Line illustration showing a black application window on a dark orange to black gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � July 24, 2024

In this report, 93 vulnerabilities have been publicly disclosed. Security patches for 72 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 21 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.1 is now available! This minor release features�7 bug fixes in Core�and�9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the�Release Candidate announcement.

WordPress Plugins � 72 Patched / 15 Unpatched

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smartsupp � live chat, chatbots, AI and lead generation

Plugin Slug:
smartsupp-live-chat

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Booking Ultra Pro

Plugin:

Booking Ultra Pro

Plugin Slug:
booking-ultra-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Testimonials

Plugin:

Easy Testimonials

Plugin Slug:
easy-testimonials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Keydatas

Plugin:

Keydatas

Plugin Slug:
keydatas

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Light Poll

Plugin:

Light Poll

Plugin Slug:
light-poll

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

RegLevel

Plugin:

RegLevel

Plugin Slug:
reglevel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVG Support

Plugin:

SVG Support

Plugin Slug:
svg-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Telegram Bot & Channel

Plugin:

Telegram Bot & Channel

Plugin Slug:
telegram-bot

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:

Timeline Event History

Plugin Slug:
timeline-event-history

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.1.

Redux Framework

Plugin Slug:
redux-framework

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.4.18.

WPS Hide Login

Plugin Slug:
wps-hide-login

Installations
1,000,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.16.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.16.4.

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.14.

GiveWP � Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.14.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.34.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.34.1.

CTX Feed � WooCommerce Product Feed Manager Plugin

Plugin Slug:
webappick-product-feed-for-woocommerce

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
6.5.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.5.7.

Mercado Pago payments for WooCommerce

Plugin Slug:
woocommerce-mercadopago

Installations
100,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
7.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.6.2.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.6.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.6.1.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.45

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.4.45.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.45

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.45.

AI Engine

Plugin Slug:
ai-engine

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.8.

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.3.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

Image Hover Effects � Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.4.

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
7.5.47.7212

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.5.47.7212.

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Directory Traversal

Patched in Version:
4.24.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.24.8.

BSK PDF Manager

Plugin Slug:
bsk-pdf-manager

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.1.

CM Popup Plugin for WordPress � Popup Maker

Plugin Slug:
cm-pop-up-banners

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

Language Translate Widget for WP � ConveyThis

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
235

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 235.

JetWidgets for Elementor and WooCommerce

Plugin Slug:
jetwoo-widgets-for-elementor

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

Arconix FAQ

Plugin Slug:
arconix-faq

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.5.

HTML Forms � Simple WordPress Forms Plugin

Plugin Slug:
html-forms

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.33

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.33.

YITH Essential Kit for WooCommerce #1

Plugin Slug:
yith-essential-kit-for-woocommerce-1

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.35.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.35.0.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.12.

AI ChatBot for WordPress � WPBot

Plugin Slug:
chatbot

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.8.

WP QuickLaTeX

Plugin Slug:
wp-quicklatex

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.8.

Livemesh Addons for Beaver Builder

Plugin Slug:
addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.

Cooked � Recipe Management

Plugin Slug:
cooked

Installations
4,000+

Vulnerability:
Content Injection

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

Cooked � Recipe Management

Plugin Slug:
cooked

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.0.

AForms � Form Builder for Price Calculator & Cost Estimation

Plugin Slug:
aforms-form-builder-for-price-calculator-cost-estimation

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.3000000024

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.3000000024.

Addonify � Quick View For WooCommerce

Plugin Slug:
addonify-quick-view

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.17.

Glossary

Plugin:

Glossary

Plugin Slug:
glossary-by-codeat

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.27

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.27.

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.6.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
fulltext-search

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.70.236

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.70.236.

Custom Query Blocks

Plugin Slug:
post-type-archive-mapping

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.0.

Filter & Grids

Plugin Slug:
ymc-smart-filter

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.8.33

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.33.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
7.5.18

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.5.18.

ArtPlacer Widget

Plugin Slug:
artplacer-widget

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.21.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.21.2.

ArtPlacer Widget

Plugin Slug:
artplacer-widget

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.21.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.21.2.

Bug Library

Plugin Slug:
bug-library

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Community Events

Plugin Slug:
community-events

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.

PZ Frontend Manager

Plugin Slug:
pz-frontend-manager

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.6.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.19.20.1.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.5.5.

CopySafe Web Protection

Plugin:

CopySafe Web Protection

Plugin Slug:
wp-copysafe-web

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.

WP GoToWebinar

Plugin:

WP GoToWebinar

Plugin Slug:
wp-gotowebinar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
15.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 15.8.

WPForms User Registration

Plugin:

WPForms User Registration

Plugin Slug:
wpforms-user-registration

Vulnerability:
Privilege Escalation

Patched in Version:
2.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.2.

WordPress Themes � 0 Patched / 6 Unpatched

CoziPress

Theme Slug:
cozipress

Downloads
144,938

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Himalayas

Theme Slug:
himalayas

Downloads
334,322

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Zenon Lite

Theme:

Zenon Lite

Theme Slug:
zenon-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…