Line illustration showing a black application window on a dark blue gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � November 27, 2024

In this report, 277 vulnerabilities have been publicly disclosed. Security patches for 156 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 121 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7, code-named �Rollins,� is out now, paying tribute to the legendary jazz saxophonist Sonny Rollins. WordPress 6.7 debuts the modern Twenty Twenty-Five theme, offering design flexibility for blogs.

WordPress Plugins � 153 Patched / 115 Unpatched

Dynamic “To Top” Plugin

Plugin Slug:
dynamic-to-top

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Meteor Slides

Plugin Slug:
meteor-slides

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Weather Atlas Widget

Plugin Slug:
weather-atlas

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Premium Packages � Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Announcement & Notification Banner � Bulletin

Plugin Slug:
bulletin-announcements

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Yaad Sarig Payment Gateway For WC

Plugin Slug:
yaad-sarig-payment-gateway-for-wc

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Extensions for Elementor

Plugin Slug:
extensions-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Absolute Addons For Elementor

Plugin Slug:
absolute-addons

Installations
700+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Library Bookshelves

Plugin Slug:
library-bookshelves

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SuevaFree Essential Kit

Plugin Slug:
suevafree-essential-kit

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team Rosters

Plugin Slug:
team-rosters

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Buying Buddy IDX CRM

Plugin Slug:
buying-buddy-idx-crm

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post By Email

Plugin Slug:
post-by-email

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Subaccounts for WooCommerce

Plugin Slug:
subaccounts-for-woocommerce

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ai-responsive-gallery-album

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

amr shortcodes

Plugin Slug:
amr-shortcodes

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator

Installations
100+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lazy load videos and sticky control

Plugin Slug:
lazy-load-videos-and-sticky-control

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LeadBoxer

Plugin Slug:
leadboxer

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LGPD Framework By Data443

Plugin Slug:
lgpd-framework

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

SP Blog Designer

Plugin Slug:
sp-blog-designer

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Tailored Tools

Plugin Slug:
tailored-tools

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TM Islamic Helper

Plugin Slug:
tm-islamic-helper

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Elementor Portfolio Builder

Plugin Slug:
portfolio-builder-elementor

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AI Quiz | Quiz Maker

Plugin Slug:
ai-quiz

Installations
70+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Open edX LMS and WordPress integrator (LITE)

Plugin Slug:
edunext-openedx-integrator

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Geolocator

Plugin Slug:
geolocator

Installations
50+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Infinite Slider

Plugin Slug:
infinite-slider

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Price Alert

Plugin Slug:
price-alert-woocommerce

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

QRMenu Restaurant QR Menu Lite

Plugin Slug:
qrmenu-lite

Installations
50+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP e-Commerce Style Email

Plugin Slug:
wp-e-commerce-style-email

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Office Locator

Plugin Slug:
office-locator

Installations
40+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Event Manager

Plugin Slug:
advanced-event-manager

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

de:branding

Plugin Slug:
debranding

Installations
30+

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fintelligence Calculator

Plugin Slug:
fintelligence-calculator

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ITERAS

Plugin:

ITERAS

Plugin Slug:
iteras

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Studio

Plugin Slug:
awesome-studio

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Lyrics Karaoke Player

Plugin Slug:
html5-lyrics-karaoke-player

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

nBlocks � Responsive Gutenberg News Blocks

Plugin Slug:
nblocks

Installations
20+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Post Ideas

Plugin Slug:
post-ideas

Installations
20+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings

Installations
20+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings

Installations
20+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AtaraPay WooCommerce Payment Gateway

Plugin Slug:
atarapay-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Chameleoni Jobs

Plugin Slug:
chameleon-jobs

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Explara Events

Plugin Slug:
explara-events

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GoQMieruca

Plugin Slug:
goqmieruca

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GoQSmile

Plugin:

GoQSmile

Plugin Slug:
goqsmile

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pathomation

Plugin Slug:
pathomation

Installations
10+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Pricing table addon for elementor

Plugin Slug:
pricing-table-addon-for-elementor

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

YaDisk Files

Plugin Slug:
wp-yadisk-files

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Xpresslane Fast Checkout

Plugin Slug:
xpresslane-integration-for-woocommerce

Installations
10+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ahmeti Wp G�zel S�zler

Plugin:

Ahmeti Wp G�zel S�zler

Plugin Slug:
ahmeti-wp-guzel-sozler

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Alphabetical List

Plugin:

Alphabetical List

Plugin Slug:
alphabetical-list

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

April’s Call Posts

Plugin:

April’s Call Posts

Plugin Slug:
aprils-call-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Banner System

Plugin:

Banner System

Plugin Slug:
banner-system

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Email Add on

Plugin:

Contact Form 7 Email Add on

Plugin Slug:
cf7-email-add-on

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Contact Page With Google Map

Plugin:

Contact Page With Google Map

Plugin Slug:
contact-page-with-google-map

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Continue Shopping From Cart

Plugin:

Continue Shopping From Cart

Plugin Slug:
continue-shopping-from-cart-page

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Control horas

Plugin:

Control horas

Plugin Slug:
control-horas

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Custom Shortcode Sidebars

Plugin:

Custom Shortcode Sidebars

Plugin Slug:
custom-shortcode-sidebars

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Dynamic URL SEO

Plugin:

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Twitter Feed

Plugin:

Easy Twitter Feed

Plugin Slug:
easy-twitter-feeds

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

F4 Improvements

Plugin:

F4 Improvements

Plugin Slug:
f4-improvements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Favicon My Blog

Plugin:

Favicon My Blog

Plugin Slug:
favicon-my-blog

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Fence URL

Plugin:

Fence URL

Plugin Slug:
fence-url

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Footer Flyout Widget

Plugin Slug:
footer-flyout-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Plus Share and +1 Button

Plugin:

Google Plus Share and +1 Button

Plugin Slug:
google-plus-share-and-plusone-button

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Grey Owl Lightbox

Plugin:

Grey Owl Lightbox

Plugin Slug:
grey-owl-lightbox

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Grid View Gallery

Plugin Slug:
grid-view-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Brute Force Protection � Stop Brute Force Attacks

Plugin:

WordPress Brute Force Protection � Stop Brute Force Attacks

Plugin Slug:
guardgiant

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Hotlink2Watermark

Plugin:

Hotlink2Watermark

Plugin Slug:
hotlink2watermark

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

IceStats

Plugin:

IceStats

Plugin Slug:
icestats

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Idealien Category Enhancements

Plugin:

Idealien Category Enhancements

Plugin Slug:
idealien-category-enhancements

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Image horizontal reel scroll slideshow

Plugin:

Image horizontal reel scroll slideshow

Plugin Slug:
image-horizontal-reel-scroll-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ImbaChat

Plugin:

ImbaChat

Plugin Slug:
imbachat-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

iPhone Webclip Manager

Plugin:

iPhone Webclip Manager

Plugin Slug:
iphone-webclip-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kevin’s

Plugin:

Kevin’s

Plugin Slug:
kevins-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LeanPress

Plugin:

LeanPress

Plugin Slug:
leanpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

LinkLaunder SEO

Plugin:

LinkLaunder SEO

Plugin Slug:
linklaunder-seo-plugin

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Lock User Account

Plugin:

Lock User Account

Plugin Slug:
lock-user-account

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Feed Reader

Plugin:

Multi Feed Reader

Plugin Slug:
multi-feed-reader

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Social Login

Plugin:

Social Login

Plugin Slug:
oa-social-login

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Community by PeepSo

Plugin:

Community by PeepSo

Plugin Slug:
peepso-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Product Designer

Plugin:

Product Designer

Plugin Slug:
product-designer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Protect Your Content

Plugin:

Protect Your Content

Plugin Slug:
protect-your-content

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pure CSS Circle Progress Bar

Plugin:

Pure CSS Circle Progress Bar

Plugin Slug:
pure-css-circle-progress-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Quick Learn

Plugin Slug:
quick-learn

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Quotes llama

Plugin:

Quotes llama

Plugin Slug:
quotes-llama

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

RealtyCandy IDX Broker Extended

Plugin:

RealtyCandy IDX Broker Extended

Plugin Slug:
realtycandy-idx-broker-extended

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RecipePress Reloaded

Plugin:

RecipePress Reloaded

Plugin Slug:
recipepress-reloaded

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

salavat counter

Plugin:

salavat counter

Plugin Slug:
salavat-counter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Crypto and DeFi Widgets

Plugin:

Crypto and DeFi Widgets

Plugin Slug:
security-force

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shine PDF Embeder

Plugin:

Shine PDF Embeder

Plugin Slug:
shine-pdf

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Simple Travel Map

Plugin:

Simple Travel Map

Plugin Slug:
simple-travel-map

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Slick Sitemap

Plugin:

Slick Sitemap

Plugin Slug:
slick-sitemap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Silverlight Video Player

Plugin:

Silverlight Video Player

Plugin Slug:
smooth-streaming-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Sticky Social Icons

Plugin:

Sticky Social Icons

Plugin Slug:
sticky-social-icons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

LSX Tour Operator

Plugin:

LSX Tour Operator

Plugin Slug:
tour-operator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tribute Testimonials

Plugin:

Tribute Testimonials

Plugin Slug:
tribute-testimonial-gridslider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin:

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin Slug:
ultimate-youtube-video-player

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin:

Ultimate YouTube Video & Shorts Player With Vimeo

Plugin Slug:
ultimate-youtube-video-player

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UltraAddons Elementor Lite

Plugin:

UltraAddons Elementor Lite

Plugin Slug:
ultraaddons-elementor-lite

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:

UserPlus

Plugin Slug:
userplus

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WPBakery Visual Composer WHMCS Elements

Plugin:

WPBakery Visual Composer WHMCS Elements

Plugin Slug:
void-visual-whmcs-element

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wc Recently viewed products

Plugin:

Wc Recently viewed products

Plugin Slug:
wc-recently-viewed-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

wp auto top

Plugin:

wp auto top

Plugin Slug:
wp-auto-top

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP-ISPConfig 3

Plugin:

WP-ISPConfig 3

Plugin Slug:
wp-ispconfig3

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WPDash Notes

Plugin:

WPDash Notes

Plugin Slug:
wpdash-notes

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Youneeq Recommendations

Plugin:

Youneeq Recommendations

Plugin Slug:
youneeq-panel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

yPHPlista

Plugin:

yPHPlista

Plugin Slug:
yphplista

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Zajax � Ajax Navigation

Plugin:

Zajax � Ajax Navigation

Plugin Slug:
zajax-ajax-navigation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO � AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math

Installations
3,000,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.0.232

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.232.

Google for WooCommerce

Plugin Slug:
google-listings-and-ads

Installations
900,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.7.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.1002

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.1002.

Activity Log � Monitor & Record User Changes

Plugin Slug:
aryo-activity-log

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.11.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.11.2.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect

Installations
200,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.45

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.45.

Spam protection, Anti-Spam, FireWall by CleanTalk

Plugin Slug:
cleantalk-spam-protect

Installations
200,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.44

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.44.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.10.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.10.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
12.3.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 12.3.21.

HUSKY � Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.6.4.

Parsi Date

Plugin Slug:
wp-parsidate

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.1.2.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.62.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.62.0.

Clone

Plugin:

Clone

Plugin Slug:
wp-clone-by-wp-academy

Installations
70,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.7.

Getwid � Gutenberg Blocks

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.13.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.4.2.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.3.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.2.4.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.2.4.

Ditty � Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.47

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.47.

Simple Membership

Plugin Slug:
simple-membership

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.5.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.6.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.145.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 2.145.1.

Stratum � Elementor Widgets

Plugin Slug:
stratum

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.5.

MailChimp Forms by MailMunch

Plugin Slug:
mailchimp-forms-by-mailmunch

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.4.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.22.22

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.22.22.

404 Solution

Plugin Slug:
404-solution

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.35.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.35.20.

CM Pop-Up Banners for WordPress

Plugin Slug:
cm-pop-up-banners

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.6.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

Simple Side Tab

Plugin Slug:
simple-side-tab

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.0.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.7.

WP User Manager � User Profile Builder & Membership

Plugin Slug:
wp-user-manager

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.12.

WP User Manager � User Profile Builder & Membership

Plugin Slug:
wp-user-manager

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.12.

Category Ajax Filter

Plugin Slug:
category-ajax-filter

Installations
8,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.3.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.3.12.

GD bbPress Attachments

Plugin Slug:
gd-bbpress-attachments

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.7.3.

If-So Dynamic Content Personalization

Plugin Slug:
if-so

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.2.2.

MailMunch � Grow your Email List

Plugin Slug:
mailmunch

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.0.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.9.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.3.7.

Product Input Fields for WooCommerce

Plugin Slug:
product-input-fields-for-woocommerce

Installations
6,000+

Vulnerability:
Path Traversal

Patched in Version:
2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.

WPAdverts � Classifieds Plugin

Plugin Slug:
wpadverts

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.8.

GEO my WP

Plugin Slug:
geo-my-wp

Installations
5,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.5

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.5.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.16

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.16.

CM WordPress Search And Replace Plugin

Plugin Slug:
cm-on-demand-search-and-replace

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.3.

Sp*tify Play Button for WordPress

Plugin Slug:
spotify-play-button-for-wordpress

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.12.

Premium Packages � Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.9.4.

Add Chat App Button

Plugin Slug:
add-whatsapp-button

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

Parallax Image

Plugin Slug:
parallax-image

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.1.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.22.

affiliate-toolkit � WP Affiliate Plugin with Amazon

Plugin Slug:
affiliate-toolkit-starter

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.8.

Email Subscription Popup

Plugin Slug:
email-subscribe

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.23

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.23.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.3.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.2.

SVG Block

Plugin Slug:
svg-block

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.25

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.25.

Theme Builder For Elementor

Plugin Slug:
theme-builder-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

Checkout with Cash App on WooCommerce

Plugin Slug:
wc-cashapp

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.0.3.

What Would Seth Godin Do

Plugin Slug:
what-would-seth-godin-do

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Anonymous Restricted Content

Plugin Slug:
anonymous-restricted-content

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.6.

AppPresser � Mobile App Framework

Plugin Slug:
apppresser

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.4.7

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.4.7.

Attesa Extra

Plugin Slug:
attesa-extra

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.3.
Plugin Slug:
bne-gallery-extended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

Name: CM E-Mail Registration Blacklist

Plugin Slug:
cm-email-blacklist

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.5.4.
Plugin Slug:
cm-header-footer-script-loader

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.2.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.5.77

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.5.77.

Friendly Functions for Welcart

Plugin Slug:
friendly-functions-for-welcart

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.5.

GD Rating System

Plugin Slug:
gd-rating-system

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.6.2.
Plugin Slug:
inpost-gallery

Installations
1,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.3.

JobBoardWP � Job Board Listings and Submissions

Plugin Slug:
jobboardwp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.7.2.

????? ?? ???? � ???? ?? ????

Plugin Slug:
pgall-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.0.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.2.2.

Image Optimizer, Resizer and CDN � Sirv

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
7.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.3.1.

Bard Extra

Plugin Slug:
bard-extra

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.8.

Include Mastodon Feed

Plugin Slug:
include-mastodon-feed

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.6.

System Dashboard

Plugin Slug:
system-dashboard

Installations
800+

Vulnerability:
Path Traversal

Patched in Version:
2.8.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.15.

System Dashboard

Plugin Slug:
system-dashboard

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.15

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.8.15.

StreamWeasels Online Status Bar

Plugin Slug:
stream-status-for-twitch

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.10.

Theater for WordPress

Plugin Slug:
theatre

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.18.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.18.7.

Block Editor Bootstrap Blocks

Plugin Slug:
block-editor-bootstrap-blocks

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.6.2.

Memberlite Shortcodes

Plugin Slug:
memberlite-shortcodes

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.

???? ???

Plugin:

???? ???

Plugin Slug:
mshop-naver-talktalk

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.0.

WP Mailster

Plugin Slug:
wp-mailster

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.17.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.17.0.

CM Table Of Contents � WordPress TOC Plugin

Plugin Slug:
cm-table-of-content

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.4.

CM Table Of Contents � WordPress TOC Plugin

Plugin Slug:
cm-table-of-content

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.3.

???? ?????

Plugin Slug:
mshop-npay

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.0.

Custom CSS, JS & PHP

Plugin Slug:
custom-css

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.4.0.

FireCask�s Twitter Follow Button

Plugin Slug:
twitter-follow

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.3.

Easy Liveblogs

Plugin Slug:
easy-liveblogs

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.6.

Opal Woo Custom Product Variation

Plugin Slug:
opal-woo-custom-product-variation

Installations
200+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.4.

Slotti Ajanvaraus

Plugin Slug:
slotti-ajanvaraus

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.1.

WIP Incoming Lite

Plugin Slug:
wip-incoming-lite

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.2.

WP-Orphanage Extended

Plugin Slug:
wp-orphanage-extended

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.

Chessgame Shizzle

Plugin Slug:
chessgame-shizzle

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.1.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.4.

My Contador lesr

Plugin Slug:
my-contador-wp

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

Skt NURCaptcha

Plugin Slug:
skt-nurcaptcha

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.6.0.

Ortto

Plugin:

Ortto

Plugin Slug:
autopilot

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.21.

AutoListicle: Automatically Update Numbered List Articles

Plugin Slug:
autolisticle-automatically-update-numbered-list-articles

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.4.

Video Lessons Manager � WordPress LMS Plugin

Plugin Slug:
cm-video-lesson-manager

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.3.

PDF Invoices & Packing Slips Generator for WooCommerce

Plugin Slug:
pdf-invoicing-for-woocommerce

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.2.

Page Parts

Plugin Slug:
page-parts

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.4.

Fediverse Embeds

Plugin Slug:
fediverse-embeds

Installations
40+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.5.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.4.

WordPress Bootscraper

Plugin Slug:
wp-bootscraper

Installations
40+

Vulnerability:
Local File Inclusion

Patched in Version:
4.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.0.

???????? ??????? ????????? ??????

Plugin Slug:
express-pay

Installations
20+

Vulnerability:
SQL Injection

Patched in Version:
1.1.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.9.

Document & Data Automation

Plugin:

Document & Data Automation

Plugin Slug:
document-data-automation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.2.

MP3 Sticky Player

Plugin:

MP3 Sticky Player

Plugin Slug:
fwdmsp

Vulnerability:
Path Traversal

Patched in Version:
8.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 8.1.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Broken Access Control

Patched in Version:
67.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 67.2.0.

WPGYM

Plugin:

WPGYM

Plugin Slug:
gym-management

Vulnerability:
Arbitrary File Upload

Patched in Version:
67.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 67.2.0.

Leopard – WordPress offload media

Plugin:

Leopard – WordPress offload media

Plugin Slug:
leopard-wordpress-offload-media

Vulnerability:
Broken Access Control

Patched in Version:
3.1.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.2.

School Management

Plugin:

School Management

Plugin Slug:
school-management

Vulnerability:
Arbitrary File Upload

Patched in Version:
92.0.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 92.0.0.

Wishlist for WooCommerce Pro

Plugin:

Wishlist for WooCommerce Pro

Plugin Slug:
wish-list-for-woocommerce-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.3.

Booking & Appointment Plugin for WooCommerce

Plugin:

Booking & Appointment Plugin for WooCommerce

Plugin Slug:
woocommerce-booking

Vulnerability:
Broken Access Control

Patched in Version:
6.10.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 6.10.0.

WordPress GDPR & CCPA

Plugin:

WordPress GDPR & CCPA

Plugin Slug:
wordpress-gdpr

Vulnerability:
Broken Access Control

Patched in Version:
2.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.3.

WordPress GDPR & CCPA

Plugin:

WordPress GDPR & CCPA

Plugin Slug:
wordpress-gdpr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.3.

WordPress Themes � 3 Patched / 6 Unpatched

Grip

Theme:

Grip

Theme Slug:
grip

Downloads
27,482

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

AccessPress Staple

Theme:

AccessPress Staple

Theme Slug:
accesspress-staple

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:

Jobify – Job Board WordPress Theme

Theme Slug:
jobify

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:

Jobify – Job Board WordPress Theme

Theme Slug:
jobify

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:

Jobify – Job Board WordPress Theme

Theme Slug:
jobify

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Jobify – Job Board WordPress Theme

Theme:

Jobify – Job Board WordPress Theme

Theme Slug:
jobify

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Ashe

Theme:

Ashe

Theme Slug:
ashe

Downloads
2,043,009

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.244

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.244.

Bard

Theme:

Bard

Theme Slug:
bard

Downloads
939,343

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.217

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.217.

ForumEngine

Theme:

ForumEngine

Theme Slug:
forumengine

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…