WordPress Vulnerability Report – January 4, 2023
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website. Each vulnerability will have a severity rating of low, medium, high, or critical.
Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!
WordPress Core News
WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.
There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.
Get SolidWP tips direct in your inbox
Sign up
Get started with confidence — risk free, guaranteed
WordPress Plugin Vulnerabilities
In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
All In One WP Security & Firewall
- Plugin Slug:
- all-in-one-wp-security-and-firewall
- Installations:
- 1,000,000+
- Vulnerability:
- Configuration Leak
- Patched in Version:
- 5.1.3
- Severity Score:
- Medium
- CVE:
- 2022-4346
WP Statistics
- Plugin:
- WP Statistics
- Plugin Slug:
- wp-statistics
- Installations:
- 600,000+
- Vulnerability:
- Authenticated SQLi
- Patched in Version:
- 13.2.9
- Severity Score:
- High
- CVE:
- 2022-4230
Sassy Social Share
- Plugin Slug:
- sassy-social-share
- Installations:
- 100,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 3.3.45
- Severity Score:
- Medium
- CVE:
- 2022-4451
Google Analyticator
- Plugin:
- Analyticator
- Plugin Slug:
- google-analyticator
- Installations:
- 100,000+
- Vulnerability:
- Admin+ PHP Object Injection
- Patched in Version:
- 6.5.6
- Severity Score:
- Low
- CVE:
- 2022-4323
Simple Sitemap
- Plugin Slug:
- simple-sitemap
- Installations:
- 90,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 3.5.8
- Severity Score:
- Medium
- CVE:
- 2022-4472
Booster for WooCommerce
- Plugin:
- Booster for WooCommerce
- Plugin Slug:
- woocommerce-jetpack
- Installations:
- 70,000+
- Vulnerability:
- Multiple CSRF
- Patched in Version:
- 6.0.1
- Severity Score:
- Medium
- CVE:
- 2022-4017
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box
- Plugin Slug:
- easy-facebook-likebox
- Installations:
- 70,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 6.4.0
- Severity Score:
- Medium
- CVE:
- 2022-4474
Collapse-O-Matic
- Plugin:
- Collapse-O-Matic
- Plugin Slug:
- jquery-collapse-o-matic
- Installations:
- 60,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 1.8.3
- Severity Score:
- Medium
- CVE:
- 2022-4475
Search & Filter
- Plugin:
- Search & Filter
- Plugin Slug:
- search-filter
- Installations:
- 50,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 1.2.16
- Severity Score:
- Medium
- CVE:
- 2022-4467
Content Control
- Plugin Slug:
- content-control
- Installations:
- 40,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 1.1.10
- Severity Score:
- Medium
- CVE:
- 2022-4509
Page-list
OneClick Chat to Order
- Plugin:
- OneClick Chat to Order
- Plugin Slug:
- oneclick-whatsapp-order
- Installations:
- 30,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.0.4.2
- Severity Score:
- Medium
- CVE:
- 2022-4760
Sitemap
Compact WP Audio Player
- Plugin:
- Compact WP Audio Player
- Plugin Slug:
- compact-wp-audio-player
- Installations:
- 30,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 1.9.8
- Severity Score:
- Medium
- CVE:
- 2022-4542
WP Popups
- Plugin Slug:
- wp-popups-lite
- Installations:
- 30,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 2.1.4.8
- Severity Score:
- Medium
- CVE:
- 2022-4716
Top 10
- Plugin Slug:
- top-10
- Installations:
- 30,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2022-4570
Login Logout Menu
- Plugin:
- Login Logout Menu
- Plugin Slug:
- login-logout-menu
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 1.4.0
- Severity Score:
- Medium
- CVE:
- 2022-4625
ShiftNav – Responsive Mobile Menu
- Plugin Slug:
- shiftnav-responsive-mobile-menu
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 1.7.2
- Severity Score:
- Medium
- CVE:
- 2022-4627
Product Slider for WooCommerce
- Plugin Slug:
- woo-product-slider
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 2.6.4
- Severity Score:
- Medium
- CVE:
- 2022-4629
Mongoose Page Plugin
- Plugin:
- Mongoose Page Plugin
- Plugin Slug:
- facebook-page-feed-graph-api
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.9.0
- Severity Score:
- Medium
- CVE:
- 2022-4675
Rate my Post – WP Rating System
- Plugin Slug:
- rate-my-post
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 3.3.9
- Severity Score:
- Medium
- CVE:
- 2022-4673
WordPress Simple Shopping Cart
- Plugin Slug:
- wordpress-simple-paypal-shopping-cart
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 4.6.2
- Severity Score:
- Medium
- CVE:
- 2022-4672
Structured Content
- Plugin Slug:
- structured-content
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2022-4715
GS Logo Slider
- Plugin Slug:
- gs-logo-slider
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 3.3.8
- Severity Score:
- Medium
- CVE:
- 2022-4624
Video Conferencing with Zoom
- Plugin:
- Video Conferencing with Zoom
- Plugin Slug:
- video-conferencing-with-zoom-api
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- 4.0.10
- Severity Score:
- Medium
- CVE:
- 2022-4578
Easy Appointments
- Plugin:
- Easy Appointments
- Plugin Slug:
- easy-appointments
- Installations:
- 20,000+
- Vulnerability:
- Contributor+ Stored XSS in Shortcode
- Patched in Version:
- 3.11.2
- Severity Score:
- Medium
- CVE:
- 2022-4668
GeoDirectory
- Plugin Slug:
- geodirectory
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 2.2.22
- Severity Score:
- Medium
- CVE:
- 2022-4775
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio
- Plugin Slug:
- portfolio-elementor
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 2.3.1
- Severity Score:
- Medium
- CVE:
- 2022-4765
WP Google My Business Auto Publish
- Plugin Slug:
- wp-google-my-business-auto-publish
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 3.4
- Severity Score:
- Medium
- CVE:
- 2022-4790
Landing Page Builder
- Plugin:
- Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages
- Plugin Slug:
- page-builder-add
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Cross-Site Scripting via Shortcode
- Patched in Version:
- 1.4.9.9
- Severity Score:
- Medium
- CVE:
- 2022-4718
WPZOOM Portfolio
- Plugin:
- WPZOOM Portfolio
- Plugin Slug:
- wpzoom-portfolio
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2022-4789
10WebMapBuilder
- Plugin:
- 10WebMapBuilder
- Plugin Slug:
- wd-google-maps
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.0.72
- Severity Score:
- Medium
- CVE:
- 2022-4758
Word Balloon
- Plugin:
- Word Balloon
- Plugin Slug:
- word-balloon
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 4.19.3
- Severity Score:
- Medium
- CVE:
- 2022-4751
PDF Viewer
- Plugin:
- PDF Viewer
- Plugin Slug:
- pdf-viewer
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.0.0
- Severity Score:
- Medium
- CVE:
- 2023-0033
Print-O-Matic
- Plugin:
- Print-O-Matic
- Plugin Slug:
- print-o-matic
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 2.1.8
- Severity Score:
- Medium
- CVE:
- 2022-4753
HashBar – WordPress Notification Bar
- Plugin Slug:
- hashbar-wp-notification-bar
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2022-4650
PixCodes
Genesis Columns Advanced
- Plugin:
- Genesis Columns Advanced
- Plugin Slug:
- genesis-columns-advanced
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 2.0.4
- Severity Score:
- Medium
- CVE:
- 2022-4706
Passster
- Plugin Slug:
- content-protector
- Installations:
- 10,000+
- Vulnerability:
- Protection Bypass & Arbitrary Post Access; Contributor+ Stored Cross-Site Scripting
- Patched in Version:
- 3.5.5.9
- Severity Score:
- High
- CVE:
- 2021-24881
Bold Timeline Lite
- Plugin:
- Bold Timeline Lite
- Plugin Slug:
- bold-timeline-lite
- Installations:
- 10,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.1.5
- Severity Score:
- Medium
- CVE:
- 2022-4828
Icon Widget
- Plugin:
- Icon Widget
- Plugin Slug:
- icon-widget
- Installations:
- 9,000+
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2022-4763
User Verification
- Plugin:
- User Verification
- Plugin Slug:
- user-verification
- Installations:
- 5,000+
- Vulnerability:
- Authentication Bypass
- Patched in Version:
- 1.0.94
- Severity Score:
- Critical
- CVE:
- 2022-4693
Survey Maker
- Plugin Slug:
- survey-maker
- Installations:
- 3,000+
- Vulnerability:
- Unauthenticated Stored XSS
- Patched in Version:
- 3.1.4
- Severity Score:
- High
- CVE:
- 2023-0038
Pardakht Delkhah
- Plugin:
- ?????? ?????? ??????
- Plugin Slug:
- pardakht-delkhah
- Installations:
- 1,000+
- Vulnerability:
- Unauthenticated Stored XSS
- Patched in Version:
- 2.9.3
- Severity Score:
- High
- CVE:
- 2022-4307
Optimize images ALT Text (alt tag) & names for SEO using AI
- Plugin Slug:
- imageseo
- Installations:
- 1,000+
- Vulnerability:
- Settings Update via CSRF
- Patched in Version:
- 2.0.8
- Severity Score:
- Low
- CVE:
- 2022-4548
FluentAuth
- Plugin Slug:
- fluent-security
- Installations:
- 700+
- Vulnerability:
- Bypass blocks by IP Spoofing
- Patched in Version:
- 1.0.2
- Severity Score:
- Medium
- CVE:
- 2022-4746
Login as User or Customer
- Plugin:
- Login as User or Customer
- Plugin Slug:
- login-as-customer-or-user
- Installations:
- 400+
- Vulnerability:
- Unauthenticated Privilege Escalation to Admin
- Patched in Version:
- 3.3
- Severity Score:
- Critical
- CVE:
- 2022-4305
Booster for WooCommerce
- Plugin Slug:
- booster-elite-for-woocommerce
- Vulnerability:
- Multiple CSRF
- Patched in Version:
- 6.0.1
- Severity Score:
- Medium
- CVE:
- 2022-4017
BruteBank – WP Security & Firewall
- Plugin Slug:
- brutebank
- Vulnerability:
- Settings Update via CSRF
- Patched in Version:
- 1.9
- Severity Score:
- Medium
- CVE:
- 2022-4443
Booster for WooCommerce
- Plugin:
- Booster Plus for WooCommerce
- Plugin Slug:
- booster-plus-for-woocommerce
- Vulnerability:
- Multiple CSRF
- Patched in Version:
- 6.0.1
- Severity Score:
- Medium
- CVE:
- 2022-4017
Justified Gallery
- Plugin:
- Justified Gallery
- Plugin Slug:
- justified-gallery
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- 1.7.1
- Severity Score:
- Medium
- CVE:
- 2022-4651
WordPress Plugin Vulnerabilities – No Known Fix
This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.
WP Limit Login Attempts
- Plugin:
- WP Limit Login Attempts
- Plugin Slug:
- wp-limit-login-attempts
- Installations:
- 20,000+
- Vulnerability:
- IP Spoofing
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4303
Members Import
- Plugin:
- Members Import
- Plugin Slug:
- members-import
- Vulnerability:
- XSS via Imported CSV
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4663
Accordion Shortcodes
- Plugin:
- Accordion Shortcodes
- Plugin Slug:
- accordion-shortcodes
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4781
CPT Bootstrap Carousel
- Plugin:
- CPT Bootstrap Carousel
- Plugin Slug:
- cpt-bootstrap-carousel
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4834
Meteor Slides
- Plugin:
- Meteor Slides
- Plugin Slug:
- meteor-slides
- Vulnerability:
- Contributor+ Stored XSS
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4486
CBX Petition for WordPress
- Plugin:
- CBX Petition for WordPress
- Plugin Slug:
- cbxpetition
- Vulnerability:
- Unauthenticated SQLi
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2022-4383
Social Sharing Toolkit
- Plugin:
- Social Sharing Toolkit
- Plugin Slug:
- social-sharing-toolkit
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4835
MediaElement.js – HTML5 Video & Audio Player
- Plugin Slug:
- media-element-html5-video-and-audio-player
- Vulnerability:
- Contributor+ Stored XSS via Shortcode
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2022-4699
EU Cookie Law
- Plugin:
- EU Cookie Law for GDPR/CCPA
- Plugin Slug:
- eu-cookie-law
- Vulnerability:
- Admin+ Stored XSS
- Patched in Version:
- No Fix
- Severity Score:
- Low
- CVE:
- 2022-3811
WordPress Theme Vulnerabilities
In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
WordPress Theme Vulnerabilities – No Known Fix
This section contains theme vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the theme.
Aidreform
Kingclub-theme
- Theme:
- kingclub-theme
- Theme Slug:
- kingclub-theme
- Vulnerability:
- Unauthenticated Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2022-0316
Footysquare
- Theme:
- footysquare
- Theme Slug:
- footysquare
- Vulnerability:
- Unauthenticated Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2022-0316
Spikes-black
- Theme:
- spikes-black
- Theme Slug:
- spikes-black
- Vulnerability:
- Unauthenticated Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2022-0316
Stratfort
Spikes
Club-theme
- Theme:
- club-theme
- Theme Slug:
- club-theme
- Vulnerability:
- Unauthenticated Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2022-0316
Soundblast
- Theme:
- soundblast
- Theme Slug:
- soundblast
- Vulnerability:
- Unauthenticated Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2022-0316
Bolster
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed