Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – July 27, 2023

Written by Dan Knauss on July 27, 2023

Last Updated on August 7, 2023

Since last week, 329 total vulnerabilities emerged in public disclosure. They may affect over 9 million WordPress sites. There are 209 plugin vulnerabilities and 18 theme vulnerabilities with security patches, so run those updates!

Additionally, there are 66 plugin vulnerabilities and 36 theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

Such an unusually high number of vulnerability reports is due to outdated versions of many plugins and themes that may use a common third-party dependency, Freemius’ WordPress SDK 2.5.9. Please see the Freemius WordPress SDK 2.5.9 Security Disclosure for more details.

New Today: Patchstack lists multiple high-severity vulnerabilities in the Ninja Forms plugin, potentially affecting 900k active WordPress sites. These vulnerabilities include a POST-based reflected XSS and broken access control on the form submissions export feature. Please update to version 3.6.26.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the July 27, 2023 Report
  1. WordPress Core Vulnerabilities – Patched
  2. WordPress Plugin Vulnerabilities – Patched
  3. WordPress Plugin Vulnerabilities – Unpatched
  4. WordPress Theme Vulnerabilities
  5. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Essential Addons For Elementor

Product image for Essential Addons for Elementor.
Plugin
Essential Addons for Elementor
Plugin Slug
essential-addons-for-elementor-lite
Installations
1,000,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
5.8.2
Severity Score
Medium
CVE
2023-3779
The vulnerability has been patched, so you should update to version 5.8.2.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.
Plugin
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug
ninja-forms
Installations
900,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6.26
Severity Score
High
CVE
2023-37979
The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.
Plugin
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug
ninja-forms
Installations
900,000+
Vulnerability
Broken Access Control
Patched in Version
3.6.26
Severity Score
High
CVE
2023-38393
The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.
Plugin
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug
ninja-forms
Installations
900,000+
Vulnerability
Broken Access Control
Patched in Version
3.6.26
Severity Score
High
CVE
2023-38386
The vulnerability has been patched, so you should update to version 3.6.26.

The Events Calendar

Product image for The Events Calendar.
Plugin
The Events Calendar
Plugin Slug
the-events-calendar
Installations
800,000+
Vulnerability
Broken Access Control
Patched in Version
6.1.3
Severity Score
Medium
CVE
2023-35777
The vulnerability has been patched, so you should update to version 6.1.3.

The Events Calendar

Product image for The Events Calendar.
Plugin
The Events Calendar
Plugin Slug
the-events-calendar
Installations
800,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 6.1.0.

Popup Maker

Product image for Popup Maker – Popup for opt-ins, lead gen, & more.
Plugin
Popup Maker – Popup for opt-ins, lead gen, & more
Plugin Slug
popup-maker
Installations
700,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.10.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.10.0.

NextGEN Gallery

Product image for WordPress Gallery Plugin – NextGEN Gallery.
Plugin
WordPress Gallery Plugin – NextGEN Gallery
Plugin Slug
nextgen-gallery
Installations
600,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4.7
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.4.7.

WP Activity Log

Product image for WP Activity Log.
Plugin
WP Activity Log
Plugin Slug
wp-security-audit-log
Installations
200,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.4.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 4.4.3.

404 to 301

Product image for 404 to 301 – Redirect, Log and Notify 404 Errors.
Plugin
404 to 301 – Redirect, Log and Notify 404 Errors
Plugin Slug
404-to-301
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.6.

Elementor Addon Elements

Product image for Elementor Addon Elements.
Plugin
Elementor Addon Elements
Plugin Slug
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.12
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.12.

CAPTCHA 4WP

Product image for CAPTCHA 4WP.
Plugin
CAPTCHA 4WP
Plugin Slug
advanced-nocaptcha-recaptcha
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.0.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 7.0.6.

WP AutoTerms: Privacy Policy Generator (GDPR & CCPA), Terms & Conditions Generator, Cookie Notice Banner

Product image for WP AutoTerms: Privacy Policy Generator (GDPR & CCPA), Terms & Conditions Generator, Cookie Notice Banner.
Plugin
WP AutoTerms: Privacy Policy Generator (GDPR & CCPA), Terms & Conditions Generator, Cookie Notice Banner
Plugin Slug
auto-terms-of-service-and-privacy-policy
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

Blocksy Companion

Product image for Blocksy Companion.
Plugin
Blocksy Companion
Plugin Slug
blocksy-companion
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.47
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.47.

Meta Tag Manager

Product image for Meta Tag Manager.
Plugin
Meta Tag Manager
Plugin Slug
meta-tag-manager
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.

Pods

Product image for Pods – Custom Content Types and Fields.
Plugin
Pods – Custom Content Types and Fields
Plugin Slug
pods
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.8.23
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.8.23.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.
Plugin
TI WooCommerce Wishlist
Plugin Slug
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.7.0.

Asset CleanUp: Page Speed Booster

Product image for Asset CleanUp: Page Speed Booster.
Plugin
Asset CleanUp: Page Speed Booster
Plugin Slug
wp-asset-clean-up
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.5.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.5.5.

AnyWhere Elementor

Product image for AnyWhere Elementor.
Plugin
AnyWhere Elementor
Plugin Slug
anywhere-elementor
Installations
90,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.8.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.
Plugin
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor
Plugin Slug
embedpress
Installations
80,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.3.

Event Tickets

Product image for Event Tickets and Registration.
Plugin
Event Tickets and Registration
Plugin Slug
event-tickets
Installations
70,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.6.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 5.6.0.

Easy Watermark

Product image for Easy Watermark.
Plugin
Easy Watermark
Plugin Slug
easy-watermark
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.7
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.7.

Simple Author Box

Product image for Simple Author Box.
Plugin
Simple Author Box
Plugin Slug
simple-author-box
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.4.

WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to fix Insecure Content

Product image for WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score.
Plugin
WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score
Plugin Slug
wp-letsencrypt-ssl
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.3.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 6.3.0.

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor

Product image for Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor.
Plugin
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor
Plugin Slug
gutentor
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.3.

Preloader Plus – WordPress Loading Screen Plugin

Product image for Preloader Plus – WordPress Loading Screen Plugin.
Plugin
Preloader Plus – WordPress Loading Screen Plugin
Plugin Slug
preloader-plus
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.

Spotlight Social Media Feeds

Product image for Spotlight Social Feeds [Block, Shortcode, and Widget].
Plugin
Spotlight Social Feeds [Block, Shortcode, and Widget]
Plugin Slug
spotlight-social-photo-feeds
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.6.1.

Weglot Translate – Translate your WordPress website and go multilingual

Plugin
Weglot Translate – Translate your WordPress website and go multilingual
Plugin Slug
weglot
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.9.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.9.3.

Better Notifications for WP

Product image for Customize WordPress Emails and Alerts – Better Notifications for WP.
Plugin
Customize WordPress Emails and Alerts – Better Notifications for WP
Plugin Slug
bnfw
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.7.

Stop User Enumeration

Product image for Stop User Enumeration.
Plugin
Stop User Enumeration
Plugin Slug
stop-user-enumeration
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.0.

Mail Bank – #1 Mail SMTP Plugin for WordPress

Product image for Mail Bank – #1 Mail SMTP Plugin for WordPress.
Plugin
Mail Bank – #1 Mail SMTP Plugin for WordPress
Plugin Slug
wp-mail-bank
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.13
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.13.

Gutenberg Block Editor Toolkit

Product image for Gutenberg Block Editor Toolkit – EditorsKit.
Plugin
Gutenberg Block Editor Toolkit – EditorsKit
Plugin Slug
block-options
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.17
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.17.

Divi Contact Form 7

Product image for Contact Form 7 Module For Divi Builder.
Plugin
Contact Form 7 Module For Divi Builder
Plugin Slug
cf7-styler-for-divi
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.3.

Cost Calculator Builder

Product image for Cost Calculator Builder.
Plugin
Cost Calculator Builder
Plugin Slug
cost-calculator-builder
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.3.3.

Image Photo Gallery Final Tiles Grid

Product image for Image Photo Gallery Final Tiles Grid.
Plugin
Image Photo Gallery Final Tiles Grid
Plugin Slug
final-tiles-grid-gallery-lite
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.5.8.

Hide Admin Bar Based on User Roles

Product image for Hide Admin Bar Based on User Roles.
Plugin
Hide Admin Bar Based on User Roles
Plugin Slug
hide-admin-bar-based-on-user-roles
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.

Divi Carousel Lite

Plugin
Divi Carousel Lite
Plugin Slug
wow-carousel-for-divi-lite
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.12
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.12.

WP Google Review Slider

Product image for WP Google Review Slider.
Plugin
WP Google Review Slider
Plugin Slug
wp-google-places-review-slider
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
12.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 12.6.

DiviTorque – Divi Theme, Divi Builder and Extra Theme

Product image for Divi Torque Lite.
Plugin
Divi Torque Lite
Plugin Slug
addons-for-divi
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.6.0.

Contact Form 7 Skins

Product image for CF7 Skins for Contact Form 7.
Plugin
CF7 Skins for Contact Form 7
Plugin Slug
contact-form-7-skins
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.1.

Greenshift – animation and page builder blocks

Product image for Greenshift – animation and page builder blocks.
Plugin
Greenshift – animation and page builder blocks
Plugin Slug
greenshift-animation-and-page-builder-blocks
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.8.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 4.8.1.

New User Approve

Product image for New User Approve.
Plugin
New User Approve
Plugin Slug
new-user-approve
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.5.1.

HP Everywhere

Product image for PHP Everywhere.
Plugin
PHP Everywhere
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
CVE
2022-24664
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.
Plugin
PHP Everywhere
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
CVE
2022-24665
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.
Plugin
PHP Everywhere
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
CVE
2022-24663
The vulnerability has been patched, so you should update to version 3.0.0.

Redirect 404 Error Page to Homepage or Custom Page with Logs

Plugin
Redirect 404 Error Page to Homepage or Custom Page with Logs
Plugin Slug
redirect-404-error-page-to-homepage-or-custom-page
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.0.

Gallery Blocks with Lightbox

Product image for Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery.
Plugin
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery
Plugin Slug
simply-gallery-block
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.1.5.

Disable Emojis & Disable Embeds for WordPress Performance & SpeedUp

Plugin
Reduce HTTP Requests, Disable Emojis & Disable Embeds, Speedup WooCommerce
Plugin Slug
wp-disable
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.5.0.

Media Library Categories

Product image for Media Library Categories.
Plugin
Media Library Categories
Plugin Slug
wp-media-library-categories
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.1
Severity Score
Medium
CVE
2023-36382
The vulnerability has been patched, so you should update to version 2.0.1.

WP to Twitter

Product image for WP to Twitter.
Plugin
WP to Twitter
Plugin Slug
wp-to-twitter
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.3.0.

Product Feed Manager

Product image for Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces.
Plugin
Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces
Plugin Slug
best-woocommerce-feed
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.

DeMomentSomTres WordPress Export Posts With Images

Product image for DeMomentSomTres WordPress Export Posts With Images.
Plugin
DeMomentSomTres WordPress Export Posts With Images
Plugin Slug
demomentsomtres-wp-export
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
20200610
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 20200610.

Enjoy Social Feed plugin for WordPress website

Product image for Enjoy Social Feed plugin for WordPress website.
Plugin
Enjoy Social Feed plugin for WordPress website
Plugin Slug
enjoy-instagram-instagram-responsive-images-gallery-and-carousel
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 6.2.1.

eRoom – Zoom Meetings & Webinar

Product image for eRoom – Zoom Meetings & Webinars.
Plugin
eRoom – Zoom Meetings & Webinars
Plugin Slug
eroom-zoom-meetings-webinar
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.4.

MasterStudy LMS

Product image for MasterStudy LMS WordPress Plugin – for Online Courses and Education.
Plugin
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Plugin Slug
masterstudy-lms-learning-management-system
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.8.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.8.0.

Notification

Product image for Notification – Custom Notifications and Alerts for WordPress.
Plugin
Notification – Custom Notifications and Alerts for WordPress
Plugin Slug
notification
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 6.1.0.

PowerPack Lite for Beaver Builder

Product image for PowerPack Lite for Beaver Builder.
Plugin
PowerPack Lite for Beaver Builder
Plugin Slug
powerpack-addon-for-beaver-builder
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.9.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.9.3.

Seo Optimized Images

Product image for Seo Optimized Images.
Plugin
Seo Optimized Images
Plugin Slug
seo-optimized-images
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.

WP News and Scrolling Widgets

Product image for WP News and Scrolling Widgets.
Plugin
WP News and Scrolling Widgets
Plugin Slug
sp-news-and-widget
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 4.2.

Stop WP Emails Going to Spam

Plugin
Stop WP Emails Going to Spam
Plugin Slug
stop-wp-emails-going-to-spam
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Tiered Price Table

Product image for Tiered Pricing Table for WooCommerce.
Plugin
Tiered Pricing Table for WooCommerce
Plugin Slug
tier-pricing-table
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.5.1.

WP Review Slider

Product image for WP Review Slider.
Plugin
WP Review Slider
Plugin Slug
wp-facebook-reviews
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.6.

WP Mail Log

Product image for WP Mail Log.
Plugin
WP Mail Log
Plugin Slug
wp-mail-log
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.1.

WP VR

Product image for WP VR – 360 Panorama and Virtual Tour Builder For WordPress.
Plugin
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
Plugin Slug
wpvr
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.2.

ACF Frontend – Add and edit posts, pages, users and more all from the frontend

Plugin
Frontend Admin by DynamiApps
Plugin Slug
acf-frontend-form-element
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.8.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.8.0.

HuCommerce | Magyar WooCommerce kiegészítések

Product image for HuCommerce | Magyar WooCommerce kiegészítések.
Plugin
HuCommerce | Magyar WooCommerce kiegészítések
Plugin Slug
surbma-magyar-woocommerce
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2022.0.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2022.0.3.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).
Plugin
Post to Google My Business (Google Business Profile)
Plugin Slug
post-to-google-my-business
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.14
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.1.14.

PublishPress Planner: Organize and Schedule Your WordPress Content

Product image for PublishPress Planner: Organize and Schedule Your WordPress Content.
Plugin
PublishPress Planner: Organize and Schedule Your WordPress Content
Plugin Slug
publishpress
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.9.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.9.5.

Salon booking system

Product image for Salon booking system.
Plugin
Salon booking system
Plugin Slug
salon-booking-system
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
8.4.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 8.4.9.

Easy Photography Portfolio

Product image for Easy Photography Portfolio.
Plugin
Easy Photography Portfolio
Plugin Slug
photography-portfolio
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.9.

Quiz Cat

Product image for Quiz Cat – WordPress Quiz Plugin.
Plugin
Quiz Cat – WordPress Quiz Plugin
Plugin Slug
quiz-cat
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.0.

WooCommerce Google Ads Dynamic Remarketing

Product image for WooCommerce Google Ads Dynamic Remarketing.
Plugin
WooCommerce Google Ads Dynamic Remarketing
Plugin Slug
woocommerce-google-dynamic-retargeting-tag
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.17
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.7.17.

WP Travel

Product image for WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine.
Plugin
WP Travel – Best Travel Booking WordPress Plugin, Tour Management Engine
Plugin Slug
wp-travel
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 4.2.0.

WpStream – Live Streaming, Video on Demand, Pay Per View

Product image for WpStream – Live Streaming, Video on Demand, Pay Per View.
Plugin
WpStream – Live Streaming, Video on Demand, Pay Per View
Plugin Slug
wpstream
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.5.5
Severity Score
Medium
CVE
2023-38512
The vulnerability has been patched, so you should update to version 4.5.5.

ACF-VC Integrator

Product image for ACF-VC Integrator.
Plugin
ACF-VC Integrator
Plugin Slug
acf-vc-integrator
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.1.

AnyComment

Product image for AnyComment.
Plugin
AnyComment
Plugin Slug
anycomment
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.0.99
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.0.99.

WordPress Tag Cloud Plugin – Tag Groups

Product image for Tag Groups is the Advanced Way to Display Your Taxonomy Terms.
Plugin
Tag Groups is the Advanced Way to Display Your Taxonomy Terms
Plugin Slug
tag-groups
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

Search Console

Product image for Search Console.
Plugin
Search Console
Plugin Slug
search-console
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.2.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.2.2.

Discussion Board

Product image for Discussion Board – WordPress Forum Plugin.
Plugin
Discussion Board – WordPress Forum Plugin
Plugin Slug
wp-discussion-board
Installations
3,000+
Vulnerability
Content Injection
Patched in Version
2.4.9
Severity Score
Medium
CVE
2023-39161
The vulnerability has been patched, so you should update to version 2.4.9.

Photo Engine

Product image for Photo Engine (Media Organizer & Lightroom).
Plugin
Photo Engine (Media Organizer & Lightroom)
Plugin Slug
wplr-sync
Installations
3,000+
Vulnerability
Insecure Direct Object References (IDOR)
Patched in Version
6.2.6
Severity Score
Medium
CVE
2023-38513
The vulnerability has been patched, so you should update to version 6.2.6.

Image Carousel For Divi

Product image for Image Carousel For Divi.
Plugin
Image Carousel For Divi
Plugin Slug
image-carousel-for-divi
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.6.1.

Market Exporter

Product image for Market Exporter.
Plugin
Market Exporter
Plugin Slug
market-exporter
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.19
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.19.

Multiple Page Generator Plugin – MPG

Product image for Multiple Page Generator Plugin – MPG.
Plugin
Multiple Page Generator Plugin – MPG
Plugin Slug
multiple-pages-generator-by-porthas
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.0.

Share This Image

Product image for Share This Image.
Plugin
Share This Image
Plugin Slug
share-this-image
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.81
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.81.

Client Invoicing by Sprout Invoices

Product image for Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress.
Plugin
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress
Plugin Slug
sprout-invoices
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
19.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 19.1.

Integration for WooCommerce and Zoho CRM

Product image for Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.
Plugin
Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin
Plugin Slug
woo-zoho
Installations
2,000+
Vulnerability
Open Redirection
Patched in Version
1.3.7
Severity Score
Medium
CVE
2023-38481
The vulnerability has been patched, so you should update to version 1.3.7.

Spanish Market Enhancements for WooCommerce

Product image for Spanish Market Enhancements for WooCommerce.
Plugin
Spanish Market Enhancements for WooCommerce
Plugin Slug
woocommerce-es
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.

Pay For Post with WooCommerce

Product image for Pay For Post with WooCommerce.
Plugin
Pay For Post with WooCommerce
Plugin Slug
woocommerce-pay-per-post
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.11
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.1.11.

360 Javascript Viewer

Product image for 360 Javascript Viewer.
Plugin
360 Javascript Viewer
Plugin Slug
360deg-javascript-viewer
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.5.3.

Activity Log For MainWP

Product image for Activity Log For MainWP.
Plugin
Activity Log For MainWP
Plugin Slug
activity-log-mainwp
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Attribute Stock – Share Stock Between Products (Lite Version)

Product image for WooCommerce Attribute Stock – Share Stock Between Products (Lite Version).
Plugin
WooCommerce Attribute Stock – Share Stock Between Products (Lite Version)
Plugin Slug
attribute-stock-for-woocommerce
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.0.

Message Filter for Contact Form 7

Plugin
Message Filter for Contact Form 7
Plugin Slug
cf7-message-filter
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.3.

Church Admin

Product image for Church Admin.
Plugin
Church Admin
Plugin Slug
church-admin
Installations
1,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
3.8.0
Severity Score
Medium
CVE
2023-38515
The vulnerability has been patched, so you should update to version 3.8.0.

TempTool [Show Current Template Info]

Product image for TempTool  [Show Current Template Info].
Plugin
TempTool [Show Current Template Info]
Plugin Slug
current-template-name
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.10
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.10.

XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]

Product image for XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin].
Plugin
XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin]
Plugin Slug
faq-for-woocommerce
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.0.

WordPress Team Members – GS Plugins

Product image for Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More.
Plugin
Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More
Plugin Slug
gs-team-members
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.2.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.2.2.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.
Plugin
Remove Duplicate Posts
Plugin Slug
remove-duplicate-posts
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.

WP Required Taxonomies – Categories and Tags Mandatory

Plugin
WP Required Taxonomies – Categories and Tags Mandatory
Plugin Slug
required-taxonomies
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.8.

SV Proven Expert

Product image for SV Proven Expert.
Plugin
SV Proven Expert
Plugin Slug
sv-provenexpert
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

SV Tracking Manager

Product image for SV Tracking Manager.
Plugin
SV Tracking Manager
Plugin Slug
sv-tracking-manager
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

UltraAddons Elementor Lite (Header & Footer Builder, Menu Builder, Cart Icon, Shortcode)

Product image for UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode).
Plugin
UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode)
Plugin Slug
ultraaddons-elementor-lite
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.0.

WooBuddy

Product image for BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages.
Plugin
BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages
Plugin Slug
wc4bp
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4.16
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.4.16.

Live Sales Notification for Woocommerce – Woomotiv

Product image for Live Sales Notification for Woocommerce – Woomotiv.
Plugin
Live Sales Notification for Woocommerce – Woomotiv
Plugin Slug
woomotiv
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.4.

Integration for WooCommerce and QuickBooks

Product image for Integration for WooCommerce and QuickBooks.
Plugin
Integration for WooCommerce and QuickBooks
Plugin Slug
wp-woocommerce-quickbooks
Installations
1,000+
Vulnerability
Open Redirection
Patched in Version
1.2.4
Severity Score
Medium
CVE
2023-38478
The vulnerability has been patched, so you should update to version 1.2.4.

wpShopGermany IT-RECHT KANZLEI

Plugin
wpShopGermany IT-RECHT KANZLEI
Plugin Slug
wpshopgermany-it-recht-kanzlei
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
Medium
CVE
2023-37993
The vulnerability has been patched, so you should update to version 1.8.

WordPress Gallery Plugin – Limb Image Gallery

Product image for Limb Gallery | Create Beautiful Image & Video Galleries.
Plugin
Limb Gallery | Create Beautiful Image & Video Galleries
Plugin Slug
limb-gallery
Installations
800+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.5.6.

GraphComment Comment system

Product image for GraphComment Comment system.
Plugin
GraphComment Comment system
Plugin Slug
graphcomment-comment-system
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.3.5.

Terms & Conditions Per Product

Product image for Terms & Conditions Per Product.
Plugin
Terms & Conditions Per Product
Plugin Slug
terms-and-conditions-per-product
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.6.

Chamber Dashboard Business Directory

Product image for Chamber Dashboard Business Directory.
Plugin
Chamber Dashboard Business Directory
Plugin Slug
chamber-dashboard-business-directory
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.3.2.

Embed Docs – Elementor Files Addon,Elementor Docs Addon,Embed PDF, Word, PowerPoint and Excel Files in Gutenberg & Elementor

Product image for Embed Docs – Elementor Files Addon,Elementor Docs Addon,Embed PDF, Word, PowerPoint and Excel Files in Gutenberg & Elementor.
Plugin
Embed Docs – Elementor Files Addon,Elementor Docs Addon,Embed PDF, Word, PowerPoint and Excel Files in Gutenberg & Elementor
Plugin Slug
embed-docs
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.1.

Embed Video Thumbnail

Product image for Embed Video Thumbnail.
Plugin
Embed Video Thumbnail
Plugin Slug
embed-video-thumbnail
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.1.

WordPress Form Builder Plugin – Gutenberg Forms

Product image for Gutenberg Forms – WordPress Form Builder Plugin.
Plugin
Gutenberg Forms – WordPress Form Builder Plugin
Plugin Slug
forms-gutenberg
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.0.

FormsCRM

Product image for FormsCRM.
Plugin
FormsCRM
Plugin Slug
formscrm
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.6.

WZ Followed Posts – Display what visitors are reading

Product image for WZ Followed Posts – Display what visitors are reading.
Plugin
WZ Followed Posts – Display what visitors are reading
Plugin Slug
where-did-they-go-from-here
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.0.

Member Profile Forms / Custom Registration / Post From Profile in BuddyPress / BuddyBoss

Product image for Member Profile Forms / Custom Registration / Post From Profile in BuddyPress / BuddyBoss.
Plugin
Member Profile Forms / Custom Registration / Post From Profile in BuddyPress / BuddyBoss
Plugin Slug
buddyforms-members
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.12
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.12.

WPEventPartners Demo Import

Plugin
WPEventPartners Demo Import
Plugin Slug
wep-demo-import
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.4.

Advanced WC Analytics – Google Analytics Dashboard for WooCommerce

Product image for WooCommerce Google Analytics Integration By Advanced WC Analytics.
Plugin
WooCommerce Google Analytics Integration By Advanced WC Analytics
Plugin Slug
advance-wc-analytics
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.4.0.

Display WP Admin Pages in the Frontend – WP Frontend Admin

Product image for WP Frontend Admin – Display WP Admin Pages in the Frontend.
Plugin
WP Frontend Admin – Display WP Admin Pages in the Frontend
Plugin Slug
display-admin-page-on-frontend
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.21.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.21.1.

Product Filter Widget for Elementor

Plugin
Product Filter Widget for Elementor
Plugin Slug
product-filter-widget-for-elementor
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.2.

what3words Address Field

Product image for what3words Address Field.
Plugin
what3words Address Field
Plugin Slug
3-word-address-validation-field
Installations
300+
Vulnerability
Sensitive Data Exposure
Patched in Version
4.0.1
Severity Score
Medium
CVE
2021-4428
The vulnerability has been patched, so you should update to version 4.0.1.

Advanced Custom Fields Frontend Forms – ACF Forms – ACF Post Form – ACF Registration Form – ACF Content Form – ACF Profile Form

Product image for Advanced Custom Fields Frontend Forms – ACF Forms – ACF Post Form – ACF Registration Form – ACF Content Form – ACF Profile Form.
Plugin
Advanced Custom Fields Frontend Forms – ACF Forms – ACF Post Form – ACF Registration Form – ACF Content Form – ACF Profile Form
Plugin Slug
buddyforms-acf
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.5.

BuddyForms Ultimate Member

Product image for BuddyForms Ultimate Member.
Plugin
BuddyForms Ultimate Member
Plugin Slug
buddyforms-ultimate-member
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.8.

Gift Message for WooCommerce

Product image for Gift Message for WooCommerce.
Plugin
Gift Message for WooCommerce
Plugin Slug
gift-message-for-woocommerce
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.7.5.

Ultimate LinkedIn Integration

Product image for Ultimate LinkedIn Integration.
Plugin
Ultimate LinkedIn Integration
Plugin Slug
linkedin-login
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.

Shipping for Nova Poshta

Product image for Shipping for Nova Poshta.
Plugin
Shipping for Nova Poshta
Plugin Slug
nova-poshta-ttn
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.1.

Spice Blocks

Plugin
Spice Blocks
Plugin Slug
spice-blocks
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.

WooCommerce Country Catalogs – Product Country Restrictions

Plugin
WooCommerce Country Catalogs – Product Country Restrictions
Plugin Slug
woo-country-restrictions-advanced
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.14.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.14.3.

2MB Autocode

Plugin
2MB Autocode
Plugin Slug
2mb-autocode
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.6.

Checkbox

Product image for Checkbox.
Plugin
Checkbox
Plugin Slug
checkbox
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.8.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.8.5.

WordPress Image Compression and Optimizer Plugin – CheetahO

Product image for WordPress Image Compression and Optimizer Plugin – CheetahO.
Plugin
WordPress Image Compression and Optimizer Plugin – CheetahO
Plugin Slug
cheetaho-image-optimizer
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.3.1.

Multicollab – Google Doc-Style Editorial Commenting for WordPress

Product image for Multicollab – Google Docs-Style Editorial Collaboration in WordPress.
Plugin
Multicollab – Google Docs-Style Editorial Collaboration in WordPress
Plugin Slug
commenting-feature
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.2.

Content Blocks Builder

Product image for Content Blocks Builder.
Plugin
Content Blocks Builder
Plugin Slug
content-blocks-builder
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.17
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.3.17.

WordPress Job Board and Recruitment Plugin – JobWP

Product image for WordPress Job Board and Recruitment Plugin – JobWP.
Plugin
WordPress Job Board and Recruitment Plugin – JobWP
Plugin Slug
jobwp
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.

Joli FAQ SEO – WordPress FAQ Plugin

Product image for Joli FAQ SEO – WordPress FAQ Plugin.
Plugin
Joli FAQ SEO – WordPress FAQ Plugin
Plugin Slug
joli-faq-seo
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.1.

RSS Control

Product image for RSS Control.
Plugin
RSS Control
Plugin Slug
rss-control
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.8.

Simple Tour Guide

Plugin
Simple Tour Guide
Plugin Slug
simple-tour-guide
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.6.

Coming Soon Pages for WordPress – Coming Soon Booster

Product image for Coming Soon Pages for WordPress – Coming Soon Booster.
Plugin
Coming Soon Pages for WordPress – Coming Soon Booster
Plugin Slug
wp-coming-soon-booster
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.7
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.7.

WP SPID Italia

Product image for WP SPID Italia.
Plugin
WP SPID Italia
Plugin Slug
wp-spid-italia
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.5.

AI Tools – Chatbot, ChatGPT, Content Generator, Image Generator, Artificial Intelligence GPT

Product image for AI Tools – Chatbot, ChatGPT, Content Generator, Image Generator, Artificial Intelligence GPT.
Plugin
AI Tools – Chatbot, ChatGPT, Content Generator, Image Generator, Artificial Intelligence GPT
Plugin Slug
artificial-intelligence-auto-content-generator
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.0.

Coming Soon Master

Product image for Coming Soon Master.
Plugin
Coming Soon Master
Plugin Slug
coming-soon-master
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.

EthereumICO

Plugin
EthereumICO
Plugin Slug
ethereumico
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.4.4.

Files Download Delay

Plugin
Files Download Delay
Plugin Slug
files-download-delay
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.9.

Bulk Landing Page Creator for WordPress – LPagery

Product image for Bulk Landing Page Creator for WordPress – LPagery.
Plugin
Bulk Landing Page Creator for WordPress – LPagery
Plugin Slug
lpagery
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.6.

Mobile App Editor – WordPress to Android App Builder

Product image for Mobile App Editor – WordPress to Android App Builder.
Plugin
Mobile App Editor – WordPress to Android App Builder
Plugin Slug
mobile-app-editor
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.0.

Search Field for Gravity Forms

Product image for Search Field for Gravity Forms.
Plugin
Search Field for Gravity Forms
Plugin Slug
search-field-for-gravity-forms
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.6.

Stellar Places

Product image for Stellar Places.
Plugin
Stellar Places
Plugin Slug
stellar-places
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.

Subaccounts for WooCommerce

Product image for Subaccounts for WooCommerce.
Plugin
Subaccounts for WooCommerce
Plugin Slug
subaccounts-for-woocommerce
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.0.

WN Flipbox Pro

Product image for WN Flipbox Pro.
Plugin
WN Flipbox Pro
Plugin Slug
wn-flipbox-pro
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.1.

Bing Custom Search for WordPress

Product image for Bing Custom Search for WordPress.
Plugin
Bing Custom Search for WordPress
Plugin Slug
wp-bing-search
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.6.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.6.3.

WP Tools Divi Blog Carousel

Product image for WP Tools Divi Blog Carousel.
Plugin
WP Tools Divi Blog Carousel
Plugin Slug
wp-tools-divi-blog-carousel
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.1.

Display Data on your site! Create Dynamic Content Templates from any form of data. Works with ACF, Pods, BuddyPress/ BuddyBoss

Product image for Display Data on your site! Create Dynamic Content Templates from any form of data. Works with ACF, Pods, BuddyPress/ BuddyBoss.
Plugin
Display Data on your site! Create Dynamic Content Templates from any form of data. Works with ACF, Pods, BuddyPress/ BuddyBoss
Plugin Slug
buddyforms-hook-fields
Installations
90+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.2.

Contact Form By Mega Forms – Drag and Drop Form Builder

Product image for Contact Form By Mega Forms – Drag and Drop Form Builder.
Plugin
Contact Form By Mega Forms – Drag and Drop Form Builder
Plugin Slug
mega-forms
Installations
90+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.3.

Ultimate Custom ScrollBar

Product image for Ultimate Custom ScrollBar.
Plugin
Ultimate Custom ScrollBar
Plugin Slug
ultimate-custom-scrollbar
Installations
90+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.

WPGutenBlog Demo Import

Plugin
WPGutenBlog Demo Import
Plugin Slug
layouts-importer
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.3.

SV100 Companion

Product image for SV100 Companion.
Plugin
SV100 Companion
Plugin Slug
sv100-companion
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

Blocks Product Editor for WooCommerce

Plugin
Blocks Product Editor for WooCommerce
Plugin Slug
blocks-product-editor-for-woocommerce
Installations
70+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.2.

Variable Inspector

Product image for Variable Inspector.
Plugin
Variable Inspector
Plugin Slug
variable-inspector
Installations
70+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.4.0.

Stripe Express

Product image for Stripe Express.
Plugin
Stripe Express
Plugin Slug
wp-stripe-express
Installations
60+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.12.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.12.1.

BuddyForms Form Elements for WooCommerce

Product image for BuddyForms Form Elements for WooCommerce.
Plugin
BuddyForms Form Elements for WooCommerce
Plugin Slug
buddyforms-woocommerce-form-elements
Installations
50+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.3.

Order Redirects for WooCommerce

Product image for Order Redirects for WooCommerce.
Plugin
Order Redirects for WooCommerce
Plugin Slug
order-redirects-for-woocommerce
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.8.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.8.1.

Simple blueprint installer

Product image for Simple blueprint installer.
Plugin
Simple blueprint installer
Plugin Slug
simple-blueprint-installer
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.2.

BuddyForms Moderation ( Former: Review Logic )

Product image for BuddyForms Moderation ( Former: Review Logic ).
Plugin
BuddyForms Moderation ( Former: Review Logic )
Plugin Slug
buddyforms-review
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.8.

Import Holded for WooCommerce or Easy Digital Downloads

Product image for Connect WooCommerce Holded.
Plugin
Connect WooCommerce Holded
Plugin Slug
import-holded-products-woocommerce
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.

Order Picking For WooCommerce

Product image for Order Picking For WooCommerce.
Plugin
Order Picking For WooCommerce
Plugin Slug
order-picking-for-woocommerce
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.2.

ShortcodeHub – MultiPurpose Shortcode Builder

Product image for ShortcodeHub – MultiPurpose Shortcode Builder.
Plugin
ShortcodeHub – MultiPurpose Shortcode Builder
Plugin Slug
shortcodehub
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.0.

WPEForm Lite – Drag and Drop Live Form Builder for Contact, Payment & Quiz Forms

Product image for WPEForm Lite – Drag and Drop Live Form Builder for Contact, Payment & Quiz Forms.
Plugin
WPEForm Lite – Drag and Drop Live Form Builder for Contact, Payment & Quiz Forms
Plugin Slug
wpeform-lite
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.6.5.

CO2ok: carbon offsetting for e-commerce

Product image for ClimateClick: Climate Action for all.
Plugin
ClimateClick: Climate Action for all
Plugin Slug
co2ok-for-woocommerce
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.4.

SV Forms

Product image for SV Forms.
Plugin
SV Forms
Plugin Slug
sv-forms
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.02
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.02.

SV Posts

Product image for SV Posts.
Plugin
SV Posts
Plugin Slug
sv-posts
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

Video Analytics for Cloudflare Stream

Plugin
Video Analytics for Cloudflare Stream
Plugin Slug
video-analytics-for-cloudflare-stream
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.

WP Table Pixie

Product image for WP Table Pixie.
Plugin
WP Table Pixie
Plugin Slug
wp-table-pixie
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.0.

CF7 ReCaptcha Mine

Product image for CF7 ReCaptcha Mine.
Plugin
CF7 ReCaptcha Mine
Plugin Slug
cf7-recaptcha-mine
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

Convoworks WP

Product image for Convoworks WP.
Plugin
Convoworks WP
Plugin Slug
convoworks-wp
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.22.15
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.22.15.

Custom Welcome Guide

Plugin
Custom Welcome Guide
Plugin Slug
custom-welcome-guide
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.9.

DeMomentSomTres Gravity Forms Improvements

Product image for DeMomentSomTres Gravity Forms Improvements.
Plugin
DeMomentSomTres Gravity Forms Improvements
Plugin Slug
demomentsomtres-gravity-forms-improvements
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
201805021810
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 201805021810.

Fast Custom Social Share by CodeBard

Product image for Fast Custom Social Share by CodeBard.
Plugin
Fast Custom Social Share by CodeBard
Plugin Slug
fast-custom-social-share-by-codebard
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.0.

Contact form builder for Gutenberg – Formello

Product image for Contact form builder for Gutenberg – Formello.
Plugin
Contact form builder for Gutenberg – Formello
Plugin Slug
formello
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.3.1.

Menukaart – Restaurant Menu & Online Ordering with WooCommerce

Product image for Menukaart – Restaurant Menu & Online Ordering with WooCommerce.
Plugin
Menukaart – Restaurant Menu & Online Ordering with WooCommerce
Plugin Slug
menukaart
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.4.

SV Columns Manager

Product image for SV Columns Manager.
Plugin
SV Columns Manager
Plugin Slug
sv-columns-manager
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

Divi Testimonial Plus

Product image for Divi Testimonial Plus.
Plugin
Divi Testimonial Plus
Plugin Slug
website-testimonials
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 6.1.1.

WP Signals

Product image for WP Signals.
Plugin
WP Signals
Plugin Slug
wp-signals
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

BuddyForms Anonymous Author

Plugin
BuddyForms Anonymous Author
Plugin Slug
buddyforms-anonymous-author
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.

BuddyForms Attach Post with Group

Plugin
BuddyForms Attach Post with Group
Plugin Slug
buddyforms-attach-posts-to-groups-extension
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.3.

BuddyForms Hierarchical Posts

Plugin
BuddyForms Hierarchical Posts
Plugin Slug
buddyforms-hierarchical-posts
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.4.

BuddyForms Posts 2 Posts

Plugin
BuddyForms Posts 2 Posts
Plugin Slug
buddyforms-posts-to-posts-integration
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.

BuddyForms Remote

Plugin
BuddyForms Remote
Plugin Slug
buddyforms-remote
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.5.

Caldera Forms

Plugin
Caldera Forms
Plugin Slug
caldera-forms
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.5.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.7.5.1.

Simple Freemius Shop

Plugin
Simple Freemius Shop
Plugin Slug
checkout-freemius-rewamped
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

Convert Pro

Plugin
Convert Pro
Plugin Slug
convertpro
Vulnerability
Broken Access Control
Patched in Version
1.7.6
Severity Score
High
CVE
2023-36684
The vulnerability has been patched, so you should update to version 1.7.6.

DeMomentSomTres Subscribe

Plugin
DeMomentSomTres Subscribe
Plugin Slug
demomentsomtres-mailchimp-subscribe
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.201903272301
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.201903272301.

DEV.LAND

Product image for DEV.LAND.
Plugin
DEV.LAND
Plugin Slug
dev-land
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.5
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.0.5.

DokoBuilder : DIY Product Bundle for WooCommerce

Plugin
DokoBuilder : DIY Product Bundle for WooCommerce
Plugin Slug
doko-box-builder
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.1.

Expandable Paywall

Product image for Expandable Paywall.
Plugin
Expandable Paywall
Plugin Slug
expandable-paywall
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.17
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.17.

External Media Upload

Plugin
External Media Upload
Plugin Slug
external-media-upload
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.4.

Frontend Admin – Add and edit posts, pages, users and more all from the frontend

Plugin
Frontend Admin – Add and edit posts, pages, users and more all from the frontend
Plugin Slug
frontend-admin
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.8.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.8.0.

Gallery Bank

Plugin
Gallery Bank
Plugin Slug
gallery-bank
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.0.19
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 4.0.19.

Map Plugin alternative to Google Maps using MapQuest, with directions

Plugin
Map Plugin alternative to Google Maps using MapQuest, with directions
Plugin Slug
get-directions
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.16.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.16.2.

Information for help

Plugin
Information for help
Plugin Slug
information-for-help
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.0.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 0.0.3.

Google Maps Plugin by Intergeo

Plugin
Google Maps Plugin by Intergeo
Plugin Slug
intergeo-maps
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.6.

Oxygen Builder

Plugin
Oxygen Builder
Plugin Slug
oxygen
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.4
Severity Score
Medium
CVE
2022-46841
The vulnerability has been patched, so you should update to version 4.4.

Popups

Plugin
Popups
Plugin Slug
popups
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.

Remove WP Update Nags

Plugin
Remove WP Update Nags
Plugin Slug
remove-wp-update-nags
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.5.0.

SV Media Library

Product image for SV Media Library.
Plugin
SV Media Library
Plugin Slug
sv-media-library
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.00.

BuddyPress Groups Integration for WooCommerce

Plugin
BuddyPress Groups Integration for WooCommerce
Plugin Slug
wc4bp-groups
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.1.

WP Cloud Server

Plugin
WP Cloud Server
Plugin Slug
wp-cloud-server
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.0.

WP Native Articles – Instant Articles Plugin for WordPress

Plugin
WP Native Articles – Instant Articles Plugin for WordPress
Plugin Slug
wp-native-articles
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.0.

Schema Pro

Plugin
Schema Pro
Plugin Slug
wp-schema-pro
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.7.8
Severity Score
Medium
CVE
2023-36682
The vulnerability has been patched, so you should update to version 2.7.8.

WP Scrive by Webbstart

Plugin
WP Scrive by Webbstart
Plugin Slug
wp-scrive
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.4.

WPCasa Mail Alert

Plugin
WPCasa Mail Alert
Plugin Slug
wpcasa-mail-alert
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 3.3.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WPS Limit Login

Product image for WPS Limit Login.
Plugin
WPS Limit Login
Plugin Slug
wps-limit-login
Installations
60,000+
Vulnerability
Race Condition
Patched in Version
No Fix
Severity Score
Low
CVE
2023-39160
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Product image for Custom Field Template.
Plugin
Custom Field Template
Plugin Slug
custom-field-template
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-38392
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Icons & Social Share Buttons

Product image for Social Share Icons & Social Share Buttons.
Plugin
Social Share Icons & Social Share Buttons
Plugin Slug
ultimate-social-media-plus
Installations
30,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38514
The vulnerability has not been patched. You should deactivate the plugin.

WP-CopyProtect [Protect your blog posts]

Product image for WP-CopyProtect [Protect your blog posts].
Plugin
WP-CopyProtect [Protect your blog posts]
Plugin Slug
wp-copyprotect
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25025
The vulnerability has not been patched. You should deactivate the plugin.

Elastic Email Sender

Product image for Elastic Email Sender.
Plugin
Elastic Email Sender
Plugin Slug
elastic-email-sender
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38387
The vulnerability has not been patched. You should deactivate the plugin.

GTmetrix for WordPress

Product image for GTmetrix for WordPress.
Plugin
GTmetrix for WordPress
Plugin Slug
gtmetrix-for-wordpress
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37996
The vulnerability has not been patched. You should deactivate the plugin.

Molongui

Product image for Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui.
Plugin
Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui
Plugin Slug
molongui-authorship
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-39164
The vulnerability has not been patched. You should deactivate the plugin.

Pinpoint Booking System

Product image for Pinpoint Booking System – #1 WordPress Booking Plugin.
Plugin
Pinpoint Booking System – #1 WordPress Booking Plugin
Plugin Slug
booking-system
Installations
5,000+
Vulnerability
Content Spoofing
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38520
The vulnerability has not been patched. You should deactivate the plugin.

Borderless

Product image for Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg.
Plugin
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg
Plugin Slug
borderless
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38518
The vulnerability has not been patched. You should deactivate the plugin.

Art Decoration Shortcode

Product image for Art Decoration Shortcode.
Plugin
Art Decoration Shortcode
Plugin Slug
art-decoration-shortcode
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37994
The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Product image for Banner Management For WooCommerce.
Plugin
Banner Management For WooCommerce
Plugin Slug
banner-management-for-woocommerce
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-39158
The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Product image for Fraud Prevention For Woocommerce.
Plugin
Fraud Prevention For Woocommerce
Plugin Slug
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-39159
The vulnerability has not been patched. You should deactivate the plugin.

Google Map Shortcode

Plugin
Google Map Shortcode
Plugin Slug
google-map-shortcode
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38396
The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Product image for MultiParcels Shipping For WooCommerce.
Plugin
MultiParcels Shipping For WooCommerce
Plugin Slug
multiparcels-shipping-for-woocommerce
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Server Info

Product image for Server Info.
Plugin
Server Info
Plugin Slug
server-info
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should deactivate the plugin.

Language

Product image for WordPress Language.
Plugin
WordPress Language
Plugin Slug
wordpress-language
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38383
The vulnerability has not been patched. You should deactivate the plugin.

WP Emoji One

Product image for WP Emoji One.
Plugin
WP Emoji One
Plugin Slug
wp-emoji-one
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37991
The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Product image for WP Quick Post Duplicator.
Plugin
WP Quick Post Duplicator
Plugin Slug
wp-quick-post-duplicator
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-31214
The vulnerability has not been patched. You should deactivate the plugin.

Booster Elementor Addons

Product image for Booster Elementor Addons.
Plugin
Booster Elementor Addons
Plugin Slug
booster-for-elementor
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38480
The vulnerability has not been patched. You should deactivate the plugin.

Instant CSS

Product image for Instant CSS.
Plugin
Instant CSS
Plugin Slug
instant-css
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38483
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Product image for CodeBard's Patron Button and Widgets for Patreon.
Plugin
CodeBard's Patron Button and Widgets for Patreon
Plugin Slug
patron-button-and-widgets-by-codebard
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-30491
The vulnerability has not been patched. You should deactivate the plugin.

Simple Googlebot Visit

Product image for Simple Googlebot Visit.
Plugin
Simple Googlebot Visit
Plugin Slug
simple-googlebot-visit
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38479
The vulnerability has not been patched. You should deactivate the plugin.

QR code MeCard/vCard generator

Product image for QR code MeCard/vCard generator.
Plugin
QR code MeCard/vCard generator
Plugin Slug
wp-qrcode-me-v-card
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38477
The vulnerability has not been patched. You should deactivate the plugin.

WRC Pricing Tables

Product image for WRC Pricing Tables.
Plugin
WRC Pricing Tables
Plugin Slug
wrc-pricing-tables
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38517
The vulnerability has not been patched. You should deactivate the plugin.

Audio Player with Playlist Ultimate

Product image for Audio Player with Playlist Ultimate.
Plugin
Audio Player with Playlist Ultimate
Plugin Slug
audio-player-with-playlist-ultimate
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38516
The vulnerability has not been patched. You should deactivate the plugin.

Client Portal : SuiteDash Direct Login

Product image for Client Portal : SuiteDash Direct Login.
Plugin
Client Portal : SuiteDash Direct Login
Plugin Slug
client-portal-suitedash-login
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38476
The vulnerability has not been patched. You should deactivate the plugin.

Go Fetch Jobs (for WP Job Manager)

Product image for Go Fetch Jobs (for WP Job Manager).
Plugin
Go Fetch Jobs (for WP Job Manager)
Plugin Slug
go-fetch-jobs-wp-job-manager
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Product image for Mobile Address Bar Changer.
Plugin
Mobile Address Bar Changer
Plugin Slug
mobile-address-bar-changer
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38390
The vulnerability has not been patched. You should deactivate the plugin.

Perelink Pro

Plugin
Perelink Pro
Plugin Slug
perelink
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37990
The vulnerability has not been patched. You should deactivate the plugin.

Post List With Featured Image

Plugin
Post List With Featured Image
Plugin Slug
post-list-with-featured-image
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-37997
The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Product image for Post Affiliate Pro.
Plugin
Post Affiliate Pro
Plugin Slug
postaffiliatepro
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38482
The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.
Plugin
Remove Duplicate Posts
Plugin Slug
remove-duplicate-posts
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-29237
The vulnerability has not been patched. You should deactivate the plugin.

Donations Made Easy – Smart Donations

Product image for Donations Made Easy – Smart Donations.
Plugin
Donations Made Easy – Smart Donations
Plugin Slug
smart-donations
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38475
The vulnerability has not been patched. You should deactivate the plugin.

Taboola

Product image for Taboola.
Plugin
Taboola
Plugin Slug
taboola
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38398
The vulnerability has not been patched. You should deactivate the plugin.

Exifography

Product image for Exifography.
Plugin
Exifography
Plugin Slug
thesography
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38521
The vulnerability has not been patched. You should deactivate the plugin.

Onepage Builder – Easiest Landing Page Builder For WordPress

Product image for Onepage Builder – Easiest Landing Page Builder For WordPress.
Plugin
Onepage Builder – Easiest Landing Page Builder For WordPress
Plugin Slug
tx-onepager
Installations
1,000+
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38391
The vulnerability has not been patched. You should deactivate the plugin.

eaSYNC

Product image for Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC.
Plugin
Free Booking Plugin for Hotels, Restaurant and Car Rental – eaSYNC
Plugin Slug
easync-booking
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-38384
The vulnerability has not been patched. You should deactivate the plugin.

Post Connector

Product image for Post Connector.
Plugin
Post Connector
Plugin Slug
post-connector
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-28931
The vulnerability has not been patched. You should deactivate the plugin.

Smarty for WordPress

Plugin
Smarty for WordPress
Plugin Slug
smarty-for-wordpress
Installations
100+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37992
The vulnerability has not been patched. You should deactivate the plugin.

Gestion-Pymes

Product image for Gestion-Pymes.
Plugin
Gestion-Pymes
Plugin Slug
gestion-pymes
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38397
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Delivery Date Premium

Product image for Woocommerce Delivery Date Premium.
Plugin
Woocommerce Delivery Date Premium
Plugin Slug
woocommerce-delivery-date
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should deactivate the plugin.

bbResolutions

Plugin
bbResolutions
Plugin Slug
bbresolutions
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BlogPost – BlogPost Widgets – Amazing Blog Layouts

Plugin
BlogPost – BlogPost Widgets – Amazing Blog Layouts
Plugin Slug
blogpost-widgets
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CF7 Constant Contact Fields Mapping

Plugin
CF7 Constant Contact Fields Mapping
Plugin Slug
cf7-constant-contact-fields-mapping
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

Plugin
WP Clone Menu
Plugin Slug
clone-menu
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38395
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DancePress (TRWA)

Plugin
DancePress (TRWA)
Plugin Slug
dancepress-trwa
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DeMomentSomTres Immediate Send

Plugin
DeMomentSomTres Immediate Send
Plugin Slug
demomentsomtres-mailchimp-immediate-send
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Disabler

Plugin
Disabler
Plugin Slug
disabler
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-37998
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Easy Call Now Button by elixirs.io

Plugin
WordPress Easy Call Now Button by elixirs.io
Plugin Slug
easy-call-now-button
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Extend Filter Products By Price Widget

Plugin
Extend Filter Products By Price Widget
Plugin Slug
extend-filter-products-by-price-widget
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Easy Responsive Pricing Tables

Plugin
Easy Responsive Pricing Tables
Plugin Slug
fullworks-pricing-tables
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Jupiter X Core

Plugin
JupiterX Core
Plugin Slug
jupiterx-core
Vulnerability
Arbitrary File Download
Patched in Version
No Fix
Severity Score
High
CVE
2023-3813
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Logger

Product image for WP Logger.
Plugin
WP Logger
Plugin Slug
lite-wp-logger
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin
LWS Affiliation
Plugin Slug
lws-affiliation
Vulnerability
Local File Inclusion
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-32297
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Menu Item Scheduler

Plugin
Menu Item Scheduler
Plugin Slug
menu-item-scheduler
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Protect Uploads with Login – Protect Your Uploads

Plugin
Protect Uploads with Login – Protect Your Uploads
Plugin Slug
protect-uploads-with-login-page
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

Plugin
Quasar form
Plugin Slug
quasar-form
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2023-35910
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Role Based Bulk Quantity Pricing

Plugin
Role Based Bulk Quantity Pricing
Plugin Slug
role-based-bulk-quantity-pricing
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder for Gutenberg – StarterBlocks

Plugin
Page Builder for Gutenberg – StarterBlocks
Plugin Slug
starterblocks
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Subscribe to Category

Plugin
Subscribe to Category
Plugin Slug
subscribe-to-category
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-32590
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

Plugin
tagDiv Composer
Plugin Slug
td-composer
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2023-39166
The vulnerability has not been patched. You should deactivate the plugin.

Ultra Elementor Addons

Plugin
Ultra Elementor Addons
Plugin Slug
ultra-elementor-addons
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Auto SEO Plugin – Upfiv SEO Wizard

Plugin
WordPress Auto SEO Plugin – Upfiv SEO Wizard
Plugin Slug
upfiv-complete-all-in-one-seo-wizard
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

Plugin
User Email Verification for WooCommerce
Plugin Slug
woo-confirmation-email
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-39162
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-FlyBox

Plugin
WP-FlyBox
Plugin Slug
wp-flybox
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-38381
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WooCommerce Sync for Google Sheet

Plugin
WordPress WooCommerce Sync for Google Sheet
Plugin Slug
wp-woo-commerce-sync-for-g-sheet
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bootstrap Blog

Product image for Bootstrap Blog.
Theme
Bootstrap Blog
Theme Slug
bootstrap-blog
Downloads
87,177
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.2.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 10.2.3.

Ona

Product image for Ona.
Theme
Ona
Theme Slug
ona
Downloads
86,847
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.18.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.18.3.

Yuki

Product image for Yuki.
Theme
Yuki
Theme Slug
yuki
Downloads
74,316
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Techism

Product image for Techism.
Theme
Techism
Theme Slug
techism
Downloads
58,069
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Chic Lifestyle

Product image for Chic Lifestyle.
Theme
Chic Lifestyle
Theme Slug
chic-lifestyle
Downloads
57,532
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.0.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 10.0.8.

Lifestyle Magazine

Product image for Lifestyle Magazine.
Theme
Lifestyle Magazine
Theme Slug
lifestyle-magazine
Downloads
49,638
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.2.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 10.2.1.

SalesZone

Product image for SalesZone.
Theme
SalesZone
Theme Slug
saleszone
Downloads
45,813
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Travel Tour

Product image for Travel Tour.
Theme
Travel Tour
Theme Slug
travel-tour
Downloads
39,431
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.0.

Brand

Product image for Brand.
Theme
Brand
Theme Slug
brand
Downloads
32,911
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

WP Sierra

Product image for WP Sierra.
Theme
WP Sierra
Theme Slug
wp-sierra
Downloads
31,861
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Eighteen tags

Product image for Eighteen tags.
Theme
Eighteen tags
Theme Slug
eighteen-tags
Downloads
26,056
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Hasium

Product image for Hasium.
Theme
Hasium
Theme Slug
hasium
Downloads
23,338
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Broadcast Lite

Product image for Broadcast Lite.
Theme
Broadcast Lite
Theme Slug
broadcast-lite
Downloads
21,268
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.0.8.

Salzburg Blog

Product image for Salzburg Blog.
Theme
Salzburg Blog
Theme Slug
salzburg-blog
Downloads
21,114
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Everse

Product image for Everse.
Theme
Everse
Theme Slug
everse
Downloads
19,143
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.12
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.8.12.

Speculor

Product image for Speculor.
Theme
Speculor
Theme Slug
speculor
Downloads
17,306
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Meridia

Product image for Meridia.
Theme
Meridia
Theme Slug
meridia
Downloads
16,976
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.2.8
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 2.2.8.

Aquarella Lite

Product image for Aquarella Lite.
Theme
Aquarella Lite
Theme Slug
aquarella-lite
Downloads
16,673
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Consultpress Lite

Product image for ConsultPress Lite.
Theme
ConsultPress Lite
Theme Slug
consultpress-lite
Downloads
15,868
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Topcat Lite

Product image for Topcat Lite.
Theme
Topcat Lite
Theme Slug
topcat-lite
Downloads
15,747
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Shuban

Product image for Shuban.
Theme
Shuban
Theme Slug
shuban
Downloads
13,783
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Purus

Product image for Purus.
Theme
Purus
Theme Slug
purus
Downloads
13,561
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Elation

Product image for Elation.
Theme
Elation
Theme Slug
elation
Downloads
13,250
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

GutenBook

Product image for GutenBook.
Theme
GutenBook
Theme Slug
gutenbook
Downloads
13,216
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Chained

Product image for Chained.
Theme
Chained
Theme Slug
chained
Downloads
12,157
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Elasta

Product image for Elasta.
Theme
Elasta
Theme Slug
elasta
Downloads
11,744
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.9.

Purosa

Product image for Purosa.
Theme
Purosa
Theme Slug
purosa
Downloads
11,224
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.3.

LearnMore

Product image for LearnMore.
Theme
LearnMore
Theme Slug
learnmore
Downloads
9,915
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

WPCake

Product image for WPCake.
Theme
WPCake
Theme Slug
wpcake
Downloads
8,708
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Nokke

Product image for Nokke.
Theme
Nokke
Theme Slug
nokke
Downloads
8,472
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.4
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.4.

Arendelle

Product image for Arendelle.
Theme
Arendelle
Theme Slug
arendelle
Downloads
8,463
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.13
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.13.

PixiGo

Product image for PixiGo.
Theme
PixiGo
Theme Slug
pixigo
Downloads
7,670
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

WP Moose

Product image for WP Moose.
Theme
WP Moose
Theme Slug
wp-moose
Downloads
7,516
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

G Blog

Product image for G Blog.
Theme
G Blog
Theme Slug
g-blog
Downloads
6,993
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

NicheBase

Product image for NicheBase.
Theme
NicheBase
Theme Slug
nichebase
Downloads
6,985
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.3
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.2.3.

Cuisine Palace

Product image for Cuisine Palace.
Theme
Cuisine Palace
Theme Slug
cuisine-palace
Downloads
6,091
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Amela

Product image for Amela.
Theme
Amela
Theme Slug
amela
Downloads
6,063
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.14
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.14.

Agncy

Product image for Agncy.
Theme
Agncy
Theme Slug
agncy
Downloads
6,032
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Travel Agency Booking

Product image for Travel Agency Booking.
Theme
Travel Agency Booking
Theme Slug
travel-agency-booking
Downloads
5,703
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Bootstrap Fitness

Product image for Bootstrap Fitness.
Theme
Bootstrap Fitness
Theme Slug
bootstrap-fitness
Downloads
5,569
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.6
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.6.

Bootstrap Coach

Product image for Bootstrap Coach.
Theme
Bootstrap Coach
Theme Slug
bootstrap-coach
Downloads
5,146
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.2
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.2.

Blockst

Product image for Blockst.
Theme
Blockst
Theme Slug
blockst
Downloads
3,309
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.0.9.

Relax Spa

Product image for Relax Spa.
Theme
Relax Spa
Theme Slug
relax-spa
Downloads
2,572
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
CVE
2023-33999
The vulnerability has been patched, so you should update to version 1.1.1.

Villar

Product image for Villar.
Theme
Villar
Theme Slug
villar
Downloads
3,995
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

BlogHub

Product image for BlogHub.
Theme
BlogHub
Theme Slug
bloghub
Downloads
3,575
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Viralike

Product image for Viralike.
Theme
Viralike
Theme Slug
viralike
Downloads
3,245
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

NewsHit

Product image for NewsHit.
Theme
NewsHit
Theme Slug
newshit
Downloads
3,073
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Simplifii

Product image for Simplifii.
Theme
Simplifii
Theme Slug
simplifii
Downloads
2,700
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Roven Blog

Product image for Roven Blog.
Theme
Roven Blog
Theme Slug
roven-blog
Downloads
2,598
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Krste

Product image for Krste.
Theme
Krste
Theme Slug
krste
Downloads
2,526
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Unakit

Product image for Unakit.
Theme
Unakit
Theme Slug
unakit
Downloads
2,259
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Temp Mail X

Product image for Temp Mail X.
Theme
Temp Mail X
Theme Slug
temp-mail-x
Downloads
2,215
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Rovenstart

Product image for Rovenstart.
Theme
Rovenstart
Theme Slug
rovenstart
Downloads
1,845
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.

Bani

Theme
Bani
Theme Slug
bani
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-33999
The vulnerability has not been patched. You should switch themes.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023
WordPress vulnerability report
WordPress Vulnerability Report – August 9, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.