Line illustration showing a black application window on a dark purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 19, 2024

In this report, 87 vulnerabilities have been publicly disclosed. Security patches for 73 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 14 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6 Beta 3 was released on June 18, 2024. The target release date for WordPress 6.6 is July 16, 2024. Your help testing Beta and RC versions over the next four weeks is vital to making sure the final release is everything it should be: stable, powerful, and intuitive.

WordPress Plugins � 71 Patched / 14 Unpatched

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Suite

Plugin Slug:
custom-field-suite

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
elespare

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shariff for WordPress

Plugin Slug:
shariff-sharing

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Scheduling Plugin � Online Booking for WordPress

Plugin:

Scheduling Plugin � Online Booking for WordPress

Plugin Slug:
calendar-booking

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:

Canto

Plugin Slug:
canto

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Collapse-O-Matic

Plugin:

Collapse-O-Matic

Plugin Slug:
jquery-collapse-o-matic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Master Slider

Plugin:

Master Slider

Plugin Slug:
master-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PDF Viewer for Elementor

Plugin:

PDF Viewer for Elementor

Plugin Slug:
pdf-viewer-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Schema App Structured Data

Plugin:

Schema App Structured Data

Plugin Slug:
schema-app-structured-data-for-schemaorg

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Where I Was, Where I Will Be

Plugin:

Where I Was, Where I Will Be

Plugin Slug:
where-i-was-where-i-will-be

Vulnerability:
Remote File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Video Gallery

Plugin Slug:
yotuwp-easy-youtube-embed

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Video Gallery

Plugin Slug:
yotuwp-easy-youtube-embed

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce

Installations
7,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.9.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.9.3.
Plugin Slug:
header-footer-elementor

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.36.

WPS Hide Login

Plugin Slug:
wps-hide-login

Installations
1,000,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.16.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.34

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.34.

Ocean Extra

Plugin Slug:
ocean-extra

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.9.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.62.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.62.0.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.39

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.39.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.0.39

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.39.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.6.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.90

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.90.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.87

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.87.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.94

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.94.

Social Sharing Plugin � Sassy Social Share

Plugin Slug:
sassy-social-share

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.63

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.63.

Search & Replace

Plugin Slug:
search-and-replace

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.2.

Simple Sitemap � Create a Responsive HTML Sitemap

Plugin Slug:
simple-sitemap

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.5.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.14.

WordPress Online Booking and Scheduling Plugin � Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
23.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 23.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social

Installations
60,000+

Vulnerability:
SQL Injection

Patched in Version:
7.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.4.2.

Divi Torque Lite � Divi Theme and Extra Theme

Plugin Slug:
addons-for-divi

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Custom Field Template

Plugin Slug:
custom-field-template

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.9.4.

Stratum � Elementor Widgets

Plugin Slug:
stratum

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Serious Slider

Plugin Slug:
cryout-serious-slider

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.5.

Futurio Extra

Plugin Slug:
futurio-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.6.

WordPress Header Builder Plugin � Pearl

Plugin Slug:
pearl-header-builder

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.7.

Themify Builder

Plugin Slug:
themify-builder

Installations
7,000+

Vulnerability:
Open Redirection

Patched in Version:
7.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.5.8.

Dashboard Widgets Suite

Plugin Slug:
dashboard-widgets-suite

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.4.

WP Job Portal � A Complete Job Board

Plugin Slug:
wp-job-portal

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

WP Job Portal � A Complete Job Board

Plugin Slug:
wp-job-portal

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

InstaWP Connect � 1-click WP Staging & Migration

Plugin Slug:
instawp-connect

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.1.0.39

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 0.1.0.39.

Tickera � WordPress Event Ticketing

Plugin Slug:
tickera-event-ticketing-system

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.9.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.5.

Easy Age Verify

Plugin Slug:
easy-age-verify

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.3.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.5.

Activity Reactions For Buddypress

Plugin Slug:
activity-reactions-for-buddypress

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.5.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.5.1.
Plugin Slug:
left-right-image-slideshow-gallery

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
1.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.2.

Dokan Pro

Plugin:

Dokan Pro

Plugin Slug:
dokan-pro

Vulnerability:
SQL Injection

Patched in Version:
3.11.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.11.0.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.3.

Folders Pro

Plugin:

Folders Pro

Plugin Slug:
folders-pro

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.3.

Folders Pro

Plugin:

Folders Pro

Plugin Slug:
folders-pro

Vulnerability:
Path Traversal

Patched in Version:
3.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.3.

FooEvents for WooCommerce

Plugin:

FooEvents for WooCommerce

Plugin Slug:
fooevents

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.19.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.19.21.

FooGallery Premium

Plugin:

FooGallery Premium

Plugin Slug:
foogallery-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.15.

Ibtana

Plugin:

Ibtana

Plugin Slug:
ibtana-visual-editor

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.4.

LatePoint

Plugin:

LatePoint

Plugin Slug:
latepoint

Vulnerability:
Broken Access Control

Patched in Version:
4.9.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.1.

Newsletter – API addon (Premium)

Plugin:

Newsletter – API addon (Premium)

Plugin Slug:
newsletter-api

Vulnerability:
Broken Access Control

Patched in Version:
2.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.6.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
Broken Access Control

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

WooCommerce Social Login

Plugin:

WooCommerce Social Login

Plugin Slug:
woo-social-login

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.6.3.

Wp Staging Pro

Plugin:

Wp Staging Pro

Plugin Slug:
wp-staging-pro

Vulnerability:
Local File Inclusion

Patched in Version:
5.6.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.6.1.

WordPress Themes � 2 Patched / 0 Unpatched

Excellent

Theme Slug:
excellent

Downloads
116,551

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Interface

Theme Slug:
interface

Downloads
429,770

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…