WordPress Vulnerability Report � January 17, 2024

In this report, 77 new vulnerabilities have been publicly disclosed. Security patches for 61 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 16 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Free Online Training Event! Register Now!

January 24, 2024 @ 1:00 PM – 2:00 PM (CST)

Not all WordPress threats and vulnerabilities are �created equal.� Some require more immediate attention and pose a greater risk than others. Even with preventive tools in place, such as Solid Security Pro with Patchstack, you need to understand how to assess and respond to threats and vulnerabilities.

This livestream will help you understand what needs your attention first, how to use Security tools like Solid Security Pro to view, rank, and respond to threats, and how to harden your site moving forward.

Can’t make the live event? Go ahead and register, and we’ll email you the replay. See webinar time in your time zone.

WordPress Core

WordPress 6.4.2 was released on December 6, 2023, as a short-cycle maintenance and security release with seven bug fixes and one security patch for a potential Remote Code Execution (RCE) vulnerability that is not directly exploitable in most situations. However, combined with certain vulnerabilities in third-party plugins on a multisite network, this vulnerability could be exploited and pose a high-severity risk. The 6.4.1 update will prevent PHP object injections from being chained into a potential RCE, according to details published by Patchstack.

WordPress Plugins � 61 Patched / 16 Unpatched

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Manuten��o

Plugin Slug:
wp-manutencao

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Constant Contact Forms by MailMunch

Plugin Slug:
constant-contact-forms-by-mailmunch

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Revolut Gateway for WooCommerce

Plugin Slug:
revolut-gateway-for-woocommerce

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Finder

Plugin Slug:
shortcodes-finder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Word Replacer Pro

Plugin Slug:
word-replacer-ultra

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Flamingo

Plugin Slug:
advanced-flamingo

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CformsII

Plugin:

CformsII

Plugin Slug:
cforms2

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Extension For Mailchimp

Plugin:

Contact Form 7 Extension For Mailchimp

Plugin Slug:
contact-form-7-mailchimp-extension

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy SVG Allow

Plugin:

Easy SVG Allow

Plugin Slug:
easy-svg-image-allow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Voting Record

Plugin:

Voting Record

Plugin Slug:
voting-record

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Voting Record

Plugin:

Voting Record

Plugin Slug:
voting-record

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Smart Editor

Plugin:

WP Smart Editor

Plugin Slug:
wp-smart-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Social Bookmark Menu

Plugin:

WP Social Bookmark Menu

Plugin Slug:
wp-social-bookmark-menu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.4.

Hostinger

Plugin Slug:
hostinger

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.8.

WPS Hide Login

Plugin Slug:
wps-hide-login

Installations
1,000,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.12

Severity Score:
Low


The vulnerability has been patched, so you should update to version 1.9.12.

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.2.9.

Metform Elementor Contact Form Builder

Plugin Slug:
metform

Installations
300,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.2.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
SQL Injection

Patched in Version:
3.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.7.6.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.28

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.28.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.27.

Contact Form 7 � Dynamic Text Extension

Plugin Slug:
contact-form-7-dynamic-text-extension

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.0.

Download Monitor

Plugin Slug:
download-monitor

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
4.9.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.5.
Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.7.3.

List category posts

Plugin Slug:
list-category-posts

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.89.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.89.4.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.

Plugin for Google Reviews

Plugin Slug:
widget-google-reviews

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.
Plugin Slug:
advanced-woo-search

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.97

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.97.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
60,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.38.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.38.10.

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.4.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Index Now

Plugin Slug:
mihdan-index-now

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.4.

MailerLite � WooCommerce integration

Plugin Slug:
woo-mailerlite

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

MailerLite � WooCommerce integration

Plugin Slug:
woo-mailerlite

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.9.

Swift SMTP (formerly Welcome Email Editor)

Plugin Slug:
welcome-email-editor

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.7.

Woocommerce Vietnam Checkout

Plugin Slug:
woo-vietnam-checkout

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.8.

RabbitLoader

Plugin Slug:
rabbit-loader

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.19.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.19.14.

WP Testimonials

Plugin Slug:
testimonial-widgets

Installations
3,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

WP Spell Check

Plugin Slug:
wp-spell-check

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.18

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.18.

WordPress Live Chat Plugin for WooCommerce � LiveChat

Plugin Slug:
livechat-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.14.

WordPress Live Chat Plugin for WooCommerce � LiveChat

Plugin Slug:
livechat-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.17.

Football Pool

Plugin Slug:
football-pool

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.11.4.

GD Rating System

Plugin Slug:
gd-rating-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.1.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
0.1.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.9.

TNC PDF viewer

Plugin Slug:
pdf-viewer-by-themencode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.0.

WP Register Profile With Shortcode

Plugin Slug:
wp-register-profile-with-shortcode

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.0.

Seraphinite Alternative Slugs Manager

Plugin Slug:
seraphinite-old-slugs-mgr

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

Email Newsletter

Plugin:

Email Newsletter

Plugin Slug:
email-newsletter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.0.7.

EventON Pro

Plugin:

EventON Pro

Plugin Slug:
eventon-wordpress-event-calendar-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

EventON Pro

Plugin:

EventON Pro

Plugin Slug:
eventon-wordpress-event-calendar-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

EventON Pro

Plugin:

EventON Pro

Plugin Slug:
eventon-wordpress-event-calendar-plugin

Vulnerability:
Broken Access Control

Patched in Version:
4.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.5.

MaxButtons

Plugin:

MaxButtons

Plugin Slug:
maxbutton

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.7.6.

Oxygen Builder

Plugin:

Oxygen Builder

Plugin Slug:
oxygenbuilder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.1.

Profile Builder Pro

Plugin:

Profile Builder Pro

Plugin Slug:
profile-builder-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.10.1.

Profile Builder Pro

Plugin:

Profile Builder Pro

Plugin Slug:
profile-builder-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.10.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.1.

Profile Builder Pro

Plugin:

Profile Builder Pro

Plugin Slug:
profile-builder-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.10.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.10.1.

WordPress Themes � 0 Patched / 0 Unpatched

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…