Quantcast
Channel: SolidWP
Viewing all articles
Browse latest Browse all 97

WordPress Vulnerability Report — October 30, 2024

$
0
0

In this report, 251 vulnerabilities have been publicly disclosed. Security patches for 141 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 110 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7 Beta 3 is available and ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 136 Patched / 109 Unpatched

Countdown, Coming Soon, Maintenance – Countdown & Clock

Plugin Slug:
countdown-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DarkMySite – Advanced Dark Mode Plugin for WordPress

Plugin Slug:
darkmysite
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACL Floating Cart for WooCommerce

Plugin:
ACL Floating Cart for WooCommerce
Plugin Slug:
acl-floating-cart-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Acnoo Flutter API

Plugin:
Acnoo Flutter API
Plugin Slug:
acnoo-flutter-api
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Online Ordering and Delivery Platform

Plugin:
Advanced Online Ordering and Delivery Platform
Plugin Slug:
advanced-online-ordering-and-delivery-platform
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Agile Video Player Lite

Plugin:
Agile Video Player Lite
Plugin Slug:
agile-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
AI Image Generator for Your Content & Featured Images – AI Postpix
Plugin Slug:
ai-postpix
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ajar in5 Embed

Plugin:
Ajar in5 Embed
Plugin Slug:
ajar-productions-in5-embed
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Amilia Store

Plugin:
Amilia Store
Plugin Slug:
amilia-store
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AR For Woocommerce

Plugin:
AR For Woocommerce
Plugin Slug:
ar-for-woocommerce
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

AR For WordPress

Plugin:
AR For WordPress
Plugin Slug:
ar-for-wordpress
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Automatic Translation

Plugin:
Automatic Translation
Plugin Slug:
automatic-translation
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bamazoo Button Generator

Plugin:
Bamazoo Button Generator
Plugin Slug:
bamazoo-button-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Banner Slider

Plugin:
Banner Slider
Plugin Slug:
banner-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Beek Widget Extention

Plugin:
Beek Widget Extention
Plugin Slug:
beek-widget-extention
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bet WC 2018 Russia

Plugin:
Bet WC 2018 Russia
Plugin Slug:
bet-wc-2018-russia
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Greeting Message

Plugin:
BuddyPress Greeting Message
Plugin Slug:
bp-greeting-message
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BP Member Type Manager

Plugin:
BP Member Type Manager
Plugin Slug:
bp-member-type-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bstone Demo Importer

Plugin:
Bstone Demo Importer
Plugin Slug:
bstone-demo-importer
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Change Role

Plugin:
Bulk Change Role
Plugin Slug:
bulk-role-change
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clever Addons for Elementor

Plugin:
Clever Addons for Elementor
Plugin Slug:
cafe-lite
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Campus Explorer Widget

Plugin:
Campus Explorer Widget
Plugin Slug:
campus-explorer-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

chatplusjp

Plugin:
chatplusjp
Plugin Slug:
chatplusjp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Generate

Plugin:
Code Generate
Plugin Slug:
code-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Coub

Plugin:
Coub
Plugin Slug:
coub
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
CWD 3D Image Gallery
Plugin Slug:
cwd-3d-image-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DocumentPress

Plugin:
DocumentPress
Plugin Slug:
documentpress-display-any-document-on-your-site
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DS.DownloadList

Plugin:
DS.DownloadList
Plugin Slug:
dsdownloadlist
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Editor Custom Color Palette

Plugin:
Editor Custom Color Palette
Plugin Slug:
editor-custom-color-palette
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EKC Tournament Manager

Plugin:
EKC Tournament Manager
Plugin Slug:
ekc-tournament-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Exam Matrix

Plugin:
Exam Matrix
Plugin Slug:
exam-matrix
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Extra Privacy for Elementor

Plugin:
Extra Privacy for Elementor
Plugin Slug:
extra-privacy-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Whitelist

Plugin:
Whitelist
Plugin Slug:
fifthsegment-whitelist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Docs RSVP

Plugin:
Google Docs RSVP
Plugin Slug:
google-docs-rsvp-guestlist
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TeploBot – Telegram Bot for WP

Plugin:
TeploBot – Telegram Bot for WP
Plugin Slug:
green-wp-telegram-bot-by-teplitsa
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iBryl Switch User

Plugin:
iBryl Switch User
Plugin Slug:
ibryl-switch-user
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ID-SK Toolkit

Plugin:
ID-SK Toolkit
Plugin Slug:
idsk-toolkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

INK Official

Plugin:
INK Official
Plugin Slug:
ink-official
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Kodex Posts likes

Plugin:
Kodex Posts likes
Plugin Slug:
kodex-posts-likes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

League of Legends Shortcodes

Plugin:
League of Legends Shortcodes
Plugin Slug:
league-of-legends-shortcodes
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

League of Legends Shortcodes

Plugin:
League of Legends Shortcodes
Plugin Slug:
league-of-legends-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

leenk.me

Plugin:
leenk.me
Plugin Slug:
leenkme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MaanStore API

Plugin:
MaanStore API
Plugin Slug:
maanstore-api
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Forms for Mailchimp by Optin Cat

Plugin:
Forms for Mailchimp by Optin Cat
Plugin Slug:
mailchimp-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Local Business Addons For Elementor

Plugin:
Local Business Addons For Elementor
Plugin Slug:
map-addons-for-elementor-waze-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketing Automation by AZEXO

Plugin:
Marketing Automation by AZEXO
Plugin Slug:
marketing-automation-by-azexo
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Marketing Automation by AZEXO

Plugin:
Marketing Automation by AZEXO
Plugin Slug:
marketing-automation-by-azexo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Meetup

Plugin:
Meetup
Plugin Slug:
meetup
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Monitor.chat

Plugin:
Monitor.chat
Plugin Slug:
monitor-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Monkee-Boy Essentials

Plugin:
Monkee-Boy Essentials
Plugin Slug:
monkee-boy-wp-essentials
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Purpose Mail Form

Plugin:
Multi Purpose Mail Form
Plugin Slug:
multi-purpose-mail-form
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Order Notification for Telegram

Plugin:
Order Notification for Telegram
Plugin Slug:
order-notification-for-telegram
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PegaPoll

Plugin:
PegaPoll
Plugin Slug:
pegapoll
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Portfolleo

Plugin:
Portfolleo
Plugin Slug:
portfolleo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PriPre

Plugin:
PriPre
Plugin Slug:
pripre
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realty Workstation

Plugin:
Realty Workstation
Plugin Slug:
realty-workstation
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

3D Work In Progress

Plugin:
3D Work In Progress
Plugin Slug:
renee-work-in-progress
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

3D Work In Progress

Plugin:
3D Work In Progress
Plugin Slug:
renee-work-in-progress
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Risk Warning Bar

Plugin:
Risk Warning Bar
Plugin Slug:
risk-warning-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RSVP ME

Plugin:
RSVP ME
Plugin Slug:
rsvp-me
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Extensions by HocWP Team

Plugin:
Extensions by HocWP Team
Plugin Slug:
sb-core
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ScottCart

Plugin:
ScottCart
Plugin Slug:
scottcart
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin

Plugin:
Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin
Plugin Slug:
scrollbar-by-webxapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shoutcast Icecast HTML5 Radio Player

Plugin:
Shoutcast Icecast HTML5 Radio Player
Plugin Slug:
shoutcast-icecast-html5-radio-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Signup Page

Plugin:
Signup Page
Plugin Slug:
signup-page
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple Custom Admin

Plugin:
Simple Custom Admin
Plugin Slug:
simple-custom-admin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Load More

Plugin:
Simple Load More
Plugin Slug:
simple-load-more
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple News

Plugin:
Simple News
Plugin Slug:
simple-news
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Platform

Plugin:
Affiliate Platform
Plugin Slug:
smdp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GRÜN spendino Spendenformular

Plugin:
GRÜN spendino Spendenformular
Plugin Slug:
spendino
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Stacks Mobile App Builder

Plugin:
Stacks Mobile App Builder
Plugin Slug:
stacks-mobile-app-builder
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SVG Captcha

Plugin:
SVG Captcha
Plugin Slug:
svg-captcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

1-Click Login: Passwordless Authentication

Plugin:
1-Click Login: Passwordless Authentication
Plugin Slug:
swoop-password-free-authentication
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Textboxes

Plugin:
Textboxes
Plugin Slug:
textboxes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themes4WP YouTube External Subtitles

Plugin:
Themes4WP YouTube External Subtitles
Plugin Slug:
themes4wp-youtube-external-subtitles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tida URL Screenshot

Plugin:
Tida URL Screenshot
Plugin Slug:
tida-url-screenshot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Todo Custom Field

Plugin:
Todo Custom Field
Plugin Slug:
todo-custom-field
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Token Login

Plugin:
Token Login
Plugin Slug:
token-login
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Trip Plan

Plugin:
Trip Plan
Plugin Slug:
tripplan
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

uCAT – Next Story

Plugin:
uCAT – Next Story
Plugin Slug:
ucat-next-story
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Uix Shortcodes

Plugin:
Uix Shortcodes
Plugin Slug:
uix-shortcodes
Vulnerability:
Arbitrary Code Execution
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Verbalize WP

Plugin:
Verbalize WP
Plugin Slug:
verbalize-wp
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WatchTowerHQ

Plugin:
WatchTowerHQ
Plugin Slug:
watchtowerhq
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sudan Payment Gateway for WooCommerce

Plugin:
Sudan Payment Gateway for WooCommerce
Plugin Slug:
wc-sudan-payment-gateway
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

10Web Social Post Feed

Plugin:
10Web Social Post Feed
Plugin Slug:
wd-facebook-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Web Bricks Addons for Elementor

Plugin:
Web Bricks Addons for Elementor
Plugin Slug:
webbricks-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Custom Profile Picture

Plugin:
Woocommerce Custom Profile Picture
Plugin Slug:
woo-custom-profile-picture
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:
Woocommerce Product Design
Plugin Slug:
woo-product-design
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:
Woocommerce Product Design
Plugin Slug:
woo-product-design
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Product Design

Plugin:
Woocommerce Product Design
Plugin Slug:
woo-product-design
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Quote Calculator

Plugin:
Woocommerce Quote Calculator
Plugin Slug:
woo-quote-calculator-order
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Maintenance Mode

Plugin:
WooCommerce Maintenance Mode
Plugin Slug:
woocommerce-maintenance-mode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Buttons

Plugin:
Awesome Buttons
Plugin Slug:
wp-awesome-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Awesome Login

Plugin:
WP Awesome Login
Plugin Slug:
wp-awesome-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Image

Plugin:
Category and Taxonomy Image
Plugin Slug:
wp-custom-taxonomy-image
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:
Category and Taxonomy Meta Fields
Plugin Slug:
wp-custom-taxonomy-meta
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:
Category and Taxonomy Meta Fields
Plugin Slug:
wp-custom-taxonomy-meta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category and Taxonomy Meta Fields

Plugin:
Category and Taxonomy Meta Fields
Plugin Slug:
wp-custom-taxonomy-meta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP donimedia carousel
Plugin Slug:
wp-donimedia-carousel
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Plugin Propagator

Plugin:
Plugin Propagator
Plugin Slug:
wp-propagator
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Query Console

Plugin:
WP Query Console
Plugin Slug:
wp-query-console
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Raptor Editor

Plugin:
Raptor Editor
Plugin Slug:
wp-raptor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP show more

Plugin:
WP show more
Plugin Slug:
wp-show-more
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPS Telegram Chat

Plugin:
WPS Telegram Chat
Plugin Slug:
wps-telegram-chat
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPS Telegram Chat

Plugin:
WPS Telegram Chat
Plugin Slug:
wps-telegram-chat
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Plugin:
WPSchoolPress
Plugin Slug:
wpschoolpress
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wux Blog Editor

Plugin:
Wux Blog Editor
Plugin Slug:
wux-blog-editor
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Wux Blog Editor

Plugin:
Wux Blog Editor
Plugin Slug:
wux-blog-editor
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Editorial Assistant by Sovrn

Plugin:
Editorial Assistant by Sovrn
Plugin Slug:
zemanta
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration
Installations
5,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
7.87
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.87.

All-in-One WP Migration and Backup

Plugin Slug:
all-in-one-wp-migration
Installations
5,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.87
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.87.
Plugin Slug:
header-footer-elementor
Installations
2,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.6.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.44.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.0.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
400,000+
Vulnerability:
XML External Entity (XXE)
Patched in Version:
1.3.981
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.981.

Breeze – WordPress Cache Plugin

Plugin Slug:
breeze
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.15.

Breeze – WordPress Cache Plugin

Plugin Slug:
breeze
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.15.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.7.

SEOPress – On-site SEO

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.

SEOPress – On-site SEO

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.

SEOPress – On-site SEO

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.

Astra Widgets

Plugin Slug:
astra-widgets
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.15.

Firelight Lightbox

Plugin Slug:
easy-fancybox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.99.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.99.2.

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.9.

BuddyPress

Plugin:
BuddyPress
Plugin Slug:
buddypress
Installations
100,000+
Vulnerability:
Directory Traversal
Patched in Version:
14.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 14.2.1.

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.

Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Plugin Slug:
custom-twitter-feeds
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor

Plugin Slug:
embedpress
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.36.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.13.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.27.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.6.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Broken Authentication
Patched in Version:
7.6.25
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.6.25.

Call / Contact Button

Plugin Slug:
button-contact-vr
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.10.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.6.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.9.6.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
50,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.
Plugin Slug:
robo-gallery
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.22.

Product Filter by WBW

Plugin Slug:
woo-product-filter
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
2.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.7.0.

Post Grid and Gutenberg Blocks

Plugin Slug:
post-grid
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.94
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.94.

Simple Membership

Plugin Slug:
simple-membership
Installations
40,000+
Vulnerability:
Open Redirection
Patched in Version:
4.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.4.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.14.

Download Plugin

Plugin Slug:
download-plugin
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

File Upload Types by WPForms

Plugin Slug:
file-upload-types
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.

Custom Icons for Elementor

Plugin Slug:
custom-icons-for-elementor
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.3.4.

Futurio Extra

Plugin Slug:
futurio-extra
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.12.

Transients Manager

Plugin Slug:
transients-manager
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social
Installations
20,000+
Vulnerability:
Broken Authentication
Patched in Version:
3.0.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.8.

Backup and Staging by WP Time Capsule

Plugin Slug:
wp-time-capsule
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.22.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.22.22.

YITH WooCommerce Product Add-Ons

Plugin Slug:
yith-woocommerce-product-add-ons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.14.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.14.2.

Contact Form 7 + Telegram

Plugin Slug:
cf7-telegram
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.8.6.

Envo’s Elementor Templates & Widgets for WooCommerce

Plugin Slug:
envo-elementor-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.20.

Mega Elements – Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Multi Step Form

Plugin Slug:
multi-step-form
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.22.

Premium SEO Pack – WP SEO Plugin

Plugin Slug:
premium-seo-pack
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.002
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.002.

Qode Essential Addons

Plugin Slug:
qode-essential-addons
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.4.

Selection Lite

Plugin Slug:
selection-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.

WP Booking System – Booking Calendar

Plugin Slug:
wp-booking-system
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.19.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.19.11.

WooCommerce UPS Shipping – Live Rates and Access Points

Plugin Slug:
flexible-shipping-ups
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Contact Form 7 – Repeatable Fields

Plugin Slug:
cf7-repeatable-fields
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Poll Maker – Versus Polls, Anonymous Polls, Image Polls

Plugin Slug:
poll-maker
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.7.

Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.19.

Cozy Blocks – Page Builder for Gutenberg & Site Editor, Post Blocks, WooCommerce Blocks, Magazine Blocks, WordPress Gutenberg Blocks, Patterns and Templates Library

Plugin Slug:
cozy-addons
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.16.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.4.8.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.4.8.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.12.

Extra Product Options Builder for WooCommerce

Plugin Slug:
additional-product-fields-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.134
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.134.

Ads.txt & App-ads.txt Manager for WordPress

Plugin Slug:
app-ads-txt
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Anchor Episodes Index (Spotify for Podcasters)

Plugin Slug:
anchor-episodes-index
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.11.

Mapster WP Maps

Plugin Slug:
mapster-wp-maps
Installations
2,000+
Vulnerability:
Settings Change
Patched in Version:
1.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.0.

My Wp Brand – Hide menu & Hide Plugin

Plugin Slug:
my-wp-brand
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs)

Plugin Slug:
sky-elementor-addons
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.16.

Advanced Sermons

Plugin Slug:
advanced-sermons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

Church Admin

Plugin Slug:
church-admin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.0.

CodePen Embedded Pens Shortcode

Plugin Slug:
codepen-embedded-pen-shortcode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

HD Quiz – Save Results Light

Plugin Slug:
hd-quiz-save-results-light
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.

Interactive World Map

Plugin Slug:
interactive-world-map
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.8.

myCred Elementor

Plugin Slug:
mycred-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.5.

Posti Shipping

Plugin Slug:
posti-shipping
Installations
1,000+
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
3.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.3.

SEUR Oficial

Plugin Slug:
seur
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.12.

Terms descriptions

Plugin Slug:
terms-descriptions
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.7.

WP Flow Plus

Plugin Slug:
wp-imageflow2
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.4.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.5.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.3.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.3.5.

Accept Stripe Donation and Payments – AidWP

Plugin Slug:
wp-stripe-donation
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
1.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.0.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.4.1.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations
500+
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.4.

Namaste! LMS

Plugin Slug:
namaste-lms
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.3.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.2.

LaTeX2HTML

Plugin:
LaTeX2HTML
Plugin Slug:
latex2html
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.5.

Rover IDX

Plugin:
Rover IDX
Plugin Slug:
rover-idx
Installations
300+
Vulnerability:
Privilege Escalation
Patched in Version:
3.0.0.2906
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.0.2906.

Rover IDX

Plugin:
Rover IDX
Plugin Slug:
rover-idx
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0.2905
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.2905.

WPC Shop as a Customer for WooCommerce

Plugin Slug:
wpc-shop-as-customer
Installations
300+
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

User Toolkit

Plugin Slug:
user-toolkit
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.4.

aDirectory – Directory Listing WordPress Plugin

Plugin Slug:
adirectory
Installations
80+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.1.

Client Power Tools Portal

Plugin Slug:
client-power-tools
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

Image Map Pro

Plugin:
Image Map Pro
Plugin Slug:
image-map-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.21.

Image Map Pro

Plugin:
Image Map Pro
Plugin Slug:
image-map-pro
Vulnerability:
Broken Access Control
Patched in Version:
6.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.21.

ProfilePress Pro

Plugin:
ProfilePress Pro
Plugin Slug:
profilepress-pro
Vulnerability:
Broken Authentication
Patched in Version:
4.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.11.2.

WooCommerce Order Proposal

Plugin:
WooCommerce Order Proposal
Plugin Slug:
woocommerce-order-proposal
Vulnerability:
Broken Authentication
Patched in Version:
2.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.6.

WordPress Themes — 5 Patched / 1 Unpatched

js paper

Theme:
js paper
Theme Slug:
js-paper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Clean Retina

Theme Slug:
clean-retina
Downloads
272,266
Vulnerability:
Local File Inclusion
Patched in Version:
3.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.7.

Mags

Theme:
Mags
Theme Slug:
mags
Downloads
25,904
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.7.

Meta News

Theme Slug:
meta-news
Downloads
17,650
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

NewsCard

Theme:
NewsCard
Theme Slug:
newscard
Downloads
435,520
Vulnerability:
Local File Inclusion
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Nioland

Theme:
Nioland
Theme Slug:
nioland
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — October 30, 2024 appeared first on SolidWP.


Viewing all articles
Browse latest Browse all 97

Trending Articles