin Slug:
nd-restaurant-reservations

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WordPress Picture / Portfolio / Media Gallery

Plugin Slug:
nimble-portfolio

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OSM Map Widget for Elementor

Plugin:

OSM Map Widget for Elementor

Plugin Slug:
osm-map-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich � Front-End Page Builder

Plugin:

Page Builder Sandwich � Front-End Page Builder

Plugin Slug:
page-builder-sandwich

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich � Front-End Page Builder

Plugin:

Page Builder Sandwich � Front-End Page Builder

Plugin Slug:
page-builder-sandwich

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Page Builder Sandwich � Front-End Page Builder

Plugin:

Page Builder Sandwich � Front-End Page Builder

Plugin Slug:
page-builder-sandwich

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode

Plugin:

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode

Plugin Slug:
paypal-pay-buy-donation-and-cart-buttons-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin:

PDF Viewer for Elementor

Plugin Slug:
pdf-viewer-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Photo Video Gallery Master

Plugin Slug:
photo-video-gallery-master

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

phpinfo() WP

Plugin:

phpinfo() WP

Plugin Slug:
phpinfo-wp

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Play.ht

Plugin:

Play.ht

Plugin Slug:
play-ht

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Promolayer

Plugin:

Promolayer

Plugin Slug:
promolayer-popup-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Replace Image

Plugin:

Replace Image

Plugin Slug:
replace-image

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sketchfab Embed

Plugin:

Sketchfab Embed

Plugin Slug:
sketchfab-oembed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slideshow SE

Plugin:

Slideshow SE

Plugin Slug:
slideshow-se

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slideshow SE

Plugin:

Slideshow SE

Plugin Slug:
slideshow-se

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Directory Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Transition Slider � Responsive Image Slider and Gallery

Plugin Slug:
transition-slider-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

User Rights Access Manager

Plugin:

User Rights Access Manager

Plugin Slug:
user-rights-access-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tabs

Plugin:

Tabs

Plugin Slug:
vc-tabs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wheel of Life

Plugin:

Wheel of Life

Plugin Slug:
wheel-of-life

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Denial of Service Attack

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Arbitrary Code Execution

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:

WishList Member X

Plugin Slug:
wishlist-member-x

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Customers Order History

Plugin:

Woocommerce Customers Order History

Plugin Slug:
woo-customers-order-history

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Word Balloon

Plugin:

Word Balloon

Plugin Slug:
word-balloon

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Blog Post Layouts

Plugin:

WP Blog Post Layouts

Plugin Slug:
wp-blog-post-layouts

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Hotel Booking

Plugin:

WP Hotel Booking

Plugin Slug:
wp-hotel-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Logs Book

Plugin:

WP Logs Book

Plugin Slug:
wp-logs-book

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Logs Book

Plugin:

WP Logs Book

Plugin Slug:
wp-logs-book

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pexels: Free Stock Photos

Plugin:

Pexels: Free Stock Photos

Plugin Slug:
wp-pexels-free-stock-photos

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Scraper

Plugin:

WP Scraper

Plugin Slug:
wp-scraper

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widget Bundle

Plugin:

Widget Bundle

Plugin Slug:
wp-widget-bundle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widget Bundle

Plugin:

Widget Bundle

Plugin Slug:
wp-widget-bundle

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Widget Bundle

Plugin:

Widget Bundle

Plugin Slug:
wp-widget-bundle

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Loco Translate

Plugin Slug:
loco-translate

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.10.

SiteGuard WP Plugin

Plugin Slug:
siteguard

Installations
500,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Open Redirection

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.9.1.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.35.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.8.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
SQL Injection

Patched in Version:
3.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.17.

User Profile Picture

Plugin Slug:
metronet-profile-picture

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

WP 2FA � Two-factor authentication for WordPress

Plugin Slug:
wp-2fa

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.20.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.20.
Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.5.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

WP Maintenance

Plugin Slug:
wp-maintenance

Installations
50,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
6.1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.9.3.

BlossomThemes Email Newsletter

Plugin Slug:
blossomthemes-email-newsletter

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.9.4.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.0.

Hide Dashboard Notifications

Plugin Slug:
wp-hide-backed-notices

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

WP SVG Images

Plugin Slug:
wp-svg-images

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.

Serious Slider

Plugin Slug:
cryout-serious-slider

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Table Addons for Elementor

Plugin Slug:
table-addons-for-elementor

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin Slug:
wpzoom-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.39

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.39.

JetWidgets For Elementor

Plugin Slug:
jetwidgets-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.18.

Sparkle Demo Importer

Plugin Slug:
sparkle-demo-importer

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.8.

WP Child Theme Generator

Plugin Slug:
wp-child-theme-generator

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.
Plugin Slug:
vimeography

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

WP Magazine Modules Lite

Plugin Slug:
wp-magazine-modules-lite

Installations
7,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.3.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Salon Booking System

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
10.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.0.

Salon Booking System

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
10.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 10.3.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.1.0.39

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.1.0.39.

Tickera � WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.9.

MaxGalleria

Plugin Slug:
maxgalleria

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.5.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.8.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.10.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.9.

affiliate-toolkit � WordPress Affiliate Plugin

Plugin Slug:
affiliate-toolkit-starter

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.5.

WP Secure Maintenance

Plugin Slug:
wp-secure-maintainance

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.5.

Easy Age Verify

Plugin Slug:
easy-age-verify

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.3.

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.52

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.52.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.35

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.35.

Newspack Newsletters

Plugin Slug:
newspack-newsletters

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.3.

Shariff for WordPress

Plugin Slug:
shariff-sharing

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.6.14

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.14.

Image Optimizer, Resizer and CDN � Sirv

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.2.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.2.7.

Typing Text

Plugin Slug:
typing-text

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.6.

WPPizza � A Restaurant Plugin

Plugin Slug:
wppizza

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.18.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.18.14.

Responsive video embed

Plugin Slug:
responsive-video-embed

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.5.1.

Squeeze

Plugin:

Squeeze

Plugin Slug:
squeeze

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.4.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.1.

Bricks Builder (Premium)

Plugin:

Bricks Builder (Premium)

Plugin Slug:
bricksbuilder

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.

Consulting Elementor Widgets

Plugin:

Consulting Elementor Widgets

Plugin Slug:
consulting-elementor-widgets

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Consulting Elementor Widgets

Plugin:

Consulting Elementor Widgets

Plugin Slug:
consulting-elementor-widgets

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.1.

Consulting Elementor Widgets

Plugin:

Consulting Elementor Widgets

Plugin Slug:
consulting-elementor-widgets

Vulnerability:
SQL Injection

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Consulting Elementor Widgets

Plugin:

Consulting Elementor Widgets

Plugin Slug:
consulting-elementor-widgets

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.1.

Cost Calculator Builder Pro

Plugin:

Cost Calculator Builder Pro

Plugin Slug:
cost-calculator-builder-pro

Vulnerability:
Content Spoofing

Patched in Version:
3.1.76

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.76.

Hercules Core

Plugin:

Hercules Core

Plugin Slug:
hercules-core

Vulnerability:
Settings Change

Patched in Version:
6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.7.

Ibtana

Plugin:

Ibtana

Plugin Slug:
ibtana-visual-editor

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.4.

Ibtana

Plugin:

Ibtana

Plugin Slug:
ibtana-visual-editor

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.4.

Newspack Blocks

Plugin:

Newspack Blocks

Plugin Slug:
newspack-blocks

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

The Plus Addons for Elementor Pro

Plugin:

The Plus Addons for Elementor Pro

Plugin Slug:
theplus_elementor_addon

Vulnerability:
Local File Inclusion

Patched in Version:
5.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.0.

The Plus Addons for Elementor Pro

Plugin:

The Plus Addons for Elementor Pro

Plugin Slug:
theplus_elementor_addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.0.

Uber Menu

Plugin:

Uber Menu

Plugin Slug:
ubermenu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.4.

Shortcodes by United Themes

Plugin:

Shortcodes by United Themes

Plugin Slug:
ut-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.5.

WP Job Manager – Resume Manager

Plugin:

WP Job Manager – Resume Manager

Plugin Slug:
wp-job-manager-resumes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

WordPress Themes � 15 Patched / 3 Unpatched

Sinatra

Theme:

Sinatra

Theme Slug:
sinatra

Downloads
1,639,897

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Grey Opaque

Theme:

Grey Opaque

Theme Slug:
grey-opaque

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Mosaic

Theme:

Mosaic

Theme Slug:
mosaic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Book Landing Page

Theme Slug:
book-landing-page

Downloads
128,701

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

Chic Lite

Theme Slug:
chic-lite

Downloads
216,515

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

Customizr

Theme Slug:
customizr

Downloads
4,188,035

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.4.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.22.

Digital Newspaper

Theme Slug:
digital-newspaper

Downloads
47,141

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

Education Zone

Theme Slug:
education-zone

Downloads
444,963

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Excellent

Theme Slug:
excellent

Downloads
116,583

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Hueman

Theme:

Hueman

Theme Slug:
hueman

Downloads
3,005,399

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.25.

Interface

Theme Slug:
interface

Downloads
429,855

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

Materialis

Theme Slug:
materialis

Downloads
255,867

Vulnerability:
Broken Access Control

Patched in Version:
1.1.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.30.

Vandana Lite

Theme Slug:
vandana-lite

Downloads
117,403

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

Vilva

Theme:

Vilva

Theme Slug:
vilva

Downloads
441,200

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Divi

Theme:

Divi

Theme Slug:
divi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.25.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.25.2.

Enfold

Theme:

Enfold

Theme Slug:
enfold

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.10.

Flatsome

Theme:

Flatsome

Theme Slug:
flatsome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.0.

Flatsome

Theme:

Flatsome

Theme Slug:
flatsome

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…