Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � July 3, 2024

In this report, 223 vulnerabilities have been publicly disclosed. Security patches for 182 of these plugins, themes, and Core are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 41 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.5 is now available! This release features three security fixes. Because this is a security release, it is recommended that you update your sites immediately. This minor release also includes 3 bug fixes in Core.

WordPress 6.6 RC2 is ready for download and testing! The target release date for WordPress 6.6 is July 16, 2024. Your help testing RC versions over the next few weeks is vital to ensuring the final release is everything it should be: stable, powerful, and intuitive.

WordPress Core

Vulnerability:
Path Traversal

Patched in Version:
6.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.5.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.5.

WordPress Core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.5.

WordPress Plugins � 153 Patched / 32 Unpatched

SEO SIMPLE PACK

Plugin Slug:
seo-simple-pack

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

NextScripts: Social Networks Auto-Poster

Plugin Slug:
social-networks-auto-poster-facebook-twitter-g

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ARI Fancy Lightbox � WordPress Popup

Plugin Slug:
ari-fancy-lightbox

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BSK PDF Manager

Plugin Slug:
bsk-pdf-manager

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer

Plugin Slug:
pdf-viewer

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Logo Manager For Enamad

Plugin Slug:
logo-manager-for-enamad

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Directory Kit

Plugin Slug:
wpdirectorykit

Installations
3,000+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Low


The vulnerability has not been patched. You should deactivate the plugin.

Pagerank tools

Plugin Slug:
pagerank-tools

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Animated AL List

Plugin Slug:
animated-al-list

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple AL Slider

Plugin Slug:
simple-al-slider

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Widget4Call

Plugin Slug:
widget4call

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

All In One Redirection

Plugin:

All In One Redirection

Plugin Slug:
all-in-one-redirection

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Auto Featured Image

Plugin Slug:
auto-featured-image

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Bible Text

Plugin:

Bible Text

Plugin Slug:
bible-text

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bookster

Plugin:

Bookster

Plugin Slug:
bookster

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ContentLock

Plugin:

ContentLock

Plugin Slug:
contentlock

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Floating Social Buttons

Plugin:

Floating Social Buttons

Plugin Slug:
floating-social-buttons

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Frontend Checklist

Plugin:

Frontend Checklist

Plugin Slug:
frontend-checklist

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Gallery Slideshow

Plugin Slug:
gallery-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

jQuery T(-) Countdown Widget

Plugin:

jQuery T(-) Countdown Widget

Plugin Slug:
jquery-t-countdown-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mime Types Extended

Plugin:

Mime Types Extended

Plugin Slug:
mime-types-extended

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Muslim Prayer Time BD

Plugin:

Muslim Prayer Time BD

Plugin Slug:
muslim-prayer-time-bd

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ninja Beaver Add-ons for Beaver Builder

Plugin:

Ninja Beaver Add-ons for Beaver Builder

Plugin Slug:
ninja-beaver-lite-addons-for-beaver-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin:

PDF Viewer for Elementor

Plugin Slug:
pdf-viewer-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Photoswipe

Plugin:

Simple Photoswipe

Plugin Slug:
simple-photoswipe

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Photoswipe

Plugin:

Simple Photoswipe

Plugin Slug:
simple-photoswipe

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simply Show Hooks

Plugin:

Simply Show Hooks

Plugin Slug:
simply-show-hooks

Vulnerability:
Backdoor

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Spotify Play Button

Plugin:

Spotify Play Button

Plugin Slug:
spotify-play-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Video Widget

Plugin:

Video Widget

Plugin Slug:
video-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WebP & SVG Support

Plugin:

WebP & SVG Support

Plugin Slug:
webp-svg-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7

Plugin Slug:
contact-form-7

Installations
10,000,000+

Vulnerability:
Open Redirection

Patched in Version:
5.9.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.5.

WooCommerce

Plugin Slug:
woocommerce

Installations
7,000,000+

Vulnerability:
Content Injection

Patched in Version:
9.0.0

Severity Score:
Low


The vulnerability has been patched, so you should update to version 9.0.0.
Plugin Slug:
header-footer-elementor

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.36.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

File Manager

Plugin Slug:
wp-file-manager

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.8.

Easy Table of Contents

Plugin Slug:
easy-table-of-contents

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.66

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.66.

SiteGuard WP Plugin

Plugin Slug:
siteguard

Installations
500,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.2.

PDF Embedder

Plugin Slug:
pdf-embedder

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.8.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.0.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Open Redirection

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.8.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.5.

HT Mega � Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.6.

Pods � Custom Content Types and Fields

Plugin Slug:
pods

Installations
100,000+

Vulnerability:
Backdoor

Patched in Version:
3.2.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.2.2.

Stackable � Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.13.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.13.2.

WP Chat App

Plugin Slug:
wp-whatsapp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.5.

Slider & Popup Builder by Depicter � Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.0.
Plugin Slug:
featured-image-from-url

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.8.2.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.6.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.8.2.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.6.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.8.2.

WP Mobile Menu � The Mobile-Friendly Responsive Menu

Plugin Slug:
mobile-menu

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.8.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.4.4.
Plugin Slug:
permalink-manager

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.3.4.

WP Maps � Display Google Maps Perfectly with Ease

Plugin Slug:
wp-google-map-plugin

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
4.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.6.2.

3D FlipBook � PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.6.

Media Library Assistant

Plugin Slug:
media-library-assistant

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.18.

Page and Post Clone

Plugin Slug:
page-or-post-clone

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 6.1.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.9.
Plugin Slug:
sina-extension-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.6.

Ultimate Blocks � WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.0.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.6.

Interactive Content � H5P

Plugin Slug:
h5p

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.8.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
40,000+

Vulnerability:
Backdoor

Patched in Version:
11.9.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 11.9.5.

Void Contact Form 7 Widget For Elementor Page Builder

Plugin Slug:
cf7-widget-elementor

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.13.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.13.

Easy Google Maps

Plugin Slug:
google-maps-easy

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.11.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.11.16.

PDF Poster � PDF Embedder Plugin

Plugin Slug:
pdf-poster

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.22.
Plugin Slug:
portfolio-filter-gallery

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.5.

Rife Elementor Extensions & Templates

Plugin Slug:
rife-elementor-extensions

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Twenty20 Image Before-After

Plugin Slug:
twenty20

Installations
30,000+

Vulnerability:
Backdoor

Patched in Version:
1.6.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.4.

Ad Invalid Click Protector (AICP)

Plugin Slug:
ad-invalid-click-protector

Installations
20,000+

Vulnerability:
Backdoor

Patched in Version:
1.2.10

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.10.

Funnel Builder for WordPress by FunnelKit � Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells

Plugin Slug:
funnel-builder

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.0.

PDF.js Viewer

Plugin Slug:
pdfjs-viewer-shortcode

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.

Quiz Maker

Plugin Slug:
quiz-maker

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
6.5.8.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.5.8.4.

Ultimate Post Kit Addons For Elementor � (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud)

Plugin Slug:
ultimate-post-kit

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.8.

E2Pdf � Export To Pdf Tool for WordPress

Plugin Slug:
e2pdf

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.23.00

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.23.00.

E2Pdf � Export To Pdf Tool for WordPress

Plugin Slug:
e2pdf

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.25.01

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.25.01.
Plugin Slug:
easy-affiliate-links

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.7.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.4.

AI Power: Complete AI Pack � Powered by GPT-4

Plugin Slug:
gpt3-ai-content-generator

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.67

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.67.

HTML5 Audio Player- Audio Player Plugin

Plugin Slug:
html5-audio-player

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.24

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.24.

Mailster WordPress Newsletter Plugin

Plugin Slug:
mailster

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.10

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.10.

Mega Elements � Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Simple Newsletter Plugin � Noptin

Plugin Slug:
newsletter-optin-box

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.3.

All-in-One Addons for Elementor � WidgetKit

Plugin Slug:
widgetkit-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.1.

Wonder PDF Embed

Plugin Slug:
wonderplugin-pdf-embed

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.8.00.003

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.8.00.003.

WP Server Health Stats

Plugin Slug:
wp-server-stats

Installations
10,000+

Vulnerability:
Backdoor

Patched in Version:
1.7.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.7.

Motors � Car Dealer, Classifieds & Listing

Plugin Slug:
motors-car-dealership-classified-listings

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.11.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
9,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.4.

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.5.

Create by Mediavine

Plugin Slug:
mediavine-create

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.8.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.8.

Ultimate Bootstrap Elements for Elementor

Plugin Slug:
ultimate-bootstrap-elements-for-elementor

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

Beaver Builder Addons by WPZOOM

Plugin Slug:
wpzoom-addons-for-beaver-builder

Installations
6,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.6.

Easy Image Collage

Plugin Slug:
easy-image-collage

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.13.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.6.

AWSM Team � Team Showcase Plugin

Plugin Slug:
awsm-team

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Patreon WordPress

Plugin Slug:
patreon-connect

Installations
4,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

Social Rocket � Social Sharing Plugin

Plugin Slug:
social-rocket

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.4.

Stock Ticker

Plugin Slug:
stock-ticker

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.24.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.24.6.

Cards for Beaver Builder

Plugin Slug:
bb-bootstrap-cards

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Chained Quiz

Plugin Slug:
chained-quiz

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.9.

Cowidgets � Elementor Addons

Plugin Slug:
cowidgets-elementor-addons

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.0.

CRM Perks Forms � WordPress Form Builder

Plugin Slug:
crm-perks-forms

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.6.

WP Secure Maintenance

Plugin Slug:
wp-secure-maintainance

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.5.

Extensions for Elementor

Plugin Slug:
extensions-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.31.
Plugin Slug:
gallery-photo-gallery

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
5.7.1

Severity Score:
Low


The vulnerability has been patched, so you should update to version 5.7.1.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.66

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.66.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.61

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.61.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.36.

Newspack Newsletters

Plugin Slug:
newspack-newsletters

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.13.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.13.3.

PayPlus Payment Gateway

Plugin Slug:
payplus-payment-gateway

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
6.6.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.6.9.

PayPlus Payment Gateway

Plugin Slug:
payplus-payment-gateway

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.6.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.6.9.

Post Meta Data Manager

Plugin Slug:
post-meta-data-manager

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

SuperSaaS � online appointment scheduling

Plugin Slug:
supersaas-appointment-scheduling

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.10.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.21.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.21.6.

WP-Lister Lite for Amazon

Plugin Slug:
wp-lister-for-amazon

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.17

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.17.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.0.

Zita Elementor Site Library

Plugin Slug:
zita-site-library

Installations
1,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.6.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.6.2.

Zita Elementor Site Library

Plugin Slug:
zita-site-library

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.3.

Progress Planner

Plugin Slug:
progress-planner

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.3.

Progress Planner

Plugin Slug:
progress-planner

Installations
30+

Vulnerability:
Broken Access Control

Patched in Version:
0.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.2.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.2.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Broken Access Control

Patched in Version:
6.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.2.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Broken Access Control

Patched in Version:
6.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.2.

ARMember Premium

Plugin:

ARMember Premium

Plugin Slug:
armember

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.1.

BLAZE Retail Widget

Plugin:

BLAZE Retail Widget

Plugin Slug:
blaze-widget

Vulnerability:
Backdoor

Patched in Version:
2.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.5.4.

Bricks Builder (Premium)

Plugin:

Bricks Builder (Premium)

Plugin Slug:
bricksbuilder

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.9.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.9.

Contact Form 7 Multi-Step Addon

Plugin:

Contact Form 7 Multi-Step Addon

Plugin Slug:
contact-form-7-multi-step-addon

Vulnerability:
Backdoor

Patched in Version:
1.0.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.7.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.21.3.

Blocks Pro

Plugin Slug:
kadence-blocks-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.8.

Masterstudy Elementor Widgets

Plugin:

Masterstudy Elementor Widgets

Plugin Slug:
masterstudy-elementor-widgets

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.2.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.3.

Masterstudy Elementor Widgets

Plugin:

Masterstudy Elementor Widgets

Plugin Slug:
masterstudy-elementor-widgets

Vulnerability:
SQL Injection

Patched in Version:
1.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.3.

Masterstudy Elementor Widgets

Plugin:

Masterstudy Elementor Widgets

Plugin Slug:
masterstudy-elementor-widgets

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Newspack Ads

Plugin:

Newspack Ads

Plugin Slug:
newspack-ads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.47.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.47.2.

Newspack Blocks

Plugin:

Newspack Blocks

Plugin Slug:
newspack-blocks

Vulnerability:
Broken Access Control

Patched in Version:
3.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.9.

Newspack Blocks

Plugin:

Newspack Blocks

Plugin Slug:
newspack-blocks

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.0.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.9.

Newspack Blocks

Plugin:

Newspack Blocks

Plugin Slug:
newspack-blocks

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

Newspack Content Converter

Plugin:

Newspack Content Converter

Plugin Slug:
newspack-content-converter

Vulnerability:
Broken Access Control

Patched in Version:
1.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.0.

Newspack Campaigns

Plugin:

Newspack Campaigns

Plugin Slug:
newspack-popups

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.31.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.31.2.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.14.

Seo Optimized Images

Plugin:

Seo Optimized Images

Plugin Slug:
seo-optimized-images

Vulnerability:
Backdoor

Patched in Version:
2.1.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.1.4.

Social Warfare

Plugin:

Social Warfare

Plugin Slug:
social-warfare

Vulnerability:
Backdoor

Patched in Version:
4.4.7.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.4.7.3.

Uber Menu

Plugin:

Uber Menu

Plugin Slug:
ubermenu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.8.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.4.

Ultimate Addons for Elementor

Plugin:

Ultimate Addons for Elementor

Plugin Slug:
ultimate-elementor

Vulnerability:
Privilege Escalation

Patched in Version:
1.36.32

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.36.32.

Uncanny Automator Pro

Plugin:

Uncanny Automator Pro

Plugin Slug:
uncanny-automator-pro

Vulnerability:
Settings Change

Patched in Version:
5.3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.0.1.

Uncanny Automator Pro

Plugin:

Uncanny Automator Pro

Plugin Slug:
uncanny-automator-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.0.1.

Uncanny Toolkit Pro for LearnDash

Plugin:

Uncanny Toolkit Pro for LearnDash

Plugin Slug:
uncanny-toolkit-pro

Vulnerability:
Other Vulnerability Type

Patched in Version:
4.1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.1.

Uncanny Toolkit Pro for LearnDash

Plugin:

Uncanny Toolkit Pro for LearnDash

Plugin Slug:
uncanny-toolkit-pro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.4.1.

Uncanny Toolkit Pro for LearnDash

Plugin:

Uncanny Toolkit Pro for LearnDash

Plugin Slug:
uncanny-toolkit-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.4.1.

TrustedLogin Vendor

Plugin:

TrustedLogin Vendor

Plugin Slug:
vendor

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.9.

Woffice Core

Plugin:

Woffice Core

Plugin Slug:
woffice-core

Vulnerability:
Broken Access Control

Patched in Version:
5.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.9.

WP Job Manager – Resume Manager

Plugin:

WP Job Manager – Resume Manager

Plugin Slug:
wp-job-manager-resumes

Vulnerability:
Broken Access Control

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.
Plugin:

Wrapper Link Elementor

Plugin Slug:
wrapper-link-elementor

Vulnerability:
Backdoor

Patched in Version:
1.0.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.5.

WordPress Themes � 26 Patched / 9 Unpatched

Anima

Theme:

Anima

Theme Slug:
anima

Downloads
168,999

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Infinite Photography

Theme Slug:
infinite-photography

Downloads
107,414

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Boot Store

Theme:

Boot Store

Theme Slug:
boot-store

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Grey Opaque

Theme:

Grey Opaque

Theme Slug:
grey-opaque

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Mosaic

Theme:

Mosaic

Theme Slug:
mosaic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Schema Lite

Theme:

Schema Lite

Theme Slug:
schema-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Scylla lite

Theme:

Scylla lite

Theme Slug:
scylla-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Silesia

Theme:

Silesia

Theme Slug:
silesia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Theron Lite

Theme:

Theron Lite

Theme Slug:
theron-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Ashe

Theme:

Ashe

Theme Slug:
ashe

Downloads
1,957,104

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.234

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.234.

Benevolent

Theme Slug:
benevolent

Downloads
160,655

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,336,053

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.23.

Blossom Shop

Theme Slug:
blossom-shop

Downloads
150,907

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

Coachify

Theme Slug:
coachify

Downloads
28,532

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.8.

Elegant Pink

Theme Slug:
elegant-pink

Downloads
196,614

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Esteem

Theme:

Esteem

Theme Slug:
esteem

Downloads
354,167

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.1.

Hestia

Theme:

Hestia

Theme Slug:
hestia

Downloads
4,062,876

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Highlight

Theme Slug:
highlight

Downloads
435,589

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.30

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.30.

JobScout

Theme Slug:
jobscout

Downloads
91,924

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Mesmerize

Theme Slug:
mesmerize

Downloads
1,557,420

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.124

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.124.

NewsMash

Theme Slug:
newsmash

Downloads
64,856

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.35

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.35.

Newsmatic

Theme Slug:
newsmatic

Downloads
213,444

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

OnePress

Theme Slug:
onepress

Downloads
2,262,614

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.7.

Perfect Portfolio

Theme Slug:
perfect-portfolio

Downloads
251,932

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

Preschool and Kindergarten

Theme Slug:
preschool-and-kindergarten

Downloads
120,182

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Travel Agency

Theme Slug:
travel-agency

Downloads
289,086

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Travel Monster

Theme Slug:
travel-monster

Downloads
28,852

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Trendy News

Theme Slug:
trendy-news

Downloads
24,678

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.16.

Basil

Theme:

Basil

Theme Slug:
basil

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

The7

Theme:

The7

Theme Slug:
dt-the7

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.14.0.

Foxiz

Theme:

Foxiz

Theme Slug:
foxiz

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.3.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.6.

Goya

Theme:

Goya

Theme Slug:
goya

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.8.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.8.8.

Striking

Theme:

Striking

Theme Slug:
striking-r

Vulnerability:
Local File Inclusion

Patched in Version:
2.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.5.

Striking

Theme:

Striking

Theme Slug:
striking-r

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.5.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.4.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…