Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � September 18, 2024

In this report, 102 vulnerabilities have been publicly disclosed. Security patches for 70 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 32 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.2 is available! This minor release includes�15 bug fixes in Core�and�11 in the Block Editor, addressing issues like unexpected CSS specificity changes in certain themes.

WordPress Plugins � 68 Patched / 23 Unpatched

IMPress for IDX Broker

Plugin Slug:
idx-broker-platinum

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woo-product-carousel-slider-and-grid-ultimate

Installations
9,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spice Starter Sites

Plugin Slug:
spice-starter-sites

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks � Unlimited blocks For Gutenberg

Plugin Slug:
unlimited-blocks

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team Showcase

Plugin Slug:
team

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pocket Widget

Plugin Slug:
pocket-widget

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Adicon Server

Plugin:

Adicon Server

Plugin Slug:
adicons

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:

AZIndex

Plugin Slug:
azindex

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:

AZIndex

Plugin Slug:
azindex

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Limits

Plugin:

Custom Post Limits

Plugin Slug:
custom-post-limits

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Email Obfuscate Shortcode

Plugin:

Email Obfuscate Shortcode

Plugin Slug:
email-obfuscate-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Exit Notifier

Plugin:

Exit Notifier

Plugin Slug:
exit-notifier

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cron Jobs

Plugin:

Cron Jobs

Plugin Slug:
leira-cron-jobs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Roles & Capabilities

Plugin:

Roles & Capabilities

Plugin Slug:
leira-roles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lucas String Replace

Plugin:

Lucas String Replace

Plugin Slug:
lucas-string-replace

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MM-Breaking News

Plugin:

MM-Breaking News

Plugin Slug:
mm-breaking-news

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MM-Breaking News

Plugin:

MM-Breaking News

Plugin Slug:
mm-breaking-news

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Quick Code

Plugin:

Quick Code

Plugin Slug:
quick-code

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slider comparison image before and after

Plugin:

Slider comparison image before and after

Plugin Slug:
slider-comparison-image-before-and-after

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Visual Sound

Plugin:

Visual Sound

Plugin Slug:
visual-sound

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Multiple Free Gift

Plugin:

WooCommerce Multiple Free Gift

Plugin Slug:
woocommerce-multiple-free-gift

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Migration, Backup, Staging � WPvivid

Plugin Slug:
wpvivid-backuprestore

Installations
500,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
0.9.106

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.9.106.

Backuply � Backup, Restore, Migrate and Clone

Plugin Slug:
backuply

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.15.

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme � My Sticky Bar (formerly myStickymenu)

Plugin Slug:
mystickymenu

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.7.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
4.2.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.7.1.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
SQL Injection

Patched in Version:
4.2.7.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.2.7.1.

Stream

Plugin:

Stream

Plugin Slug:
stream

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.2.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

AI Engine

Plugin Slug:
ai-engine

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.8.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.2.
Plugin Slug:
carousel-slider

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.91

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.91.

Starbox � the Author Box for Humans

Plugin Slug:
starbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.

Advanced WordPress Backgrounds

Plugin Slug:
advanced-backgrounds

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.12.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.4.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.4.

WP Editor

Plugin Slug:
wp-editor

Installations
30,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.9.1.

WP Meta SEO

Plugin Slug:
wp-meta-seo

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.14.

WP Meta SEO

Plugin Slug:
wp-meta-seo

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.14.

WP Simple Booking Calendar

Plugin Slug:
wp-simple-booking-calendar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.11.

WP Test Email

Plugin Slug:
wp-test-email

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

CM Pop-Up Banners for WordPress

Plugin Slug:
cm-pop-up-banners

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.3.

Maintenance Redirect

Plugin Slug:
jf3-maintenance-mode

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.1.0

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.1.0.

Product Slider for WooCommerce by PickPlugins

Plugin Slug:
woocommerce-products-slider

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.51

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.13.51.

WP Booking System � Booking Calendar

Plugin Slug:
wp-booking-system

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.19.9.

WordPress Affiliates Plugin � SliceWP Affiliates

Plugin Slug:
slicewp

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.21.

YITH Custom Login

Plugin Slug:
yith-custom-login

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

Easy Property Listings

Plugin Slug:
easy-property-listings

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.4.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.17.

Geo Mashup

Plugin Slug:
geo-mashup

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.13.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.4.

Waitlist Woocommerce ( Back in stock notifier )

Plugin Slug:
waitlist-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.6.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.20.

Simple Spoiler

Plugin Slug:
simple-spoiler

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.14.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.14.

Affiliate Super Assistent

Plugin Slug:
amazonsimpleadmin

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

amCharts: Charts and Maps

Plugin Slug:
amcharts-charts-and-maps

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.5.

Floating Contact Button

Plugin Slug:
floating-contact

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.50

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.50.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

PDF Thumbnail Generator

Plugin Slug:
pdf-thumbnail-generator

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Share This Image

Plugin Slug:
share-this-image

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
2.04

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.04.
Plugin Slug:
wp-responsive-video-gallery-with-lightbox

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

WPFactory Helper

Plugin Slug:
wpcodefactory-helper

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.1.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.5.

Flipping Cards

Plugin Slug:
flipping-cards

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.
Plugin Slug:
header-footer-code

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.10.

WooCommerce Photo Reviews – Review Reminders – Review for Discounts

Plugin:

WooCommerce Photo Reviews – Review Reminders – Review for Discounts

Plugin Slug:
woocommerce-photo-reviews

Vulnerability:
Broken Authentication

Patched in Version:
1.3.14

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.14.

WordPress Themes � 2 Patched / 9 Unpatched

Beauty

Theme:

Beauty

Theme Slug:
beauty

Downloads
28,174

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Blogvi

Theme:

Blogvi

Theme Slug:
blogvi

Downloads
25,101

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Delicate

Theme Slug:
delicate

Downloads
686,668

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Neighborly

Theme Slug:
neighborly

Downloads
10,160

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Roseta

Theme:

Roseta

Theme Slug:
roseta

Downloads
95,920

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Septera

Theme:

Septera

Theme Slug:
septera

Downloads
125,318

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Tweaker5

Theme Slug:
tweaker5

Downloads
5,718

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Verbosa

Theme:

Verbosa

Theme Slug:
verbosa

Downloads
108,094

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Triton Lite

Theme:

Triton Lite

Theme Slug:
triton-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Betheme

Theme:

Betheme

Theme Slug:
betheme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
27.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 27.5.6.

Bricks Builder

Theme:

Bricks Builder

Theme Slug:
bricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.2.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…