Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 31, 2024

In this report, 53 vulnerabilities have been publicly disclosed. Security patches for 36 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 17 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

WordPress Plugins � 35 Patched / 17 Unpatched

aBitGone CommentSafe

Plugin:

aBitGone CommentSafe

Plugin Slug:
abitgone-commentsafe

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Add SVG Support for Media Uploader | inventivo

Plugin:

Add SVG Support for Media Uploader | inventivo

Plugin Slug:
add-svg-support-for-media-uploader-inventivo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Schedule Posts

Plugin:

Advanced Schedule Posts

Plugin Slug:
advanced-schedule-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Better Follow Button for Jetpack

Plugin:

Better Follow Button for Jetpack

Plugin Slug:
better-follow-button-for-jetpack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

enigma chart.js

Plugin:

enigma chart.js

Plugin Slug:
enigma-chartjs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

(Simply) Guest Author Name

Plugin:

(Simply) Guest Author Name

Plugin Slug:
guest-author-name

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

lasTunes

Plugin:

lasTunes

Plugin Slug:
lastunes

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

illi Link Party!

Plugin Slug:
link-party

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

illi Link Party!

Plugin Slug:
link-party

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

illi Link Party!

Plugin Slug:
link-party

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mang Board WP

Plugin:

Mang Board WP

Plugin Slug:
mangboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Splashscreen

Plugin:

Splashscreen

Plugin Slug:
splashscreen

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVG Uploads Support

Plugin:

SVG Uploads Support

Plugin Slug:
svg-uploads-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Noindex Nofollow Tool

Plugin:

Ultimate Noindex Nofollow Tool

Plugin Slug:
ultimate-noindex-nofollow-tool

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketing Twitter Bot

Plugin:

Marketing Twitter Bot

Plugin Slug:
wordpress-twitterbot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Reply Notify

Plugin:

WP-Reply Notify

Plugin Slug:
wp-reply-notify

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Better Search Replace

Plugin Slug:
better-search-replace

Installations
1,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.4.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.4.5.

File Manager

Plugin Slug:
wp-file-manager

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.2.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.29

Severity Score:
High


The vulnerability has been patched, so you should update to version 9.0.29.

Migration, Backup, Staging � WPvivid

Plugin Slug:
wpvivid-backuprestore

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.9.95

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.95.

Backuply � Backup, Restore, Migrate and Clone

Plugin Slug:
backuply

Installations
200,000+

Vulnerability:
Directory Traversal

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.93

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.93.

VK Block Patterns

Plugin Slug:
vk-block-patterns

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.31.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.2.0.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.

10Web AI Assistant � AI content writing assistant

Plugin Slug:
ai-assistant-by-10web

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.19.

WP Dashboard Notes

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.11.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.4.

PDF Poster � PDF Embedder Plugin for WordPress

Plugin Slug:
pdf-poster

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.18.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.2.

Cryptocurrency Widgets � Price Ticker & Coins List

Plugin Slug:
cryptocurrency-price-ticker-widget

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.6.

WP Customer Area

Plugin Slug:
customer-area

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.2.3.

Category Discount Woocommerce

Plugin Slug:
woo-product-category-discount

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.12.

Category Discount Woocommerce

Plugin Slug:
woo-product-category-discount

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.13.

Sticky Buttons � floating buttons builder

Plugin Slug:
sticky-buttons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.3.

Dragfy Addons for Elementor

Plugin Slug:
dragfy-addons-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.3.2.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
0.1.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.10.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
0.1.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.1.0.10.

Allow SVG

Plugin Slug:
allow-svg

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

MaxButtons

Plugin:

MaxButtons

Plugin Slug:
maxbutton

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.7.7.

File Manager Pro

Plugin:

File Manager Pro

Plugin Slug:
wp-file-manager-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
8.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.5.

WPForms Pro

Plugin:

WPForms Pro

Plugin Slug:
wpforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.4.

WordPress Themes � 1 Patched / 0 Unpatched

ColorMag

Theme Slug:
colormag

Downloads
3,799,423

Vulnerability:
Broken Access Control

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…