Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � December 18, 2024

In this report, 345 vulnerabilities have been publicly disclosed. Security patches for 164 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 181 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 156 Patched / 179 Unpatched

WP Mega Menu

Plugin Slug:
wp-megamenu

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

News Ticker for Elementor

Plugin Slug:
news-ticker-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Menu Image

Plugin Slug:
wp-menu-image

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smaily for WP

Plugin Slug:
smaily-for-wp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SQL Chart Builder

Plugin Slug:
sql-chart-builder

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SIP Calculator

Plugin Slug:
sip-calculator

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LDD Directory Lite

Plugin Slug:
ldd-directory-lite

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

The Permalinker

Plugin Slug:
the-permalinker

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nias course | ???? ??? ????

Plugin Slug:
nias-course

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Role Includer

Plugin Slug:
role-includer

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks � WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Cookies Enabler

Plugin Slug:
wp-cookies-enabler

Installations
30+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Blog Post Block

Plugin Slug:
advanced-blog-post-block

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Blocks � Woolook

Plugin Slug:
woolook

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-NERD Toolkit

Plugin Slug:
wp-nerd-toolkit

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

3D Avatar User Profile

Plugin:

3D Avatar User Profile

Plugin Slug:
3d-avatar-user-profile

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add image to Post

Plugin:

Add image to Post

Plugin Slug:
add-image-to-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advance Menu Manager

Plugin:

Advance Menu Manager

Plugin Slug:
advance-menu-manager

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Data Table For Elementor

Plugin:

Advanced Data Table For Elementor

Plugin Slug:
advanced-data-table-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Fancybox

Plugin:

Advanced Fancybox

Plugin Slug:
advanced-fancybox

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced What should we write next about

Plugin:

Advanced What should we write next about

Plugin Slug:
advanced-what-should-we-write-about-next

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AI Post Generator | AutoWriter

Plugin:

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zita Site Builder

Plugin:

Zita Site Builder

Plugin Slug:
ai-site-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Amazon Product Price

Plugin:

Amazon Product Price

Plugin Slug:
amazon-product-price

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Animated Counters

Plugin:

Animated Counters

Plugin Slug:
animated-counters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aphorismus

Plugin:

Aphorismus

Plugin Slug:
aphorismus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AppMaps

Plugin:

AppMaps

Plugin Slug:
appmaps

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Appsplate

Plugin:

Appsplate

Plugin Slug:
appsplate

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Arabic Webfonts

Plugin:

Arabic Webfonts

Plugin Slug:
arabic-webfonts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM � Live Blogging for real-time events

Plugin:

Arena.IM � Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM � Live Blogging for real-time events

Plugin:

Arena.IM � Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Firebase OTP Authentication

Plugin:

Firebase OTP Authentication

Plugin Slug:
authentication-via-otp-using-firebase

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Banner System

Plugin:

Banner System

Plugin Slug:
banner-system

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bet sport Free

Plugin:

Bet sport Free

Plugin Slug:
bet-sport-free

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Better WP Login Page

Plugin:

Better WP Login Page

Plugin Slug:
better-wp-login-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Buttons

Plugin:

Bootstrap Buttons

Plugin Slug:
bootstrap-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Buk

Plugin:

Buk

Plugin Slug:
buk-appointments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Caldera SMTP Mailer

Plugin:

Caldera SMTP Mailer

Plugin Slug:
caldera-smtp-mailer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mollie for Contact Form 7

Plugin:

Mollie for Contact Form 7

Plugin Slug:
cf7-mollie

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

??????

Plugin:

??????

Plugin Slug:
changyan

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CK and SyntaxHighlighter

Plugin:

CK and SyntaxHighlighter

Plugin Slug:
ck-and-syntaxhighlighter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Generator Pro

Plugin:

Code Generator Pro

Plugin Slug:
code-generator-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Comments On Feed

Plugin:

Comments On Feed

Plugin Slug:
comments-on-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Companion Portfolio

Plugin:

Companion Portfolio

Plugin Slug:
companion-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Connatix Video Embed

Plugin:

Connatix Video Embed

Plugin Slug:
connatix-video-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CoSchool LMS

Plugin:

CoSchool LMS

Plugin Slug:
coschool

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Crafthemes Demo Import

Plugin:

Crafthemes Demo Import

Plugin Slug:
crafthemes-demo-import

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Cricket Live Score

Plugin:

Cricket Live Score

Plugin Slug:
cricket-score

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Critical Site Intel

Plugin:

Critical Site Intel

Plugin Slug:
critical-site-intel-stats

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

CRUDLab Google Plus Button

Plugin:

CRUDLab Google Plus Button

Plugin Slug:
crudlab-google-plus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CSV to html

Plugin:

CSV to html

Plugin Slug:
csv-to-html

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Custom Skins Contact Form 7

Plugin:

Custom Skins Contact Form 7

Plugin Slug:
custom-skins-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Endpoints With Rest Api

Plugin:

Ultimate Endpoints With Rest Api

Plugin Slug:
custom-wp-rest-api

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mimoos

Plugin:

Mimoos

Plugin Slug:
devoluciones-packback

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Display Future Posts

Plugin:

Display Future Posts

Plugin Slug:
display-future-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dr Affiliate

Plugin:

Dr Affiliate

Plugin Slug:
dr-affiliate

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DTC Documents

Plugin:

DTC Documents

Plugin Slug:
dtc-documents

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Site Importer

Plugin:

Easy Site Importer

Plugin Slug:
easy-site-importer

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

ECT Product Carousel

Plugin Slug:
ect-product-carousel

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ECT Social Share

Plugin:

ECT Social Share

Plugin Slug:
ect-social-share

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

EELV Newsletter

Plugin:

EELV Newsletter

Plugin Slug:
eelv-newsletter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mandrill WP

Plugin:

Mandrill WP

Plugin Slug:
email-form-under-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

eTemplates

Plugin:

eTemplates

Plugin Slug:
etemplates

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Evernote Sync

Plugin:

Evernote Sync

Plugin Slug:
evernote-sync

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Feedpress Generator

Plugin:

Feedpress Generator

Plugin Slug:
feedpress-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin:

Flaming Forms

Plugin Slug:
flaming-forms

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flash News / Post (Responsive)

Plugin:

Flash News / Post (Responsive)

Plugin Slug:
flashnews-fading-effect-pearlbells

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Floating Video Player

Plugin:

Floating Video Player

Plugin Slug:
floating-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gaxx Keywords

Plugin:

Gaxx Keywords

Plugin Slug:
gaxx-keywords

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Geoportail Shortcode

Plugin:

Geoportail Shortcode

Plugin Slug:
geoportail-shortcode

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Get Post Content Shortcode

Plugin:

Get Post Content Shortcode

Plugin Slug:
get-post-content-shortcode

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GitSync

Plugin:

GitSync

Plugin Slug:
git-sync

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

glomex oEmbed

Plugin:

glomex oEmbed

Plugin Slug:
glomex-oembed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Go Animate

Plugin:

Go Animate

Plugin Slug:
goanimate

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus

Plugin:

Grid Plus

Plugin Slug:
grid-plus

Vulnerability:
Arbitrary Code Execution

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gutensee

Plugin:

Gutensee

Plugin Slug:
gutensee

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Opt-In Downloads

Plugin:

Opt-In Downloads

Plugin Slug:
halfdata-optin-downloads

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Hello In All Languages

Plugin:

Hello In All Languages

Plugin Slug:
hello-in-all-languages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Horizontal scroll image slideshow

Plugin:

Horizontal scroll image slideshow

Plugin Slug:
horizontal-scroll-image-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HostFact bestelformulier integratie

Plugin:

HostFact bestelformulier integratie

Plugin Slug:
hostfact-bestelformulier-integratie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HQ Rental Software

Plugin:

HQ Rental Software

Plugin Slug:
hq-rental-software

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

IDer Login

Plugin:

IDer Login

Plugin Slug:
ider-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Image Mapper

Plugin:

Image Mapper

Plugin Slug:
image-mapper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Increase Sociability

Plugin:

Increase Sociability

Plugin Slug:
increase-sociability

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Insertify

Plugin:

Insertify

Plugin Slug:
insertify

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:

Instant Appointment

Plugin Slug:
instant-appointment

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

jCarousel

Plugin:

jCarousel

Plugin Slug:
jcarousel-for-wordpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Jet Footer Code

Plugin Slug:
jet-footer-code

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

KH Easy User Settings

Plugin:

KH Easy User Settings

Plugin Slug:
kh-easy-user-settings

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kredeum NFTs

Plugin:

Kredeum NFTs

Plugin Slug:
kredeum-nfts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

kvCORE IDX

Plugin:

kvCORE IDX

Plugin Slug:
kvcore-idx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LaunchPage.app Importer

Plugin:

LaunchPage.app Importer

Plugin Slug:
launchpage-app-importer

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Leader

Plugin:

Leader

Plugin Slug:
leader

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LeaderBoard Plugin

Plugin:

LeaderBoard Plugin

Plugin Slug:
leaderboard-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:

Library Management System

Plugin Slug:
library-management-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Like in Vk.com

Plugin:

Like in Vk.com

Plugin Slug:
like-on-vkontakte

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Category of Posts

Plugin:

Category of Posts

Plugin Slug:
list-one-category-of-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListApp Mobile Manager

Plugin:

ListApp Mobile Manager

Plugin Slug:
listapp-mobile-manager

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

LionScripts: Site Maintenance & Noindex Nofollow Plugin

Plugin:

LionScripts: Site Maintenance & Noindex Nofollow Plugin

Plugin Slug:
maintenance-and-noindex-nofollow

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MDC Comment Toolbar

Plugin:

MDC Comment Toolbar

Plugin Slug:
mdc-comment-toolbar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Metrika

Plugin:

Metrika

Plugin Slug:
metrika

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Minterpress

Plugin:

Minterpress

Plugin Slug:
minterpress

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multiple Admin Emails

Plugin:

Multiple Admin Emails

Plugin Slug:
multiple-admin-emails

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

My IDX Home Search

Plugin Slug:
my-idx-home-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

addWeather

Plugin:

addWeather

Plugin Slug:
myweather

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Nabz Image Gallery

Plugin Slug:
nabz-image-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Navayan CSV Export

Plugin:

Navayan CSV Export

Plugin Slug:
navayan-csv-export

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Subscriptions

Plugin:

Newsletter Subscriptions

Plugin Slug:
newsletter-subscriptions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Onlywire Multi Autosubmitter

Plugin:

Onlywire Multi Autosubmitter

Plugin Slug:
onlywire-multi-autosubmitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery & Pickup Location Date Time

Plugin:

Order Delivery & Pickup Location Date Time

Plugin Slug:
order-delivery-pickup-location-date-time-free-version

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

phZoom

Plugin:

phZoom

Plugin Slug:
phzoom

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PixProof

Plugin:

PixProof

Plugin Slug:
pixproof

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Popup Surveys & Polls for WordPress (Mare.io)

Plugin:

Popup Surveys & Polls for WordPress (Mare.io)

Plugin Slug:
popup-surveys

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Portfolio � Filterable Masonry Portfolio Gallery for Professionals

Plugin Slug:
portfolio-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel & Slider

Plugin:

Post Carousel & Slider

Plugin Slug:
post-types-carousel-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Posts and Products Views for WooCommerce

Plugin:

Posts and Products Views for WooCommerce

Plugin Slug:
posts-and-products-views

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Posts Date Ranges

Plugin:

Posts Date Ranges

Plugin Slug:
posts-date-ranges

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PowerFormBuilder

Plugin:

PowerFormBuilder

Plugin Slug:
power-forms-builder

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Push Monkey Pro � Web Push Notifications and WooCommerce Abandoned Cart

Plugin:

Push Monkey Pro � Web Push Notifications and WooCommerce Abandoned Cart

Plugin Slug:
push-monkey-desktop-push-notifications

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Quietly Insights

Plugin:

Quietly Insights

Plugin Slug:
quietly-insights

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Share Buttons � Social Media

Plugin:

Share Buttons � Social Media

Plugin Slug:
rich-web-share-button

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Saksh Escrow System

Plugin:

Saksh Escrow System

Plugin Slug:
saksh-escrow-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Saoshyant Element

Plugin:

Saoshyant Element

Plugin Slug:
saoshyant-element

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Service

Plugin:

Service

Plugin Slug:
service

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sign In With Google

Plugin:

Sign In With Google

Plugin Slug:
sign-in-with-google

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Simple Booking Widget

Plugin:

Simple Booking Widget

Plugin Slug:
simple-booking-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slope Widgets

Plugin:

Slope Widgets

Plugin Slug:
slope-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Media Sharing

Plugin:

Social Media Sharing

Plugin Slug:
social-media-sharing

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SOPA Blackout

Plugin:

SOPA Blackout

Plugin Slug:
sopa-blackout

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Pay Lite Manager

Plugin:

WP Simple Pay Lite Manager

Plugin Slug:
stripe-manager

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Surbma | SalesAutopilot Shortcode

Plugin:

Surbma | SalesAutopilot Shortcode

Plugin Slug:
surbma-salesautopilot-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVG Shortcode

Plugin:

SVG Shortcode

Plugin Slug:
svg-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TagGator

Plugin:

TagGator

Plugin Slug:
taggator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TCBD Popover

Plugin:

TCBD Popover

Plugin Slug:
tcbd-popover

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tidy Up

Plugin:

Tidy Up

Plugin Slug:
tidy-up

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TPG Get Posts

Plugin:

TPG Get Posts

Plugin Slug:
tpg-get-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TSB Occasion Editor

Plugin:

TSB Occasion Editor

Plugin Slug:
tsb-occasion-editor

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ui Slider Filter By Price

Plugin:

Ui Slider Filter By Price

Plugin Slug:
ui-slider-filter-by-price

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Utech World Time

Plugin:

Utech World Time

Plugin Slug:
utech-world-time-for-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

vBSSO-lite

Plugin:

vBSSO-lite

Plugin Slug:
vbsso-lite

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Visual Recent Posts

Plugin:

Visual Recent Posts

Plugin Slug:
visual-recent-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Visualmodo Elements

Plugin:

Visualmodo Elements

Plugin Slug:
visualmodo-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Website Toolbox Community

Plugin:

Website Toolbox Community

Plugin Slug:
website-toolbox-forums

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Cart Count Shortcode

Plugin:

WooCommerce Cart Count Shortcode

Plugin Slug:
woo-cart-count-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Basic Ordernumbers

Plugin:

WooCommerce Basic Ordernumbers

Plugin Slug:
woocommerce-basic-ordernumbers

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Filter

Plugin:

WordPress Filter

Plugin Slug:
wordpress-filter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wovax IDX

Plugin:

Wovax IDX

Plugin Slug:
wovax-idx

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Ban-User

Plugin:

WP-Ban-User

Plugin Slug:
wp-ban-user

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Fiddle

Plugin:

WP Fiddle

Plugin Slug:
wp-fiddle

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Flipkart Importer

Plugin:

WP Flipkart Importer

Plugin Slug:
wp-flipkart-importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-HideThat

Plugin:

WP-HideThat

Plugin Slug:
wp-hide-that

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wp Login with Ajax

Plugin:

Wp Login with Ajax

Plugin Slug:
wp-login-with-ajax

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Controller

Plugin:

WP Controller

Plugin Slug:
wp-management-controller

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wp NssUser Register

Plugin:

Wp NssUser Register

Plugin Slug:
wp-nssuser-register

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wp photo text slider 50

Plugin:

Wp photo text slider 50

Plugin Slug:
wp-photo-text-slider-50

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Service Payment Form With Authorize.net

Plugin:

WP Service Payment Form With Authorize.net

Plugin Slug:
wp-service-payment-form-with-authorizenet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tithe.ly Giving Button

Plugin:

Tithe.ly Giving Button

Plugin Slug:
wp-tithely

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP?????

Plugin:

WP?????

Plugin Slug:
wp-weixin-robot

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Admin Customization

Plugin:

Admin Customization

Plugin Slug:
wpp-customization

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:

Wr Age Verification

Plugin Slug:
wr-age-verification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:

Wr Age Verification

Plugin Slug:
wr-age-verification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

XML Multilanguage Sitemap Generator

Plugin:

XML Multilanguage Sitemap Generator

Plugin Slug:
xml-multilanguage-sitemap-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

XPD Reduce Image Filesize

Plugin:

XPD Reduce Image Filesize

Plugin Slug:
xpd-reduce-image-filesize

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YDS Support Ticket System

Plugin:

YDS Support Ticket System

Plugin Slug:
yds-support-ticket-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

States Map US

Plugin:

States Map US

Plugin Slug:
ymc-states-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YooBar

Plugin:

YooBar

Plugin Slug:
yoo-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Youtube Video Grid

Plugin:

Youtube Video Grid

Plugin Slug:
youmax-channel-embeds-for-youtube-businesses

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.8.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.8.2.1.

User Role Editor

Plugin Slug:
user-role-editor

Installations
700,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.64.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.64.4.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.64.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.64.1.

Members � Membership & User Role Editor Plugin

Plugin Slug:
members

Installations
300,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.11.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.5.3.

Image Widget

Plugin Slug:
image-widget

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.11.

LuckyWP Table of Contents

Plugin Slug:
luckywp-table-of-contents

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

Web Stories

Plugin Slug:
web-stories

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.38.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.38.0.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.7.2.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.7.4.

AI Engine

Plugin Slug:
ai-engine

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.5.

Ajax Search Lite � Live Search & Filter

Plugin Slug:
ajax-search-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.12.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.4.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Path Traversal

Patched in Version:
5.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.6.

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
5.2.64

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.64.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.9.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.9.9.4.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.0.6.

FULL � Cliente

Plugin Slug:
full-customer

Installations
30,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.26.

NotificationX � Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar

Plugin Slug:
notificationx

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.4.

PPWP � Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.6.

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.

Rate My Post � Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.5.

Minify HTML

Plugin Slug:
minify-html-markup

Installations
10,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
2.1.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.11.

Simple Side Tab

Plugin Slug:
simple-side-tab

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Essential Real Estate

Plugin Slug:
essential-real-estate

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.7.

MyParcel

Plugin:

MyParcel

Plugin Slug:
woocommerce-myparcel

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.24.2.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.3.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.2.

Notibar � Notification Bar for WordPress

Plugin Slug:
notibar

Installations
7,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.

Notibar � Notification Bar for WordPress

Plugin Slug:
notibar

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.
Plugin Slug:
vimeography

Installations
7,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

OAuth Single Sign On � SSO (OAuth Client)

Plugin Slug:
miniorange-login-with-eve-online-google-facebook

Installations
6,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.26.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.26.4.

Coupon Affiliates � Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage

Installations
5,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
5.16.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.16.7.2.

WPMobile.App � Android and iOS Mobile Application

Plugin Slug:
wpappninja

Installations
5,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
11.53

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.53.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.9.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.6.0.

GEO my WP

Plugin Slug:
geo-my-wp

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.1.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.13.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.13.

Hash Form � Drag & Drop Form Builder

Plugin Slug:
hash-form

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Cognito Forms

Plugin Slug:
cognito-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Falcon � WordPress Optimizations & Tweaks

Plugin Slug:
falcon

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.2.

Responsive Filterable Portfolio

Plugin Slug:
responsive-filterable-portfolio

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.0.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.9.

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.9.
Plugin Slug:
simple-link-directory

Installations
2,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
8.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.4.1.

360 Javascript Viewer

Plugin Slug:
360deg-javascript-viewer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.30.

Barcode Scanner and Inventory manager. POS (Point of Sale) � scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.7.

FormFacade � WordPress plugin for Google Forms

Plugin Slug:
formfacade

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.7.

ForumWP � Forum & Discussion Board

Plugin Slug:
forumwp

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.1.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.17.

Memberful � Membership Plugin

Plugin Slug:
memberful-wp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.74.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.74.0.

Posti Shipping

Plugin Slug:
posti-shipping

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.10.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.4.

Simple Restrict

Plugin Slug:
simple-restrict

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

Property Hive Mortgage Calculator

Plugin Slug:
property-hive-mortgage-calculator

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

Property Hive Stamp Duty Calculator

Plugin Slug:
property-hive-stamp-duty-calculator

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

WPC Order Notes for WooCommerce

Plugin Slug:
woo-order-notes

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.3.

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.22.

Waymark

Plugin:

Waymark

Plugin Slug:
waymark

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

AR for WordPress

Plugin Slug:
ar-for-wordpress

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
7.4

Severity Score:
Low


The vulnerability has been patched, so you should update to version 7.4.

Car Dealer (Dealership) and Vehicle sales

Plugin Slug:
cardealer

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
4.48

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.48.

Device Detector

Plugin Slug:
device-detector

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.1.

Last Viewed Posts by WPBeginner

Plugin Slug:
last-viewed-posts

Installations
600+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.2.

Out of the Block: OpenStreetMap

Plugin Slug:
ootb-openstreetmap

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.

AIcomments � ??????????? ? ?????? ChatGPT

Plugin Slug:
aicomments

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

CM Answers � Powerful WordPress Forum Plugin

Plugin Slug:
cm-answers

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.7.

Cryptocurrency Price Widget

Plugin Slug:
cryptocurrency-price-widget

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

iChart � Easy Charts and Graphs

Plugin Slug:
ichart

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

Mark New Posts

Plugin Slug:
mark-new-posts

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

WP Email Log � PostBox

Plugin Slug:
postbox-email-logs

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.5.

Themify Store Locator

Plugin Slug:
themify-store-locator

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

WooCommerce Additional Fees On Checkout (Free)

Plugin Slug:
woo-additional-fees-on-checkout-wordpress

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.8.

Gutenberg Blocks and Page Layouts � Attire Blocks

Plugin Slug:
attire-blocks

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.6.

Projectopia � WordPress Project Management

Plugin Slug:
projectopia-core

Installations
400+

Vulnerability:
Broken Authentication

Patched in Version:
5.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.8.

Payment Gateway Per Product for WooCommerce

Plugin Slug:
woocommerce-product-payments

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.9.

Check Pincode For Woocommerce

Plugin Slug:
check-pincode-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.

Currency Converter Widget ? PRO

Plugin Slug:
currency-converter-widget-pro

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

NewsmanApp

Plugin Slug:
newsmanapp

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.7.

Print Science Designer

Plugin Slug:
print-science-designer

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3.153

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.153.

Stop Registration Spam

Plugin Slug:
stop-registration-spam

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.24

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.24.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.2.

WP Mailster

Plugin Slug:
wp-mailster

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.18.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.18.0.

AutoWP � AI Content Writer & Rewriter

Plugin Slug:
autowp-ai-content-writer-rewriter

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Booking System Trafft

Plugin Slug:
booking-system-trafft

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

dejure.org Vernetzungsfunktion

Plugin Slug:
dejureorg-vernetzungsfunktion

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.98.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.98.0.

Email Reminders

Plugin Slug:
email-reminders

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

J&T Express Malaysia

Plugin Slug:
jt-express

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.15.

Revi.io � Customer & Products Reviews

Plugin Slug:
revi-io-customer-and-product-reviews

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8.0.

Staggs � Product Configurator Toolkit

Plugin Slug:
staggs

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.0.
Plugin Slug:
gallery-for-ultimate-member

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.1.

Gou Manage My Account Menu � User Roles

Plugin Slug:
gou-wc-account-tabs

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.9.

ICDSoft Reseller Store

Plugin Slug:
icdsoft-reseller-store

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.0.

Ksher

Plugin:

Ksher

Plugin Slug:
ksher-payment

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Media Downloader

Plugin Slug:
media-downloader

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.4.7.5.

Invoice Payment for WooCommerce

Plugin Slug:
invoice-payment-for-woocommerce

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.0.

Seraphinite Bulk Discounts for WooCommerce

Plugin Slug:
seraphinite-discount-for-woocommerce

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.7.

Hurrakify

Plugin Slug:
hurrakify

Installations
80+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.0.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.0.1.

SMS for WooCommerce

Plugin Slug:
wc-sms

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.1.1.

LabelGrid Tools

Plugin Slug:
label-grid-tools

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.59

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.59.

Simple Payment

Plugin Slug:
simple-payment

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.8.

CarDealerPress

Plugin Slug:
cardealerpress

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.2411.00

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.7.2411.00.

CE21 Suite

Plugin Slug:
ce21-suite

Installations
30+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.2.1.

EduAdmin Booking

Plugin Slug:
eduadmin-booking

Installations
30+

Vulnerability:
Local File Inclusion

Patched in Version:
5.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.0.

Hack-Info

Plugin Slug:
hack-info

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.18.
Plugin Slug:
clevernode-related-content

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.6.

Connect Contact Form 7 to Constant Contact V3

Plugin Slug:
connect-contact-form-7-to-constant-contact-v3

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.

Fancy Roller Scroller

Plugin Slug:
fancy-roller-scroller

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.1.

I Plant A Tree

Plugin Slug:
i-plant-a-tree

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.4.

ImmoToolBox Connect

Plugin Slug:
immotoolbox-connect

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.0.

Simple Presenter

Plugin Slug:
simple-presenter

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.2.

SMSify

Plugin:

SMSify

Plugin Slug:
smsify

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.1.0.

UNIVERSAM

Plugin Slug:
universam-demo

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.59

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.59.

WP Currency Exchange Rates

Plugin Slug:
wp-currency-exchange-rates

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

WP Quick Shop

Plugin Slug:
wp-quick-shop

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.2.

DX Dark Site

Plugin Slug:
devrix-dark-site

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.1.

FooGallery Premium

Plugin:

FooGallery Premium

Plugin Slug:
foogallery-premium

Vulnerability:
Directory Traversal

Patched in Version:
2.4.27

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.27.

GeoFlickr

Plugin Slug:
geoflickr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Hello Event Widgets For Elementor

Plugin Slug:
hello-event-widgets-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.0.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.

Kundgenerator

Plugin:

Kundgenerator

Plugin Slug:
kundgenerator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.7.

Quran Phrases About Most People Shortcodes

Plugin Slug:
quran-phrases-about-most-people-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

Responsive Google Maps | by imbaa

Plugin:

Responsive Google Maps | by imbaa

Plugin Slug:
responsive-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Termin-Kalender

Plugin:

Termin-Kalender

Plugin Slug:
termin-kalender

Vulnerability:
Broken Access Control

Patched in Version:
1.00.04

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.00.04.

WooCommerce PDF Vouchers

Plugin:

WooCommerce PDF Vouchers

Plugin Slug:
woocommerce-pdf-vouchers

Vulnerability:
Privilege Escalation

Patched in Version:
4.9.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.9.9.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.4.

WordPress Themes � 8 Patched / 2 Unpatched

Olivia

Theme:

Olivia

Theme Slug:
olivia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Zerif Lite

Theme:

Zerif Lite

Theme Slug:
zerif-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Barter

Theme:

Barter

Theme Slug:
barter

Downloads
7,610

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Bicycleshop

Theme Slug:
bicycleshop

Downloads
9,127

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.

Brand

Theme:

Brand

Theme Slug:
brand

Downloads
32,921

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.7.

hmd

Theme:

hmd

Theme Slug:
hmd

Downloads
892

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Plain Post

Theme Slug:
plain-post

Downloads
1,459

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.4.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.11.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.11.11.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Broken Authentication

Patched in Version:
5.4.15

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.4.15.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
Arbitrary Code Execution

Patched in Version:
8.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.0.4.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…