Line illustration showing a black application window on a dark red gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � September 25, 2024

In this report, 72 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 24 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.6.2 is available! This minor release includes 15 bug fixes in Core and 11 in the Block Editor, addressing issues like unexpected CSS specificity changes in certain themes.

WordPress Plugins � 46 Patched / 20 Unpatched

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WCFM Marketplace � Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

IMPress for IDX Broker

Plugin Slug:
idx-broker-platinum

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woo-product-carousel-slider-and-grid-ultimate

Installations
9,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Spice Starter Sites

Plugin Slug:
spice-starter-sites

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks � Unlimited blocks For Gutenberg

Plugin Slug:
unlimited-blocks

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Team Showcase

Plugin Slug:
team

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Accordion Image Menu

Plugin:

Accordion Image Menu

Plugin Slug:
accordion-image-menu

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Thanh To�n Qu�t M� QR Code T? ??ng

Plugin:

Thanh To�n Qu�t M� QR Code T? ??ng

Plugin Slug:
bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:

Kodex Posts likes

Plugin Slug:
kodex-posts-likes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Limit Login Attempts Plus

Plugin:

Limit Login Attempts Plus

Plugin Slug:
limit-login-attempts-plus

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Logo Manager For Enamad

Plugin:

Logo Manager For Enamad

Plugin Slug:
logo-manager-for-enamad

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Posts reminder

Plugin:

Posts reminder

Plugin Slug:
posts-reminder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Multiple Free Gift

Plugin:

WooCommerce Multiple Free Gift

Plugin Slug:
woocommerce-multiple-free-gift

Vulnerability:
Bypass Vulnerability

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

WP Category Dropdown

Plugin:

WP Category Dropdown

Plugin Slug:
wp-category-dropdown

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Custom Fields Search

Plugin Slug:
wp-custom-fields-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Easy Gallery

Plugin Slug:
wp-easy-gallery

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin:

WP Easy Gallery

Plugin Slug:
wp-easy-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

MC4WP: Mailchimp for WordPress

Plugin Slug:
mailchimp-for-wp

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.17

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.17.

W3 Total Cache

Plugin Slug:
w3-total-cache

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.7.6

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.7.6.

Backuply � Backup, Restore, Migrate and Clone

Plugin Slug:
backuply

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.5.

WooCommerce Multilingual & Multicurrency with WPML

Plugin Slug:
woocommerce-multilingual

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.3.7.

FOX � Currency Switcher Professional for WooCommerce

Plugin Slug:
woocommerce-currency-switcher

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.2.

Pixel Cat � Conversion Pixel Manager

Plugin Slug:
facebook-conversion-pixel

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.0.6.

Koko Analytics

Plugin Slug:
koko-analytics

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.13

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.13.

Greenshift � animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
9.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 9.4.

Themify � WooCommerce Product Filter

Plugin Slug:
themify-wc-product-filter

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.2.

WP Hardening (discontinued)

Plugin Slug:
wp-security-hardening

Installations
20,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.2.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.7.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.21

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.6.21.

BA Book Everything

Plugin Slug:
ba-book-everything

Installations
10,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.6.21.

Gum Elementor Addon

Plugin Slug:
gum-elementor-addon

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.8.

Maintenance Redirect

Plugin Slug:
jf3-maintenance-mode

Installations
10,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
2.1.0

Severity Score:
Low


The vulnerability has been patched, so you should update to version 2.1.0.

WP Booking System � Booking Calendar

Plugin Slug:
wp-booking-system

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.19.9.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.2.

Affiliate Program Suite � SliceWP Affiliates

Plugin Slug:
slicewp

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.21

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.21.

Seriously Simple Stats

Plugin Slug:
seriously-simple-stats

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.0.

Garden Gnome Package

Plugin Slug:
garden-gnome-package

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.0.

Geo Mashup

Plugin Slug:
geo-mashup

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.13.13.

Waitlist Woocommerce ( Back in stock notifier )

Plugin Slug:
waitlist-woocommerce

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.7.6.

PropertyHive

Plugin Slug:
propertyhive

Installations
3,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.0.20.

Simple Spoiler

Plugin Slug:
simple-spoiler

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.16.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 0.16.8.

IdeaPush

Plugin:

IdeaPush

Plugin Slug:
ideapush

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.69

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 8.69.

Login with phone number

Plugin Slug:
login-with-phone-number

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.7.50

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.7.50.

Share This Image

Plugin Slug:
share-this-image

Installations
1,000+

Vulnerability:
Open Redirection

Patched in Version:
2.04

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.04.

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.65

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 4.9.65.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.3.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.3.3.4.

MDTF � Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.3.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.3.4.

XT Ajax Add To Cart for WooCommerce

Plugin Slug:
xt-woo-ajax-add-to-cart

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.1.3.

Webo-facto

Plugin Slug:
webo-facto-connector

Installations
900+

Vulnerability:
Privilege Escalation

Patched in Version:
1.41

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.41.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.7.0.

Houzez Login Register

Plugin:

Houzez Login Register

Plugin Slug:
houzez-login-register

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.0.

WooEvents

Plugin:

WooEvents

Plugin Slug:
woo-events

Vulnerability:
Arbitrary File Deletion

Patched in Version:
4.1.3

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 4.1.3.

WordPress Themes � 2 Patched / 4 Unpatched

Blogvi

Theme:

Blogvi

Theme Slug:
blogvi

Downloads
25,426

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Roseta

Theme:

Roseta

Theme Slug:
roseta

Downloads
97,031

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Septera

Theme:

Septera

Theme Slug:
septera

Downloads
126,076

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Verbosa

Theme:

Verbosa

Theme Slug:
verbosa

Downloads
108,792

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should switch themes.

Bricks Builder

Theme:

Bricks Builder

Theme Slug:
bricks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.10.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.2.

Houzez

Theme:

Houzez

Theme Slug:
houzez

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.0

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.3.0.

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…