Line illustration showing a black application window on a purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � October 30, 2024

In this report, 251 vulnerabilities have been publicly disclosed. Security patches for 141 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 110 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7 Beta 3 is available and ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site.

WordPress Plugins � 136 Patched / 109 Unpatched

DarkMySite � Advanced Dark Mode Plugin for WordPress

Plugin Slug:
darkmysite

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ACL Floating Cart for WooCommerce

Plugin:

ACL Floating Cart for WooCommerce

Plugin Slug:
acl-floating-cart-for-woocommerce

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Acnoo Flutter API

Plugin:

Acnoo Flutter API

Plugin Slug:
acnoo-flutter-api

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Advanced Online Ordering and Delivery Platform

Plugin:

Advanced Online Ordering and Delivery Platform

Plugin Slug:
advanced-online-ordering-and-delivery-platform

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Agile Video Player Lite

Plugin:

Agile Video Player Lite

Plugin Slug:
agile-video-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

AI Image Generator for Your Content & Featured Images � AI Postpix

Plugin Slug:
ai-postpix

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Ajar in5 Embed

Plugin:

Ajar in5 Embed

Plugin Slug:
ajar-productions-in5-embed

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Amilia Store

Plugin:

Amilia Store

Plugin Slug:
amilia-store

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AR For Woocommerce

Plugin:

AR For Woocommerce

Plugin Slug:
ar-for-woocommerce

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

AR For WordPress

Plugin:

AR For WordPress

Plugin Slug:
ar-for-wordpress

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Automatic Translation

Plugin:

Automatic Translation

Plugin Slug:
automatic-translation

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Bamazoo Button Generator

Plugin:

Bamazoo Button Generator

Plugin Slug:
bamazoo-button-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Banner Slider

Plugin:

Banner Slider

Plugin Slug:
banner-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Beek Widget Extention

Plugin:

Beek Widget Extention

Plugin Slug:
beek-widget-extention

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Bet WC 2018 Russia

Plugin:

Bet WC 2018 Russia

Plugin Slug:
bet-wc-2018-russia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Greeting Message

Plugin:

BuddyPress Greeting Message

Plugin Slug:
bp-greeting-message

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

BP Member Type Manager

Plugin:

BP Member Type Manager

Plugin Slug:
bp-member-type-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bstone Demo Importer

Plugin:

Bstone Demo Importer

Plugin Slug:
bstone-demo-importer

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Bulk Change Role

Plugin:

Bulk Change Role

Plugin Slug:
bulk-role-change

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Clever Addons for Elementor

Plugin:

Clever Addons for Elementor

Plugin Slug:
cafe-lite

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Campus Explorer Widget

Plugin:

Campus Explorer Widget

Plugin Slug:
campus-explorer-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

chatplusjp

Plugin:

chatplusjp

Plugin Slug:
chatplusjp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Code Generate

Plugin:

Code Generate

Plugin Slug:
code-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Coub

Plugin:

Coub

Plugin Slug:
coub

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

CWD 3D Image Gallery

Plugin Slug:
cwd-3d-image-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DocumentPress

Plugin:

DocumentPress

Plugin Slug:
documentpress-display-any-document-on-your-site

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

DS.DownloadList

Plugin:

DS.DownloadList

Plugin Slug:
dsdownloadlist

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Editor Custom Color Palette

Plugin:

Editor Custom Color Palette

Plugin Slug:
editor-custom-color-palette

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

EKC Tournament Manager

Plugin:

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Exam Matrix

Plugin:

Exam Matrix

Plugin Slug:
exam-matrix

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Extra Privacy for Elementor

Plugin:

Extra Privacy for Elementor

Plugin Slug:
extra-privacy-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Whitelist

Plugin:

Whitelist

Plugin Slug:
fifthsegment-whitelist

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Google Docs RSVP

Plugin:

Google Docs RSVP

Plugin Slug:
google-docs-rsvp-guestlist

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

TeploBot – Telegram Bot for WP

Plugin:

TeploBot – Telegram Bot for WP

Plugin Slug:
green-wp-telegram-bot-by-teplitsa

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

iBryl Switch User

Plugin:

iBryl Switch User

Plugin Slug:
ibryl-switch-user

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

ID-SK Toolkit

Plugin:

ID-SK Toolkit

Plugin Slug:
idsk-toolkit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

INK Official

Plugin:

INK Official

Plugin Slug:
ink-official

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:

Kodex Posts likes

Plugin Slug:
kodex-posts-likes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

League of Legends Shortcodes

Plugin:

League of Legends Shortcodes

Plugin Slug:
league-of-legends-shortcodes

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

League of Legends Shortcodes

Plugin:

League of Legends Shortcodes

Plugin Slug:
league-of-legends-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

leenk.me

Plugin:

leenk.me

Plugin Slug:
leenkme

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MaanStore API

Plugin:

MaanStore API

Plugin Slug:
maanstore-api

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Forms for Mailchimp by Optin Cat

Plugin:

Forms for Mailchimp by Optin Cat

Plugin Slug:
mailchimp-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Local Business Addons For Elementor

Plugin:

Local Business Addons For Elementor

Plugin Slug:
map-addons-for-elementor-waze-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Marketing Automation by AZEXO

Plugin:

Marketing Automation by AZEXO

Plugin Slug:
marketing-automation-by-azexo

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Marketing Automation by AZEXO

Plugin:

Marketing Automation by AZEXO

Plugin Slug:
marketing-automation-by-azexo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Meetup

Plugin:

Meetup

Plugin Slug:
meetup

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Monitor.chat

Plugin:

Monitor.chat

Plugin Slug:
monitor-chat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Monkee-Boy Essentials

Plugin:

Monkee-Boy Essentials

Plugin Slug:
monkee-boy-wp-essentials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Multi Purpose Mail Form

Plugin:

Multi Purpose Mail Form

Plugin Slug:
multi-purpose-mail-form

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Order Notification for Telegram

Plugin:

Order Notification for Telegram

Plugin Slug:
order-notification-for-telegram

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

PegaPoll

Plugin:

PegaPoll

Plugin Slug:
pegapoll

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Portfolleo

Plugin:

Portfolleo

Plugin Slug:
portfolleo

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

PriPre

Plugin:

PriPre

Plugin Slug:
pripre

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Realty Workstation

Plugin:

Realty Workstation

Plugin Slug:
realty-workstation

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

3D Work In Progress

Plugin:

3D Work In Progress

Plugin Slug:
renee-work-in-progress

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

3D Work In Progress

Plugin:

3D Work In Progress

Plugin Slug:
renee-work-in-progress

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Risk Warning Bar

Plugin:

Risk Warning Bar

Plugin Slug:
risk-warning-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RSVP ME

Plugin:

RSVP ME

Plugin Slug:
rsvp-me

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Extensions by HocWP Team

Plugin:

Extensions by HocWP Team

Plugin Slug:
sb-core

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

ScottCart

Plugin:

ScottCart

Plugin Slug:
scottcart

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Scrollbar by webxapp � Best vertical/horizontal scrollbars plugin

Plugin:

Scrollbar by webxapp � Best vertical/horizontal scrollbars plugin

Plugin Slug:
scrollbar-by-webxapp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Shoutcast Icecast HTML5 Radio Player

Plugin:

Shoutcast Icecast HTML5 Radio Player

Plugin Slug:
shoutcast-icecast-html5-radio-player

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Signup Page

Plugin:

Signup Page

Plugin Slug:
signup-page

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Simple Custom Admin

Plugin:

Simple Custom Admin

Plugin Slug:
simple-custom-admin

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple Load More

Plugin:

Simple Load More

Plugin Slug:
simple-load-more

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Simple News

Plugin:

Simple News

Plugin Slug:
simple-news

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Platform

Plugin:

Affiliate Platform

Plugin Slug:
smdp-affiliate-platform

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

GR�N spendino Spendenformular

Plugin:

GR�N spendino Spendenformular

Plugin Slug:
spendino

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Stacks Mobile App Builder

Plugin:

Stacks Mobile App Builder

Plugin Slug:
stacks-mobile-app-builder

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

SVG Captcha

Plugin:

SVG Captcha

Plugin Slug:
svg-captcha

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

1-Click Login: Passwordless Authentication

Plugin:

1-Click Login: Passwordless Authentication

Plugin Slug:
swoop-password-free-authentication

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Textboxes

Plugin:

Textboxes

Plugin Slug:
textboxes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Themes4WP YouTube External Subtitles

Plugin:

Themes4WP YouTube External Subtitles

Plugin Slug:
themes4wp-youtube-external-subtitles

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Tida URL Screenshot

Plugin:

Tida URL Screenshot

Plugin Slug:
tida-url-screenshot

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Todo Custom Field

Plugin:

Todo Custom Field

Plugin Slug:
todo-custom-field

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Token Login

Plugin:

Token Login

Plugin Slug:
token-login

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Trip Plan

Plugin:

Trip Plan

Plugin Slug:
tripplan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

uCAT � Next Story

Plugin:

uCAT � Next Story

Plugin Slug:
ucat-next-story

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Uix Shortcodes

Plugin:

Uix Shortcodes

Plugin Slug:
uix-shortcodes

Vulnerability:
Arbitrary Code Execution

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Verbalize WP

Plugin:

Verbalize WP

Plugin Slug:
verbalize-wp

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WatchTowerHQ

Plugin:

WatchTowerHQ

Plugin Slug:
watchtowerhq

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Sudan Payment Gateway for WooCommerce

Plugin:

Sudan Payment Gateway for WooCommerce

Plugin Slug:
wc-sudan-payment-gateway

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

10Web Social Post Feed

Plugin:

10Web Social Post Feed

Plugin Slug:
wd-facebook-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Web Bricks Addons for Elementor

Plugin:

Web Bricks Addons for Elementor

Plugin Slug:
webbricks-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Custom Profile Picture

Plugin:

Woocommerce Custom Profile Picture

Plugin Slug:
woo-custom-profile-picture

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:

Woocommerce Product Design

Plugin Slug:
woo-product-design

Vulnerability:
Arbitrary File Deletion

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:

Woocommerce Product Design

Plugin Slug:
woo-product-design

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:

Woocommerce Product Design

Plugin Slug:
woo-product-design

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Quote Calculator

Plugin:

Woocommerce Quote Calculator

Plugin Slug:
woo-quote-calculator-order

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Maintenance Mode

Plugin:

WooCommerce Maintenance Mode

Plugin Slug:
woocommerce-maintenance-mode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Awesome Buttons

Plugin:

Awesome Buttons

Plugin Slug:
wp-awesome-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Awesome Login

Plugin:

WP Awesome Login

Plugin Slug:
wp-awesome-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Image

Plugin:

Category and Taxonomy Image

Plugin Slug:
wp-custom-taxonomy-image

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:

Category and Taxonomy Meta Fields

Plugin Slug:
wp-custom-taxonomy-meta

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:

Category and Taxonomy Meta Fields

Plugin Slug:
wp-custom-taxonomy-meta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:

Category and Taxonomy Meta Fields

Plugin Slug:
wp-custom-taxonomy-meta

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP donimedia carousel

Plugin Slug:
wp-donimedia-carousel

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Plugin Propagator

Plugin:

Plugin Propagator

Plugin Slug:
wp-propagator

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

WP Query Console

Plugin:

WP Query Console

Plugin Slug:
wp-query-console

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Raptor Editor

Plugin:

Raptor Editor

Plugin Slug:
wp-raptor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP show more

Plugin:

WP show more

Plugin Slug:
wp-show-more

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPS Telegram Chat

Plugin:

WPS Telegram Chat

Plugin Slug:
wps-telegram-chat

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPS Telegram Chat

Plugin:

WPS Telegram Chat

Plugin Slug:
wps-telegram-chat

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:

WPSchoolPress

Plugin Slug:
wpschoolpress

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Wux Blog Editor

Plugin:

Wux Blog Editor

Plugin Slug:
wux-blog-editor

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Wux Blog Editor

Plugin:

Wux Blog Editor

Plugin Slug:
wux-blog-editor

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

Editorial Assistant by Sovrn

Plugin:

Editorial Assistant by Sovrn

Plugin Slug:
zemanta

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration

Installations
5,000,000+

Vulnerability:
PHP Object Injection

Patched in Version:
7.87

Severity Score:
High


The vulnerability has been patched, so you should update to version 7.87.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration

Installations
5,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.87

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.87.
Plugin Slug:
header-footer-elementor

Installations
2,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.6.44

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.44.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.0.

WP Shortcodes Plugin � Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 7.3.0.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
400,000+

Vulnerability:
XML External Entity (XXE)

Patched in Version:
1.3.981

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.981.

Breeze � WordPress Cache Plugin

Plugin Slug:
breeze

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.15.

Breeze � WordPress Cache Plugin

Plugin Slug:
breeze

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.15.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.8.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.8.7.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.

SEOPress � On-site SEO

Plugin Slug:
wp-seopress

Installations
300,000+

Vulnerability:
Broken Access Control

Patched in Version:
8.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.2.

Astra Widgets

Plugin Slug:
astra-widgets

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.15.

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.4.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor

Installations
200,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.8.1.

AMP for WP � Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.99.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.0.99.2.

Beaver Builder � WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.3.9.

BuddyPress

Plugin Slug:
buddypress

Installations
100,000+

Vulnerability:
Directory Traversal

Patched in Version:
14.2.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 14.2.1.

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.

Custom Twitter Feeds � A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.4.

EmbedPress � Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

Plugin Slug:
embedpress

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.36

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.36.

Download Monitor

Plugin Slug:
download-monitor

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.13.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.27.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.27.6.

Comments � wpDiscuz

Plugin Slug:
wpdiscuz

Installations
80,000+

Vulnerability:
Broken Authentication

Patched in Version:
7.6.25

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 7.6.25.

Call / Contact Button

Plugin Slug:
button-contact-vr

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7.10

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.7.10.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.9.6.

WP-Members Membership Plugin

Plugin Slug:
wp-members

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.9.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.9.6.

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.1.4.

Qi Blocks

Plugin Slug:
qi-blocks

Installations
50,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.
Plugin Slug:
robo-gallery

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.22.

Product Filter by WBW

Plugin Slug:
woo-product-filter

Installations
50,000+

Vulnerability:
SQL Injection

Patched in Version:
2.7.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.7.0.

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.94

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.94.

Simple Membership

Plugin Slug:
simple-membership

Installations
40,000+

Vulnerability:
Open Redirection

Patched in Version:
4.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.5.4.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.14.

Download Plugin

Plugin Slug:
download-plugin

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.1.

File Upload Types by WPForms

Plugin Slug:
file-upload-types

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.8.

Custom Icons for Elementor

Plugin Slug:
custom-icons-for-elementor

Installations
20,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.3.4.

Futurio Extra

Plugin Slug:
futurio-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.12.

Transients Manager

Plugin Slug:
transients-manager

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.7.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social

Installations
20,000+

Vulnerability:
Broken Authentication

Patched in Version:
3.0.8

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 3.0.8.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule

Installations
20,000+

Vulnerability:
PHP Object Injection

Patched in Version:
1.22.22

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.22.22.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.14.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.14.2.

Contact Form 7 + Telegram

Plugin Slug:
cf7-telegram

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.8.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.8.6.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.20.

Mega Elements � Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

Multi Step Form

Plugin Slug:
multi-step-form

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.22

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.22.

Premium SEO Pack � WP SEO Plugin

Plugin Slug:
premium-seo-pack

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.6.002

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.002.

Qode Essential Addons

Plugin Slug:
qode-essential-addons

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.4.

Selection Lite

Plugin Slug:
selection-lite

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.14

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.14.

WP Booking System � Booking Calendar

Plugin Slug:
wp-booking-system

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.19.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.19.11.

Contact Form 7 � Repeatable Fields

Plugin Slug:
cf7-repeatable-fields

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.2.

Cozy Blocks � Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.19.

Cozy Blocks � Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.16.

Survey Maker

Plugin Slug:
survey-maker

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.3.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.1.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.4.8.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.0.4.8.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.12

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.12.

Extra Product Options Builder for WooCommerce

Plugin Slug:
additional-product-fields-for-woocommerce

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.134

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.134.

Ads.txt & App-ads.txt Manager for WordPress

Plugin Slug:
app-ads-txt

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.8.

Anchor Episodes Index (Spotify for Podcasters)

Plugin Slug:
anchor-episodes-index

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.11

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.11.

Mapster WP Maps

Plugin Slug:
mapster-wp-maps

Installations
2,000+

Vulnerability:
Settings Change

Patched in Version:
1.6.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.0.

My Wp Brand � Hide menu & Hide Plugin

Plugin Slug:
my-wp-brand

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.3.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs)

Plugin Slug:
sky-elementor-addons

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.16

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.16.

Advanced Sermons

Plugin Slug:
advanced-sermons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.5.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.4.3.

Church Admin

Plugin Slug:
church-admin

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.0.0.

CodePen Embedded Pens Shortcode

Plugin Slug:
codepen-embedded-pen-shortcode

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.3.

HD Quiz � Save Results Light

Plugin Slug:
hd-quiz-save-results-light

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.6.

Interactive World Map

Plugin Slug:
interactive-world-map

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.8.

myCred Elementor

Plugin Slug:
mycred-for-elementor

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.2.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.7.5.

Posti Shipping

Plugin Slug:
posti-shipping

Installations
1,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
3.10.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.10.3.

SEUR Oficial

Plugin Slug:
seur

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.12

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.12.

Terms descriptions

Plugin Slug:
terms-descriptions

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.7.

WP Flow Plus

Plugin Slug:
wp-imageflow2

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.2.4.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.3.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.5.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.3.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.5.

Accept Stripe Donation and Payments � AidWP

Plugin Slug:
wp-stripe-donation

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.2.4.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime

Installations
500+

Vulnerability:
SQL Injection

Patched in Version:
1.1.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.1.0.

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.4.1.

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.6.3.

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
PHP Object Injection

Patched in Version:
2.6.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.4.

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.6.3.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.2.

LaTeX2HTML

Plugin Slug:
latex2html

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.5.5.

Rover IDX

Plugin Slug:
rover-idx

Installations
300+

Vulnerability:
Privilege Escalation

Patched in Version:
3.0.0.2906

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.0.2906.

Rover IDX

Plugin Slug:
rover-idx

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.0.2905

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.0.2905.

WPC Shop as a Customer for WooCommerce

Plugin Slug:
wpc-shop-as-customer

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
1.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.7.

User Toolkit

Plugin Slug:
user-toolkit

Installations
100+

Vulnerability:
Privilege Escalation

Patched in Version:
1.2.4

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.2.4.

aDirectory � Directory Listing WordPress Plugin

Plugin Slug:
adirectory

Installations
80+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.3.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.3.1.

Client Power Tools Portal

Plugin Slug:
client-power-tools

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.1

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.9.1.

Image Map Pro

Plugin:

Image Map Pro

Plugin Slug:
image-map-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.21.

Image Map Pro

Plugin:

Image Map Pro

Plugin Slug:
image-map-pro

Vulnerability:
Broken Access Control

Patched in Version:
6.0.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 6.0.21.

ProfilePress Pro

Plugin:

ProfilePress Pro

Plugin Slug:
profilepress-pro

Vulnerability:
Broken Authentication

Patched in Version:
4.11.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.11.2.

WooCommerce Order Proposal

Plugin:

WooCommerce Order Proposal

Plugin Slug:
woocommerce-order-proposal

Vulnerability:
Broken Authentication

Patched in Version:
2.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.6.

WordPress Themes � 5 Patched / 1 Unpatched

js paper

Theme:

js paper

Theme Slug:
js-paper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should switch themes.

Clean Retina

Theme Slug:
clean-retina

Downloads
272,266

Vulnerability:
Local File Inclusion

Patched in Version:
3.0.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.7.

Mags

Theme:

Mags

Theme Slug:
mags

Downloads
25,904

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.7.

Meta News

Theme Slug:
meta-news

Downloads
17,650

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.8.

NewsCard

Theme Slug:
newscard

Downloads
435,520

Vulnerability:
Local File Inclusion

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

Nioland

Theme:

Nioland

Theme Slug:
nioland

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.7.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…