Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.
The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.
WordPress Core News
WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.
There is a known unpatched vulnerability in WordPress core affecting all versions of WordPress. If you’re using iThemes Security, you’ve probably been alerted to this. As we are unsure when this very low-severity vulnerability will be patched, emails from iThemes Security will no longer alert for this specific vulnerability. Read our blog post about this vulnerability.
WordPress Plugin Vulnerabilities
In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
All In One WP Security & Firewall

- Plugin Slug
- all-in-one-wp-security-and-firewall
- Installations
- 1,000,000+
- Vulnerability
- Configuration Leak
- Patched in Version
- 5.1.3
- Severity Score
- Medium
- CVE
- 2022-4346
WP Statistics

- Plugin
- WP Statistics
- Plugin Slug
- wp-statistics
- Installations
- 600,000+
- Vulnerability
- Authenticated SQLi
- Patched in Version
- 13.2.9
- Severity Score
- High
- CVE
- 2022-4230
Sassy Social Share

- Plugin Slug
- sassy-social-share
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.3.45
- Severity Score
- Medium
- CVE
- 2022-4451
Google Analyticator

- Plugin
- Analyticator
- Plugin Slug
- google-analyticator
- Installations
- 100,000+
- Vulnerability
- Admin+ PHP Object Injection
- Patched in Version
- 6.5.6
- Severity Score
- Low
- CVE
- 2022-4323
Simple Sitemap

- Plugin Slug
- simple-sitemap
- Installations
- 90,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.5.8
- Severity Score
- Medium
- CVE
- 2022-4472
Booster for WooCommerce

- Plugin
- Booster for WooCommerce
- Plugin Slug
- woocommerce-jetpack
- Installations
- 70,000+
- Vulnerability
- Multiple CSRF
- Patched in Version
- 6.0.1
- Severity Score
- Medium
- CVE
- 2022-4017
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box

- Plugin Slug
- easy-facebook-likebox
- Installations
- 70,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 6.4.0
- Severity Score
- Medium
- CVE
- 2022-4474
Collapse-O-Matic

- Plugin
- Collapse-O-Matic
- Plugin Slug
- jquery-collapse-o-matic
- Installations
- 60,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.8.3
- Severity Score
- Medium
- CVE
- 2022-4475
Search & Filter

- Plugin
- Search & Filter
- Plugin Slug
- search-filter
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.2.16
- Severity Score
- Medium
- CVE
- 2022-4467
Content Control

- Plugin Slug
- content-control
- Installations
- 40,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.1.10
- Severity Score
- Medium
- CVE
- 2022-4509
Page-list

OneClick Chat to Order

- Plugin
- OneClick Chat to Order
- Plugin Slug
- oneclick-whatsapp-order
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.0.4.2
- Severity Score
- Medium
- CVE
- 2022-4760
Sitemap

Compact WP Audio Player

- Plugin
- Compact WP Audio Player
- Plugin Slug
- compact-wp-audio-player
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.9.8
- Severity Score
- Medium
- CVE
- 2022-4542
WP Popups

- Plugin Slug
- wp-popups-lite
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.1.4.8
- Severity Score
- Medium
- CVE
- 2022-4716
Top 10

- Plugin Slug
- top-10
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.2.3
- Severity Score
- Medium
- CVE
- 2022-4570
Login Logout Menu

- Plugin
- Login Logout Menu
- Plugin Slug
- login-logout-menu
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 1.4.0
- Severity Score
- Medium
- CVE
- 2022-4625
ShiftNav – Responsive Mobile Menu

- Plugin Slug
- shiftnav-responsive-mobile-menu
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 1.7.2
- Severity Score
- Medium
- CVE
- 2022-4627
Product Slider for WooCommerce

- Plugin Slug
- woo-product-slider
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 2.6.4
- Severity Score
- Medium
- CVE
- 2022-4629
Mongoose Page Plugin

- Plugin
- Mongoose Page Plugin
- Plugin Slug
- facebook-page-feed-graph-api
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.9.0
- Severity Score
- Medium
- CVE
- 2022-4675
Rate my Post – WP Rating System

- Plugin Slug
- rate-my-post
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 3.3.9
- Severity Score
- Medium
- CVE
- 2022-4673
WordPress Simple Shopping Cart

- Plugin Slug
- wordpress-simple-paypal-shopping-cart
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 4.6.2
- Severity Score
- Medium
- CVE
- 2022-4672
Structured Content

- Plugin Slug
- structured-content
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 1.5.1
- Severity Score
- Medium
- CVE
- 2022-4715
GS Logo Slider

- Plugin Slug
- gs-logo-slider
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 3.3.8
- Severity Score
- Medium
- CVE
- 2022-4624
Video Conferencing with Zoom

- Plugin Slug
- video-conferencing-with-zoom-api
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 4.0.10
- Severity Score
- Medium
- CVE
- 2022-4578
Easy Appointments

- Plugin
- Easy Appointments
- Plugin Slug
- easy-appointments
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS in Shortcode
- Patched in Version
- 3.11.2
- Severity Score
- Medium
- CVE
- 2022-4668
GeoDirectory

- Plugin Slug
- geodirectory
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 2.2.22
- Severity Score
- Medium
- CVE
- 2022-4775
Portfolio for Elementor, Image Gallery & Post Grid | PowerFolio

- Plugin Slug
- portfolio-elementor
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 2.3.1
- Severity Score
- Medium
- CVE
- 2022-4765
WP Google My Business Auto Publish

- Plugin Slug
- wp-google-my-business-auto-publish
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 3.4
- Severity Score
- Medium
- CVE
- 2022-4790
Landing Page Builder

- Plugin Slug
- page-builder-add
- Installations
- 10,000+
- Vulnerability
- Contributor+ Cross-Site Scripting via Shortcode
- Patched in Version
- 1.4.9.9
- Severity Score
- Medium
- CVE
- 2022-4718
WPZOOM Portfolio

- Plugin
- WPZOOM Portfolio
- Plugin Slug
- wpzoom-portfolio
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.2.2
- Severity Score
- Medium
- CVE
- 2022-4789
10WebMapBuilder

- Plugin
- 10WebMapBuilder
- Plugin Slug
- wd-google-maps
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.0.72
- Severity Score
- Medium
- CVE
- 2022-4758
Word Balloon

- Plugin
- Word Balloon
- Plugin Slug
- word-balloon
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 4.19.3
- Severity Score
- Medium
- CVE
- 2022-4751
PDF Viewer

- Plugin
- PDF Viewer
- Plugin Slug
- pdf-viewer
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.0.0
- Severity Score
- Medium
- CVE
- 2023-0033
Print-O-Matic

- Plugin
- Print-O-Matic
- Plugin Slug
- print-o-matic
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 2.1.8
- Severity Score
- Medium
- CVE
- 2022-4753
HashBar – WordPress Notification Bar

- Plugin Slug
- hashbar-wp-notification-bar
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.3.6
- Severity Score
- Medium
- CVE
- 2022-4650
PixCodes
Genesis Columns Advanced

- Plugin
- Genesis Columns Advanced
- Plugin Slug
- genesis-columns-advanced
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 2.0.4
- Severity Score
- Medium
- CVE
- 2022-4706
Passster

- Plugin Slug
- content-protector
- Installations
- 10,000+
- Vulnerability
- Protection Bypass & Arbitrary Post Access; Contributor+ Stored Cross-Site Scripting
- Patched in Version
- 3.5.5.9
- Severity Score
- High
- CVE
- 2021-24881
Bold Timeline Lite

- Plugin
- Bold Timeline Lite
- Plugin Slug
- bold-timeline-lite
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.1.5
- Severity Score
- Medium
- CVE
- 2022-4828
Icon Widget

- Plugin
- Icon Widget
- Plugin Slug
- icon-widget
- Installations
- 9,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.3.0
- Severity Score
- Medium
- CVE
- 2022-4763
User Verification

- Plugin
- User Verification
- Plugin Slug
- user-verification
- Installations
- 5,000+
- Vulnerability
- Authentication Bypass
- Patched in Version
- 1.0.94
- Severity Score
- Critical
- CVE
- 2022-4693
Survey Maker

- Plugin Slug
- survey-maker
- Installations
- 3,000+
- Vulnerability
- Unauthenticated Stored XSS
- Patched in Version
- 3.1.4
- Severity Score
- High
- CVE
- 2023-0038
Pardakht Delkhah

- Plugin
- ?????? ?????? ??????
- Plugin Slug
- pardakht-delkhah
- Installations
- 1,000+
- Vulnerability
- Unauthenticated Stored XSS
- Patched in Version
- 2.9.3
- Severity Score
- High
- CVE
- 2022-4307
Optimize images ALT Text (alt tag) & names for SEO using AI

- Plugin Slug
- imageseo
- Installations
- 1,000+
- Vulnerability
- Settings Update via CSRF
- Patched in Version
- 2.0.8
- Severity Score
- Low
- CVE
- 2022-4548
FluentAuth

- Plugin Slug
- fluent-security
- Installations
- 700+
- Vulnerability
- Bypass blocks by IP Spoofing
- Patched in Version
- 1.0.2
- Severity Score
- Medium
- CVE
- 2022-4746
Login as User or Customer

- Plugin Slug
- login-as-customer-or-user
- Installations
- 400+
- Vulnerability
- Unauthenticated Privilege Escalation to Admin
- Patched in Version
- 3.3
- Severity Score
- Critical
- CVE
- 2022-4305
Booster for WooCommerce
- Plugin
- Booster Elite for WooCommerce
- Plugin Slug
- booster-elite-for-woocommerce
- Vulnerability
- Multiple CSRF
- Patched in Version
- 6.0.1
- Severity Score
- Medium
- CVE
- 2022-4017
BruteBank – WP Security & Firewall

- Plugin Slug
- brutebank
- Vulnerability
- Settings Update via CSRF
- Patched in Version
- 1.9
- Severity Score
- Medium
- CVE
- 2022-4443
Booster for WooCommerce
- Plugin
- Booster Plus for WooCommerce
- Plugin Slug
- booster-plus-for-woocommerce
- Vulnerability
- Multiple CSRF
- Patched in Version
- 6.0.1
- Severity Score
- Medium
- CVE
- 2022-4017
Justified Gallery
- Plugin
- Justified Gallery
- Plugin Slug
- justified-gallery
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 1.7.1
- Severity Score
- Medium
- CVE
- 2022-4651
WordPress Plugin Vulnerabilities – No Known Fix
This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.
WP Limit Login Attempts

- Plugin
- WP Limit Login Attempts
- Plugin Slug
- wp-limit-login-attempts
- Installations
- 20,000+
- Vulnerability
- IP Spoofing
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4303
Members Import
- Plugin
- Members Import
- Plugin Slug
- members-import
- Vulnerability
- XSS via Imported CSV
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4663
Accordion Shortcodes
- Plugin
- Accordion Shortcodes
- Plugin Slug
- accordion-shortcodes
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4781
CPT Bootstrap Carousel
- Plugin
- CPT Bootstrap Carousel
- Plugin Slug
- cpt-bootstrap-carousel
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4834
Meteor Slides
- Plugin
- Meteor Slides
- Plugin Slug
- meteor-slides
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4486
CBX Petition for WordPress
- Plugin Slug
- cbxpetition
- Vulnerability
- Unauthenticated SQLi
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2022-4383
Social Sharing Toolkit
- Plugin
- Social Sharing Toolkit
- Plugin Slug
- social-sharing-toolkit
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4835
MediaElement.js – HTML5 Video & Audio Player
- Plugin Slug
- media-element-html5-video-and-audio-player
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-4699
EU Cookie Law
- Plugin Slug
- eu-cookie-law
- Vulnerability
- Admin+ Stored XSS
- Patched in Version
- No Fix
- Severity Score
- Low
- CVE
- 2022-3811
WordPress Theme Vulnerabilities
In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
Multiple themes – Unauthenticated Arbitrary File Upload
- Theme
- WeStand
- Theme Slug
- westand
- Vulnerability
- RCE
- Patched in Version
- 2.1
- Severity Score
- Critical
- CVE
- 2022-0316
WordPress Theme Vulnerabilities – No Known Fix
This section contains theme vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the theme.
Aidreform
- Theme
- aidreform
- Theme Slug
- aidreform
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Kingclub-theme
- Theme
- kingclub-theme
- Theme Slug
- kingclub-theme
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Footysquare
- Theme
- footysquare
- Theme Slug
- footysquare
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Spikes-black
- Theme
- spikes-black
- Theme Slug
- spikes-black
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Stratfort
- Theme
- stratfort
- Theme Slug
- statfort
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Spikes
- Theme
- spikes
- Theme Slug
- spikes
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Club-theme
- Theme
- club-theme
- Theme Slug
- club-theme
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Soundblast
- Theme
- soundblast
- Theme Slug
- soundblast
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Bolster
- Theme
- bolster
- Theme Slug
- bolster
- Vulnerability
- Unauthenticated Arbitrary File Upload
- Patched in Version
- No Fix
- Severity Score
- Critical
- CVE
- 2022-0316
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.
Scans Your Website Twice a Day for Vulnerabilities
Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.
Automatically Updates if a Security Fix is Available
Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.
Emails You if Site Scan Detects a Vulnerability
You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.