Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � April 3, 2024

In this report, 255 vulnerabilities have been publicly disclosed. Security patches for 178 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 77 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5 “Regina” was released on April 2, 2024, as the first major release of 2024. With the new release, you can add and manage fonts across your site, get more from your revisions, play with enhanced background and shadow tools, discover new Data Views, and so much more.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

WordPress Plugins � 175 Patched / 77 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Social Feed � Social Photos Gallery � Post Feed � Like Box

Plugin Slug:
easy-facebook-likebox

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin Slug:
pdf-viewer-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GetResponse for WordPress

Plugin Slug:
getresponse-integration

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yoo Slider

Plugin:

Yoo Slider

Plugin Slug:
yoo-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Responsive flipbook

Plugin:

Responsive flipbook

Plugin Slug:
wppdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Mega Fan Box Widget

Plugin:

WP Twitter Mega Fan Box Widget

Plugin Slug:
wp-twitter-mega-fan-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sponsors

Plugin:

Sponsors

Plugin Slug:
wp-sponsors

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Eggdrop

Plugin:

WP-Eggdrop

Plugin Slug:
wp-eggdrop

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Eggdrop

Plugin:

WP-Eggdrop

Plugin Slug:
wp-eggdrop

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Broken Images

Plugin:

Broken Images

Plugin Slug:
wp-broken-images

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Popup Cart Lite for WooCommerce

Plugin:

Popup Cart Lite for WooCommerce

Plugin Slug:
woocommerce-woocart-popup-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Social Media Share Buttons

Plugin:

Woocommerce Social Media Share Buttons

Plugin Slug:
woocommerce-social-media-share-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bookings Calendar

Plugin:

WooCommerce Bookings Calendar

Plugin Slug:
woo-bookings-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Whizzy

Plugin:

Whizzy

Plugin Slug:
whizzy

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Whizzy

Plugin:

Whizzy

Plugin Slug:
whizzy

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weekly Class Schedule

Plugin:

Weekly Class Schedule

Plugin Slug:
weekly-class-schedule

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

10Web Map Builder for Google Maps

Plugin:

10Web Map Builder for Google Maps

Plugin Slug:
wd-google-maps

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

User Rights Access Manager

Plugin:

User Rights Access Manager

Plugin Slug:
user-rights-access-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Social Comments � Email Notification & Lazy Load

Plugin:

Ultimate Social Comments � Email Notification & Lazy Load

Plugin Slug:
ultimate-facebook-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Anything

Plugin:

Sticky Anything

Plugin Slug:
toast-stick-anything

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Thumbs Rating

Plugin:

Thumbs Rating

Plugin Slug:
thumbs-rating

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tax Rate Upload

Plugin:

Tax Rate Upload

Plugin Slug:
tax-rate-upload

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Spin 360 deg and 3D Model Viewer

Plugin:

Spin 360 deg and 3D Model Viewer

Plugin Slug:
spin360

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SpiderFAQ

Plugin:

SpiderFAQ

Plugin Slug:
spider-faq

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Special Box for Content

Plugin:

Special Box for Content

Plugin Slug:
special-box-for-content

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Author Bio

Plugin:

Social Author Bio

Plugin Slug:
social-autho-bio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Lightbox slider � Responsive Lightbox Gallery

Plugin Slug:
simple-lightbox-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Addons

Plugin:

Shortcode Addons

Plugin Slug:
shortcode-addons

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SEO Title Tag

Plugin:

SEO Title Tag

Plugin Slug:
seo-title-tag

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Prenotazioni

Plugin:

Prenotazioni

Plugin Slug:
prenotazioni

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post-Plugin Library

Plugin:

Post-Plugin Library

Plugin Slug:
post-plugin-library

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pocket News Generator

Plugin:

Pocket News Generator

Plugin Slug:
pocket-news-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pocket News Generator

Plugin:

Pocket News Generator

Plugin Slug:
pocket-news-generator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Platinum SEO

Plugin:

Platinum SEO

Plugin Slug:
platinum-seo-pack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

pageMash > Page Management

Plugin:

pageMash > Page Management

Plugin Slug:
pagemash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Oxygen Builder

Plugin:

Oxygen Builder

Plugin Slug:
oxygen

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

OpenID

Plugin:

OpenID

Plugin Slug:
openid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

News Wall

Plugin:

News Wall

Plugin Slug:
news-wall

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

New Order Notification for Woocommerce

Plugin:

New Order Notification for Woocommerce

Plugin Slug:
new-order-notification-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lordicon Animated Icons

Plugin:

Lordicon Animated Icons

Plugin Slug:
lordicon-interactive-icons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Plugin:

Kanban Boards for WordPress

Plugin Slug:
kanban

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Mighty Classic Pros And Cons

Plugin:

Mighty Classic Pros And Cons

Plugin Slug:
joomdev-wp-pros-cons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IP Blocker Lite

Plugin:

IP Blocker Lite

Plugin Slug:
ip-address-blocker

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iFlyChat � WordPress Chat

Plugin:

iFlyChat � WordPress Chat

Plugin Slug:
iflychat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

HeartThis

Plugin:

HeartThis

Plugin Slug:
heart-this

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Header Image Slider

Plugin:

Header Image Slider

Plugin Slug:
header-image-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Responsive Image Gallery, Gallery Album

Plugin Slug:
gallery-album

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Responsive Image Gallery, Gallery Album

Plugin Slug:
gallery-album

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Filter Custom Fields & Taxonomies Light

Plugin:

Filter Custom Fields & Taxonomies Light

Plugin Slug:
filter-custom-fields-taxonomies-light

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP ERP

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Env�aloSimple

Plugin:

Env�aloSimple

Plugin Slug:
envialosimple-email-marketing-y-newsletters-gratis

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

DX-Watermark

Plugin:

DX-Watermark

Plugin Slug:
dx-watermark

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Hacklog Down As PDF

Plugin:

Hacklog Down As PDF

Plugin Slug:
down-as-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DD Rating

Plugin:

DD Rating

Plugin Slug:
dd-rating

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Bulk Editor

Plugin:

Custom Field Bulk Editor

Plugin Slug:
custom-field-bulk-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Convert Post Types

Plugin:

Convert Post Types

Plugin Slug:
convert-post-types

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Forms by Cimatti

Plugin:

Contact Forms by Cimatti

Plugin Slug:
contact-forms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Newsletter

Plugin:

Contact Form 7 Newsletter

Plugin Slug:
contact-form-7-newsletter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Comic Easel

Plugin:

Comic Easel

Plugin Slug:
comic-easel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Christmas Greetings

Plugin:

Christmas Greetings

Plugin Slug:
christmas-greetings

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chauffeur Taxi Booking System for WordPress

Plugin:

Chauffeur Taxi Booking System for WordPress

Plugin Slug:
chauffeur-booking-system

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Change default login logo,url and title

Plugin:

Change default login logo,url and title

Plugin Slug:
change-default-login-logo-url-and-title

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

CGC Maintenance Mode

Plugin:

CGC Maintenance Mode

Plugin Slug:
cgc-maintenance-mode

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Carousel Anything For WPBakery Page Builder

Plugin Slug:
carousel-anything

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Button

Plugin:

Button

Plugin Slug:
button

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Breakdance

Plugin:

Breakdance

Plugin Slug:
breakdance

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Appointment Calendar

Plugin:

Appointment Calendar

Plugin Slug:
appointment-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All In One Redirection

Plugin:

All In One Redirection

Plugin Slug:
all-in-one-redirection-404-pages-list

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AI Twitter Feeds (Twitter widget & shortcode)

Plugin:

AI Twitter Feeds (Twitter widget & shortcode)

Plugin Slug:
ai-twitter-feeds

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Aesop Story Engine

Plugin:

Aesop Story Engine

Plugin Slug:
aesop-story-engine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AdsPlace’r � Ad Manager, Inserter, AdSense Ads

Plugin:

AdsPlace’r � Ad Manager, Inserter, AdSense Ads

Plugin Slug:
adsplacer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Add Shortcodes Actions And Filters

Plugin:

Add Shortcodes Actions And Filters

Plugin Slug:
add-actions-and-filters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All-In-One Security (AIOS) � Security and Firewall

Plugin Slug:
all-in-one-wp-security-and-firewall

Installations
1,000,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.7.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.7.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.7.

Page Builder Gutenberg Blocks � CoBlocks

Plugin Slug:
coblocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.7.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
8.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.1.

CMP � Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance

Installations
200,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.11.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.

WooCommerce Cart Abandonment Recovery

Plugin Slug:
woo-cart-abandonment-recovery

Installations
200,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.27.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.2.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.3.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.0.7.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.4.5.

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.270

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.270.

Download Monitor

Plugin Slug:
download-monitor

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.5.

Genesis Blocks

Plugin Slug:
genesis-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

List category posts

Plugin Slug:
list-category-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.89.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.89.7.

Meta Tag Manager

Plugin Slug:
meta-tag-manager

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.10.2.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.0.10.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.10.2.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
3.0.10.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.10.2.

Social Icons Widget & Block by WPZOOM

Plugin Slug:
social-icons-widget-by-wpzoom

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.16.

Stackable � Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.12.

Template Kit � Import

Plugin Slug:
template-kit-import

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.15.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.5.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.3.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.2.

WP Chat App

Plugin Slug:
wp-whatsapp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

Events Manager � Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.7.2.

Events Manager � Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.4.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.4.7.2.

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.27.

BoldGrid Easy SEO � Simple and Effective SEO

Plugin Slug:
boldgrid-easy-seo

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.14.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.

Export and Import Users and Customers

Plugin Slug:
users-customers-import-export-for-wp-woocommerce

Installations
70,000+

Vulnerability:
Path Traversal

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

underConstruction

Plugin Slug:
underconstruction

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.22.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.1.8.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.9.3.

WordPress Infinite Scroll � Ajax Load More

Plugin Slug:
ajax-load-more

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.2.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Hubbub Lite � Fast, Reliable Social Sharing Buttons

Plugin Slug:
social-pug

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.33.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.33.1.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.0.

Klarna Payments for WooCommerce

Plugin Slug:
klarna-payments-for-woocommerce

Installations
40,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

SecuPress Free � WordPress Security

Plugin Slug:
secupress

Installations
40,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.2.

Pz-LinkCard

Plugin Slug:
pz-linkcard

Installations
30,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

Pz-LinkCard

Plugin Slug:
pz-linkcard

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.3.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

Ultimate Addons for Beaver Builder � Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Easy Appointments

Plugin Slug:
easy-appointments

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.19.

Easy Appointments

Plugin Slug:
easy-appointments

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.11.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.19.

Ecwid Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.12.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.12.11.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.1.

MP3 Audio Player for Music, Radio & Podcast by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.1.

My Calendar

Plugin Slug:
my-calendar

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.24.

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.24.6.

Booking Package

Plugin Slug:
booking-package

Installations
10,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.6.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.29.

Favorites

Plugin Slug:
favorites

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.4.

LWS Optimize

Plugin Slug:
lws-optimize

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

Mang Board WP

Plugin Slug:
mangboard

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.1.

Simple Revisions Delete

Plugin Slug:
simple-revisions-delete

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

VS Contact Form

Plugin Slug:
very-simple-contact-form

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
14.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.8.

140+ Widgets | Best Addons For Elementor � FREE

Plugin Slug:
xpro-elementor-addons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.3.

Media Library Folders

Plugin Slug:
media-library-plus

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
8.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.8.

WP Hotel Booking

Plugin Slug:
wp-hotel-booking

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.3.

Collect.chat � Chatbot ??

Plugin Slug:
collectchat

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

Finale Lite � Sales Countdown Timer & Discount for WooCommerce

Plugin Slug:
finale-woocommerce-sales-countdown-timer-discount

Installations
7,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.18.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.18.1.

Hash Elements

Plugin Slug:
hash-elements

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

ProfileGrid � User Profiles, Memberships, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

The Plus Blocks for Block Editor | Gutenberg

Plugin Slug:
the-plus-addons-for-block-editor

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.6.

wp-forecast

Plugin Slug:
wp-forecast

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.3.

Announce from the Dashboard

Plugin Slug:
announce-from-the-dashboard

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Better Elementor Addons

Plugin Slug:
better-elementor-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

JCH Optimize

Plugin Slug:
jch-optimize

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.1.

Salon booking system

Plugin Slug:
salon-booking-system

Installations
6,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
9.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.5.1.

Sliced Invoices � WordPress Invoice Plugin

Plugin Slug:
sliced-invoices

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.9.3.

Beaver Builder Addons by WPZOOM

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Booking Activities

Plugin Slug:
booking-activities

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.15.20.

Paid Memberships Pro � Mailchimp Add On

Plugin Slug:
pmpro-mailchimp

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.5.

B Slider � Slider for your block editor

Plugin Slug:
b-slider

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.13.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Builderall Builder for WordPress

Plugin Slug:
builderall-cheetah-for-wp

Installations
3,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.13.

Landingi Landing Pages

Plugin Slug:
landingi-landing-pages

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.2.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.11.

Spiffy Calendar

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.10.

Themify Event Post

Plugin Slug:
themify-event-post

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Product Sort and Display for WooCommerce

Plugin Slug:
woocommerce-product-sort-and-display

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

CRM Perks Forms � WordPress Form Builder

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.5.

CRM Perks Forms � WordPress Form Builder

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.5.

CRM Perks Forms � WordPress Form Builder

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Layouts for Elementor

Plugin Slug:
layouts-for-elementor

Installations
2,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.

WP Responsive Tabs horizontal vertical and accordion Tabs

Plugin Slug:
responsive-horizontal-vertical-and-accordion-tabs

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.1.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.18.

RT Easy Builder � Advanced addons for Elementor

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

WP Express Checkout (Accept PayPal Payments Easily)

Plugin Slug:
wp-express-checkout

Installations
2,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
2.3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.8.

WPC Badge Management for WooCommerce

Plugin Slug:
wpc-badge-management

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

WordPress Page Builder � Zion Builder

Plugin Slug:
zionbuilder

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.10.

Zotpress

Plugin:

Zotpress

Plugin Slug:
zotpress

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
7.3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.3.8.

Announcement & Notification Banner � Bulletin

Plugin Slug:
bulletin-announcements

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
3.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.0.

Geo Controller

Plugin Slug:
cf-geoplugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.6.5.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.1.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.19.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.8.

Creative Addons for Elementor

Plugin Slug:
creative-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

WPCS � WordPress Currency Switcher Professional

Plugin Slug:
currency-switcher

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.2.

Easy Form Builder

Plugin Slug:
easy-form-builder

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.5.

Falang multilanguage for WordPress

Plugin Slug:
falang

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.48

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.48.

FG PrestaShop to WooCommerce

Plugin Slug:
fg-prestashop-to-woocommerce

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.47.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.47.0.

Web Icons

Plugin Slug:
icon

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.0.11.

OSS Aliyun

Plugin Slug:
oss-aliyun

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.11.

Paid Memberships Pro � Payfast Gateway Add On

Plugin Slug:
pmpro-payfast

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.20.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.20.8.

Tumult Hype Animations

Plugin Slug:
tumult-hype-animations

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.12.

Tumult Hype Animations

Plugin Slug:
tumult-hype-animations

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.12.

Sharkdropship Dropshipping & Affiliate for for AliExpress

Plugin Slug:
wooshark-aliexpress-importer

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.5.

WordPress CRM Plugin � WP-CRM System

Plugin Slug:
wp-crm-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.9.1.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.2.

DELUCKS SEO

Plugin Slug:
delucks-seo

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.5.

Creative Image Slider � Responsive Slider Plugin

Plugin Slug:
creative-image-slider

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.0.

YITH WooCommerce Account Funds Premium

Plugin:

YITH WooCommerce Account Funds Premium

Plugin Slug:
yith-woocommerce-account-funds-premium

Vulnerability:
Broken Access Control

Patched in Version:
1.34.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.34.0.

WP Cost Estimation & Payment Forms Builder

Plugin:

WP Cost Estimation & Payment Forms Builder

Plugin Slug:
wp-estimation-form

Vulnerability:
SQL Injection

Patched in Version:
10.1.76

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.1.76.

Wholesale For WooCommerce

Plugin:

Wholesale For WooCommerce

Plugin Slug:
woocommerce-wholesale-pricing

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.1.

Slider by Supsystic

Plugin:

Slider by Supsystic

Plugin Slug:
slider-by-supsystic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.11.

REHub Framework

Plugin:

REHub Framework

Plugin Slug:
rehub-framework

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 19.6.2.

Limit Attempts by BestWebSoft

Plugin:

Limit Attempts by BestWebSoft

Plugin Slug:
limit-attempts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.0.

LayerSlider

Plugin:

LayerSlider

Plugin Slug:
layerslider

Vulnerability:
SQL Injection

Patched in Version:
7.10.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.10.1.

WP ERP

Plugin:

WP ERP

Plugin Slug:
erp

Vulnerability:
SQL Injection

Patched in Version:
1.30.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.30.0.

Calendarista Basic Edition

Plugin:

Calendarista Basic Edition

Plugin Slug:
calendarista-basic-edition

Vulnerability:
Broken Access Control

Patched in Version:
3.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.6.

WordPress Themes � 3 Patched / 0 Unpatched

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
SQL Injection

Patched in Version:
19.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 19.6.2.

Rehub

Theme:

Rehub

Theme Slug:
rehub-theme

Vulnerability:
Local File Inclusion

Patched in Version:
19.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 19.6.2.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…