Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � August 28, 2024

In this report, 122 vulnerabilities have been publicly disclosed. Security patches for 73 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.1 is available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

WordPress Plugins � 72 Patched / 46 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
yet-another-related-posts-plugin

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Table Builder � WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Maintenance & Coming Soon Redirect Animation

Plugin Slug:
maintenance-coming-soon-redirect-animation

Installations
5,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Super Testimonials

Plugin Slug:
super-testimonial

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Classic Addons � WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SendGrid for WordPress

Plugin Slug:
wp-sendgrid-mailer

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Skitter Slideshow

Plugin Slug:
wp-skitter-slideshow

Installations
500+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AdRotate

Plugin:

AdRotate

Plugin Slug:
adrotate1

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Animated Number Counters

Plugin:

Animated Number Counters

Plugin Slug:
animated-number-counters

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:

App Builder

Plugin Slug:
app-builder

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

azurecurve Toggle Show/Hide

Plugin:

azurecurve Toggle Show/Hide

Plugin Slug:
azurecurve-toggle-showhide

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Blog Introduction

Plugin:

Blog Introduction

Plugin Slug:
blogintroduction-wordpress-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brickscore

Plugin:

Brickscore

Plugin Slug:
brickscore

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin:

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:

Droip

Plugin Slug:
droip

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:

Droip

Plugin Slug:
droip

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GHActivity

Plugin:

GHActivity

Plugin Slug:
ghactivity

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Gixaw Chat

Plugin:

Gixaw Chat

Plugin Slug:
gixaw-chat

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hide My Site

Plugin:

Hide My Site

Plugin Slug:
hide-my-site

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ILC Thickbox

Plugin:

ILC Thickbox

Plugin Slug:
ilc-thickbox

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LatePoint

Plugin:

LatePoint

Plugin Slug:
latepoint

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin:

LWS Affiliation

Plugin Slug:
lws-affiliation

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Memberpress

Plugin:

Memberpress

Plugin Slug:
memberpress

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Misiek Paypal

Plugin:

Misiek Paypal

Plugin Slug:
misiek-paypal

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:

Misiek Photo Album

Plugin Slug:
misiek-photo-album

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Misiek Photo Album

Plugin:

Misiek Photo Album

Plugin Slug:
misiek-photo-album

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:

Music Request Manager

Plugin Slug:
music-request-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:

Music Request Manager

Plugin Slug:
music-request-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Music Request Manager

Plugin:

Music Request Manager

Plugin Slug:
music-request-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

OTA Sync Booking Engine Widget

Plugin:

OTA Sync Booking Engine Widget

Plugin Slug:
ota-sync-booking-engine-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Propovoice Pro

Plugin:

Propovoice Pro

Plugin Slug:
propovoice-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Video

Plugin:

Responsive Video

Plugin Slug:
responsive-video

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder � Advanced addons for Elementor

Plugin:

RT Easy Builder � Advanced addons for Elementor

Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Headline Rotator

Plugin:

Simple Headline Rotator

Plugin Slug:
simple-headline-rotator

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Snapshot Backup

Plugin:

Snapshot Backup

Plugin Slug:
snapshot-backup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Web and WooCommerce Addons for WPBakery Builder

Plugin:

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woo Inquiry

Plugin:

Woo Inquiry

Plugin Slug:
woo-inquiry

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordSurvey

Plugin:

WordSurvey

Plugin Slug:
wordsurvey

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:

WP Testimonial Widget

Plugin Slug:
wp-testimonial-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:

WP Testimonial Widget

Plugin Slug:
wp-testimonial-widget

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Testimonial Widget

Plugin:

WP Testimonial Widget

Plugin Slug:
wp-testimonial-widget

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:

Z Y N I T H

Plugin Slug:
zynith-seo

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Z Y N I T H

Plugin:

Z Y N I T H

Plugin Slug:
zynith-seo

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Privilege Escalation

Patched in Version:
6.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.4.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
responsive-lightbox

Installations
200,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.
Plugin Slug:
responsive-lightbox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.37.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.3.4.
Plugin Slug:
custom-permalinks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

Email Address Encoder

Plugin Slug:
email-address-encoder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.24.

EmbedPress � Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

Plugin Slug:
embedpress

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.9.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.15.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.14.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.2.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.0.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.0.

WordPress Button Plugin MaxButtons

Plugin Slug:
maxbuttons

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.8.0.

String locator

Plugin Slug:
string-locator

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.6.

Ninja Tables � Easiest Data Table Builder

Plugin Slug:
ninja-tables

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.13.

AI Engine

Plugin Slug:
ai-engine

Installations
70,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.5.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.1.

Visual CSS Style Editor

Plugin Slug:
yellow-pencil-visual-theme-customizer

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.4.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.31.

WP Last Modified Info

Plugin Slug:
wp-last-modified-info

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

Image Hotspot by DevVN

Plugin Slug:
devvn-image-hotspot

Installations
30,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.6.

Simple Job Board

Plugin Slug:
simple-job-board

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.12.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.12.4.

140+ Widgets | Xpro Addons For Elementor � FREE

Plugin Slug:
xpro-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.4.

Generate Images � Magic Post Thumbnail

Plugin Slug:
magic-post-thumbnail

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.10.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

WooCommerce Google Feed Manager

Plugin Slug:
wp-product-feed-manager

Installations
10,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
2.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.0.
Plugin Slug:
bp-profile-search

Installations
8,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.8.

Themify Builder

Plugin Slug:
themify-builder

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.2.

GEO my WP

Plugin Slug:
geo-my-wp

Installations
5,000+

Vulnerability:
Local File Inclusion

Patched in Version:
4.5.0.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.0.2.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
SQL Injection

Patched in Version:
5.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.7.3.

WPMobile.App � Android and iOS Mobile Application

Plugin Slug:
wpappninja

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.49

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.49.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Settings Change

Patched in Version:
2.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.11.

Collapsing Archives

Plugin Slug:
collapsing-archives

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.6.

Name Directory

Plugin Slug:
name-directory

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.29.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.29.1.

LH Add Media From Url

Plugin Slug:
lh-add-media-from-url

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.30

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.30.

Event Espresso � Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.22.decaf

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.22.decaf.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.15.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.15.

Image Optimizer, Resizer and CDN � Sirv

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
7.2.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.2.8.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.3.103

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.103.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.103

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.103.

Favicon Generator (CLOSED)

Plugin Slug:
favicon-generator

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp

Installations
40+

Vulnerability:
SQL Injection

Patched in Version:
2.4.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.5.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.5.

Greenshift Query and Meta Addon

Plugin:

Greenshift Query and Meta Addon

Plugin Slug:
greenshiftquery

Vulnerability:
SQL Injection

Patched in Version:
3.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.9.2.

Greenshift Woocommerce Addon

Plugin:

Greenshift Woocommerce Addon

Plugin Slug:
greenshiftwoo

Vulnerability:
SQL Injection

Patched in Version:
1.9.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.8.

Oxygen Builder

Plugin:

Oxygen Builder

Plugin Slug:
oxygenbuilder

Vulnerability:
Broken Access Control

Patched in Version:
4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.

Multilingual CMS

Plugin:

Multilingual CMS

Plugin Slug:
sitepress-multilingual-cms

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
4.6.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.6.13.

WBW Product Table PRO

Plugin:

WBW Product Table PRO

Plugin Slug:
woo-producttables-pro

Vulnerability:
SQL Injection

Patched in Version:
1.9.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.5.

WP Armour Extended

Plugin:

WP Armour Extended

Plugin Slug:
wp-armour-extended

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.32.

WP Armour Extended

Plugin:

WP Armour Extended

Plugin Slug:
wp-armour-extended

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.32.

File Manager Pro

Plugin:

File Manager Pro

Plugin Slug:
wp-file-manager-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
8.3.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 8.3.8.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
PHP Object Injection

Patched in Version:
2.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.4.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Access Control

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Access Control

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

WordPress Themes � 1 Patched / 3 Unpatched

Esotera

Theme:

Esotera

Theme Slug:
esotera

Downloads
59,465

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

IntoTheDark

Theme Slug:
intothedark

Downloads
1,994

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Tempera

Theme:

Tempera

Theme Slug:
tempera

Downloads
703,425

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Phlox PRO

Theme:

Phlox PRO

Theme Slug:
phlox-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.16.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.16.5.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…