Line illustration showing a black application window on a blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � May 8, 2024

In this report, 219 vulnerabilities have been publicly disclosed. Security patches for 135 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 84 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

WordPress Plugins � 129 Patched / 82 Unpatched

Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Xserver Migrator

Plugin Slug:
xserver-migrator

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Booster Extension

Plugin Slug:
booster-extension

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Democracy Poll

Plugin Slug:
democracy-poll

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Responsive Contact Form Builder & Lead Generation Plugin

Plugin Slug:
lead-form-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin Slug:
login-logout-register-menu

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Print-O-Matic

Plugin Slug:
print-o-matic

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All-in-One Addons for Elementor � WidgetKit

Plugin Slug:
widgetkit-for-elementor

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author � Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Post Author � Enhance Your Posts with the Author Bio, Co-Authors, Guest Authors, and Post Rating System, including User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Eleblog � Elementor Blog And Magazine Addons

Plugin Slug:
ele-blog

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Share This Image

Plugin Slug:
share-this-image

Installations
2,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Image Popup

Plugin Slug:
simple-image-popup

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Admin Page Spider

Plugin Slug:
admin-page-spider

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master � Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Viet Nam Affiliate

Plugin Slug:
viet-nam-affiliate

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

5280 Bootstrap Modal Contact Form

Plugin:

5280 Bootstrap Modal Contact Form

Plugin Slug:
5280-bootstrap-modal-contact-form

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Print Barcode Labels for your WooCommerce products/orders

Plugin:

Print Barcode Labels for your WooCommerce products/orders

Plugin Slug:
a4-barcode-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Print Barcode Labels for your WooCommerce products/orders

Plugin:

Print Barcode Labels for your WooCommerce products/orders

Plugin Slug:
a4-barcode-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AA Cash Calculator

Plugin:

AA Cash Calculator

Plugin Slug:
aa-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACF Front End Editor

Plugin:

ACF Front End Editor

Plugin Slug:
acf-front-end-editor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACF On-The-Go

Plugin:

ACF On-The-Go

Plugin Slug:
acf-on-the-go

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AJAX Login and Registration modal popup + inline form

Plugin:

AJAX Login and Registration modal popup + inline form

Plugin Slug:
ajax-login-and-registration-modal-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AnnounceKit

Plugin:

AnnounceKit

Plugin Slug:
announcekit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Archives Calendar Widget

Plugin:

Archives Calendar Widget

Plugin Slug:
archives-calendar-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AWSOM News Announcement

Plugin:

AWSOM News Announcement

Plugin Slug:
awsom-news-announcement

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

BlogLentor

Plugin:

BlogLentor

Plugin Slug:
bloglentor-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Brozzme Scroll Top

Plugin:

Brozzme Scroll Top

Plugin Slug:
brozzme-scroll-top

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Calendar

Plugin:

Calendar

Plugin Slug:
calendar

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

canvasio3D Light

Plugin:

canvasio3D Light

Plugin Slug:
canvasio3d-light

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Configure Login Timeout

Plugin:

Configure Login Timeout

Plugin Slug:
configure-login-timeout

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Corona Virus (COVID-19) Banner & Live Data

Plugin:

Corona Virus (COVID-19) Banner & Live Data

Plugin Slug:
corona-virus-covid-19-banner

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CPO Companion

Plugin:

CPO Companion

Plugin Slug:
cpo-companion

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crelly Slider

Plugin:

Crelly Slider

Plugin Slug:
crelly-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Different Menu in Different Pages

Plugin:

Different Menu in Different Pages

Plugin Slug:
different-menus-in-different-pages

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy Restaurant Table Booking

Plugin:

Easy Restaurant Table Booking

Plugin Slug:
easy-table-booking

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Event Management Tickets Booking

Plugin:

Event Management Tickets Booking

Plugin Slug:
event-monster

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fancy Elementor Flipbox

Plugin:

Fancy Elementor Flipbox

Plugin Slug:
fancy-elementor-flipbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elementor ImageBox

Plugin:

Elementor ImageBox

Plugin Slug:
fd-elementor-imagebox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Featured Content Gallery

Plugin Slug:
featured-content-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Forty Four � 404 Plugin for WordPress

Plugin:

Forty Four � 404 Plugin for WordPress

Plugin Slug:
forty-four

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Front User Submit / Front Editor

Plugin:

WP Front User Submit / Front Editor

Plugin Slug:
front-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GDPR Compliance

Plugin:

GDPR Compliance

Plugin Slug:
gdpr-compliance

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Giphypress

Plugin:

Giphypress

Plugin Slug:
giphypress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Google Document Embedder

Plugin:

Google Document Embedder

Plugin Slug:
google-document-embedder

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Google Typography

Plugin:

Google Typography

Plugin Slug:
google-typography

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Comments Evolved for WordPress

Plugin:

Comments Evolved for WordPress

Plugin Slug:
gplus-comments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GWP-Histats

Plugin:

GWP-Histats

Plugin Slug:
gwp-histats

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Inline Google Spreadsheet Viewer

Plugin:

Inline Google Spreadsheet Viewer

Plugin Slug:
inline-google-spreadsheet-viewer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MF Gig Calendar

Plugin:

MF Gig Calendar

Plugin Slug:
mf-gig-calendar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Min and Max Purchase for WooCommerce

Plugin:

Min and Max Purchase for WooCommerce

Plugin Slug:
min-and-max-purchase-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mini Loops

Plugin:

Mini Loops

Plugin Slug:
mini-loops

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Grid Gallery

Plugin Slug:
new-grid-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Photo Gallery � Responsive Photo Gallery

Plugin Slug:
new-photo-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Plugin:

CodeBard’s Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

PB MailCrypt

Plugin:

PB MailCrypt

Plugin Slug:
pb-mailcrypt-antispam-email-encryption

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Perfect Pullquotes

Plugin:

Perfect Pullquotes

Plugin Slug:
perfect-pullquotes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Pk Favicon Manager

Plugin:

Pk Favicon Manager

Plugin Slug:
phpsword-favicon-manager

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Progressive WordPress (PWA)

Plugin:

Progressive WordPress (PWA)

Plugin Slug:
progressive-wp

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QuickieBar

Plugin:

QuickieBar

Plugin Slug:
quickiebar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Realtyna Organic IDX plugin

Plugin:

Realtyna Organic IDX plugin

Plugin Slug:
real-estate-listing-realtyna-wpl

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

School Management Pro

Plugin:

School Management Pro

Plugin Slug:
school-management-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sliding Widgets

Plugin:

Sliding Widgets

Plugin Slug:
sliding-widgets

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons by Supsystic

Plugin:

Social Share Buttons by Supsystic

Plugin Slug:
social-share-buttons-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Subway � Private Site Option

Plugin:

Subway � Private Site Option

Plugin Slug:
subway

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:

SVS Pricing Tables

Plugin Slug:
svs-pricing-tables

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:

SVS Pricing Tables

Plugin Slug:
svs-pricing-tables

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Swift Framework

Plugin:

Swift Framework

Plugin Slug:
swift-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Swift Framework

Plugin:

Swift Framework

Plugin Slug:
swift-framework

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TT Custom Post Type Creator

Plugin:

TT Custom Post Type Creator

Plugin Slug:
tt-custom-post-type-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TweetScroll Widget

Plugin:

TweetScroll Widget

Plugin Slug:
tweetscroll-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Viet Affiliate Link

Plugin Slug:
viet-affiliate-link

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woo Total Sales

Plugin:

Woo Total Sales

Plugin Slug:
woo-total-sales

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP etracker

Plugin:

WP etracker

Plugin Slug:
wp-etracker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Favorite Posts

Plugin:

WP Favorite Posts

Plugin Slug:
wp-favorite-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WPCS ( WordPress Custom Search )

Plugin Slug:
wpcs-wp-custom-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WTI Like Post

Plugin:

WTI Like Post

Plugin Slug:
wti-like-post

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ZD YouTube FLV Player

Plugin:

ZD YouTube FLV Player

Plugin Slug:
zd-youtube-flv-player

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yoast SEO

Plugin Slug:
wordpress-seo

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
22.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 22.6.

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.218

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.218.

ElementsKit Elementor addons and Templates Library

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.3.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.10.31.

Spectra � WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
700,000+

Vulnerability:
Path Traversal

Patched in Version:
2.12.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.7.

Contact Form 7 Database Addon � CFDB7

Plugin Slug:
contact-form-cfdb7

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.3.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.7.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.5.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.4.

BackUpWordPress

Plugin Slug:
backupwordpress

Installations
100,000+

Vulnerability:
Directory Traversal

Patched in Version:
3.14

Severity Score:
Low


The vulnerability has been patched, so you should update to version 3.14.

BuddyPress

Plugin Slug:
buddypress

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.4.1.

MailerLite � Signup forms (official)

Plugin Slug:
official-mailerlite-sign-up-forms

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

MailerLite � Signup forms (official)

Plugin Slug:
official-mailerlite-sign-up-forms

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.7.

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.31

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.31.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

3D FlipBook � PDF Flipbook WordPress

Plugin Slug:
interactive-3d-flipbook-powered-physics-engine

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.5.

Media Cleaner: Clean your WordPress!

Plugin Slug:
media-cleaner

Installations
70,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.7.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.3.

Drag and Drop Multiple File Upload � Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.3.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.8.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.9.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.9.2.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.8.

Image Hover Effects � Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.19.

Simple Membership

Plugin Slug:
simple-membership

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.4.6.

Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms

Plugin Slug:
stop-spammer-registrations-plugin

Installations
50,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2024.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2024.5.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.1.9.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.4.0.
Plugin Slug:
sina-extension-for-elementor

Installations
40,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.2.

WP Video Lightbox

Plugin Slug:
wp-post-459161 wp-video-lightbox

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.11.

Popup Box � Best WordPress Popup Plugin

Plugin Slug:
ays-popup-box

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.1.3.

Float menu � awesome floating side menu

Plugin Slug:
float-menu

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.1.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.12.

LeadConnector

Plugin Slug:
leadconnector

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.

LeadConnector

Plugin Slug:
leadconnector

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

ClickCease Click Fraud Protection

Plugin Slug:
clickcease-click-fraud-protection

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.5.

EAN for WooCommerce

Plugin Slug:
ean-for-woocommerce

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.9.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.0.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.6.

Modal Window � create popup modal window

Plugin Slug:
modal-window

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.3.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.10.

WordPress Header Builder Plugin � Pearl

Plugin Slug:
pearl-header-builder

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

RomethemeKit For Elementor

Plugin Slug:
rometheme-for-elementor

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
20240502

Severity Score:
High


The vulnerability has been patched, so you should update to version 20240502.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.9.

Web Push Notifications � Webpushr

Plugin Slug:
webpushr-web-push-notifications

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.36.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.36.0.

Embed Google Fonts

Plugin Slug:
embed-google-fonts

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

WordPress Affiliates Plugin � SliceWP Affiliates

Plugin Slug:
slicewp

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.11.

WPC Composite Products for WooCommerce

Plugin Slug:
wpc-composite-products

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.8.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce

Installations
7,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

iPanorama 360 � WordPress Virtual Tour Builder

Plugin Slug:
ipanorama-360-virtual-tour-builder-lite

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.2.

Sticky Buttons � floating buttons builder

Plugin Slug:
sticky-buttons

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

Button Generator � easily Button Builder

Plugin Slug:
button-generation

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.

Side Menu Lite � add sticky fixed buttons

Plugin Slug:
side-menu-lite

Installations
6,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.1.

Edwiser Bridge � WordPress Moodle LMS Integration

Plugin Slug:
edwiser-bridge

Installations
5,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.0.6

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.6.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.0.

Testimonial Slider

Plugin Slug:
testimonial-slider

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.

WPify Woo Czech

Plugin Slug:
wpify-woo

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.11.

Popup Box � new WordPress popup plugin

Plugin Slug:
popup-box

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.7.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets

Installations
4,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.7.14

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.14.

Startklar Elementor Addons

Plugin Slug:
startklar-elmentor-forms-extwidgets

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.7.14

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.14.
Plugin Slug:
wp-auto-affiliate-links

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
6.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.4.4.

Custom WooCommerce Checkout Fields Editor

Plugin Slug:
add-fields-to-checkout-page-woocommerce

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.2.

Debug Log Manager

Plugin Slug:
debug-log-manager

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.2.

Mihdan: Yandex Turbo Feed

Plugin Slug:
mihdan-yandex-turbo-feed

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.11.

iPages Flipbook For WordPress

Plugin Slug:
ipages-flipbook

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

JW Player for WordPress

Plugin Slug:
jw-player-7-for-wp

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.4.

Ultimate Under Construction

Plugin Slug:
ultimate-under-construction

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.4.

Follow Us Badges

Plugin Slug:
wpsite-follow-us-badges

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.11.

Admin Bar Editor � Hide Toolbar by User Roles

Plugin Slug:
admin-bar

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.23.

Post Grid Master � Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder

Plugin Slug:
ajax-filter-posts

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.8.

ChatBot Conversational Forms

Plugin Slug:
conversational-forms

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.20.

Mooberry Book Manager

Plugin Slug:
mooberry-book-manager

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.15.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.15.13.

SimpleShop

Plugin Slug:
simpleshop-cz

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.3.

SimpleShop

Plugin Slug:
simpleshop-cz

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.10.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.10.1.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Content Injection

Patched in Version:
1.3.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.3.

Wow Skype Buttons

Plugin Slug:
mwp-skype

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.0.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.

Last Viewed Posts by WPBeginner

Plugin Slug:
last-viewed-posts

Installations
600+

Vulnerability:
PHP Object Injection

Patched in Version:
1.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.0.1.

Hostel

Plugin:

Hostel

Plugin Slug:
hostel

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.5.4.

Tabellen von faustball.com

Plugin Slug:
docollipics-faustball-de

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Breakdance

Plugin:

Breakdance

Plugin Slug:
breakdance

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1.

ConvertPlus

Plugin:

ConvertPlus

Plugin Slug:
convertplug

Vulnerability:
Broken Access Control

Patched in Version:
3.5.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.26.

ConvertPlus

Plugin:

ConvertPlus

Plugin Slug:
convertplug

Vulnerability:
PHP Object Injection

Patched in Version:
3.5.26

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.5.26.

Cost Calculator Builder Pro

Plugin:

Cost Calculator Builder Pro

Plugin Slug:
cost-calculator-builder-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.68

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.68.

Digital Publications by Supsystic

Plugin:

Digital Publications by Supsystic

Plugin Slug:
digital-publications-by-supsystic

Vulnerability:
Broken Access Control

Patched in Version:
1.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.8.

Elementor Pro

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.21.2.

Fancy Product Designer

Plugin:

Fancy Product Designer

Plugin Slug:
fancy-product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.81

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.1.81.

Gravity Forms Unique ID

Plugin:

Gravity Forms Unique ID

Plugin Slug:
gp-unique-id

Vulnerability:
Content Spoofing

Patched in Version:
1.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.6.

Mhr Post Ticker

Plugin Slug:
mhr-post-ticker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

Slider Revolution

Plugin:

Slider Revolution

Plugin Slug:
revslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.7.8.

WooCommerce AWeber Newsletter Subscription

Plugin:

WooCommerce AWeber Newsletter Subscription

Plugin Slug:
woocommerce-aweber-newsletter-subscription

Vulnerability:
Settings Change

Patched in Version:
4.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.3.

WordPress Themes � 6 Patched / 2 Unpatched

Adventure Journal

Theme:

Adventure Journal

Theme Slug:
adventure-journal

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Unique

Theme:

Unique

Theme Slug:
unique

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,141,362

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.43.

Edge

Theme:

Edge

Theme Slug:
edge

Downloads
336,008

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

Freesia Empire

Theme Slug:
freesia-empire

Downloads
203,860

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.2.

Pliska

Theme:

Pliska

Theme Slug:
pliska

Downloads
47,512

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.3.6.

raindrops

Theme Slug:
raindrops

Downloads
716,582

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.700

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.700.

Restaurant and Cafe

Theme Slug:
restaurant-and-cafe

Downloads
126,841

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…