Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � February 14, 2024

In this report, 146 vulnerabilities have been publicly disclosed. Security patches for 118 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 28 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

WordPress Plugins � 117 Patched / 26 Unpatched

Malware Scanner

Plugin Slug:
miniorange-malware-protection

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Multi Step Form

Plugin Slug:
multi-step-form

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comments Like Dislike

Plugin Slug:
comments-like-dislike

Installations
9,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PJ News Ticker

Plugin Slug:
pj-news-ticker

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE and TinyMCE Advanced Professsional Formats and Styles

Plugin Slug:
tinymce-and-tinymce-advanced-professsional-formats-and-styles

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form

Plugin Slug:
wp-contact-form

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Before After Image Slider WP

Plugin Slug:
before-after-image-slider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Content Cards

Plugin Slug:
content-cards

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MyWaze

Plugin:

MyWaze

Plugin Slug:
my-waze

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PB oEmbed HTML5 Audio � with Cache Support

Plugin Slug:
pb-oembed-html5-audio-with-cache-support

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Installations
100+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Buttons Shortcode and Widget

Plugin:

Buttons Shortcode and Widget

Plugin Slug:
buttons-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Coupon Referral Program

Plugin:

Coupon Referral Program

Plugin Slug:
coupon-referral-program

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

GigPress

Plugin:

GigPress

Plugin Slug:
gigpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Honeypot for WP Comment

Plugin:

Honeypot for WP Comment

Plugin Slug:
honeypot-for-wp-comment

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Honeypot for WP Comment

Plugin:

Honeypot for WP Comment

Plugin Slug:
honeypot-for-wp-comment

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
Denial of Service Attack

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MoveTo

Plugin:

MoveTo

Plugin Slug:
moveto

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin:

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SMTP Mail

Plugin:

SMTP Mail

Plugin Slug:
smtp-mail

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

VK Poster Group

Plugin:

VK Poster Group

Plugin Slug:
vk-poster-group

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pexels: Free Stock Photos

Plugin:

Pexels: Free Stock Photos

Plugin Slug:
wp-pexels-free-stock-photos

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Basic Log Viewer

Plugin:

Basic Log Viewer

Plugin Slug:
wpsimpletools-log-viewer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Forms for Mailchimp

Plugin:

Easy Forms for Mailchimp

Plugin Slug:
yikes-inc-easy-mailchimp-extender

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All-In-One Security (AIOS) � Security and Firewall

Plugin Slug:
all-in-one-wp-security-and-firewall

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.6.
Plugin Slug:
broken-link-checker

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

Meta Box � WordPress Custom Fields Framework

Plugin Slug:
meta-box

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.3.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.2.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.58.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.58.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.58.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.58.4.

Admin Menu Editor

Plugin Slug:
admin-menu-editor

Installations
400,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.12.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.1.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.88

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.88

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.88

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.88.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.81.

Backuply � Backup, Restore, Migrate and Clone

Plugin Slug:
backuply

Installations
200,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
1.2.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.6.

InfiniteWP Client

Plugin Slug:
iwp-client

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.12.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.3.1.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.93.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.93.2.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.12.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.12.12.

Advanced Database Cleaner

Plugin Slug:
advanced-database-cleaner

Installations
100,000+

Vulnerability:
PHP Object Injection

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Prime Slider � Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider)

Plugin Slug:
bdthemes-prime-slider-lite

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.11.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.11.

Custom Twitter Feeds � A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.2.

Insert PHP Code Snippet

Plugin Slug:
insert-php-code-snippet

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Login Lockdown � Protect Login Form

Plugin Slug:
login-lockdown

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.09

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.09.

Minimal Coming Soon � Coming Soon Page

Plugin Slug:
minimal-coming-soon-maintenance-mode

Installations
100,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.38

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.38.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.1.

Elementor Addons by Livemesh

Plugin Slug:
addons-for-elementor

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.3.

WP Booking Calendar

Plugin Slug:
booking

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
9.9.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 9.9.1.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.39.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.39.0.

AI Engine

Plugin Slug:
ai-engine

Installations
50,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.
Plugin Slug:
internal-links

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.23.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.23.5.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.88.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.88.16.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.88.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.88.15.

Shariff Wrapper

Plugin Slug:
shariff

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.10.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.7.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.2.0.

Starbox � the Author Box for Humans

Plugin Slug:
starbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

Starbox � the Author Box for Humans

Plugin Slug:
starbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.4.

WP Editor

Plugin Slug:
wp-editor

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.

Gutenberg Block Editor Toolkit � EditorsKit

Plugin Slug:
block-options

Installations
30,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.40.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.40.4.

PPWP � Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.0.

All 404 Pages Redirect to Homepage

Plugin Slug:
all-404-pages-redirect-to-homepage

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

Maspik � Spam Blacklist

Plugin Slug:
contact-forms-anti-spam

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.10.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.10.7.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.2.5.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.2.5.

NextMove Lite � Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite

Installations
20,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.18.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.18.0.

Passster � Password Protect Pages and Content

Plugin Slug:
content-protector

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.3.
Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.
Plugin Slug:
link-library

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.

Wonder Slider Lite

Plugin Slug:
wonderplugin-slider-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 14.0.

Woocommerce Vietnam Checkout

Plugin Slug:
woo-vietnam-checkout

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Product Labels For Woocommerce (Sale Badges)

Plugin Slug:
aco-product-labels-for-woocommerce

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

Themify Builder

Plugin Slug:
themify-builder

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.6.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.12.

Podlove Podcast Publisher

Plugin Slug:
podlove-podcasting-plugin-for-wordpress

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.12.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Advanced Forms for ACF

Plugin Slug:
advanced-forms

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.3.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.3.

Podlove Subscribe button

Plugin Slug:
podlove-subscribe-button

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.11.

SKT Page Builder

Plugin Slug:
skt-builder

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.
Plugin Slug:
doofinder-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.9.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.14.

Simple Page Access Restriction

Plugin Slug:
simple-page-access-restriction

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

Anonymous Restricted Content

Plugin Slug:
anonymous-restricted-content

Installations
1,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
1.0.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.72.

Polls CP

Plugin:

Polls CP

Plugin Slug:
cp-polls

Installations
1,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.0.72

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.72.

GD Rating System

Plugin Slug:
gd-rating-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.1.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
22.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 22.8.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

WP Club Manager � WordPress Sports Club Plugin

Plugin Slug:
wp-club-manager

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.11.

Ultimate Reviews

Plugin Slug:
ultimate-reviews

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.9.

Portugal CTT Tracking for WooCommerce

Plugin Slug:
portugal-ctt-tracking-woocommerce

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Web3 � Crypto wallet Login & NFT token gating

Plugin Slug:
web3-authentication

Installations
200+

Vulnerability:
Broken Authentication

Patched in Version:
3.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.0.

LearnDash LMS

Plugin:

LearnDash LMS

Plugin Slug:
sfwd-lms

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.3.

LearnDash LMS

Plugin:

LearnDash LMS

Plugin Slug:
sfwd-lms

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.2.

LearnDash LMS

Plugin:

LearnDash LMS

Plugin Slug:
sfwd-lms

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.2.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.7.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Settings Change

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

WP Media folder

Plugin:

WP Media folder

Plugin Slug:
wp-media-folder

Vulnerability:
Settings Change

Patched in Version:
5.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.7.3.

WordPress Themes � 1 Patched / 2 Unpatched

Brooklyn

Theme:

Brooklyn

Theme Slug:
brooklyn

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Brooklyn

Theme:

Brooklyn

Theme Slug:
brooklyn

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
2,812,211

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.20.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…