In this report, 200 vulnerabilities have been publicly disclosed. Security patches for 120 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 80 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.7.1 is available! This minor release features 16 bug fixes�throughout Core�and�the Block Editor.
WordPress Plugins � 120 Patched / 80 Unpatched
s2Member � Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
- Plugin Slug:
- s2member
- Installations
- 10,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2024-51815
WP Project Manager � Task, team, and project management plugin featuring kanban board and gantt charts
- Plugin Slug:
- wedevs-project-manager
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-12015
Borderless � Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg
- Plugin Slug:
- borderless
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54211
Countdown Timer for Elementor
- Plugin:
-
Countdown Timer for Elementor
- Plugin Slug:
- countdown-timer-for-elementor
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53743
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
- Plugin Slug:
- magical-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54212
WordPress Portfolio Builder � Portfolio Gallery
- Plugin Slug:
- uber-grid
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53788
Post Carousel Slider for Elementor
- Plugin Slug:
- post-carousel-slider-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53749
Beds24 Online Booking
- Plugin:
-
Beds24 Online Booking
- Plugin Slug:
- beds24-online-booking
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10177
Random Banner
- Plugin:
-
Random Banner
- Plugin Slug:
- random-banner
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53787
Video Player for WPBakery
- Plugin:
-
Video Player for WPBakery
- Plugin Slug:
- video-player-for-wpbakery
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53747
WordPress Page Builder � Zion Builder
- Plugin Slug:
- zionbuilder
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54213
Elementor Button Plus
- Plugin:
-
Elementor Button Plus
- Plugin Slug:
- fd-elementor-button-plus
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53746
Simple Popup Plugin
- Plugin:
-
Simple Popup Plugin
- Plugin Slug:
- simple-popup-plugin
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53741
Elementor Image Gallery Plugin ( Masonry Gallery, Elementor Gallery Plugin With Captions, Elementor Portfolio Gallery Widget, Filterable Gallery )
- Plugin Slug:
- skyboot-portfolio-gallery
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53744
Smart Marketing SMS and Newsletters Forms
- Plugin Slug:
- smart-marketing-for-wp
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53784
WP Revisions Manager
- Plugin:
-
WP Revisions Manager
- Plugin Slug:
- wp-revisions-manager
- Installations
- 800+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53761
Ni WooCommerce Cost Of Goods
- Plugin:
-
Ni WooCommerce Cost Of Goods
- Plugin Slug:
- ni-woocommerce-cost-of-goods
- Installations
- 500+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53783
Softtemplates For Elementor
- Plugin:
-
Softtemplates For Elementor
- Plugin Slug:
- softtemplates-for-elementor
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53764
ArCa Payment Gateway
- Plugin:
-
ArCa Payment Gateway
- Plugin Slug:
- arca-payment-gateway
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53759
Stripe Donation
- Plugin:
-
Stripe Donation
- Plugin Slug:
- bin-stripe-donation
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53752
Capitalize My Title WordPress Plugin
- Plugin Slug:
- capitalize-my-title
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53760
CultBooking Hotel Booking Engine
- Plugin:
-
CultBooking Hotel Booking Engine
- Plugin Slug:
- cultbooking-booking-engine
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53753
FastBook � Responsive Appointment Booking and Scheduling System
- Plugin Slug:
- fastbook-responsive-appointment-booking-and-scheduling-system
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53762
Load More Posts
- Plugin:
-
Load More Posts
- Plugin Slug:
- load-more-posts
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53780
Multilevel Referral Affiliate Plugin for WooCommerce
- Plugin Slug:
- multilevel-referral-plugin-for-woocommerce
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53742
Out Of Stock Badge
- Plugin:
-
Out Of Stock Badge
- Plugin Slug:
- out-of-stock-badge
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53754
SpatialMatch IDX
- Plugin:
-
SpatialMatch IDX
- Plugin Slug:
- spatialmatch-free-lifestyle-search
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53781
Third Party Cookie Eraser
- Plugin:
-
Third Party Cookie Eraser
- Plugin Slug:
- third-party-cookie-eraser
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53755
Vertical Carousel
- Plugin:
-
Vertical Carousel
- Plugin Slug:
- vertical-carousel-slider
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53756
WP Find Your Nearest
- Plugin:
-
WP Find Your Nearest
- Plugin Slug:
- wp-find-your-nearest
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53757
eDoc Easy Tables � Best WordPress Table Maker
- Plugin Slug:
- edoc-easy-tables
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53793
Simple Header and Footer
- Plugin:
-
Simple Header and Footer
- Plugin Slug:
- simple-header-and-footer
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53777
Yahoo! WebPlayer
- Plugin:
-
Yahoo! WebPlayer
- Plugin Slug:
- yahoo-media-player
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53779
Essential Breadcrumbs
- Plugin:
-
Essential Breadcrumbs
- Plugin Slug:
- essential-breadcrumbs
- Installations
- 50+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53778
Z-Downloads
- Plugin:
-
Z-Downloads
- Plugin Slug:
- z-downloads
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54206
Custom Post Type to Map Store
- Plugin:
-
Custom Post Type to Map Store
- Plugin Slug:
- cpt-to-map-store
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53769
SimpleSchema Free
- Plugin:
-
SimpleSchema Free
- Plugin Slug:
- simpleschema-free
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53771
Mins To Read
- Plugin:
-
Mins To Read
- Plugin Slug:
- mins-to-read
- Installations
- 30+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53765
RingCentral Communications Plugin � FREE
- Plugin Slug:
- rccp-free
- Installations
- 30+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53770
Sparkle Elementor Kit
- Plugin:
-
Sparkle Elementor Kit
- Plugin Slug:
- sparkle-elementor-kit
- Installations
- 30+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53774
Content Audit Exporter
- Plugin:
-
Content Audit Exporter
- Plugin Slug:
- content-audit-exporter
- Installations
- 20+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53768
Devnex Addons For Elementor
- Plugin:
-
Devnex Addons For Elementor
- Plugin Slug:
- devnex-addons-for-elementor
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53766
Donate Me
- Plugin:
-
Donate Me
- Plugin Slug:
- donate-me
- Installations
- 20+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53776
Newsletter, Email Marketing, Email Subscriber � Mail Picker
- Plugin Slug:
- mail-picker
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53772
Znajd? Prac? z Praca.pl
- Plugin:
-
Znajd? Prac? z Praca.pl
- Plugin Slug:
- znajdz-prace-z-pracapl
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53773
Awesome Shortcodes
- Plugin:
-
Awesome Shortcodes
- Plugin Slug:
- awesome-shortcodes
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54209
YaDisk Files
- Plugin:
-
YaDisk Files
- Plugin Slug:
- wp-yadisk-files
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10710
YaDisk Files
- Plugin:
-
YaDisk Files
- Plugin Slug:
- wp-yadisk-files
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10709
adBuddy+ (AdBlocker Detection)
- Plugin:
adBuddy+ (AdBlocker Detection)
- Plugin Slug:
- adbuddy-adblocker-detection
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10510
Advanced What should we write next about
- Plugin:
Advanced What should we write next about
- Plugin Slug:
- advanced-what-should-we-write-about-next
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53789
AIO Contact
- Plugin:
AIO Contact
- Plugin Slug:
- aio-contact
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54218
AIO Contact
- Plugin:
AIO Contact
- Plugin Slug:
- aio-contact
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54219
ARForms
- Plugin:
ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Path Traversal
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54216
ARForms
- Plugin:
ARForms
- Plugin Slug:
- arforms
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54217
Best Addons for Elementor
- Plugin:
-
Best Addons for Elementor
- Plugin Slug:
- best-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53763
Block Controller
- Plugin:
-
Block Controller
- Plugin Slug:
- block-controller
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54208
BP Profile Shortcodes Extra
- Plugin:
BP Profile Shortcodes Extra
- Plugin Slug:
- bp-profile-shortcodes-extra
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-11732
Build App Online
- Plugin:
Build App Online
- Plugin Slug:
- build-app-online
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53751
Charity Addon for Elementor
- Plugin:
Charity Addon for Elementor
- Plugin Slug:
- charity-addon-for-elementor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-12062
Chatter
- Plugin:
Chatter
- Plugin Slug:
- chatter
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53785
?? ?? ?? By ?????
- Plugin:
?? ?? ?? By ?????
- Plugin Slug:
- cosmosfarm-share-buttons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53745
Cowidgets � Elementor Addons
- Plugin:
Cowidgets � Elementor Addons
- Plugin Slug:
- cowidgets-elementor-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53786
Advanced Element Bucket Addons for Elementor
- Plugin Slug:
- cs-element-bucket
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54210
DancePress (TRWA)
- Plugin:
DancePress (TRWA)
- Plugin Slug:
- dancepress-trwa
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53775
FAT Services Booking
- Plugin:
FAT Services Booking
- Plugin Slug:
- fat-services-booking
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54220
FAT Services Booking
- Plugin:
FAT Services Booking
- Plugin Slug:
- fat-services-booking
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2024-54221
Lenxel Core
- Plugin:
-
Lenxel Core
- Plugin Slug:
- lenxel-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53791
Lenxel Core
- Plugin:
-
Lenxel Core
- Plugin Slug:
- lenxel-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53790
PayPal Responder
- Plugin:
PayPal Responder
- Plugin Slug:
- paypal-responder
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53750
Photo Video Store
- Plugin:
Photo Video Store
- Plugin Slug:
- photo-video-store
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-53782
Pixobe Cartography
- Plugin:
Pixobe Cartography
- Plugin Slug:
- pixobe-cartography
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53767
Paloma Widget
- Plugin:
Paloma Widget
- Plugin Slug:
- postman-widget
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
-
2024-54205
Pricing Tables For WPBakery Page Builder
- Plugin:
Pricing Tables For WPBakery Page Builder
- Plugin Slug:
- pricing-tables-for-visual-composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10175
Revy
- Plugin:
Revy
- Plugin Slug:
- revy
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2024-54215
Revy
- Plugin:
Revy
- Plugin Slug:
- revy
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2024-54214
WordPress Auction Plugin
- Plugin:
WordPress Auction Plugin
- Plugin Slug:
- wp-auctions
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
-
2024-51615
WordPress Auction Plugin
- Plugin:
WordPress Auction Plugin
- Plugin Slug:
- wp-auctions
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-54207
Counter Up
- Plugin:
Counter Up
- Plugin Slug:
- wp-counter-up
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-10895
WP MathJax
- Plugin:
WP MathJax
- Plugin Slug:
- wp-mathjax-plus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53758
WP Mermaid
- Plugin:
WP Mermaid
- Plugin Slug:
- wp-mermaid
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
-
2024-53748
Elementor Website Builder � More than Just a Page Builder
- Plugin Slug:
- elementor
- Installations
- 10,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.25.8
- Severity Score:
- Medium
- CVE:
-
2024-8236
WPForms � Easy Form Builder for WordPress � Contact Forms, Payment Forms, Surveys, & More
- Plugin Slug:
- wpforms-lite
- Installations
- 6,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.1.6
- Severity Score:
- Medium
- CVE:
-
2024-7056
Spectra � WordPress Gutenberg Blocks
- Plugin Slug:
- ultimate-addons-for-gutenberg
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.16.3
- Severity Score:
- Medium
- CVE:
-
2024-10484
Photo Gallery, Sliders, Proofing and Themes � NextGEN Gallery
- Plugin Slug:
- nextgen-gallery
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.59.5
- Severity Score:
- Medium
- CVE:
-
2024-6393
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 500,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.1004
- Severity Score:
- Medium
- CVE:
-
2024-10798
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1002
- Severity Score:
- Medium
- CVE:
-
2024-9682
FluentSMTP � WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
- Plugin Slug:
- fluent-smtp
- Installations
- 300,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.2.83
- Severity Score:
- Critical
- CVE:
-
2024-9511
Otter Blocks � Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
- Plugin Slug:
- otter-blocks
- Installations
- 300,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 3.0.7
- Severity Score:
- Medium
- CVE:
-
2024-11219
Spam protection, Anti-Spam, FireWall by CleanTalk
- Plugin Slug:
- cleantalk-spam-protect
- Installations
- 200,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 6.45
- Severity Score:
- High
- CVE:
-
2024-10781
Spam protection, Anti-Spam, FireWall by CleanTalk
- Plugin Slug:
- cleantalk-spam-protect
- Installations
- 200,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 6.44
- Severity Score:
- Critical
- CVE:
-
2024-10542
FileBird � WordPress Media Library Folders & File Manager
- Plugin Slug:
- filebird
- Installations
- 200,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.3.4
- Severity Score:
- Medium
- CVE:
-
2024-53825
Jeg Elementor Kit
- Plugin:
-
Jeg Elementor Kit
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.10
- Severity Score:
- Medium
- CVE:
-
2024-10308
Jeg Elementor Kit
- Plugin:
-
Jeg Elementor Kit
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 200,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.6.10
- Severity Score:
- Medium
- CVE:
-
2024-8899
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content � ProfilePress
- Plugin Slug:
- wp-user-avatar
- Installations
- 200,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 4.15.19
- Severity Score:
- Medium
- CVE:
-
2024-11083
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows)
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.6
- Severity Score:
- Medium
- CVE:
-
2024-9058
Beaver Builder � WordPress Page Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.4.4
- Severity Score:
- Medium
- CVE:
-
2024-53797
EmbedPress � Embed PDF, PDF 3D FlipBook, Instagram Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents
- Plugin Slug:
- embedpress
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1.4
- Severity Score:
- Medium
- CVE:
-
2024-11203
Everest Forms � Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease!
- Plugin Slug:
- everest-forms
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.4.2
- Severity Score:
- Medium
- CVE:
-
2024-10471
Advanced File Manager
- Plugin:
-
Advanced File Manager
- Plugin Slug:
- file-manager-advanced
- Installations
- 100,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 5.2.11
- Severity Score:
- High
- CVE:
-
2024-11391
Social Sharing Plugin � Sassy Social Share
- Plugin Slug:
- sassy-social-share
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.70
- Severity Score:
- High
- CVE:
-
2024-11252
The Plus Addons for Elementor � Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin:
-
The Plus Addons for Elementor � Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.0.1
- Severity Score:
- Medium
- CVE:
-
2024-53823
Widget Options � The #1 WordPress Widget & Block Control Plugin
- Plugin Slug:
- widget-options
- Installations
- 100,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 4.0.8
- Severity Score:
- Critical
- CVE:
-
2024-8672
Hustle � Email Marketing, Lead Generation, Optins, Popups
- Plugin Slug:
- wordpress-popup
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.8.6
- Severity Score:
- Medium
- CVE:
-
2024-10580
Hustle � Email Marketing, Lead Generation, Optins, Popups
- Plugin Slug:
- wordpress-popup
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.8.6
- Severity Score:
- Medium
- CVE:
-
2024-10579
Asset CleanUp: Page Speed Booster
- Plugin Slug:
- wp-asset-clean-up
- Installations
- 100,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.3.9.9
- Severity Score:
- Medium
- CVE:
-
2024-53738
Parsi Date
- Plugin:
-
Parsi Date
- Plugin Slug:
- wp-parsidate
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.2
- Severity Score:
- High
- CVE:
-
2024-11032
Total Upkeep � WordPress Backup Plugin plus Restore & Migrate by BoldGrid
- Plugin Slug:
- boldgrid-backup
- Installations
- 70,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 1.16.7
- Severity Score:
- Critical
- CVE:
-
2024-9461
File Manager Pro � Filester
- Plugin:
-
File Manager Pro � Filester
- Plugin Slug:
- filester
- Installations
- 70,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 1.8.6
- Severity Score:
- High
- CVE:
-
2024-9669
File Manager Pro � Filester
- Plugin:
-
File Manager Pro � Filester
- Plugin Slug:
- filester
- Installations
- 70,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.8.5
- Severity Score:
- High
- CVE:
-
2024-8066
FOX � Currency Switcher Professional for WooCommerce
- Plugin Slug:
- woocommerce-currency-switcher
- Installations
- 60,000+
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 1.4.2.3
- Severity Score:
- High
- CVE:
-
2024-10640
Bold Page Builder
- Plugin:
-
Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.2.2
- Severity Score:
- Medium
- CVE:
-
2024-53801
Themesflat Addons For Elementor
- Plugin:
-
Themesflat Addons For Elementor
- Plugin Slug:
- themesflat-addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.3
- Severity Score:
- Medium
- CVE:
-
2024-53796
Post Grid Gutenberg Blocks and WordPress Blog Plugin � PostX
- Plugin Slug:
- ultimate-post
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1.16
- Severity Score:
- Medium
- CVE:
-
2024-53818
Booster for WooCommerce
- Plugin:
-
Booster for WooCommerce
- Plugin Slug:
- woocommerce-jetpack
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.2.4
- Severity Score:
- Medium
- CVE:
-
2024-9170
Security & Malware scan by CleanTalk
- Plugin Slug:
- security-malware-firewall
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.145.1
- Severity Score:
- Critical
- CVE:
-
2024-10570
Tutor LMS Elementor Addons
- Plugin:
-
Tutor LMS Elementor Addons
- Plugin Slug:
- tutor-lms-elementor-addons
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.6
- Severity Score:
- Medium
- CVE:
-
2024-53816
Analytify � Google Analytics Dashboard For WordPress (GA4 analytics made easy)
- Plugin Slug:
- wp-analytify
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
-
2024-53814
Maspik � Advanced Spam Protection
- Plugin Slug:
- contact-forms-anti-spam
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.2.8
- Severity Score:
- Medium
- CVE:
-
2024-53806
Futurio Extra
- Plugin:
-
Futurio Extra
- Plugin Slug:
- futurio-extra
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.15
- Severity Score:
- Medium
- CVE:
-
2024-53802
Logo Slider � Logo Carousel, Logo Showcase & Client Logo Slider Plugin
- Plugin Slug:
- logo-slider-wp
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.0
- Severity Score:
- Medium
- CVE:
-
2024-10896
Logo Slider � Logo Carousel, Logo Showcase & Client Logo Slider Plugin
- Plugin Slug:
- logo-slider-wp
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.0
- Severity Score:
- Medium
- CVE:
-
2024-10473
Wallet for WooCommerce
- Plugin:
-
Wallet for WooCommerce
- Plugin Slug:
- woo-wallet
- Installations
- 20,000+
- Vulnerability:
- Other Vulnerability Type
- Patched in Version:
- 1.5.7
- Severity Score:
- Medium
- CVE:
-
2024-7747
Product Labels For Woocommerce (Sale Badges)
- Plugin Slug:
- aco-product-labels-for-woocommerce
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.9
- Severity Score:
- High
- CVE:
-
2024-53817
CM Pop-Up Banners for WordPress
- Plugin:
-
CM Pop-Up Banners for WordPress
- Plugin Slug:
- cm-pop-up-banners
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.6
- Severity Score:
- High
- CVE:
-
2024-11202
RegistrationMagic � User Registration Plugin with Custom Registration Forms
- Plugin Slug:
- custom-registration-form-builder-with-submission-manager
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 6.0.2.7
- Severity Score:
- Critical
- CVE:
-
2024-10508
NEX-Forms � Ultimate Form Builder � Contact forms and much more
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 8.7.9
- Severity Score:
- High
- CVE:
-
2024-53808
Paid Membership Subscriptions � Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
-
Paid Membership Subscriptions � Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 2.13.1
- Severity Score:
- High
- CVE:
-
2024-10261
Simple Side Tab
- Plugin:
-
Simple Side Tab
- Plugin Slug:
- simple-side-tab
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.0
- Severity Score:
- Medium
- CVE:
-
2024-10551
Primary Addon for Elementor
- Plugin:
-
Primary Addon for Elementor
- Plugin Slug:
- primary-addon-for-elementor
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.3
- Severity Score:
- Medium
- CVE:
-
2024-10670
Category Ajax Filter
- Plugin:
-
Category Ajax Filter
- Plugin Slug:
- category-ajax-filter
- Installations
- 7,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.8.3
- Severity Score:
- High
- CVE:
-
2024-10871
CM Tooltip Glossary
- Plugin:
-
CM Tooltip Glossary
- Plugin Slug:
- enhanced-tooltipglossary
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3.12
- Severity Score:
- High
- CVE:
-
2024-11202
WDesignKit � Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
- Plugin:
-
WDesignKit � Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
- Plugin Slug:
- wdesignkit
- Installations
- 7,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.0
- Severity Score:
- Medium
- CVE:
-
2024-53811
Product Input Fields for WooCommerce
- Plugin Slug:
- product-input-fields-for-woocommerce
- Installations
- 6,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 2.0
- Severity Score:
- Medium
- CVE:
-
2024-10857
WP Travel � Ultimate Travel Booking System, Tour Management Engine
- Plugin Slug:
- wp-travel
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 9.7.0
- Severity Score:
- Medium
- CVE:
-
2024-53813
All Bootstrap Blocks
- Plugin:
-
All Bootstrap Blocks
- Plugin Slug:
- all-bootstrap-blocks
- Installations
- 4,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.20
- Severity Score:
- High
- CVE:
-
2024-53824
Arkhe Blocks
- Plugin:
-
Arkhe Blocks
- Plugin Slug:
- arkhe-blocks
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.27.1
- Severity Score:
- Medium
- CVE:
-
2024-53794
Booking calendar, Appointment Booking System
- Plugin Slug:
- booking-calendar
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.16
- Severity Score:
- High
- CVE:
-
2024-9504
Pinpoint Booking System � #1 WordPress Booking Plugin
- Plugin Slug:
- booking-system
- Installations
- 4,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.9.9.5.2
- Severity Score:
- High
- CVE:
-
2024-53815
CM WordPress Search And Replace Plugin
- Plugin Slug:
- cm-on-demand-search-and-replace
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.3
- Severity Score:
- High
- CVE:
-
2024-11202
Image Alt Text
- Plugin:
-
Image Alt Text
- Plugin Slug:
- image-alt-text
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.0
- Severity Score:
- Medium
- CVE:
-
2024-11918
Sp*tify Play Button for WordPress
- Plugin Slug:
- spotify-play-button-for-wordpress
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.12
- Severity Score:
- Medium
- CVE:
-
2024-11192
Watu Quiz
- Plugin:
-
Watu Quiz
- Plugin Slug:
- watu
- Installations
- 4,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.4.1.3
- Severity Score:
- High
- CVE:
-
2024-53792
Additional Order Filters for WooCommerce
- Plugin Slug:
- additional-order-filters-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.22
- Severity Score:
- High
- CVE:
-
2024-11418
Cryptocurrency Widgets For Elementor
- Plugin Slug:
- cryptocurrency-widgets-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.6.5
- Severity Score:
- High
- CVE:
-
2024-53739
Restaurant & Cafe Addon for Elementor
- Plugin Slug:
- restaurant-cafe-addon-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.0
- Severity Score:
- Medium
- CVE:
-
2024-10780
Client Invoicing by Sprout Invoices � Easy Estimates and Invoices for WordPress
- Plugin Slug:
- sprout-invoices
- Installations
- 2,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 20.8.1
- Severity Score:
- Medium
- CVE:
-
2024-53819
Sugar Calendar � Event Calendar, Event Tickets, and Event Management Platform
- Plugin Slug:
- sugar-calendar-lite
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.4.0
- Severity Score:
- High
- CVE:
-
2024-10878
AppPresser � Mobile App Framework
- Plugin Slug:
- apppresser
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 4.4.7
- Severity Score:
- Critical
- CVE:
-
2024-11024
Attesa Extra
- Plugin:
-
Attesa Extra
- Plugin Slug:
- attesa-extra
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.3
- Severity Score:
- Medium
- CVE:
-
2024-10688
Internal Linking for SEO traffic & Ranking � Auto internal links (100% automatic)
- Plugin Slug:
- automatic-internal-links-for-seo
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.2.2
- Severity Score:
- High
- CVE:
-
2024-11009
BNE Gallery Extended
- Plugin:
-
BNE Gallery Extended
- Plugin Slug:
- bne-gallery-extended
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
-
2024-11119
Captivate Sync
- Plugin:
-
Captivate Sync
- Plugin Slug:
- captivatesync-trade
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.26
- Severity Score:
- Medium
- CVE:
-
2024-53820
Church Admin
- Plugin:
-
Church Admin
- Plugin Slug:
- church-admin
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.0.9
- Severity Score:
- Medium
- CVE:
-
2024-53795
Name: CM E-Mail Registration Blacklist
- Plugin Slug:
- cm-email-blacklist
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.4
- Severity Score:
- High
- CVE:
-
2024-11202
CM Header & Footer Script Loader � Insert Script Plugin
- Plugin Slug:
- cm-header-footer-script-loader
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- High
- CVE:
-
2024-11202
WordPress Contact Forms by Cimatti
- Plugin Slug:
- contact-forms
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.9.3
- Severity Score:
- Medium
- CVE:
-
2024-10521
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery � Upload, Vote, Sell via PayPal, Social Share Buttons
- Plugin Slug:
- contest-gallery
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 24.0.8
- Severity Score:
- Critical
- CVE:
-
2024-11103
InPost Gallery
- Plugin:
-
InPost Gallery
- Plugin Slug:
- inpost-gallery
- Installations
- 1,000+
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 2.1.4.3
- Severity Score:
- Medium
- CVE:
-
2024-11002
Tumult Hype Animations
- Plugin:
-
Tumult Hype Animations
- Plugin Slug:
- tumult-hype-animations
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.9.16
- Severity Score:
- Critical
- CVE:
-
2024-11082
WPCasa
- Plugin:
-
WPCasa
- Plugin Slug:
- wpcasa
- Installations
- 1,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
-
2024-53826
Login with Vipps and MobilePay
- Plugin:
-
Login with Vipps and MobilePay
- Plugin Slug:
- login-with-vipps
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.4
- Severity Score:
- Medium
- CVE:
-
2024-11786
NiceJob
- Plugin:
-
NiceJob
- Plugin Slug:
- nicejob
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.2
- Severity Score:
- Medium
- CVE:
-
2024-10887
StreamWeasels YouTube Integration
- Plugin Slug:
- streamweasels-youtube-integration
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
-
2024-11788
jAlbum Bridge
- Plugin:
-
jAlbum Bridge
- Plugin Slug:
- jalbum-bridge
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.16
- Severity Score:
- Medium
- CVE:
-
2024-11853
AWeber Forms by Optin Cat
- Plugin:
-
AWeber Forms by Optin Cat
- Plugin Slug:
- aweber-wp
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.8
- Severity Score:
- High
- CVE:
-
2024-11325
My auctions allegro
- Plugin:
-
My auctions allegro
- Plugin Slug:
- my-auctions-allegro-free-edition
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.18
- Severity Score:
- High
- CVE:
-
2024-11707
Namaste! LMS
- Plugin:
-
Namaste! LMS
- Plugin Slug:
- namaste-lms
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.6.5
- Severity Score:
- Medium
- CVE:
-
2024-53809
WP Mailster
- Plugin:
-
WP Mailster
- Plugin Slug:
- wp-mailster
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.17.0
- Severity Score:
- Medium
- CVE:
-
2024-53803
WP Mailster
- Plugin:
-
WP Mailster
- Plugin Slug:
- wp-mailster
- Installations
- 400+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.8.17.0
- Severity Score:
- High
- CVE:
-
2024-53804
WP Mailster
- Plugin:
-
WP Mailster
- Plugin Slug:
- wp-mailster
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.17.0
- Severity Score:
- High
- CVE:
-
2024-53805
WP Mailster
- Plugin:
-
WP Mailster
- Plugin Slug:
- wp-mailster
- Installations
- 400+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.8.17.0
- Severity Score:
- High
- CVE:
-
2024-53807
Simple User Registration
- Plugin:
-
Simple User Registration
- Plugin Slug:
- wp-registration
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.0
- Severity Score:
- Critical
- CVE:
-
2024-53810
Campaign Monitor Forms by Optin Cat
- Plugin Slug:
- campaign-monitor-wp
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.8
- Severity Score:
- High
- CVE:
-
2024-11326
LegalWeb Cloud
- Plugin:
-
LegalWeb Cloud
- Plugin Slug:
- legalweb-cloud
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.3
- Severity Score:
- Medium
- CVE:
-
2024-11761
Scratch & Win � Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more
- Plugin Slug:
- scratch-win-giveaways-for-website-facebook
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.0
- Severity Score:
- Medium
- CVE:
-
2024-11898
Form Data Collector
- Plugin:
-
Form Data Collector
- Plugin Slug:
- form-data-collector
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.4
- Severity Score:
- High
- CVE:
-
2024-11461
HLS Player
- Plugin:
-
HLS Player
- Plugin Slug:
- hls-player
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.11
- Severity Score:
- Medium
- CVE:
-
2024-11333
Slotti Ajanvaraus
- Plugin:
-
Slotti Ajanvaraus
- Plugin Slug:
- slotti-ajanvaraus
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- Medium
- CVE:
-
2024-11408
WP GeoNames
- Plugin:
-
WP GeoNames
- Plugin Slug:
- wp-geonames
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9
- Severity Score:
- High
- CVE:
-
2024-53812
FAQ Builder AYS
- Plugin:
-
FAQ Builder AYS
- Plugin Slug:
- faq-builder-ays
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.2
- Severity Score:
- High
- CVE:
-
2024-11458
Kudos Donations � Easy donations and payments with Mollie
- Plugin Slug:
- kudos-donations
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.0
- Severity Score:
- High
- CVE:
-
2024-11684
SEO Landing Page Generator
- Plugin:
-
SEO Landing Page Generator
- Plugin Slug:
- seo-landing-page-generator
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.66.3
- Severity Score:
- High
- CVE:
-
2024-11366
Skt NURCaptcha
- Plugin:
-
Skt NURCaptcha
- Plugin Slug:
- skt-nurcaptcha
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.0
- Severity Score:
- High
- CVE:
-
2024-11342
Ragic Shortcode
- Plugin:
-
Ragic Shortcode
- Plugin Slug:
- ragic-shortcode
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3
- Severity Score:
- Medium
- CVE:
-
2024-11431
Video Lessons Manager � WordPress LMS Plugin
- Plugin Slug:
- cm-video-lesson-manager
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.3
- Severity Score:
- High
- CVE:
-
2024-11202
CM Business Directory Plugin � Business Listing Directory
- Plugin Slug:
- cm-business-directory
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.2
- Severity Score:
- High
- CVE:
-
2024-11202
BMLT Tabbed Map
- Plugin:
-
BMLT Tabbed Map
- Plugin Slug:
- bmlt-tabbed-map
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.0
- Severity Score:
- Medium
- CVE:
-
2024-11866
Quick License Manager � WooCommerce Plugin
- Plugin Slug:
- quick-license-manager
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.18
- Severity Score:
- High
- CVE:
-
2024-11805
Support SVG � Upload svg files in wordpress without hassle
- Plugin Slug:
- support-svg
- Installations
- 30+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.1
- Severity Score:
- Medium
- CVE:
-
2024-11091
FloristPress � Customize your Woo store for your Florist
- Plugin Slug:
- bakkbone-florist-companion
- Installations
- 10+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 7.4.0
- Severity Score:
- Medium
- CVE:
-
2024-53799
FloristPress � Customize your Woo store for your Florist
- Plugin Slug:
- bakkbone-florist-companion
- Installations
- 10+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 7.4.0
- Severity Score:
- Medium
- CVE:
-
2024-53798
CMSMasters Elementor Addon
- Plugin:
CMSMasters Elementor Addon
- Plugin Slug:
- cmsmasters-elementor-addon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.0
- Severity Score:
- Medium
- CVE:
-
2024-9694
MP3 Sticky Player
- Plugin:
MP3 Sticky Player
- Plugin Slug:
- fwdmsp
- Vulnerability:
- Path Traversal
- Patched in Version:
- 8.1
- Severity Score:
- High
- CVE:
-
2024-10803
WPGYM
- Plugin:
WPGYM
- Plugin Slug:
- gym-management
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 67.2.0
- Severity Score:
- Critical
- CVE:
-
2024-9941
Leopard – WordPress offload media
- Plugin:
Leopard – WordPress offload media
- Plugin Slug:
- leopard-wordpress-offload-media
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.1.2
- Severity Score:
- High
- CVE:
-
2024-10589
Pie Register Premium
- Plugin:
Pie Register Premium
- Plugin Slug:
- pie-register-premium
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.3.3
- Severity Score:
- High
- CVE:
-
2024-53821
Pie Register Premium
- Plugin:
Pie Register Premium
- Plugin Slug:
- pie-register-premium
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.8.3.3
- Severity Score:
- Critical
- CVE:
-
2024-53822
Booking & Appointment Plugin for WooCommerce
- Plugin:
Booking & Appointment Plugin for WooCommerce
- Plugin Slug:
- woocommerce-booking
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.10.0
- Severity Score:
- High
- CVE:
-
2024-10729
WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates
- Plugin:
WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates
- Plugin Slug:
- woocommerce-ultimate-gift-card
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.1
- Severity Score:
- High
- CVE:
-
2024-53740
JobSearch
- Plugin:
JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.6.8
- Severity Score:
- Critical
- CVE:
-
2024-11925

