WordPress Vulnerability Report

WordPress Vulnerability Report – August 2, 2023

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates! Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet.

Dan Knauss

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT AUG 8TH @ 1:00 P.M. (CT)

New research from Snicco, WeWatchYourWebsite, Automattic-backed GridPane, and PatchStack claims WordPress security plugins with malware scanners are fundamentally flawed. And they’re being actively defeated by malware in the wild right now!

In this webinar, StellarWP technical writer Dan Knauss will explain the problem with malware scanners and the WordPress security best practices you need to implement to keep your sites truly safe.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations:
800,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.3.

Duplicate Post

Plugin Slug:
copy-delete-posts
Installations:
200,000+
Vulnerability:
Missing Authorization on handle_installation function
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Duplicate Post

Plugin Slug:
copy-delete-posts
Installations:
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.2.

Social Media Share Buttons & Social Sharing Icons

Plugin Slug:
ultimate-social-media-icons
Installations:
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.2.

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations:
100,000+
Vulnerability:
SQL Injection
Patched in Version:
2.7.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.4.

Clone

Plugin:
Clone
Plugin Slug:
wp-clone-by-wp-academy
Installations:
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.8.

Clone

Plugin:
Clone
Plugin Slug:
wp-clone-by-wp-academy
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.8.

Change WP Admin

Plugin Slug:
change-wp-admin-login
Installations:
90,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Backup Migration

Plugin Slug:
backup-backup
Installations:
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Backup Migration

Plugin Slug:
backup-backup
Installations:
80,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Simple Author Box

Plugin Slug:
simple-author-box
Installations:
60,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.52.

Custom Field Template

Plugin Slug:
custom-field-template
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.0.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget
Installations:
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Enhanced Text Widget

Plugin Slug:
enhanced-text-widget
Installations:
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.
Plugin Slug:
navz-photo-gallery
Installations:
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Redirect Redirection

Plugin Slug:
redirect-redirection
Installations:
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Redirect Redirection

Plugin Slug:
redirect-redirection
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Media from FTP

Plugin Slug:
media-from-ftp
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
11.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.16.

PHP Everywhere

Plugin Slug:
php-everywhere
Installations:
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Plugin Slug:
php-everywhere
Installations:
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Plugin Slug:
php-everywhere
Installations:
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api
Installations:
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.2.2.

SSL Mixed Content Fix

Plugin Slug:
http-https-remover
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

SSL Mixed Content Fix

Plugin Slug:
http-https-remover
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Pop-up

Plugin:
Pop-up
Plugin Slug:
pop-up-pop-up
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Pop-up

Plugin:
Pop-up
Plugin Slug:
pop-up-pop-up
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Ultimate Posts Widget

Plugin Slug:
ultimate-posts-widget
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Ultimate Posts Widget

Plugin Slug:
ultimate-posts-widget
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

User Activity Log

Plugin Slug:
user-activity-log
Installations:
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.5.

Simple Blog Card

Plugin Slug:
simple-blog-card
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.31.

Discussion Board

Plugin Slug:
wp-discussion-board
Installations:
3,000+
Vulnerability:
Content Injection
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

RSS Redirect & Feedburner Alternative

Plugin Slug:
feedburner-alternative-and-rss-redirect
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.

RSS Redirect & Feedburner Alternative

Plugin Slug:
feedburner-alternative-and-rss-redirect
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.

CodeBard's Patron Button and Widgets for Patreon

Plugin Slug:
patron-button-and-widgets-by-codebard
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.9.

QR code MeCard/vCard generator

Plugin Slug:
wp-qrcode-me-v-card
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Church Admin

Plugin Slug:
church-admin
Installations:
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

WordPress Job Board and Recruitment Plugin – JobWP

Plugin Slug:
jobwp
Installations:
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.

Local Development

Plugin Slug:
local-development
Installations:
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.

CartFlows Pro

Plugin Slug:
cartflows-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.11.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.13.

Shop as a Customer for WooCommerce

Plugin Slug:
shop-as-a-customer-for-woocommerce
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.4.

Shop as a Customer for WooCommerce

Plugin Slug:
shop-as-a-customer-for-woocommerce
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus
Vulnerability:
Broken Access Control
Patched in Version:
3.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.8.

Social Share Icons & Social Share Buttons

Plugin Slug:
ultimate-social-media-plus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.8.

Schema Pro

Plugin:
Schema Pro
Plugin Slug:
wp-schema-pro
Vulnerability:
Broken Access Control
Patched in Version:
2.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.

WP Brutal AI

Plugin Slug:
wpbrutalai
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.06.

WPML String Translation

Plugin Slug:
wpml-string-translation
Vulnerability:
SQL Injection
Patched in Version:
3.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.6.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Optimize Database after Deleting Revisions

Plugin Slug:
rvg-optimize-database
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booster for Woocommerce

Plugin Slug:
woocommerce-jetpack
Installations:
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPS Limit Login

Plugin Slug:
wps-limit-login
Installations:
60,000+
Vulnerability:
Race Condition
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Plugin Slug:
banner-management-for-woocommerce
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Plugin Slug:
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Plugin Slug:
multiparcels-shipping-for-woocommerce
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Plugin Slug:
wp-quick-post-duplicator
Installations:
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Plugin Slug:
mobile-address-bar-changer
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Plugin Slug:
remove-duplicate-posts
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

APIExperts Square for WooCommerce

Plugin Slug:
woosquare
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility By accessiBe

Plugin Slug:
accessibe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web Accessibility By accessiBe

Plugin Slug:
accessibe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

AGP Font Awesome Collection

Plugin Slug:
agp-font-awesome-collection
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Booster Elementor Addons

Plugin Slug:
booster-for-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

Plugin Slug:
clone-menu
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Map Shortcode

Plugin Slug:
google-map-shortcode
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

HTTP Auth

Plugin:
HTTP Auth
Plugin Slug:
http-auth
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Instant CSS

Plugin Slug:
instant-css
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

LWS Affiliation

Plugin Slug:
lws-affiliation
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meks Smart Social Widget

Plugin Slug:
meks-smart-social-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
perelink
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

Plugin Slug:
quasar-form
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Saphali Woocommerce Lite

Plugin Slug:
saphali-woocommerce-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Googlebot Visit

Plugin Slug:
simple-googlebot-visit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Wp Sitemap

Plugin Slug:
simple-wp-sitemap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
slider-images
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

Plugin Slug:
smart-donations
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Taboola

Plugin:
Taboola
Plugin Slug:
taboola
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

Plugin Slug:
td-composer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Update Theme and Plugins from Zip File

Plugin Slug:
update-theme-and-plugins-from-zip-file
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

Plugin Slug:
woo-confirmation-email
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Database Administrator

Plugin Slug:
wp-database-admin
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin Slug:
wp-tell-a-friend-popup-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Plugin Slug:
wp-tell-a-friend-popup-form
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

nsc

Theme:
nsc
Theme Slug:
nsc
Vulnerability:
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Winters

Theme:
winters
Theme Slug:
winters
Vulnerability:
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Your Journey

Theme Slug:
yourjourney
Vulnerability:
Prototype Pollution to Reflected Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security