Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!
Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
WordPress Core News
“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.
Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.
WordPress Core Vulnerabilities — Patched
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.
InfiniteWP Client

- Plugin
- InfiniteWP Client
- Plugin Slug
- iwp-client
- Installations
- 300,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 1.12.1
- Severity Score
- High
- CVE
- 2023-2916
Advanced File Manager

- Plugin
- Advanced File Manager
- Plugin Slug
- file-manager-advanced
- Installations
- 100,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 5.1.1
- Severity Score
- Medium
- CVE
- 2023-3814
Blog2Social

- Plugin Slug
- blog2social
- Installations
- 70,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 7.2.1
- Severity Score
- High
- CVE
- 2023-40554
wpDataTables

- Plugin Slug
- wpdatatables
- Installations
- 70,000+
- Vulnerability
- PHP Object Injection
- Patched in Version
- 2.1.66
- Severity Score
- Medium
WP-PostRatings

- Plugin
- WP-PostRatings
- Plugin Slug
- wp-postratings
- Installations
- 50,000+
- Vulnerability
- Bypass Vulnerability
- Patched in Version
- 1.91.1
- Severity Score
- Medium
- CVE
- 2023-40332
Cost Calculator Builder

- Plugin
- Cost Calculator Builder
- Plugin Slug
- cost-calculator-builder
- Installations
- 30,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.1.43
- Severity Score
- Medium
- CVE
- 2023-40011
Countdown Timer Ultimate

- Plugin
- Countdown Timer Ultimate
- Plugin Slug
- countdown-timer-ultimate
- Installations
- 20,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.4.1
- Severity Score
- Medium
- CVE
- 2023-40200
Media from FTP

- Plugin
- Media from FTP
- Plugin Slug
- media-from-ftp
- Installations
- 20,000+
- Vulnerability
- Settings Change
- Patched in Version
- 11.17
- Severity Score
- Low
- CVE
- 2023-4019
User Submitted Posts

- Plugin Slug
- user-submitted-posts
- Installations
- 20,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 20230811
- Severity Score
- High
- CVE
- 2023-4308
Album and Image Gallery plus Lightbox

- Plugin Slug
- album-and-image-gallery-plus-lightbox
- Installations
- 10,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.7.1
- Severity Score
- Medium
- CVE
- 2023-40200
Cookies and Content Security Policy

- Plugin Slug
- cookies-and-content-security-policy
- Installations
- 10,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 2.16
- Severity Score
- Medium
- CVE
- 2023-40662
Stripe Payment Plugin for WooCommerce

- Plugin Slug
- payment-gateway-stripe-and-woocommerce-integration
- Installations
- 10,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.8.0
- Severity Score
- Medium
- CVE
- 2023-4040
Smart SEO Tool

- Plugin
- Smart SEO Tool – SEO
- Plugin Slug
- smart-seo-tool
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 4.0.2
- Severity Score
- Medium
Orders Tracking for WooCommerce

- Plugin Slug
- woo-orders-tracking
- Installations
- 10,000+
- Vulnerability
- Directory Traversal
- Patched in Version
- 1.2.6
- Severity Score
- Low
- CVE
- 2023-4216
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

- Plugin Slug
- wp-testimonial-with-widget
- Installations
- 10,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.3.1
- Severity Score
- Medium
- CVE
- 2023-40200
WP VR

- Plugin Slug
- wpvr
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 8.3.5
- Severity Score
- High
- CVE
- 2023-40663
Blog Designer – Post and Widget

- Plugin Slug
- blog-designer-for-post-and-widget
- Installations
- 8,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.5.2
- Severity Score
- Medium
- CVE
- 2023-40200
WP Remote Users Sync

- Plugin
- WP Remote Users Sync
- Plugin Slug
- wp-remote-users-sync
- Installations
- 8,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.2.12
- Severity Score
- Medium
- CVE
- 2023-4374
WP Remote Users Sync

- Plugin
- WP Remote Users Sync
- Plugin Slug
- wp-remote-users-sync
- Installations
- 8,000+
- Vulnerability
- Server Side Request Forgery (SSRF)
- Patched in Version
- 1.2.13
- Severity Score
- High
- CVE
- 2023-3958
Meta Slider and Carousel with Lightbox

- Plugin Slug
- meta-slider-and-carousel-with-lightbox
- Installations
- 7,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.8.3
- Severity Score
- Medium
- CVE
- 2023-40200
Plausible Analytics

- Plugin
- Plausible Analytics
- Plugin Slug
- plausible-analytics
- Installations
- 7,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.3.4
- Severity Score
- Medium
- CVE
- 2023-40553
Post grid and filter ultimate

- Plugin Slug
- post-grid-and-filter-ultimate
- Installations
- 7,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.5.3
- Severity Score
- Medium
- CVE
- 2023-40200
Timeline and History slider

- Plugin Slug
- timeline-and-history-slider
- Installations
- 6,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.1.1
- Severity Score
- Medium
- CVE
- 2023-40200
JS Help Desk – Best Help Desk & Support Plugin

- Plugin Slug
- js-support-ticket
- Installations
- 5,000+
- Vulnerability
- Arbitrary File Upload
- Patched in Version
- 2.7.8
- Severity Score
- Critical
- CVE
- 2023-25444
Team Slider and Team Grid Showcase plus Team Carousel

- Plugin Slug
- wp-team-showcase-and-slider
- Installations
- 4,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.6.1
- Severity Score
- Medium
- CVE
- 2023-40200
Trending/Popular Post Slider and Widget

- Plugin Slug
- wp-trending-post-slider-and-widget
- Installations
- 4,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.6.1
- Severity Score
- Medium
- CVE
- 2023-40200
Video Gallery & Management

- Plugin Slug
- youtube-showcase
- Installations
- 4,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.3.6
- Severity Score
- Medium
- CVE
- 2023-40558
Accordion and Accordion Slider

- Plugin Slug
- accordion-and-accordion-slider
- Installations
- 3,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.2.5
- Severity Score
- Medium
- CVE
- 2023-40200
DoLogin Security
- Plugin
- DoLogin Security
- Plugin Slug
- dologin
- Installations
- 3,000+
- Vulnerability
- Bypass Vulnerability
- Patched in Version
- 3.7
- Severity Score
- Medium
Video gallery and Player

- Plugin
- Video gallery and Player
- Plugin Slug
- html5-videogallery-plus-player
- Installations
- 3,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.6.6
- Severity Score
- Medium
- CVE
- 2023-40200
WooCommerce PDF Invoice Builder

- Plugin Slug
- woo-pdf-invoice-builder
- Installations
- 3,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.2.92
- Severity Score
- Medium
- CVE
- 2023-4245
WooCommerce PDF Invoice Builder

- Plugin Slug
- woo-pdf-invoice-builder
- Installations
- 3,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.2.91
- Severity Score
- Medium
- CVE
- 2023-4160
WooCommerce PDF Invoice Builder

- Plugin Slug
- woo-pdf-invoice-builder
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.91
- Severity Score
- Medium
- CVE
- 2023-4161
Accordion Slider

- Plugin
- Accordion Slider
- Plugin Slug
- accordion-slider
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.9.7
- Severity Score
- Medium
- CVE
- 2023-40331
Doofinder for WooCommerce
- Plugin Slug
- doofinder-for-woocommerce
- Installations
- 2,000+
- Vulnerability
- Open Redirection
- Patched in Version
- 2.0.0
- Severity Score
- Medium
- CVE
- 2023-40602
Portfolio and Projects

- Plugin
- Portfolio and Projects
- Plugin Slug
- portfolio-and-projects
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.3.8
- Severity Score
- Medium
- CVE
- 2023-40200
Post Ticker Ultimate

- Plugin
- Post Ticker Ultimate
- Plugin Slug
- ticker-ultimate
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.5.6
- Severity Score
- Medium
- CVE
- 2023-40200
CLUEVO LMS

- Plugin Slug
- cluevo-lms
- Installations
- 700+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.11.0
- Severity Score
- Medium
- CVE
- 2023-40607
Serial Codes Generator and Validator with WooCommerce Support

- Plugin Slug
- serial-codes-generator-and-validator
- Installations
- 600+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.4.15
- Severity Score
- Medium
Event Tickets with Ticket Scanner

- Plugin Slug
- event-tickets-with-ticket-scanner
- Installations
- 500+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.5.5
- Severity Score
- Medium
Products Quick View for WooCommerce

- Plugin Slug
- woocommerce-products-quick-view
- Installations
- 100+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.3.0
- Severity Score
- Medium
123.chat

- Plugin Slug
- 123-chat-videochat
- Installations
- 40+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.3.1
- Severity Score
- Medium
- CVE
- 2023-4298
Paid Memberships Pro CCBill Gateway
- Plugin
- Paid Memberships Pro CCBill Gateway
- Plugin Slug
- pmpro-ccbill
- Vulnerability
- Broken Access Control
- Patched in Version
- 0.4
- Severity Score
- High
- CVE
- 2023-40608
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Simple URLs

- Plugin Slug
- simple-urls
- Installations
- 5,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40678
Simple URLs

- Plugin Slug
- simple-urls
- Installations
- 5,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40674
Simple URLs

- Plugin Slug
- simple-urls
- Installations
- 5,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40667
Enhanced Ecommerce Google Analytics for WooCommerce

- Plugin Slug
- woo-ecommerce-tracking-for-google-and-facebook
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40561
GD Security Headers

- Plugin
- GD Security Headers
- Plugin Slug
- gd-security-headers
- Installations
- 2,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40330
LINE Notify
- Plugin
- WP LINE Notify
- Plugin Slug
- wp-line-notify
- Installations
- 2,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-30497
fitness calculators plugin

- Plugin Slug
- fitness-calculators
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40552
Kanban Boards for WordPress

- Plugin Slug
- kanban
- Installations
- 1,000+
- Vulnerability
- Arbitrary Code Execution
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2023-40606
Save as PDF plugin by Pdfcrowd
- Plugin Slug
- save-as-pdf-by-pdfcrowd
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40668
Schedule Posts Calendar

- Plugin
- Schedule Posts Calendar
- Plugin Slug
- schedule-posts-calendar
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40556
Schedule Posts Calendar

- Plugin
- Schedule Posts Calendar
- Plugin Slug
- schedule-posts-calendar
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40560
Tabs & Accordion

- Plugin
- Tabs & Accordion
- Plugin Slug
- tabs
- Installations
- 1,000+
- Vulnerability
- Content Injection
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40557
Dynamic Pricing and Discount Rules for WooCommerce

- Plugin Slug
- woo-conditional-discount-rules-for-checkout
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40559
rsvpmaker

- Plugin
- RSVPMaker
- Plugin Slug
- rsvpmaker
- Installations
- 400+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-27616
rsvpmaker

- Plugin
- RSVPMaker
- Plugin Slug
- rsvpmaker
- Installations
- 400+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-27617
Save as Image plugin by Pdfcrowd
- Plugin Slug
- save-as-image-by-pdfcrowd
- Installations
- 50+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40665
Typing Effect
- Plugin
- Typing Effect
- Plugin Slug
- animated-typing-effect
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40605
Password Reset with Code for WordPress REST API
- Plugin
- Password Reset with Code for WordPress REST API
- Plugin Slug
- bdvs-password-reset
- Vulnerability
- Broken Authentication
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2023-35039
BigBlueButton
- Plugin
- BigBlueButton
- Plugin Slug
- bigbluebutton
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
Carrot
- Plugin
- Carrot
- Plugin Slug
- carrrot
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40328
Cartpauj Register Captcha
- Plugin
- Cartpauj Register Captcha
- Plugin Slug
- cartpauj-register-captcha
- Vulnerability
- Bypass Vulnerability
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40673
Contact form 7 Custom validation
- Plugin
- Contact form 7 Custom validation
- Plugin Slug
- cf7-field-validation
- Vulnerability
- SQL Injection
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40609
Cleverwise Daily Quotes
- Plugin
- Cleverwise Daily Quotes
- Plugin Slug
- cleverwise-daily-quotes
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40335
Cookies by JM
- Plugin
- Cookies by JM
- Plugin Slug
- cookies-by-jm
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40604
CT Commerce
- Plugin
- CT Commerce
- Plugin Slug
- ct-commerce
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40007
Custom Admin Login Page | WPZest
- Plugin
- Custom Admin Login Page | WPZest
- Plugin Slug
- custom-admin-login-styler-wpzest
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40329
DX-auto-save-images
- Plugin
- DX-auto-save-images
- Plugin Slug
- dx-auto-save-images
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40671
Mortgage Calculator Estatik
- Plugin
- Mortgage Calculator Estatik
- Plugin Slug
- estatik-mortgage-calculator
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40601
Make Paths Relative
- Plugin
- Make Paths Relative
- Plugin Slug
- make-paths-relative
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-27433
Simple Org Chart
- Plugin
- Simple Org Chart
- Plugin Slug
- simple-org-chart
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40603
Simple Org Chart
- Plugin
- Simple Org Chart
- Plugin Slug
- simple-org-chart
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28791
Simple Staff List
- Plugin
- Simple Staff List
- Plugin Slug
- simple-staff-list
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28790
Donations Made Easy – Smart Donations
- Plugin
- Donations Made Easy – Smart Donations
- Plugin Slug
- smart-donations
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-40664
Sticky Social Media Icons
- Plugin
- Sticky Social Media Icons
- Plugin Slug
- sticky-social-media-icons
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40672
WebLibrarian
- Plugin
- WebLibrarian
- Plugin Slug
- weblibrarian
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-29441
Putler Connector for WooCommerce
- Plugin
- Putler Connector for WooCommerce
- Plugin Slug
- woocommerce-putler-connector
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40326
Putler Connector for WooCommerce
- Plugin
- Putler Connector for WooCommerce
- Plugin Slug
- woocommerce-putler-connector
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-40327
WordPress Theme Vulnerabilities
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.
Bazaar Lite

- Theme
- Bazaar Lite
- Theme Slug
- bazaar-lite
- Downloads
- 70,170
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.8.6
- Severity Score
- High
- CVE
- 2023-2813
Aapna

College

BunnyPressLite

- Theme
- BunnyPressLite
- Theme Slug
- bunnypresslite
- Downloads
- 17,962
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.1
- Severity Score
- High
- CVE
- 2023-2813
Anfaust

Brain Power

- Theme
- Brain Power
- Theme Slug
- brain-power
- Downloads
- 15,015
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-2813
Cafe Bistro

- Theme
- Cafe Bistro
- Theme Slug
- cafe-bistro
- Downloads
- 10,047
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.1.4
- Severity Score
- High
- CVE
- 2023-2813
Anand

Arendelle

Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.