Line illustration showing a black application window on a red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � October 16, 2024

In this report, 176 vulnerabilities have been publicly disclosed. Security patches for 87 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 89 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Don’t install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 2 on a test server and site.

WordPress Plugins � 87 Patched / 86 Unpatched

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Docs

Plugin Slug:
buddypress-docs

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
linkz-ai

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
linkz-ai

Installations
90+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

2D Tag Cloud

Plugin:

2D Tag Cloud

Plugin Slug:
2d-tag-cloud-widget-by-sujin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

AB Categories Search Widget

Plugin:

AB Categories Search Widget

Plugin Slug:
ab-categories-search-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ACF Images Search And Insert

Plugin:

ACF Images Search And Insert

Plugin Slug:
acf-images-search-and-insert

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Add Categories Post Footer

Plugin:

Add Categories Post Footer

Plugin Slug:
add-categories-post-footer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ADIF Log Search Widget

Plugin:

ADIF Log Search Widget

Plugin Slug:
adif-log-search-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Blocks Pro

Plugin:

Advanced Blocks Pro

Plugin Slug:
advanced-blocks-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Ahime Image Printer

Plugin:

Ahime Image Printer

Plugin Slug:
ahime-image-printer

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ahmeti Wp Timeline

Plugin:

Ahmeti Wp Timeline

Plugin Slug:
ahmeti-wp-timeline

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Ajax Custom CSS/JS

Plugin:

Ajax Custom CSS/JS

Plugin Slug:
ajax-awesome-css

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ajax-extend

Plugin:

ajax-extend

Plugin Slug:
ajax-extend

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ajax Rating with Custom Login

Plugin:

Ajax Rating with Custom Login

Plugin Slug:
ajax-rating-with-custom-login

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Analyse Uploads

Plugin:

Analyse Uploads

Plugin Slug:
analyse-uploads

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Arkhe Blocks

Plugin:

Arkhe Blocks

Plugin Slug:
arkhe-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Azz Anonim Posting

Plugin:

Azz Anonim Posting

Plugin Slug:
azz-anonim-posting

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Better Author Bio

Plugin:

Better Author Bio

Plugin Slug:
better-author-bio

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Better Registration

Plugin:

BuddyPress Better Registration

Plugin Slug:
better-bp-registration

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Booking.com Banner Creator

Plugin:

Booking.com Banner Creator

Plugin Slug:
bookingcom-banner-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bot for Telegram on WooCommerce

Plugin:

Bot for Telegram on WooCommerce

Plugin Slug:
bot-for-telegram-on-woocommerce

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

bVerse Convert

Plugin:

bVerse Convert

Plugin Slug:
bverse-convert

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CJ Change Howdy

Plugin:

CJ Change Howdy

Plugin Slug:
cj-change-howdy

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Cookie Scanner

Plugin Slug:
cookie-scanner

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Country Flags for Elementor

Plugin:

Country Flags for Elementor

Plugin Slug:
country-flags-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Crazy Call To Action Box

Plugin:

Crazy Call To Action Box

Plugin Slug:
crazy-call-to-action-box

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Creates 3D Flipbook, PDF Flipbook

Plugin:

Creates 3D Flipbook, PDF Flipbook

Plugin Slug:
create-flipbook-from-pdf

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

cSlider

Plugin:

cSlider

Plugin Slug:
cslider

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Builder

Plugin:

WP Builder

Plugin Slug:
cssjockey-add-ons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

CSV Product Import Export for WooCommerce

Plugin:

CSV Product Import Export for WooCommerce

Plugin Slug:
csv-wc-product-import-export

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Curator.io

Plugin:

Curator.io

Plugin Slug:
curatorio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Digital Lottery

Plugin:

Digital Lottery

Plugin Slug:
digital-lottery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Disc Golf Manager

Plugin:

Disc Golf Manager

Plugin Slug:
disc-golf-manager

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Elementor Addons

Plugin:

Dynamic Elementor Addons

Plugin Slug:
dynamic-elementor-addons

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Easy Social Share Buttons

Plugin:

Easy Social Share Buttons

Plugin Slug:
easy-social-share-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Events Addon for Elementor

Plugin:

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

External featured image from bing

Plugin Slug:
external-featured-image-from-bing

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Featured Posts with Multiple Custom Groups (FPMCG)

Plugin Slug:
featured-posts-with-multiple-custom-groups-fpmcg

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Featured Posts with Multiple Custom Groups (FPMCG)

Plugin Slug:
featured-posts-with-multiple-custom-groups-fpmcg

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Feed Comments Number

Plugin:

Feed Comments Number

Plugin Slug:
feed-comments-number

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Free Stock Photos Foter

Plugin:

Free Stock Photos Foter

Plugin Slug:
free-stock-photos-foter

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GDPR-Extensions-com

Plugin:

GDPR-Extensions-com

Plugin Slug:
gdpr-consent-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Elementor Inline SVG

Plugin:

Elementor Inline SVG

Plugin Slug:
inline-svg-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

IP Loc8

Plugin:

IP Loc8

Plugin Slug:
ip-loc8

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Keep Backup Daily

Plugin:

Keep Backup Daily

Plugin Slug:
keep-backup-daily

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WordPress Gallery Plugin � Limb Image Gallery

Plugin Slug:
limb-gallery

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WordPress Gallery Plugin � Limb Image Gallery

Plugin Slug:
limb-gallery

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Linked Variation for WooCommerce

Plugin:

Linked Variation for WooCommerce

Plugin Slug:
linked-variation-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Contact Forms, Live Support, CRM, Video Messages

Plugin:

Contact Forms, Live Support, CRM, Video Messages

Plugin Slug:
live-support-tickets

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Maan Addons For Elementor

Plugin:

Maan Addons For Elementor

Plugin Slug:
maan-elementor-addons

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Forms for Mailchimp by Optin Cat

Plugin:

Forms for Mailchimp by Optin Cat

Plugin Slug:
mailchimp-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketing and SEO Booster

Plugin:

Marketing and SEO Booster

Plugin Slug:
marketing-and-seo-booster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

MAS Elementor

Plugin:

MAS Elementor

Plugin Slug:
mas-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

El mejor Cluster

Plugin:

El mejor Cluster

Plugin Slug:
mejorcluster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mighty Builder

Plugin:

Mighty Builder

Plugin Slug:
mighty-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mitm Bug Tracker

Plugin:

Mitm Bug Tracker

Plugin Slug:
mitm-bug-tracker

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

My Favorites

Plugin:

My Favorites

Plugin Slug:
my-favorites

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Mynx Page Builder

Plugin:

Mynx Page Builder

Plugin Slug:
mynx-page-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Easy PayPal Gift Certificate

Plugin:

Easy PayPal Gift Certificate

Plugin Slug:
paypal-gift-certificate

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pedalo Connector

Plugin:

Pedalo Connector

Plugin Slug:
pedalo-connector

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Plexx Elementor Extension

Plugin:

Plexx Elementor Extension

Plugin Slug:
plexx-elementor-extension

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

QA Analytics

Plugin:

QA Analytics

Plugin Slug:
qa-heatmap-analytics

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Read more By Adam

Plugin:

Read more By Adam

Plugin Slug:
read-more

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Recently

Plugin:

Recently

Plugin Slug:
recently-viewed-most-viewed-and-sold-products-for-woocommerce

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Restaurant Reservations Widget

Plugin:

Restaurant Reservations Widget

Plugin Slug:
restaurantconnect-reswidget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RS-Members

Plugin:

RS-Members

Plugin Slug:
rs-members

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Shortcode For Elementor Templates

Plugin:

Shortcode For Elementor Templates

Plugin Slug:
shortcode-support-for-elementor-templates

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes AnyWhere

Plugin:

Shortcodes AnyWhere

Plugin Slug:
shortcodes-anywhere

Vulnerability:
Content Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Baseball Scoreboard

Plugin:

Simple Baseball Scoreboard

Plugin Slug:
simple-baseball-scoreboard

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Plus

Plugin:

Table of Contents Plus

Plugin Slug:
table-of-contents-plus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

TAKETIN To WP Membership

Plugin:

TAKETIN To WP Membership

Plugin Slug:
taketin-to-wp-membership

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Talkback

Plugin:

Talkback

Plugin Slug:
talkback-secure-linkback-protocol

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Telecash Ricaricaweb

Plugin:

Telecash Ricaricaweb

Plugin Slug:
telecash-ricaricaweb

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Tito

Plugin:

Tito

Plugin Slug:
tito

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Addon For Elementor

Plugin:

Unlimited Addon For Elementor

Plugin Slug:
unlimited-addon-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Adding drop down roles in registration

Plugin:

Adding drop down roles in registration

Plugin Slug:
user-drop-down-roles-in-registration

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:

UserPlus

Plugin Slug:
userplus

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WordPress Video

Plugin:

WordPress Video

Plugin Slug:
wordpress-video

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP-Spreadplugin

Plugin:

WP-Spreadplugin

Plugin Slug:
wp-spreadplugin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Users Masquerade

Plugin:

WP Users Masquerade

Plugin Slug:
wp-users-masquerade

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

wpPricing Builder

Plugin:

wpPricing Builder

Plugin Slug:
wppricing-builder-lite-responsive-pricing-table-builder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Wsify Widget

Plugin:

Wsify Widget

Plugin Slug:
wsify-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce

Installations
7,000,000+

Vulnerability:
Content Injection

Patched in Version:
9.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.1.0.

Jetpack � WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
13.9.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 13.9.1.

Secure Custom Fields

Plugin Slug:
advanced-custom-fields

Installations
2,000,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
6.3.6.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.6.1.

TablePress � Tables in WordPress made easy

Plugin Slug:
tablepress

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.3.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.12.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.12.4.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.987

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.987.

Ad Inserter � Ad Manager & AdSense Ads

Plugin Slug:
ad-inserter

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.38

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.38.

Elementor Addon Elements

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.13.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.9.

Custom Twitter Feeds � A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.3.
Plugin Slug:
relevanssi

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.23.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.23.1.

Stackable � Page Builder Gutenberg Blocks

Plugin Slug:
stackable-ultimate-gutenberg-blocks

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.13.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.13.7.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.3.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.3.8.

SlimStat Analytics

Plugin Slug:
wp-slimstat

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.7.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.22.

Download Plugins and Themes in ZIP from Dashboard

Plugin Slug:
download-plugins-dashboard

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.2.

WPIDE � File Manager & Code Editor

Plugin Slug:
wpide

Installations
40,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
3.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.0.

FULL � Cliente

Plugin Slug:
full-customer

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.23

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.23.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
11.9.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 11.9.19.

VOD Infomaniak

Plugin Slug:
vod-infomaniak

Installations
30,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Embed PDF Viewer

Plugin Slug:
embed-pdf-viewer

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.5.

Smart Post Show � Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More

Plugin Slug:
post-carousel

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.1.

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Path Traversal

Patched in Version:
4.24.12

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.24.12.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
1.22.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.22.22.

Contact Form 7 � PayPal & Stripe Add-on

Plugin Slug:
contact-form-7-paypal-add-on

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.3.1.

Hunk Companion

Plugin Slug:
hunk-companion

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.8.5.

WP Post Author � Boost Your Blog’s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.2.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.29

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.29.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic

Installations
9,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
1.7.29

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.7.29.

CM Tooltip Glossary

Plugin Slug:
enhanced-tooltipglossary

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.3.11.

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.9.

ProfileGrid � User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.9.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.9.3.1.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.6.

Auto iFrame

Plugin Slug:
auto-iframe

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.

Easy Mega Menu Plugin for WordPress � ThemeHunk

Plugin Slug:
themehunk-megamenu-plus

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

WP Ultimate Post Grid

Plugin Slug:
wp-ultimate-post-grid

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.0.

CubeWP � All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.16.

Social Sharing (by Danny)

Plugin Slug:
dvk-social-sharing

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Category Icon

Plugin Slug:
category-icon

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

WordPress Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce

Installations
3,000+

Vulnerability:
Directory Traversal

Patched in Version:
2.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.9.

Products, Order & Customers Export for WooCommerce

Plugin Slug:
export-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.0.

Notification for Telegram

Plugin Slug:
notification-for-telegram

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.2.

Embed videos and respect privacy

Plugin Slug:
video-embed-privacy

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.

BlockMeister � Block Pattern Builder

Plugin Slug:
blockmeister

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.11.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.8.

Leyka

Plugin:

Leyka

Plugin Slug:
leyka

Installations
2,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
3.31.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.31.7.

SKT Blocks � Gutenberg based Page Builder

Plugin Slug:
skt-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.

Smart Blocks

Plugin Slug:
smart-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.71

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.71.

Increase upload file size & Maximum Execution Time limit

Plugin Slug:
increase-upload-file-size-maximum-execution-time-limit

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.

Language Switcher

Plugin Slug:
language-switcher

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.0.

Maximum Products per User for WooCommerce

Plugin Slug:
maximum-products-per-user-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.2.9.

Order Attachments for WooCommerce

Plugin Slug:
order-attachments-for-woocommerce

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.0.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.9.

Image Optimizer, Resizer and CDN � Sirv

Plugin Slug:
sirv

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.3.0.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.21.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.21.11.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
0.21.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 0.21.9.

wp-Monalisa

Plugin Slug:
wp-monalisa

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
6.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.5.
Plugin Slug:
wp-advanced-search

Installations
600+

Vulnerability:
SQL Injection

Patched in Version:
3.3.9.2

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.3.9.2.

AADMY � Add Auto Date Month Year Into Posts

Plugin Slug:
auto-date-year-month

Installations
300+

Vulnerability:
Content Injection

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Da Reactions

Plugin Slug:
da-reactions

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.0.

Limit Login Attempts (Spam Protection)

Plugin Slug:
wp-limit-failed-login-attempts

Installations
200+

Vulnerability:
Bypass Vulnerability

Patched in Version:
5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.
Plugin Slug:
image-gallery

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.
Plugin Slug:
image-gallery

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.
Plugin Slug:
image-gallery

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.0.

pretix widget

Plugin Slug:
pretix-widget

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
1.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.6.

WP 2FA with Telegram

Plugin Slug:
two-factor-login-telegram

Installations
100+

Vulnerability:
Broken Authentication

Patched in Version:
3.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.1.

WP 2FA with Telegram

Plugin Slug:
two-factor-login-telegram

Installations
100+

Vulnerability:
Bypass Vulnerability

Patched in Version:
3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.

SB Random Posts Widget

Plugin Slug:
sb-random-posts-widget

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Arbitrary Code Execution

Patched in Version:
6.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.3.8.

Bridge Core

Plugin:

Bridge Core

Plugin Slug:
bridge-core

Vulnerability:
Broken Access Control

Patched in Version:
3.3.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.1.

CMSMasters Content Composer

Plugin:

CMSMasters Content Composer

Plugin Slug:
cmsmasters-content-composer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.0.

LatePoint

Plugin:

LatePoint

Plugin Slug:
latepoint

Vulnerability:
Broken Authentication

Patched in Version:
5.0.13

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.13.

LatePoint

Plugin:

LatePoint

Plugin Slug:
latepoint

Vulnerability:
SQL Injection

Patched in Version:
5.0.12

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 5.0.12.

Social Auto Poster

Plugin:

Social Auto Poster

Plugin Slug:
social-auto-poster

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.3.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.16.

WordPress Themes � 0 Patched / 3 Unpatched

disconnected

Theme:

disconnected

Theme Slug:
disconnected

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my flatonica

Theme:

my flatonica

Theme Slug:
my-flatonica

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

my wooden under construction

Theme:

my wooden under construction

Theme Slug:
my-wooden-under-construction

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…