Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � October 2, 2024

In this report, 302 vulnerabilities have been publicly disclosed. Security patches for 216 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 86 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7 Beta 1 is ready for download and testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, set up a test environment or a local site to explore the new features.

WordPress Plugins � 213 Patched / 83 Unpatched

Crowdsignal Dashboard � Polls, Surveys & more

Plugin Slug:
polldaddy

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form to Any API

Plugin Slug:
contact-form-to-any-api

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Premium Packages � Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Copyscape Premium

Plugin Slug:
copyscape-premium

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Keap Official Opt-in Forms

Plugin Slug:
infusionsoft-official-opt-in-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Include Fussball.de Widgets

Plugin Slug:
include-fussball-de-widgets

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Payflex Payment Gateway

Plugin Slug:
payflex-payment-gateway

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Terms descriptions

Plugin Slug:
terms-descriptions

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Review & testimonial widgets

Plugin Slug:
trustmary

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VdoCipher: Secure Video Player and Hosting

Plugin Slug:
vdocipher

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPExperts Square For GiveWP

Plugin Slug:
wpexperts-square-for-give

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

012 PS Multi Languages

Plugin:

012 PS Multi Languages

Plugin Slug:
012-ps-multi-languages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

123.chat

Plugin:

123.chat

Plugin Slug:
123-chat-videochat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ABCApp Creator

Plugin:

ABCApp Creator

Plugin Slug:
abcapp-creator

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

adstxt

Plugin:

adstxt

Plugin Slug:
adstxt

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Thanh To�n Qu�t M� QR Code T? ??ng

Plugin:

Thanh To�n Qu�t M� QR Code T? ??ng

Plugin Slug:
bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Charity Addon for Elementor

Plugin:

Charity Addon for Elementor

Plugin Slug:
charity-addon-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Common Tools for Site

Plugin:

Common Tools for Site

Plugin Slug:
common-tools-for-site

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Confetti Fall Animation

Plugin:

Confetti Fall Animation

Plugin Slug:
confetti-fall-animation

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Campaign Monitor Extension

Plugin:

Contact Form 7 Campaign Monitor Extension

Plugin Slug:
contact-form-7-campaign-monitor-extension

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Banners

Plugin:

Custom Banners

Plugin Slug:
custom-banners

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DK PDF

Plugin:

DK PDF

Plugin Slug:
dk-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Math Captcha

Plugin:

Contact Form 7 Math Captcha

Plugin Slug:
ds-cf7-math-captcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Load More

Plugin:

Easy Load More

Plugin Slug:
easy-load-more

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elastik Page Builder

Plugin:

Elastik Page Builder

Plugin Slug:
elastik-page-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GF Custom Style

Plugin:

GF Custom Style

Plugin Slug:
gf-custom-style

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Graphicsly

Plugin:

Graphicsly

Plugin Slug:
graphicsly

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gravity Forms Toolbar

Plugin:

Gravity Forms Toolbar

Plugin Slug:
gravity-forms-toolbar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GutenGeek Free Gutenberg Blocks for WordPress

Plugin:

GutenGeek Free Gutenberg Blocks for WordPress

Plugin Slug:
gtg-advanced-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Hello World

Plugin:

Hello World

Plugin Slug:
hello-world

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Iconize

Plugin:

Iconize

Plugin Slug:
iconize

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Instant Chat Floating Button for WordPress Websites

Plugin:

Instant Chat Floating Button for WordPress Websites

Plugin Slug:
instant-chat-wp

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Joy Of Text Lite

Plugin:

Joy Of Text Lite

Plugin Slug:
joy-of-text

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:

KB Support

Plugin Slug:
kb-support

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:

KB Support

Plugin Slug:
kb-support

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

king_IE

Plugin:

king_IE

Plugin Slug:
king-ie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:

Kodex Posts likes

Plugin Slug:
kodex-posts-likes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:

Kodex Posts likes

Plugin Slug:
kodex-posts-likes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LH Copy Media File

Plugin:

LH Copy Media File

Plugin Slug:
lh-copy-media-file

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LocateAndFilter

Plugin:

LocateAndFilter

Plugin Slug:
locateandfilter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Loggedin

Plugin:

Loggedin

Plugin Slug:
loggedin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mapplic Lite

Plugin:

Mapplic Lite

Plugin Slug:
mapplic-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Material Design Icons

Plugin:

Material Design Icons

Plugin Slug:
material-design-icons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Medical Addon for Elementor

Plugin:

Medical Addon for Elementor

Plugin Slug:
medical-addon-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MH Board

Plugin:

MH Board

Plugin Slug:
mh-board

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

nm-visitors

Plugin:

nm-visitors

Plugin Slug:
nm-visitors

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OneElements � Best Elementor Addons

Plugin:

OneElements � Best Elementor Addons

Plugin Slug:
oneelements-ultimate-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Optin Hound

Plugin:

Optin Hound

Plugin Slug:
opt-in-hound

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PDF Image Generator

Plugin:

PDF Image Generator

Plugin Slug:
pdf-image-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Podiant

Plugin:

Podiant

Plugin Slug:
podiant

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

R Animated Icon

Plugin:

R Animated Icon

Plugin Slug:
r-animated-icon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Relogo

Plugin Slug:
relogo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:

REST API TO MiniProgram

Plugin Slug:
rest-api-to-miniprogram

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:

REST API TO MiniProgram

Plugin Slug:
rest-api-to-miniprogram

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

RumbleTalk Live Group Chat

Plugin:

RumbleTalk Live Group Chat

Plugin Slug:
rumbletalk-chat-a-chat-with-themes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Search Analytics

Plugin:

WP Search Analytics

Plugin Slug:
search-analytics

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Super Testimonials

Plugin:

Super Testimonials

Plugin Slug:
sola-testimonials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVG Complete

Plugin:

SVG Complete

Plugin Slug:
svg-complete

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin:

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin:

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Truepush

Plugin:

Truepush

Plugin Slug:
truepush-free-web-push-notifications

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Users Control

Plugin:

Users Control

Plugin Slug:
users-control

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Vmax Project Manager

Plugin:

Vmax Project Manager

Plugin Slug:
vmax-project-manager

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wechat Social login

Plugin:

Wechat Social login

Plugin Slug:
wechat-social-login

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wechat Social login

Plugin:

Wechat Social login

Plugin Slug:
wechat-social-login

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce � Store Exporter

Plugin:

WooCommerce � Store Exporter

Plugin Slug:
woocommerce-exporter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Category Dropdown

Plugin:

WP Category Dropdown

Plugin Slug:
wp-category-dropdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Easy Gallery

Plugin Slug:
wp-easy-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Easy Gallery

Plugin Slug:
wp-easy-gallery

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Easy Gallery

Plugin Slug:
wp-easy-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Free SSL � Free SSL Certificate for WordPress and force HTTPS

Plugin:

WP Free SSL � Free SSL Certificate for WordPress and force HTTPS

Plugin Slug:
wp-free-ssl

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP GPX Map

Plugin:

WP GPX Map

Plugin Slug:
wp-gpx-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Newsletter Subscription

Plugin:

WP Newsletter Subscription

Plugin Slug:
wp-newsletter-subscription

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Special Text Boxes

Plugin:

Special Text Boxes

Plugin Slug:
wp-special-textboxes

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Ticket Ultra Help Desk & Support Plugin

Plugin:

WP Ticket Ultra Help Desk & Support Plugin

Plugin Slug:
wp-ticket-ultra

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-WebAuthn

Plugin:

WP-WebAuthn

Plugin Slug:
wp-webauthn

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Spreadsheet Integration � Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins.

Plugin Slug:
wpgsi

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPSPX

Plugin:

WPSPX

Plugin Slug:
wpspx

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPZOOM Shortcodes

Plugin:

WPZOOM Shortcodes

Plugin Slug:
wpzoom-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Path Traversal

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.1.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.17.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.8.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.7.6

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.7.6.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.53

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.53.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.6.4.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
SQL Injection

Patched in Version:
6.6.4.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.6.4.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.12.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.3.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

TinyPNG � JPEG, PNG & WebP image compression

Plugin Slug:
tiny-compress-images

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.4.

Use Any Font | Custom Font Uploader

Plugin Slug:
use-any-font

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.09

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.09.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.7.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.7.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.3.7.

Slider & Popup Builder by Depicter � Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Slider & Popup Builder by Depicter � Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Path Traversal

Patched in Version:
5.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.9.

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.9.

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.9.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.16.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.16.2.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.16.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.16.0.

Strong Testimonials

Plugin Slug:
strong-testimonials

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.17.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.2.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.10.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.6.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.6.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.6.

Jupiter X Core

Plugin Slug:
jupiterx-core

Installations
90,000+

Vulnerability:
Broken Authentication

Patched in Version:
4.7.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.8.

WP Bulk Delete

Plugin Slug:
wp-bulk-delete

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.2.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.1.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.1.

Simple Calendar � Google Calendar Plugin

Plugin Slug:
google-calendar-events

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.3.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.1.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.2.

Pixel Cat � Conversion Pixel Manager

Plugin Slug:
facebook-conversion-pixel

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.6.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.2.

Visual CSS Style Editor

Plugin Slug:
yellow-pencil-visual-theme-customizer

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.5.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

Koko Analytics

Plugin Slug:
koko-analytics

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.13.

Page-list

Plugin Slug:
page-list

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.90

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.90.
Plugin Slug:
yith-woocommerce-ajax-search

Installations
40,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.8.1.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.29.

Ads by WPQuads � Adsense Ads, Banner Ads, Popup Ads

Plugin Slug:
quick-adsense-reloaded

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.85

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.85.

Starbox � the Author Box for Humans

Plugin Slug:
starbox

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.3.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

Accordion

Plugin Slug:
accordions

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.100

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.100.

MAS Static Content

Plugin Slug:
mas-static-content

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.9.

PWA for WP & AMP

Plugin Slug:
pwa-for-wp

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.73

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.73.

Simple Membership After Login Redirection

Plugin Slug:
simple-membership-after-login-redirection

Installations
20,000+

Vulnerability:
Open Redirection

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Slider by 10Web � Responsive Image Slider

Plugin Slug:
slider-wd

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.59

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.59.

Advanced Woo Labels � Product Labels for WooCommerce

Plugin Slug:
advanced-woo-labels

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.02

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.02.

ARI Fancy Lightbox � Popup for WordPress

Plugin Slug:
ari-fancy-lightbox

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.18.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.21.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.21.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.21.

Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites � Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed

Plugin Slug:
blockspare

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.5.

Multi Step for Contact Form 7

Plugin Slug:
cf7-multi-step

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.7.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.7.8.

Classic Editor and Classic Widgets

Plugin Slug:
classic-editor-and-classic-widgets

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
gallery-lightbox-slider

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.0.41

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.0.41.

Prisna GWT � Google Website Translator

Plugin Slug:
google-website-translator

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.12.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.9.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.7.

Mega Elements � Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

myCred � Loyalty Points and Rewards plugin for WordPress and WooCommerce � Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

Plugin Slug:
mycred

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.

OSM � OpenStreetMap

Plugin Slug:
osm

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.1.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Mail logging � WP Mail Catcher

Plugin Slug:
wp-mail-catcher

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.10.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.13.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.13.1.

Form plugin for WordPress � Zoho Forms

Plugin Slug:
zoho-forms

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.

Absolute Reviews

Plugin Slug:
absolute-reviews

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.4.

MaxSlider

Plugin Slug:
maxslider

Installations
9,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.4.

Affiliate Program Suite � SliceWP Affiliates

Plugin Slug:
slicewp

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.19

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.19.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.
Plugin Slug:
slideshow-gallery

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.4.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.3.3.

WP Compress � Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.21.01

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.21.01.

Author Avatars List/Block

Plugin Slug:
author-avatars

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.22.

Cozy Blocks � Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.12.
Plugin Slug:
meta-slider-and-carousel-with-lightbox

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Seriously Simple Stats

Plugin Slug:
seriously-simple-stats

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.0.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
5,000+

Vulnerability:
Open Redirection

Patched in Version:
6.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.3.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.1.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Garden Gnome Package

Plugin Slug:
garden-gnome-package

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Geo Mashup

Plugin Slug:
geo-mashup

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.14.

GEO my WP

Plugin Slug:
geo-my-wp

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.0.4.

Revolut Gateway for WooCommerce

Plugin Slug:
revolut-gateway-for-woocommerce

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.17.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.17.4.

Salon Booking System

Plugin Slug:
salon-booking-system

Installations
5,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
10.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.9.1.

Easy Mega Menu Plugin for WordPress � ThemeHunk

Plugin Slug:
themehunk-megamenu-plus

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

WPMobile.App � Android and iOS Mobile Application

Plugin Slug:
wpappninja

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.51

Severity Score:
High


The vulnerability has been patched, so you should update to version 11.51.

Cities Shipping Zones for WooCommerce

Plugin Slug:
cities-shipping-zones-for-woocommerce

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

CubeWP Forms � All-in-One Form Builder

Plugin Slug:
cubewp-forms

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

EU/UK VAT Manager for WooCommerce

Plugin Slug:
eu-vat-for-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.12.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.12.14.

EU/UK VAT Manager for WooCommerce

Plugin Slug:
eu-vat-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.12.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.14.

GTM Server Side

Plugin Slug:
gtm-server-side

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.20.

Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress

Plugin Slug:
quillforms

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.0.
Plugin Slug:
sight

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.68.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.68.9.

AVIF Uploader

Plugin Slug:
avif-support

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

Multiple Page Generator Plugin � MPG

Plugin Slug:
multiple-pages-generator-by-porthas

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
3.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.8.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.2.

Store Hours for WooCommerce

Plugin Slug:
order-hours-scheduler-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.22.

Robokassa payment gateway for Woocommerce

Plugin Slug:
robokassa

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.5.

Zoho Flow for WordPress

Plugin Slug:
zoho-flow

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.1.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

Beam me up Scotty � Back to Top Button

Plugin Slug:
beam-me-up-scotty

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.22.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.16.

Chartify � WordPress Chart Plugin

Plugin Slug:
chart-builder

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.7.

Premium Blocks � Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.34.

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Share This Image

Plugin Slug:
share-this-image

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.02

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.02.

Simple LDAP Login

Plugin Slug:
simple-ldap-login

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.1.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs)

Plugin Slug:
sky-elementor-addons

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.12.

Loops & Logic

Plugin Slug:
tangible-loops-and-logic

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.5.

Directory Listings WordPress plugin � uListing

Plugin Slug:
ulisting

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.

WPCOM Member

Plugin Slug:
wpcom-member

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.1.

Zotpress

Plugin:

Zotpress

Plugin Slug:
zotpress

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.3.11.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.75

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.75.

Daily Prayer Time

Plugin Slug:
daily-prayer-time-for-mosques

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
2024.09.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 2024.09.14.

Easy PayPal Events

Plugin Slug:
easy-paypal-events-tickets

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Product Enquiry for WooCommerce, WooCommerce product catalog

Plugin Slug:
enquiry-quotation-for-woocommerce

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.2.33.34

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.33.34.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.16.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.16.8.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.69

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.69.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.5.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.5.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.
Plugin Slug:
responsive-client-logo-carousel-slider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.65

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.65.

Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider

Plugin Slug:
ultimate-store-kit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.4.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.4.
Plugin Slug:
wp-mylinks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.0.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

XT Ajax Add To Cart for WooCommerce

Plugin Slug:
xt-woo-ajax-add-to-cart

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.3.

Themedy Toolbox

Plugin Slug:
themedy-toolbox

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.16.

VR Calendar

Plugin Slug:
vr-calendar-sync

Installations
800+

Vulnerability:
Local File Inclusion

Patched in Version:
2.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.5.

Checkout Mestres do WP for WooCommerce

Plugin Slug:
checkout-mestres-wp

Installations
700+

Vulnerability:
Local File Inclusion

Patched in Version:
8.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.6.1.

QS Dark Mode Plugin

Plugin Slug:
qs-dark-mode

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.

Web Directory Free

Plugin Slug:
web-directory-free

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

AI ChatBot with ChatGPT and Content Generator by AYS

Plugin Slug:
ays-chatgpt-assistant

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

AI ChatBot with ChatGPT and Content Generator by AYS

Plugin Slug:
ays-chatgpt-assistant

Installations
300+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

CSS JS Files

Plugin Slug:
css-js-files

Installations
200+

Vulnerability:
Directory Traversal

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Top Bar � PopUps � by WPOptin

Plugin Slug:
wpoptin

Installations
90+

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.2.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp

Installations
50+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.6.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.19.

Secure Copy Content Protection and Content Locking

Plugin:

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection-subscribe-to-view

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.4.

Social Auto Poster

Plugin:

Social Auto Poster

Plugin Slug:
social-auto-poster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.16.

Uncanny Groups for LearnDash

Plugin:

Uncanny Groups for LearnDash

Plugin Slug:
uncanny-learndash-groups

Vulnerability:
Privilege Escalation

Patched in Version:
6.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.1.

Uncanny Groups for LearnDash

Plugin:

Uncanny Groups for LearnDash

Plugin Slug:
uncanny-learndash-groups

Vulnerability:
Broken Access Control

Patched in Version:
6.1.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 6.1.1.

WooEvents

Plugin:

WooEvents

Plugin Slug:
woo-events

Vulnerability:
Arbitrary File Deletion

Patched in Version:
4.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.1.3.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.1.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.1.

WP MultiTasking

Plugin:

WP MultiTasking

Plugin Slug:
wp-multitasking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.1.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.1.18.

WP Timeline � Vertical and Horizontal timeline plugin

Plugin:

WP Timeline � Vertical and Horizontal timeline plugin

Plugin Slug:
wp-timelines

Vulnerability:
Local File Inclusion

Patched in Version:
3.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.8.

WP Timeline � Vertical and Horizontal timeline plugin

Plugin:

WP Timeline � Vertical and Horizontal timeline plugin

Plugin Slug:
wp-timelines

Vulnerability:
Local File Inclusion

Patched in Version:
3.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.8.

WP Timeline � Vertical and Horizontal timeline plugin

Plugin:

WP Timeline � Vertical and Horizontal timeline plugin

Plugin Slug:
wp-timelines

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.8.

WordPress Themes � 3 Patched / 3 Unpatched

UltraPress

Theme Slug:
ultrapress

Downloads
15,920

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Unseen Blog

Theme Slug:
unseen-blog

Downloads
2,335

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

viala

Theme:

viala

Theme Slug:
viala

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Catch Base

Theme Slug:
catch-base

Downloads
203,923

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.7.

Create

Theme:

Create

Theme Slug:
create

Downloads
64,003

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.2.

Full Frame

Theme Slug:
full-frame

Downloads
199,800

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…