Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � December 4, 2024

In this report, 200 vulnerabilities have been publicly disclosed. Security patches for 120 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 80 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes�throughout Core�and�the Block Editor.

WordPress Plugins � 120 Patched / 80 Unpatched

WP Project Manager � Task, team, and project management plugin featuring kanban board and gantt charts

Plugin Slug:
wedevs-project-manager

Installations
8,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer for Elementor

Plugin Slug:
countdown-timer-for-elementor

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
uber-grid

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel Slider for Elementor

Plugin Slug:
post-carousel-slider-for-elementor

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Random Banner

Plugin Slug:
random-banner

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Player for WPBakery

Plugin Slug:
video-player-for-wpbakery

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Page Builder � Zion Builder

Plugin Slug:
zionbuilder

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elementor Button Plus

Plugin Slug:
fd-elementor-button-plus

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Popup Plugin

Plugin Slug:
simple-popup-plugin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
skyboot-portfolio-gallery

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smart Marketing SMS and Newsletters Forms

Plugin Slug:
smart-marketing-for-wp

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Revisions Manager

Plugin Slug:
wp-revisions-manager

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Cost Of Goods

Plugin Slug:
ni-woocommerce-cost-of-goods

Installations
500+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Softtemplates For Elementor

Plugin Slug:
softtemplates-for-elementor

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ArCa Payment Gateway

Plugin Slug:
arca-payment-gateway

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Stripe Donation

Plugin Slug:
bin-stripe-donation

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Capitalize My Title WordPress Plugin

Plugin Slug:
capitalize-my-title

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CultBooking Hotel Booking Engine

Plugin Slug:
cultbooking-booking-engine

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FastBook � Responsive Appointment Booking and Scheduling System

Plugin Slug:
fastbook-responsive-appointment-booking-and-scheduling-system

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
load-more-posts

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multilevel Referral Affiliate Plugin for WooCommerce

Plugin Slug:
multilevel-referral-plugin-for-woocommerce

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Out Of Stock Badge

Plugin Slug:
out-of-stock-badge

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SpatialMatch IDX

Plugin Slug:
spatialmatch-free-lifestyle-search

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
third-party-cookie-eraser

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
vertical-carousel-slider

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Find Your Nearest

Plugin Slug:
wp-find-your-nearest

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

eDoc Easy Tables � Best WordPress Table Maker

Plugin Slug:
edoc-easy-tables

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-header-and-footer

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yahoo! WebPlayer

Plugin Slug:
yahoo-media-player

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Essential Breadcrumbs

Plugin Slug:
essential-breadcrumbs

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Z-Downloads

Plugin Slug:
z-downloads

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type to Map Store

Plugin Slug:
cpt-to-map-store

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SimpleSchema Free

Plugin Slug:
simpleschema-free

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mins To Read

Plugin Slug:
mins-to-read

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RingCentral Communications Plugin � FREE

Plugin Slug:
rccp-free

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sparkle Elementor Kit

Plugin Slug:
sparkle-elementor-kit

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Audit Exporter

Plugin Slug:
content-audit-exporter

Installations
20+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Devnex Addons For Elementor

Plugin Slug:
devnex-addons-for-elementor

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Donate Me

Plugin Slug:
donate-me

Installations
20+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Znajd? Prac? z Praca.pl

Plugin Slug:
znajdz-prace-z-pracapl

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Shortcodes

Plugin Slug:
awesome-shortcodes

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

adBuddy+ (AdBlocker Detection)

Plugin:

adBuddy+ (AdBlocker Detection)

Plugin Slug:
adbuddy-adblocker-detection

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced What should we write next about

Plugin:

Advanced What should we write next about

Plugin Slug:
advanced-what-should-we-write-about-next

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AIO Contact

Plugin:

AIO Contact

Plugin Slug:
aio-contact

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AIO Contact

Plugin:

AIO Contact

Plugin Slug:
aio-contact

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Best Addons for Elementor

Plugin Slug:
best-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Block Controller

Plugin Slug:
block-controller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BP Profile Shortcodes Extra

Plugin:

BP Profile Shortcodes Extra

Plugin Slug:
bp-profile-shortcodes-extra

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin:

Build App Online

Plugin Slug:
build-app-online

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Charity Addon for Elementor

Plugin:

Charity Addon for Elementor

Plugin Slug:
charity-addon-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chatter

Plugin:

Chatter

Plugin Slug:
chatter

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

?? ?? ?? By ?????

Plugin:

?? ?? ?? By ?????

Plugin Slug:
cosmosfarm-share-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cowidgets � Elementor Addons

Plugin:

Cowidgets � Elementor Addons

Plugin Slug:
cowidgets-elementor-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Element Bucket Addons for Elementor

Plugin Slug:
cs-element-bucket

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DancePress (TRWA)

Plugin:

DancePress (TRWA)

Plugin Slug:
dancepress-trwa

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:

FAT Services Booking

Plugin Slug:
fat-services-booking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:

FAT Services Booking

Plugin Slug:
fat-services-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Lenxel Core

Plugin Slug:
lenxel-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Lenxel Core

Plugin Slug:
lenxel-core

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PayPal Responder

Plugin:

PayPal Responder

Plugin Slug:
paypal-responder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Photo Video Store

Plugin:

Photo Video Store

Plugin Slug:
photo-video-store

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pixobe Cartography

Plugin:

Pixobe Cartography

Plugin Slug:
pixobe-cartography

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Paloma Widget

Plugin:

Paloma Widget

Plugin Slug:
postman-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pricing Tables For WPBakery Page Builder

Plugin:

Pricing Tables For WPBakery Page Builder

Plugin Slug:
pricing-tables-for-visual-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:

Revy

Plugin Slug:
revy

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:

Revy

Plugin Slug:
revy

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Counter Up

Plugin:

Counter Up

Plugin Slug:
wp-counter-up

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP MathJax

Plugin:

WP MathJax

Plugin Slug:
wp-mathjax-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Mermaid

Plugin:

WP Mermaid

Plugin Slug:
wp-mermaid

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spectra � WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.16.3.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.1004

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1004.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1002

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1002.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect

Installations
200,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.45

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.45.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect

Installations
200,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.44

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.44.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.10.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.10.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.4.

EmbedPress � Embed PDF, PDF 3D FlipBook, Instagram Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents

Plugin Slug:
embedpress

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.2.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.11.

Social Sharing Plugin � Sassy Social Share

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.70

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.70.

Asset CleanUp: Page Speed Booster

Plugin Slug:
wp-asset-clean-up

Installations
100,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
1.3.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.9.

Parsi Date

Plugin Slug:
wp-parsidate

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.2.

File Manager Pro � Filester

Plugin Slug:
filester

Installations
70,000+

Vulnerability:
Path Traversal

Patched in Version:
1.8.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.6.

File Manager Pro � Filester

Plugin Slug:
filester

Installations
70,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.4.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.3.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.2.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.3.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.4.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.145.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.145.1.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Maspik � Advanced Spam Protection

Plugin Slug:
contact-forms-anti-spam

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

Futurio Extra

Plugin Slug:
futurio-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.15.

Wallet for WooCommerce

Plugin Slug:
woo-wallet

Installations
20,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.7.

Product Labels For Woocommerce (Sale Badges)

Plugin Slug:
aco-product-labels-for-woocommerce

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.9.

CM Pop-Up Banners for WordPress

Plugin Slug:
cm-pop-up-banners

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.6.

Simple Side Tab

Plugin Slug:
simple-side-tab

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

Category Ajax Filter

Plugin Slug:
category-ajax-filter

Installations
7,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.3.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.12.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce

Installations
6,000+

Vulnerability:
Path Traversal

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.20.

Arkhe Blocks

Plugin Slug:
arkhe-blocks

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.27.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.27.1.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.16.

CM WordPress Search And Replace Plugin

Plugin Slug:
cm-on-demand-search-and-replace

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

Image Alt Text

Plugin Slug:
image-alt-text

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.

Sp*tify Play Button for WordPress

Plugin Slug:
spotify-play-button-for-wordpress

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.

Watu Quiz

Plugin Slug:
watu

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
3.4.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.1.3.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.22.

Cryptocurrency Widgets For Elementor

Plugin Slug:
cryptocurrency-widgets-for-elementor

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.5.

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.0.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.4.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.4.7.

Attesa Extra

Plugin Slug:
attesa-extra

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.3.
Plugin Slug:
bne-gallery-extended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Captivate Sync

Plugin Slug:
captivatesync-trade

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.26.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.9.

Name: CM E-Mail Registration Blacklist

Plugin Slug:
cm-email-blacklist

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.
Plugin Slug:
cm-header-footer-script-loader

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.
Plugin Slug:
inpost-gallery

Installations
1,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.3.

Tumult Hype Animations

Plugin Slug:
tumult-hype-animations

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.9.16

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.9.16.

WPCasa

Plugin:

WPCasa

Plugin Slug:
wpcasa

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Login with Vipps and MobilePay

Plugin Slug:
login-with-vipps

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.4.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

StreamWeasels YouTube Integration

Plugin Slug:
streamweasels-youtube-integration

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

jAlbum Bridge

Plugin Slug:
jalbum-bridge

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.16.

AWeber Forms by Optin Cat

Plugin Slug:
aweber-wp

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.8.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.18.

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.5.

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.17.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.17.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.17.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.8.17.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.17.0.

Simple User Registration

Plugin Slug:
wp-registration

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
6.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.0.

Campaign Monitor Forms by Optin Cat

Plugin Slug:
campaign-monitor-wp

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.8.

LegalWeb Cloud

Plugin Slug:
legalweb-cloud

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Form Data Collector

Plugin Slug:
form-data-collector

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.4.

HLS Player

Plugin Slug:
hls-player

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

Slotti Ajanvaraus

Plugin Slug:
slotti-ajanvaraus

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

WP GeoNames

Plugin Slug:
wp-geonames

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.

FAQ Builder AYS

Plugin Slug:
faq-builder-ays

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.2.

SEO Landing Page Generator

Plugin Slug:
seo-landing-page-generator

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.66.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.66.3.

Skt NURCaptcha

Plugin Slug:
skt-nurcaptcha

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.0.

Ragic Shortcode

Plugin Slug:
ragic-shortcode

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Video Lessons Manager � WordPress LMS Plugin

Plugin Slug:
cm-video-lesson-manager

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.3.

BMLT Tabbed Map

Plugin Slug:
bmlt-tabbed-map

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

Quick License Manager � WooCommerce Plugin

Plugin Slug:
quick-license-manager

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.18.

CMSMasters Elementor Addon

Plugin:

CMSMasters Elementor Addon

Plugin Slug:
cmsmasters-elementor-addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.0.

MP3 Sticky Player

Plugin:

MP3 Sticky Player

Plugin Slug:
fwdmsp

Vulnerability:
Path Traversal

Patched in Version:
8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Broken Access Control

Patched in Version:
67.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 67.2.0.

Leopard – WordPress offload media

Plugin:

Leopard – WordPress offload media

Plugin Slug:
leopard-wordpress-offload-media

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.2.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.3.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.8.3.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.8.3.3.

Booking & Appointment Plugin for WooCommerce

Plugin:

Booking & Appointment Plugin for WooCommerce

Plugin Slug:
woocommerce-booking

Vulnerability:
Broken Access Control

Patched in Version:
6.10.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.10.0.

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin:

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin Slug:
woocommerce-ultimate-gift-card

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.1.

JobSearch

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Privilege Escalation

Patched in Version:
2.6.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.8.

WordPress Themes � 0 Patched / 0 Unpatched

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…