Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � September 11, 2024

In this report, 64 vulnerabilities have been publicly disclosed. Security patches for 45 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 19 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.2 is now available! This minor release includes 15 bug fixes in Core and 11 in the Block Editor, addressing issues like unexpected CSS specificity changes in certain themes.

WordPress Plugins � 45 Patched / 19 Unpatched

Form Vibes � Database Manager for Forms

Plugin Slug:
form-vibes

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin Slug:
flaming-forms

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Pocket Widget

Plugin Slug:
pocket-widget

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Amelia

Plugin:

Amelia

Plugin Slug:
ameliabooking

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:

AZIndex

Plugin Slug:
azindex

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

AZIndex

Plugin:

AZIndex

Plugin Slug:
azindex

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Cab fare calculator

Plugin:

Cab fare calculator

Plugin Slug:
cab-fare-calculator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Geo Controller

Plugin:

Geo Controller

Plugin Slug:
cf-geoplugin

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Chatbot Support AI

Plugin:

Chatbot Support AI

Plugin Slug:
chatbot-support-ai

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Cost Calculator Builder Pro

Plugin:

Cost Calculator Builder Pro

Plugin Slug:
cost-calculator-builder-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

DN Popup

Plugin:

DN Popup

Plugin Slug:
dn-popup

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

Dynamic Featured Image

Plugin Slug:
dynamic-featured-image

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

ForumWP

Plugin:

ForumWP

Plugin Slug:
forumwp

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

RD Station

Plugin:

RD Station

Plugin Slug:
integracao-rd-station

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Preloader Plus – WordPress Loading Screen Plugin

Plugin:

Preloader Plus – WordPress Loading Screen Plugin

Plugin Slug:
preloader-plus

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

S.A.F

Plugin:

S.A.F

Plugin Slug:
security-antivirus-firewall

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Slider comparison image before and after

Plugin:

Slider comparison image before and after

Plugin Slug:
slider-comparison-image-before-and-after

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Viral Signup

Plugin:

Viral Signup

Plugin Slug:
viral-signup

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache

Installations
6,000,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.5.0.1

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.5.0.1.

Ninja Forms � The Contact Form Builder That Grows With You

Plugin Slug:
ninja-forms

Installations
800,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.11

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.11.

PixelYourSite � Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite

Installations
400,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.7.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.7.2.

Customizer Export/Import

Plugin Slug:
customizer-export-import

Installations
200,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
0.9.7.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.9.7.1.

Ivory Search � WordPress Search Plugin

Plugin Slug:
add-search-to-menu

Installations
100,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.7.

Big File Uploads � Increase Maximum File Upload Size

Plugin Slug:
tuxedo-big-file-uploads

Installations
100,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
2.1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.3.

Tutor LMS � eLearning and online course solution

Plugin Slug:
tutor

Installations
90,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.7.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.5.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.6

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.3.6.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.1.7.

Sensei LMS � Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.24.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.24.2.

EventON

Plugin:

EventON

Plugin Slug:
eventon-lite

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.17.

EventPrime � Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.4.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.0.4.4.

Remember Me Controls

Plugin Slug:
remember-me-controls

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.

Newsletters

Plugin Slug:
newsletters-lite

Installations
3,000+

Vulnerability:
Privilege Escalation

Patched in Version:
4.9.9.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.9.9.3.

Affiliate Super Assistent

Plugin Slug:
amazonsimpleadmin

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.4.

Attributes for Blocks

Plugin Slug:
attributes-for-blocks

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.7.

Share This Image

Plugin Slug:
share-this-image

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.03

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.03.

WP-Recall � Registration, Profile, Commerce & More

Plugin Slug:
wp-recall

Installations
2,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
16.26.9

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 16.26.9.

WPCOM Member

Plugin Slug:
wpcom-member

Installations
2,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.5.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.5.3.

Advanced Sermons

Plugin Slug:
advanced-sermons

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.4.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

Revision Manager TMC

Plugin Slug:
revision-manager-tmc

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.20

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.8.20.

Sign-up Sheets

Plugin Slug:
sign-up-sheets

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.13.

WP AdCenter � Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.5.7.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
3.0.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.9.

The Ultimate WordPress Toolkit � WP Extended

Plugin Slug:
wpextended

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.0.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.0.9.

Frontend Dashboard

Plugin Slug:
frontend-dashboard

Installations
900+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.2.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.2.5.

Ninja Forms File Uploads Extension

Plugin:

Ninja Forms File Uploads Extension

Plugin Slug:
ninja-forms-uploads

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.18

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.18.

PixelYourSite PRO

Plugin:

PixelYourSite PRO

Plugin Slug:
pixelyoursite-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
10.4.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 10.4.3.

WordPress Themes � 0 Patched / 0 Unpatched

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…