WordPress Vulnerability Report

WordPress Vulnerability Report – March 1, 2023

Vulnerable plugins and themes are some of the most common vectors for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, now powered by Patchstack, covers new WordPress plugins, themes, and core vulnerabilities that have emerged since last week's report. Our goal is to help you decide what to do if you are using one of these vulnerable plugins or themes on your website.

Avatar photo
SolidWP Editorial Team

Vulnerable plugins and themes are some of the most common vectors for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, now powered by Patchstack, covers new WordPress plugins, themes, and core vulnerabilities that have emerged since last week’s report. Our goal is to help you decide what to do if you are using one of these vulnerable plugins or themes on your website. For a deeper, historical analysis of WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, ensure your site is backed up with BackupBuddy before updating.

WordPress 6.2 Beta 4

WordPress 6.2 Beta 4 rolled out today for testing after being postponed for a few days to deal with a regression. As of Beta 4, over 400 Trac issues have been raised and closed this cycle. The current target for the final release date is still March 28, 2023.

So far, the 6.2 release cycle has made more than 292 enhancements and 354 bug fixes just for the editor. A running total of 289 tickets have been closed in Trac for the 6.2 milestone, with more to come.

In the final 6.2 release, expect to see tight integration with Openverse in the editor and media library. The Navigation block has been significantly improved. A new Style Book feature displays all blocks in the current global styles, and there’s new custom CSS support for your full site and individual blocks. For more details on new features in 6.2, see the Beta 1 release news.

With the arrival of WordPress 6.2, Phase Two of Gutenberg’s development will have ended. Phase Two focused on the Block and Site Editor features that now allow deep customization of site designs and layouts. Next, Phase Three will focus on collaborative editing features. Take a look at the WordPress Development Roadmap to learn more.

Gutenberg 15.2

The latest release of the Gutenberg plugin, version 15.2, is available now if you’d like to get a preview of bleeding-edge features. Please note the 15.2 release offers new features that will be included in the WordPress 6.3 core release but not 6.2. These features include revisions for the full site template editor so you can roll back changes to site templates.

Other new features of note in Gutenberg 15.2 are CSS aspect-ratio controls for the Featured Image block for posts and support for border color, style, and width in the Button block. There’s new typography support for the Latest Comments block, and the Post Excerpt block will have an excerpt length limit control. You’ll find accessibility improvements to labeling, tab, arrow key navigation, and the hierarchy of headings in the editor interface. See the version notes for the full details about many other enhancements and bug fixes.

No new WordPress core vulnerabilities were disclosed this week.

Get SolidWP tips direct in your inbox

Sign up

This field is for validation purposes and should be left unchanged.
Placeholder text
Placeholder text
Thanks

Oops something went wrong, please try submitting again

Get started with confidence — risk free, guaranteed

WordPress Plugin Vulnerabilities

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

WordPress Advanced Database Cleaner plugin

Plugin Slug:
advanced-database-cleaner
Installations:
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

WordPress Strong Testimonials plugin

Plugin Slug:
strong-testimonials
Installations:
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

WordPress VK All in One Expansion Unit plugin

Plugin Slug:
vk-all-in-one-expansion-unit
Installations:
100,000+
Vulnerability:
Reflected Cross-Site Scripting via REQUEST_URI
Patched in Version:
9.87.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.87.1.0.
Plugin Slug:
contextual-related-posts
Installations:
70,000+
Vulnerability:
Missing Authorization in crp_ajax_clearcache
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

WordPress Media Library Assistant plugin

Plugin Slug:
media-library-assistant
Installations:
70,000+
Vulnerability:
Admin+ SQL Injection
Patched in Version:
3.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.06.

WordPress wpDataTables – WordPress Tables & Table Charts Plugin plugin

Plugin Slug:
wpdatatables
Installations:
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.50
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.50.

WordPress WP Table Builder – WordPress Table Plugin plugin

Plugin Slug:
wp-table-builder
Installations:
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.7.

WordPress Drag and Drop Multiple File Upload – Contact Form 7 plugin

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations:
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.6.

WordPress Feed Them Social – for Twitter feed, Youtube and more plugin

Plugin Slug:
feed-them-social
Installations:
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

WordPress Top 10 plugin

Plugin Slug:
top-10
Installations:
30,000+
Vulnerability:
Insufficient Authorization
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

WordPress Minify HTML plugin

Plugin Slug:
minify-html-markup
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

WordPress Redirect Redirection plugin

Plugin Slug:
redirect-redirection
Installations:
20,000+
Vulnerability:
Multiple Missing Authorization
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

WordPress WP Meta SEO plugin

Plugin Slug:
wp-meta-seo
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF) via 'regenerateSitemaps'
Patched in Version:
4.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.4.

WordPress WP Meta SEO plugin

Plugin Slug:
wp-meta-seo
Installations:
20,000+
Vulnerability:
Authenticated (Subscriber+) SQL Injection
Patched in Version:
4.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.3.

WordPress Maspik – Spam blacklist plugin

Plugin Slug:
contact-forms-anti-spam
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.9.

WordPress Paytm Payment Gateway plugin

Plugin Slug:
paytm-payments
Installations:
10,000+
Vulnerability:
SQL Injection
Patched in Version:
2.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.7.

WordPress Japanized For WooCommerce plugin

Plugin Slug:
woocommerce-for-japan
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.5.

WordPress My YouTube Channel plugin

Plugin Slug:
youtube-channel
Installations:
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.23.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.23.4.

WordPress WordPress Tooltips plugin

Plugin Slug:
wordpress-tooltips
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.7.

WordPress Client Portal plugin

Plugin Slug:
client-portal
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

WordPress Etsy Shop plugin

Plugin:
Etsy Shop
Plugin Slug:
etsy-shop
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

WordPress WPMobile.App — Android and iOS Mobile Application plugin

Plugin Slug:
wpappninja
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.19.

WordPress Dashboard Widgets Suite plugin

Plugin Slug:
dashboard-widgets-suite
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Publish to Schedule plugin

Plugin Slug:
publish-to-schedule
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

WordPress Publish to Schedule plugin

Plugin Slug:
publish-to-schedule
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.4.
Plugin Slug:
read-more-excerpt-link
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.
Plugin Slug:
wp-auto-affiliate-links
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.0.3.

WordPress Integration for Contact Form 7 and Zoho CRM, Bigin plugin

Plugin Slug:
cf7-zoho
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

WordPress Sp*tify Play Button for WordPress plugin

Plugin Slug:
spotify-play-button-for-wordpress
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.06.

WordPress Drag and Drop Multiple File Upload for WooCommerce plugin

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce
Installations:
3,000+
Vulnerability:
Unauth. Non-arbitrary file upload/deletion
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

WordPress We’re Open! plugin

Plugin Slug:
opening-hours
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.47
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.47.

WordPress Simple YouTube Responsive plugin

Plugin Slug:
simple-youtube-responsive
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

WordPress WP Custom Fields Search plugin

Plugin Slug:
wp-custom-fields-search
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.35.

WordPress KB Support – WordPress Help Desk plugin

Plugin Slug:
kb-support
Installations:
2,000+
Vulnerability:
CSV Injection
Patched in Version:
1.5.85
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.85.

WordPress Multiple Pages Generator by Themeisle plugin

Plugin Slug:
multiple-pages-generator-by-porthas
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.10.

WordPress Simple Slug Translate plugin

Plugin Slug:
simple-slug-translate
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.
Plugin Slug:
wp-books-gallery
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.9.

WordPress Accordions – Multiple Accordions or FAQs Builder plugin

Plugin Slug:
accordions-or-faqs
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

WordPress Clio Grow plugin

Plugin:
Clio Grow
Plugin Slug:
clio-grow-form
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

WordPress Calendar Event Multi View plugin

Plugin Slug:
cp-multi-view-calendar
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.15
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.4.15.

WordPress Sheets To WP Table Live Sync plugin

Plugin Slug:
sheets-to-wp-table-live-sync
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.0.

WordPress WP Dynamic Keywords Injector plugin

Plugin Slug:
wp-dynamic-keywords-injector
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.16.

WordPress WordPress Stripe Donation plugin

Plugin Slug:
wp-stripe-donation
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.6.

WordPress CM Answers plugin

Plugin:
CM Answers
Plugin Slug:
cm-answers
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

WordPress Coupon Zen plugin

Plugin:
Coupon Zen
Plugin Slug:
coupon-zen
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

WordPress Houzez Login Register plugin

Plugin Slug:
houzez-login-register
Vulnerability:
Privilege Escalation
Patched in Version:
2.6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.4.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WordPress All In One Favicon plugin

Plugin Slug:
all-in-one-favicon
Installations:
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Apollo13 Framework Extensions plugin

Plugin Slug:
apollo13-framework-extensions
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Markup plugin

Plugin Slug:
wp-structuring-markup
Installations:
30,000+
Vulnerability:
Contributor+ Stored XSS via Shortcode
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress TypeSquare Webfonts for ConoHa plugin

Plugin Slug:
ts-webfonts-for-conoha
Installations:
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Login Logout Menu plugin

Plugin Slug:
baw-login-logout-menu
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Jobs for WordPress plugin

Plugin Slug:
job-postings
Installations:
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress For the visually impaired plugin

Plugin Slug:
for-the-visually-impaired
Installations:
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Admin Block Country plugin

Plugin Slug:
admin-block-country
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Hero Banner Ultimate plugin

Plugin Slug:
hero-banner-ultimate
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Tweaker plugin

Plugin Slug:
theme-tweaker-lite
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Booking Ultra Pro Appointments Booking Calendar Plugin plugin

Plugin Slug:
booking-ultra-pro
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Easy Google Analytics for WordPress plugin

Plugin Slug:
easy-google-analytics-for-wordpress
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress GMAce plugin

Plugin:
GMAce
Plugin Slug:
gmace
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress GMAce plugin

Plugin:
GMAce
Plugin Slug:
gmace
Installations:
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress JS Job Manager plugin

Plugin Slug:
js-jobs
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress phpinfo() WP plugin

Plugin Slug:
phpinfo-wp
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Google Tag Manager plugin

Plugin Slug:
wp-google-tag-manager
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Bing Site Verification plugin using Meta Tag plugin

Plugin Slug:
bing-site-verification-using-meta-tag
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WordPress Custom Settings plugin

Plugin Slug:
custom-settings
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Exquisite PayPal Donation plugin

Plugin Slug:
exquisite-paypal-donation
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Sitemap Index plugin

Plugin Slug:
sitemap-index
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
sponsors-carousel
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Stock market charts from finviz plugin

Plugin Slug:
stock-market-charts-from-finviz
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP-RecentComments plugin

Plugin Slug:
wp-recentcomments
Installations:
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP-RecentComments plugin

Plugin Slug:
wp-recentcomments
Installations:
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
circles-gallery
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Upload Resume plugin

Plugin Slug:
resume-upload-form
Installations:
600+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Educare – Students & Result Management System plugin

Plugin Slug:
educare
Installations:
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Custom Login Page plugin

Plugin Slug:
wp-custom-login-page
Installations:
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress asMember plugin

Plugin:
asMember
Plugin Slug:
asmember
Installations:
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Chat Bee plugin

Plugin:
Chat Bee
Plugin Slug:
chat-bee
Installations:
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-portfolio-gallery
Installations:
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Conditional Checkout Fields for WooCommerce plugin

Plugin Slug:
conditional-checkout-fields-for-woocommerce
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CPT – Speakers plugin

Plugin Slug:
cpt-speakers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress PayGreen plugin

Plugin:
PayGreen
Plugin Slug:
paygreen-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Social Login WP plugin

Plugin Slug:
social-login-wp
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Zendrop – Global Dropshipping plugin

Plugin Slug:
zendrop-dropshipping-and-fulfillment
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Zendrop – Global Dropshipping plugin

Plugin Slug:
zendrop-dropshipping-and-fulfillment
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

WordPress OceanWP theme

Theme:
OceanWP
Theme Slug:
oceanwp
Downloads:
5,960,838
Vulnerability:
Authenticated Local File Inclusion
Patched in Version:
3.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.2.

WordPress darcie theme

Theme:
Darcie
Theme Slug:
darcie
Downloads:
14,649
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.6.

WordPress Houzez theme

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.2.

WordPress Real Estate 7 theme

Theme Slug:
realestate-7
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

Did you like this article? Spread the word: