Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � June 5, 2024

In this report, 128 vulnerabilities have been publicly disclosed. Security patches for 79 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 49 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6 Beta 1 was released on June 4, 2024. The scheduled final release date for WordPress 6.6 is�July 16, 2024. Your help testing Beta and RC versions over the next six weeks is vital to making sure the final release is everything it should be: stable, powerful, and intuitive.

WordPress Plugins � 78 Patched / 49 Unpatched

List categories

Plugin Slug:
list-categories

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
testimonials-carousel-elementor

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress

Installations
3,000+

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Spoiler

Plugin Slug:
simple-spoiler

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

KiviCare � Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Random Banner

Plugin Slug:
random-banner

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AffiEasy

Plugin:

AffiEasy

Plugin Slug:
affieasy

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Playlist for Youtube

Plugin Slug:
playlist-for-youtube

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ActiveDEMAND

Plugin:

ActiveDEMAND

Plugin Slug:
activedemand

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin Notices Manager

Plugin:

Admin Notices Manager

Plugin Slug:
admin-notices-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Authorize.net Payment Gateway For WooCommerce

Plugin:

Authorize.net Payment Gateway For WooCommerce

Plugin Slug:
authorizenet-payment-gateway-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BuddyForms

Plugin:

BuddyForms

Plugin Slug:
buddyforms

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:

Comparison Slider

Plugin Slug:
comparison-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:

Comparison Slider

Plugin Slug:
comparison-slider

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comparison Slider

Plugin:

Comparison Slider

Plugin Slug:
comparison-slider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cowidgets � Elementor Addons

Plugin:

Cowidgets � Elementor Addons

Plugin Slug:
cowidgets-elementor-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Download Attachments

Plugin:

Download Attachments

Plugin Slug:
download-attachments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:

Essential Real Estate

Plugin Slug:
essential-real-estate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin:

Essential Real Estate

Plugin Slug:
essential-real-estate

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Fluid Notification Bar

Plugin:

Fluid Notification Bar

Plugin Slug:
fluid-notification-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Frontend Registration � Contact Form 7

Plugin:

Frontend Registration � Contact Form 7

Plugin Slug:
frontend-registration-contact-form-7

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

FS Product Inquiry

Plugin Slug:
fs-product-inquiry

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gianism

Plugin:

Gianism

Plugin Slug:
gianism

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Global Notification Bar

Plugin:

Global Notification Bar

Plugin Slug:
global-notification-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Insert Post Ads

Plugin:

Insert Post Ads

Plugin Slug:
insert-post-ads

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MJ Update History

Plugin:

MJ Update History

Plugin Slug:
mj-update-history

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Nafeza Prayer Time

Plugin:

Nafeza Prayer Time

Plugin Slug:
nafeza-prayer-time

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:

Netgsm

Plugin Slug:
netgsm

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

QQWorld Auto Save Images

Plugin:

QQWorld Auto Save Images

Plugin Slug:
qqworld-auto-save-images

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Remote Content Shortcode

Plugin:

Remote Content Shortcode

Plugin Slug:
remote-content-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple COD Fees for WooCommerce

Plugin:

Simple COD Fees for WooCommerce

Plugin Slug:
simple-cod-fee-for-woocommerce

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Smartarget Message Bar

Plugin Slug:
smartarget-message-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Social Link Pages

Plugin Slug:
social-link-pages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Login Lite For WooCommerce

Plugin:

Social Login Lite For WooCommerce

Plugin Slug:
social-login-lite-for-woocommerce

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

StopBadBots

Plugin:

StopBadBots

Plugin Slug:
stopbadbots

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin:

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Upload Fields for WPForms

Plugin:

Upload Fields for WPForms

Plugin Slug:
upload-fields-for-wpforms

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Uploadcare File Uploader and Adaptive Delivery (beta)

Plugin:

Uploadcare File Uploader and Adaptive Delivery (beta)

Plugin Slug:
uploadcare

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Claudio Sanches

Plugin:

Claudio Sanches

Plugin Slug:
woocommerce-checkout-cielo

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Back Button

Plugin:

WP Back Button

Plugin Slug:
wp-back-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-DB-Table-Editor

Plugin:

WP-DB-Table-Editor

Plugin Slug:
wp-db-table-editor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:

WP-Recall

Plugin Slug:
wp-recall

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP To Do

Plugin:

WP To Do

Plugin Slug:
wp-todo

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Translate

Plugin:

WP Translate

Plugin Slug:
wp-translate

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPUpper Share Buttons

Plugin:

WPUpper Share Buttons

Plugin Slug:
wpupper-share-buttons

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Yumpu ePaper publishing

Plugin:

Yumpu ePaper publishing

Plugin Slug:
yumpu-epaper-publishing

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF)

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist

Installations
900,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.33.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.33.0.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.10.32

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.32.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.7.

Page Builder Gutenberg Blocks � CoBlocks

Plugin Slug:
coblocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.10.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.0.

Post SMTP � WP SMTP Plugin with Email Logs & Mobile App for Failure Alerts � Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark

Plugin Slug:
post-smtp

Installations
400,000+

Vulnerability:
SQL Injection

Patched in Version:
2.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.9.4.

Newsletter � Send awesome emails from WordPress

Plugin Slug:
newsletter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.3.5.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.976

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.976.

Blocksy Companion

Plugin Slug:
blocksy-companion

Installations
200,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.0.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.43.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.94

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.94.

Download Manager

Plugin Slug:
download-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.91

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.91.

Download Monitor

Plugin Slug:
download-monitor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.14.

LearnPress � WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.6.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.6.8.1.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.44.

Brizy � Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.44

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.44.

Ninja Tables � Easiest Data Table Builder

Plugin Slug:
ninja-tables

Installations
80,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
5.0.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.10.

Site Reviews

Plugin Slug:
site-reviews

Installations
60,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
7.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.0.0.

WordPress Infinite Scroll � Ajax Load More

Plugin Slug:
ajax-load-more

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.2.

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.5.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.1.

wpForo Forum

Plugin Slug:
wpforo

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
2.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.4.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.5.

LifterLMS � WordPress LMS for eLearning

Plugin Slug:
lifterlms

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
7.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.6.3.

Elements For Elementor

Plugin Slug:
nd-elements

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.

Simple Like Page Plugin

Plugin Slug:
simple-facebook-plugin

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.3.

Weaver Xtreme Theme Support

Plugin Slug:
weaverx-theme-support

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.

Five Star Restaurant Menu and Food Ordering

Plugin Slug:
food-and-drink-menu

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.17.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.8.7.
Plugin Slug:
integrate-google-drive

Installations
6,000+

Vulnerability:
Broken Authentication

Patched in Version:
1.3.94

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.94.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.6.0.

Debug Log Manager

Plugin Slug:
debug-log-manager

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
responsive-owl-carousel-elementor

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.2.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.1.

Mollie Forms

Plugin Slug:
mollie-forms

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.14.

Preferred Languages

Plugin Slug:
preferred-languages

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Simple Ajax Chat � Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20240412

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 20240412.

Site Favicon

Plugin Slug:
site-favicon

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.3.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.0.

Emergency Password Reset

Plugin Slug:
emergency-password-reset

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.0.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.2.
Plugin Slug:
gamipress-link

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.

Safety Exit

Plugin Slug:
safety-exit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

WP Flow Plus

Plugin Slug:
wp-imageflow2

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.3.

MelaPress Login Security

Plugin Slug:
melapress-login-security

Installations
600+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

Gutenberg Blocks and Page Layouts � Attire Blocks

Plugin Slug:
attire-blocks

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.3.

Just Writing Statistics

Plugin Slug:
just-writing-statistics

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.6.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.
Plugin:

Boostify Header Footer Builder for Elementor

Plugin Slug:
boostify-header-footer-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

Buddyboss Platform

Plugin:

Buddyboss Platform

Plugin Slug:
buddyboss-platform

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.6.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.0.

Contact Form Manager

Plugin:

Contact Form Manager

Plugin Slug:
contact-form-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.1.

GP Premium

Plugin:

GP Premium

Plugin Slug:
gp-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.1.

tagDiv Composer

Plugin:

tagDiv Composer

Plugin Slug:
td-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.

The Plus Addons for Elementor Pro

Plugin:

The Plus Addons for Elementor Pro

Plugin Slug:
theplus_elementor_addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.5.

Checkout Field Editor for WooCommerce (Pro)

Plugin:

Checkout Field Editor for WooCommerce (Pro)

Plugin Slug:
woocommerce-checkout-field-editor-pro

Vulnerability:
Arbitrary File Deletion

Patched in Version:
3.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.3.

WP eMember

Plugin:

WP eMember

Plugin Slug:
wp-eMember

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
10.3.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 10.3.9.

WPvivid Backup for MainWP

Plugin:

WPvivid Backup for MainWP

Plugin Slug:
wpvivid-backup-mainw

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.9.33

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.9.33.

WordPress Themes � 1 Patched / 0 Unpatched

Responsive

Theme Slug:
responsive

Downloads
4,502,287

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.3.1.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…