Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � August 14, 2024

In this report, 181 vulnerabilities have been publicly disclosed. Security patches for 118 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 63 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

WordPress Plugins � 114 Patched / 58 Unpatched

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Slider Feed

Plugin Slug:
instagram-slider-widget

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mediavine Control Panel

Plugin Slug:
mediavine-control-panel

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress � Backup Plugin

Plugin Slug:
wp-backitup

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress � Backup Plugin

Plugin Slug:
wp-backitup

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Backup and Restore WordPress � Backup Plugin

Plugin Slug:
wp-backitup

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Create by Mediavine

Plugin Slug:
mediavine-create

Installations
7,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Order Export for WooCommerce

Plugin Slug:
order-export-and-more-for-woocommerce

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin Slug:
kodex-posts-likes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Filr � Secure document library

Plugin Slug:
filr-protection

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

affiliate-toolkit

Plugin:

affiliate-toolkit

Plugin Slug:
affiliate-toolkit-starter

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:

Bit Form Pro

Plugin Slug:
bitformpro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:

Bit Form Pro

Plugin Slug:
bitformpro

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:

Bit Form Pro

Plugin Slug:
bitformpro

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Bit Form Pro

Plugin:

Bit Form Pro

Plugin Slug:
bitformpro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Blox Page Builder

Plugin:

Blox Page Builder

Plugin Slug:
blox-page-builder

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Compute Links

Plugin Slug:
compute-links

Vulnerability:
Remote File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

House Manager

Plugin:

House Manager

Plugin Slug:
house-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:

Ultimate Membership Pro

Plugin Slug:
indeed-membership-pro

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:

Ultimate Membership Pro

Plugin Slug:
indeed-membership-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Membership Pro

Plugin:

Ultimate Membership Pro

Plugin Slug:
indeed-membership-pro

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:

Leopard – WordPress offload media

Plugin Slug:
leopard-wordpress-offload-media

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Leopard – WordPress offload media

Plugin:

Leopard – WordPress offload media

Plugin Slug:
leopard-wordpress-offload-media

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Linkify Text

Plugin:

Linkify Text

Plugin Slug:
linkify-text

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

My Custom CSS PHP & ADS

Plugin:

My Custom CSS PHP & ADS

Plugin Slug:
my-custom-css

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore

Plugin:

MyBookTable Bookstore

Plugin Slug:
mybooktable

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

No Update Nag

Plugin:

No Update Nag

Plugin Slug:
no-update-nag

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Obfuscate Email

Plugin:

Obfuscate Email

Plugin Slug:
obfuscate-email

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Opal Membership

Plugin:

Opal Membership

Plugin Slug:
opal-membership

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Opal Membership

Plugin:

Opal Membership

Plugin Slug:
opal-membership

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Reveal Template

Plugin:

Reveal Template

Plugin Slug:
reveal-template

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Send Emails with Mandrill

Plugin:

Send Emails with Mandrill

Plugin Slug:
send-emails-with-mandrill

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Store Locator Plus

Plugin:

Store Locator Plus

Plugin Slug:
store-locator-le

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Traffic Manager

Plugin:

Traffic Manager

Plugin Slug:
traffic-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mega Addons For Elementor

Plugin:

Mega Addons For Elementor

Plugin Slug:
ultimate-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Unite Gallery Lite

Plugin Slug:
unite-gallery-lite

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:

WHMpress

Plugin Slug:
whmpress

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WHMpress

Plugin:

WHMpress

Plugin Slug:
whmpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woo Products Widgets For Elementor

Plugin:

Woo Products Widgets For Elementor

Plugin Slug:
woo-products-widgets-for-elementor

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bitly

Plugin:

Bitly

Plugin Slug:
wp-bitly

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Spectra � WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.15.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.15.1.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.10.39

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.39.

Meta Box � WordPress Custom Fields Framework

Plugin Slug:
meta-box

Installations
600,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.11.

Easy Table of Contents

Plugin Slug:
easy-table-of-contents

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.68

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.68.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.97

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.97.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.13.

Slider & Popup Builder by Depicter � Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

Lightbox & Modal Popup WordPress Plugin � FooBox

Plugin Slug:
foobox-image-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.32.

Hummingbird Performance � Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Plugin Slug:
hummingbird-performance

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.2.

Hummingbird Performance � Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Plugin Slug:
hummingbird-performance

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.2.

Simple Local Avatars

Plugin Slug:
simple-local-avatars

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.11.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.3.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.6.2.

TypeSquare Webfonts for ????????

Plugin Slug:
xserver-typesquare-webfonts

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
4.2.6.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.6.9.4.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.1.

??????? ?????

Plugin Slug:
persian-woocommerce

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.0.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.

Ajax Search Lite

Plugin Slug:
ajax-search-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.1.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.26.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.26.9.

3D FlipBook � PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.7.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.19

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.19.

WP Table Builder � WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Category Posts Widget

Plugin Slug:
category-posts

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.17.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.45

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.45.

Gutenberg Blocks, Page Builder � ComboBlocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.87

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.87.

Advanced Cron Manager � debug & control

Plugin Slug:
advanced-cron-manager

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.10.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.16

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.16.

Accept Stripe Payments

Plugin Slug:
stripe-payments

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.87

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.87.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.10.

Fuse Social Floating Sidebar

Plugin Slug:
fuse-social-floating-sidebar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.11.

Slider by 10Web � Responsive Image Slider

Plugin Slug:
slider-wd

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
1.2.58

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.58.

Easy PayPal & Stripe Buy Now Button

Plugin Slug:
wp-ecommerce-paypal

Installations
20,000+

Vulnerability:
Open Redirection

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.8.

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.8.

140+ Widgets | Xpro Addons For Elementor � FREE

Plugin Slug:
xpro-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.3.

Gutenberg Page Builder Blocks & Ready-Made Patterns Library for Blogs, Magazines, Newspapers, and Business Websites. Easy One-Click Import, No Coding Needed! � Blockspare

Plugin Slug:
blockspare

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.

Graphina � Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.0.

Horizontal scrolling announcements

Plugin Slug:
horizontal-scrolling-announcements

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.

myCred � Loyalty Points and Rewards plugin for WordPress and WooCommerce � Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

Plugin Slug:
mycred

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite

Installations
10,000+

Vulnerability:
Content Injection

Patched in Version:
3.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.6.

Participants Database

Plugin Slug:
participants-database

Installations
9,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.5.9.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.9.3.

Selection Lite

Plugin Slug:
selection-lite

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.

Themify Shortcodes

Plugin Slug:
themify-shortcodes

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Chatbot for WordPress by Collect.chat ??

Plugin Slug:
collectchat

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.4.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.9.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Installations
7,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.

Timeline and History slider

Plugin Slug:
timeline-and-history-slider

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.

JS Help Desk � The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket

Installations
5,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.8.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.7.

Organization chart

Plugin Slug:
organization-chart

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Pinpoint Booking System � #1 WordPress Booking Plugin

Plugin Slug:
booking-system

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.9.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.9.4.8.

Card Elements for Elementor

Plugin Slug:
card-elements-for-elementor

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Cooked � Recipe Management

Plugin Slug:
cooked

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

FormCraft � Form Builder

Plugin Slug:
formcraft-form-builder

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.11.

Waitlist Woocommerce ( Back in stock notifier )

Plugin Slug:
waitlist-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.1.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.0.

Products, Order & Customers Export for WooCommerce

Plugin Slug:
export-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.12.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.1.

CRM Perks Forms � WordPress Form Builder

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.4.

WP Search Analytics

Plugin Slug:
search-analytics

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.10.

Post Grid Master � Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.11.

Christmasify!

Plugin Slug:
christmasify

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.6.

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.53

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.53.

Football Pool

Plugin Slug:
football-pool

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.10.

Football Pool

Plugin Slug:
football-pool

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.1.

StreamCast � Radio Player for WordPress

Plugin Slug:
streamcast

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

WP Bannerize Pro

Plugin Slug:
wp-bannerize-pro

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

WPSection

Plugin Slug:
wpsection

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.

Community Events

Plugin Slug:
community-events

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

WPBakery Page Builder

Plugin:

WPBakery Page Builder

Plugin Slug:
js_composer

Vulnerability:
Local File Inclusion

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

Modern Events Calendar

Plugin:

Modern Events Calendar

Plugin Slug:
modern-events-calendar

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.13.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.13.0.

Modern Events Calendar Lite

Plugin:

Modern Events Calendar Lite

Plugin Slug:
modern-events-calendar-lite

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
7.13.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.13.0.

Search Filter Pro

Plugin:

Search Filter Pro

Plugin Slug:
search-filter-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.18.

Shortcodes Ultimate Pro

Plugin:

Shortcodes Ultimate Pro

Plugin Slug:
shortcodes-ultimate-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.1.

Term And Category Based Posts Widget

Plugin:

Term And Category Based Posts Widget

Plugin Slug:
term-and-category-based-posts-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.13.

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin:

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin Slug:
woocommerce-collections

Vulnerability:
SQL Injection

Patched in Version:
1.7.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.0.

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin:

Docket (WooCommerce Collections / Wishlist / Watchlist)

Plugin Slug:
woocommerce-collections

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
1.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.0.

WooCommerce Multiple Customer Addresses & Shipping

Plugin:

WooCommerce Multiple Customer Addresses & Shipping

Plugin Slug:
woocommerce-multiple-customer-addresses

Vulnerability:
Multiple Vulnerabilities

Patched in Version:
24.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 24.9.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.6.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:

WP eMember

Plugin Slug:
wp-eMember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.7.0.

WordPress Themes � 4 Patched / 5 Unpatched

Busiprof

Theme Slug:
busiprof

Downloads
519,822

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Visual Composer Starter

Theme Slug:
visual-composer-starter

Downloads
106,347

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Multipurpose

Theme:

Multipurpose

Theme Slug:
multipurpose

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

News Flash

Theme:

News Flash

Theme Slug:
news-flash

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

The Next LVL

Theme:

The Next LVL

Theme Slug:
the-next

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Orchid Store

Theme Slug:
orchid-store

Downloads
349,182

Vulnerability:
Broken Access Control

Patched in Version:
1.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.7.

MDx

Theme:

MDx

Theme Slug:
MDx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.4.

Houzez

Theme:

Houzez

Theme Slug:
houzez

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.5.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Privilege Escalation

Patched in Version:
5.4.12

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.12.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…