This week, the total patched and unpatched vulnerabilities may impact well over 9 million WordPress sites. There are 84 plugin vulnerabilities and one theme vulnerability with security patches available, so run those updates if you use these plugins! Additionally, there are 39 plugin vulnerabilities and 3 theme vulnerabilities with no patch available yet. If you use any of these unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or a vulnerable plugin or theme has been “closed” (dropped from the WordPress.org repository), you should consider deactivating it in favor of alternative solutions.
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
The Future of Authentication is Passkeys! Log into your WordPress site with Biometrics only available in iThemes Security Pro.
Credential stuffing, phishing, and brute force attacks using stolen, guessable, or reused passwords have made our digital lives less secure. Two-Factor Authentication (2FA) offers some protection but at the cost of usability and accessibility. Fewer than 30% of all online account holders actually use 2FA. Password-based logins are broken.
The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.
WordPress Core News
WordPress 6.1.1 is the current (short-cycle maintenance) release of WordPress core. It is a minor release issued on November 15, 2022. It features 29 bug fixes in Core and 21 bug fixes for the Gutenberg block editor. You can review a summary of the key updates in this release at WordPress.org.
If your WordPress sites have enabled automatic background updates, they should have upgraded to 6.1.1 automatically. You can download WordPress 6.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates,” and then click the “Update Now” button which will appear when any core updates are available. For more information, check out the version 6.1.1 HelpHub documentation page.
WordPress 6.2 is the next major WordPress release, and it’s on track for a March 28, 2023 debut. You can learn more about what’s coming in the WordPress 6.2 RC1 release announcement and the WordPress 6.2 Field Guide.
WordPress Plugin Vulnerabilities with Patches
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.
UpdraftPlus PRO

- Plugin Slug
- updraftplus
- Installations
- 3,000,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.23.3
- Severity Score
- High
UpdraftPlus

- Plugin Slug
- updraftplus
- Installations
- 3,000,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.23.3
- Severity Score
- High
Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Plugin

- Plugin Slug
- ml-slider
- Installations
- 700,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.28.1
- Severity Score
- Medium
- CVE
- 2022-47150
Easy Table of Contents

- Plugin
- Easy Table of Contents
- Plugin Slug
- easy-table-of-contents
- Installations
- 400,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 2.0.46
- Severity Score
- Medium
- CVE
- 2023-25469
Happy Addons for Elementor

- Plugin Slug
- happy-elementor-addons
- Installations
- 300,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.8.0
- Severity Score
- Medium
- CVE
- 2022-47150
Squirrly SEO (Peaks)

- Plugin Slug
- squirrly-seo
- Installations
- 200,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 12.1.21
- Severity Score
- Medium
- CVE
- 2022-44626
Squirrly SEO (Peaks)

- Plugin Slug
- squirrly-seo
- Installations
- 200,000+
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- 12.1.21
- Severity Score
- High
- CVE
- 2022-45065
WP Mail Logging

- Plugin
- WP Mail Logging
- Plugin Slug
- wp-mail-logging
- Installations
- 200,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.11.0
- Severity Score
- Medium
- CVE
- 2022-47150
WPML
- Plugin
- WPML – WordPress Multilingual
- Plugin Slug
- wpml
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 4.6.1
- Severity Score
- High
WordPress Ping Optimizer

- Plugin
- WordPress Ping Optimizer
- Plugin Slug
- wordpress-ping-optimizer
- Installations
- 70,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.35.1.3.0
- Severity Score
- Medium
- CVE
- 2022-30705
Bookly

- Plugin Slug
- bookly-responsive-appointment-booking-tool
- Installations
- 60,000+
- Vulnerability
- Unauthenticated Stored Cross-Site Scripting via Name vulnerability
- Patched in Version
- 21.5.1
- Severity Score
- High
- CVE
- 2023-1172
User Registration

- Plugin Slug
- user-registration
- Installations
- 60,000+
- Vulnerability
- Authenticated PHP Object Injection
- Patched in Version
- 2.3.3
- Severity Score
- High
- CVE
- 2023-27459
Exclusive Addons for Elementor

- Plugin Slug
- exclusive-addons-for-elementor
- Installations
- 40,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.6.2
- Severity Score
- Medium
- CVE
- 2022-47150
Ecwid Ecommerce Shopping Cart

- Plugin Slug
- ecwid-shopping-cart
- Installations
- 30,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 6.11.5
- Severity Score
- Medium
- CVE
- 2023-24408
Subscribe2 – Form, Email Subscribers & Newsletters

- Plugin Slug
- subscribe2
- Installations
- 30,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 10.38
- Severity Score
- Medium
- CVE
- 2022-47150
WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin

- Plugin Slug
- wp-user-frontend
- Installations
- 30,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.6.1
- Severity Score
- Medium
- CVE
- 2022-47150
Advanced Product Labels for WooCommerce

- Plugin Slug
- advanced-product-labels-for-woocommerce
- Installations
- 20,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.2.4.1
- Severity Score
- Medium
- CVE
- 2022-45813
Branda

- Plugin Slug
- branda-white-labeling
- Installations
- 20,000+
- Vulnerability
- Authenticated (Administrator+) Stored Cross-Site Scripting
- Patched in Version
- 3.4.9
- Severity Score
- Medium
Dashboard Welcome for Elementor

- Plugin Slug
- dashboard-welcome-for-elementor
- Installations
- 20,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.0.7
- Severity Score
- Medium
- CVE
- 2022-47150
Load More Products for WooCommerce

- Plugin Slug
- load-more-products-for-woocommerce
- Installations
- 20,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.1.9.8
- Severity Score
- Medium
- CVE
- 2022-45813
Min and Max Quantity for WooCommerce

- Plugin Slug
- minmax-quantity-for-woocommerce
- Installations
- 20,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.3.2.7
- Severity Score
- Medium
- CVE
- 2022-45813
Product Gallery Slider for WooCommerce

- Plugin Slug
- woo-product-gallery-slider
- Installations
- 20,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.2.7
- Severity Score
- Medium
- CVE
- 2022-47150
WP Simple Shopping Cart

- Plugin Slug
- wordpress-simple-paypal-shopping-cart
- Installations
- 20,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 4.6.4
- Severity Score
- Medium
- CVE
- 2023-1431
Store Locator WordPress

- Plugin
- Store Locator WordPress
- Plugin Slug
- agile-store-locator
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.4.10
- Severity Score
- Medium
- CVE
- 2023-27618
Contact Form 7 – PayPal & Stripe Add-on

- Plugin Slug
- contact-form-7-paypal-add-on
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.9.4
- Severity Score
- Medium
- CVE
- 2023-24405
Contact Form Email

- Plugin
- Contact Form Email
- Plugin Slug
- contact-form-to-email
- Installations
- 10,000+
- Vulnerability
- Missing Authorization Leading To Feedback Submission
- Patched in Version
- 1.3.32
- Severity Score
- Medium
- CVE
- 2023-28494
eCommerce Product Catalog

- Plugin Slug
- ecommerce-product-catalog
- Installations
- 10,000+
- Vulnerability
- Authenticated (Administrator+) Stored Cross-Site Scripting
- Patched in Version
- 3.3.9
- Severity Score
- Medium
- CVE
- 2023-1470
Hotel Booking Lite

- Plugin
- Hotel Booking Lite
- Plugin Slug
- motopress-hotel-booking-lite
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 4.7.0
- Severity Score
- Medium
- CVE
- 2023-28498
Slideshow Gallery LITE

- Plugin
- Slideshow Gallery LITE
- Plugin Slug
- slideshow-gallery
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.7.7
- Severity Score
- Medium
- CVE
- 2023-28497
Slideshow Gallery LITE

- Plugin
- Slideshow Gallery LITE
- Plugin Slug
- slideshow-gallery
- Installations
- 10,000+
- Vulnerability
- SQL Injection
- Patched in Version
- 1.7.7
- Severity Score
- Medium
- CVE
- 2023-28491
Woostify Sites Library

- Plugin
- Woostify Sites Library
- Plugin Slug
- woostify-sites-library
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.4.4
- Severity Score
- Medium
- CVE
- 2022-47150
WP Dark Mode – Best Dark Mode & Social Sharing Plugin for WordPress

- Plugin Slug
- wp-dark-mode
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.0.5
- Severity Score
- Medium
- CVE
- 2022-47150
WP VR – 360 Panorama and Virtual Tour Builder For WordPress

- Plugin Slug
- wpvr
- Installations
- 10,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 8.2.6
- Severity Score
- Medium
- CVE
- 2022-47150
Fluid Checkout for WooCommerce – Lite

- Plugin Slug
- fluid-checkout
- Installations
- 9,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.3.2
- Severity Score
- Medium
Event Manager for WooCommerce

- Plugin Slug
- mage-eventpress
- Installations
- 9,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.8.7
- Severity Score
- Medium
- CVE
- 2023-28422
Event Manager and Tickets Selling Plugin for WooCommerce

- Plugin Slug
- mage-eventpress
- Installations
- 9,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.7.8
- Severity Score
- Medium
- CVE
- 2022-47164
Team Member – Team with Slider

- Plugin Slug
- team-showcase-supreme
- Installations
- 9,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 4.5
- Severity Score
- Medium
- CVE
- 2023-23647
SMTP2GO

- Plugin Slug
- smtp2go
- Installations
- 8,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.5.0
- Severity Score
- Medium
- CVE
- 2023-28496
ProfileGrid

- Plugin Slug
- profilegrid-user-profiles-groups-and-communities
- Installations
- 7,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 5.0.4
- Severity Score
- Medium
- CVE
- 2022-36352
Brands for WooCommerce

- Plugin
- Brands for WooCommerce
- Plugin Slug
- brands-for-woocommerce
- Installations
- 6,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.7.0.6
- Severity Score
- Medium
- CVE
- 2022-45813
Contact Form 7 Redirect & Thank You Page
- Plugin Slug
- cf7-redirect-thank-you-page
- Installations
- 6,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.0.4
- Severity Score
- Medium
- CVE
- 2023-24395
Boostify Header Footer Builder for Elementor

- Plugin Slug
- boostify-header-footer-builder
- Installations
- 5,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.9
- Severity Score
- Medium
- CVE
- 2022-47150
Modern Footnotes

- Plugin
- Modern Footnotes
- Plugin Slug
- modern-footnotes
- Installations
- 5,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.4.16
- Severity Score
- Medium
- CVE
- 2023-28423
Open Graphite

- Plugin
- Open Graphite
- Plugin Slug
- open-graphite
- Installations
- 5,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.6.1
- Severity Score
- High
- CVE
- 2022-47439
W4 Post List

- Plugin
- W4 Post List
- Plugin Slug
- w4-post-list
- Installations
- 5,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.4.3
- Severity Score
- Medium
- CVE
- 2022-47150
Grid List View for WooCommerce

- Plugin Slug
- gridlist-view-for-woocommerce
- Installations
- 4,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.1.3.7
- Severity Score
- Medium
- CVE
- 2022-45813
Cart Notices for WooCommerce

- Plugin Slug
- cart-notices-for-woocommerce
- Installations
- 3,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Click to top

- Plugin
- Click to top
- Plugin Slug
- click-to-top
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.20
- Severity Score
- Medium
- CVE
- 2022-47150
Force First and Last Name as Display Name

- Plugin Slug
- force-first-last
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.1
- Severity Score
- Medium
- CVE
- 2023-28419
Gallery Box

- Plugin
- Gallery Box
- Plugin Slug
- gallery-box
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.7.31
- Severity Score
- Medium
- CVE
- 2022-47150
Magical Posts Display – Elementor & Gutenberg Posts Blocks

- Plugin Slug
- magical-posts-display
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.16
- Severity Score
- Medium
- CVE
- 2022-47150
wePOS – Point Of Sale (POS) for WooCommerce

- Plugin Slug
- wepos
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.6
- Severity Score
- Medium
- CVE
- 2022-47150
WP Email Capture

- Plugin Slug
- wp-email-capture
- Installations
- 3,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 3.11
- Severity Score
- Medium
- CVE
- 2023-28421
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

- Plugin Slug
- cart-lift
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 3.1.4
- Severity Score
- Medium
- CVE
- 2022-47150
WP Markdown Editor (Formerly Dark Mode)

- Plugin Slug
- dark-mode
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 4.1.3
- Severity Score
- Medium
- CVE
- 2022-47150
GS Testimonial Slider

- Plugin
- GS Testimonial Slider
- Plugin Slug
- gs-testimonial
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.9.8
- Severity Score
- Medium
- CVE
- 2022-47150
Product Tabs Manager for WooCommerce

- Plugin Slug
- product-tabs-manager-for-woocommerce
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.1.5.8
- Severity Score
- Medium
- CVE
- 2022-45813
Product Watermark for WooCommerce

- Plugin Slug
- product-watermark-for-woocommerce
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.3.5.7
- Severity Score
- Medium
- CVE
- 2022-45813
Stylish Cost Calculator

- Plugin
- Stylish Cost Calculator
- Plugin Slug
- stylish-cost-calculator
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 7.3.7
- Severity Score
- Medium
- CVE
- 2022-47150
Terms and Conditions Popup for WooCommerce

- Plugin Slug
- terms-and-conditions-popup-for-woocommerce
- Installations
- 2,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Webinar and Video Conference with Jitsi Meet

- Plugin Slug
- webinar-and-video-conference-with-jitsi-meet
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.0.0
- Severity Score
- Medium
- CVE
- 2022-47150
Wiremo – Product Reviews for WooCommerce

- Plugin Slug
- woo-reviews-by-wiremo
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.4.97
- Severity Score
- Medium
- CVE
- 2022-47150
Wp Edit Password Protected – Create Member/User Only Page & Design Password Protected Form

- Plugin Slug
- wp-edit-password-protected
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.4
- Severity Score
- Medium
- CVE
- 2022-47150
Products Suggestions for WooCommerce

- Plugin Slug
- cart-products-suggestions-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Calendar Event Multi View

- Plugin Slug
- cp-multi-view-calendar
- Installations
- 1,000+
- Vulnerability
- Missing Authorization Leading To Feedback Submission
- Patched in Version
- 1.4.11
- Severity Score
- Medium
- CVE
- 2023-28492
HT Feed

- Plugin
- HT Feed
- Plugin Slug
- ht-instagram
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.2.8
- Severity Score
- Medium
- CVE
- 2023-23804
Dynamics 365 Integration

- Plugin
- Dynamics 365 Integration
- Plugin Slug
- integration-dynamics
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.3.13
- Severity Score
- Medium
- CVE
- 2023-28417
Open RDW kenteken voertuiginformatie

- Plugin Slug
- open-rdw-kenteken-voertuiginformatie
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.1.0
- Severity Score
- High
- CVE
- 2022-47431
Pagination Styler for WooCommerce

- Plugin Slug
- pagination-styler-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Products Compare for WooCommerce

- Plugin Slug
- products-compare-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.8
- Severity Score
- Medium
- CVE
- 2022-45813
Sales Report for WooCommerce

- Plugin Slug
- sales-report-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Sequential Order Numbers for WooCommerce

- Plugin Slug
- sequential-order-numbers-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 3.5.7.7
- Severity Score
- Medium
- CVE
- 2022-45813
Sheets To WP Table Live Sync

- Plugin Slug
- sheets-to-wp-table-live-sync
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.12.15
- Severity Score
- Medium
- CVE
- 2022-47150
Userlike – WordPress Live Chat plugin

- Plugin Slug
- userlike
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.3
- Severity Score
- Medium
- CVE
- 2023-23734
WordPress WP Express Checkout

- Plugin Slug
- wp-express-checkout
- Installations
- 1,000+
- Vulnerability
- Authenticated (Admin+) Stored Cross-Site Scripting
- Patched in Version
- 2.2.9
- Severity Score
- Medium
- CVE
- 2023-1469
WordPress GamiPress – Youtube integration

- Plugin Slug
- gamipress-youtube-integration
- Installations
- 700+
- Vulnerability
- Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Patched in Version
- 1.0.8
- Severity Score
- Medium
Branded Social Images

- Plugin Slug
- branded-social-images
- Installations
- 600+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.1.1
- Severity Score
- Medium
- CVE
- 2023-28536
Enhanced Plugin Admin

- Plugin
- Enhanced Plugin Admin
- Plugin Slug
- enhanced-plugin-admin
- Installations
- 200+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.17
- Severity Score
- Medium
- CVE
- 2023-28618
WordPress Auto Rename Media On Upload

- Plugin Slug
- auto-rename-media-on-upload
- Installations
- 100+
- Vulnerability
- Authenticated (Administrator+) Stored Cross-Site Scripting
- Patched in Version
- 1.1.0
- Severity Score
- Medium
WSB Brands

- Plugin
- WSB Brands
- Plugin Slug
- wsb-brands
- Installations
- 100+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.2
- Severity Score
- Medium
- CVE
- 2022-47437
WordPress Amazon S3 Plugin
- Plugin Slug
- wp-s3
- Installations
- 10+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.6
- Severity Score
- High
Cyberus Key

- Plugin
- Cyberus Key
- Plugin Slug
- cyberus-key
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.1
- Severity Score
- Medium
- CVE
- 2023-28620
WordPress Drag and Drop Multiple File Upload PRO – Contact Form 7 Standard
- Plugin
- Drag and Drop Multiple File Upload PRO
- Plugin Slug
- drag-n-drop-upload-cf7-pro
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.11.1
- Severity Score
- High
WordPress WooCommerce Multiple Customer Addresses & Shipping
- Plugin
- WooCommerce Multiple Customer Addresses & Shipping
- Plugin Slug
- woocommerce-multiple-customer-addresses
- Vulnerability
- Insecure Direct Object References (IDOR)
- Patched in Version
- 21.7
- Severity Score
- Medium
- CVE
- 2023-0865
WordPress Plugin Vulnerabilities – No Known Fix
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Slide Anything

- Plugin Slug
- slide-anything
- Installations
- 100,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28499
Custom Field Template

- Plugin
- Custom Field Template
- Plugin Slug
- custom-field-template
- Installations
- 50,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-22695
Website Monetization by MageNet

- Plugin Slug
- website-monetization-by-magenet
- Installations
- 40,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-22673
Read More Without Refresh

- Plugin Slug
- read-more-without-refresh
- Installations
- 20,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23793
WP Shortcode by MyThemeShop

- Plugin Slug
- wp-shortcode
- Installations
- 20,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28495
PB SEO Friendly Images plugin

- Plugin
- PB SEO Friendly Images
- Plugin Slug
- pb-seo-friendly-images
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47434
Import External Images

- Plugin
- Import External Images
- Plugin Slug
- import-external-images
- Installations
- 8,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-46866
Disqus Conditional Load

- Plugin
- Disqus Conditional Load
- Plugin Slug
- disqus-conditional-load
- Installations
- 7,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23732
ConvertBox Auto Embed WordPress plugin
- Plugin Slug
- convertbox-auto-embed
- Installations
- 6,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23664
Weather Station

- Plugin
- Weather Station
- Plugin Slug
- live-weather-station
- Installations
- 4,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-25478
Simple Mobile URL Redirect

- Plugin Slug
- simple-mobile-url-redirect
- Installations
- 4,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23897
WordPress Mortgage Calculator Estatik

- Plugin Slug
- estatik-mortgage-calculator
- Installations
- 3,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-28490
Update Image Tag Alt Attribute

- Plugin Slug
- update-alt-attribute
- Installations
- 3,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
Return and Warranty Management System for WooCommerce

- Plugin Slug
- wc-return-warrranty
- Installations
- 3,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-22710
WP Job Portal – A Complete Job Board

- Plugin Slug
- wp-job-portal
- Installations
- 3,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28534
Bangladeshi Payment Gateways

- Plugin Slug
- bangladeshi-payment-gateways
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
Custom Options Plus

- Plugin
- Custom Options Plus
- Plugin Slug
- custom-options-plus
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28420
Google XML Sitemap for Mobile
- Plugin Slug
- google-mobile-sitemap
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23869
Lazy Social Comments

- Plugin
- Lazy Social Comments
- Plugin Slug
- lazy-facebook-comments
- Installations
- 2,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23733
BuddyPress Builder for Elementor – BuddyBuilder

- Plugin Slug
- stax-buddy-builder
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
Vertical scroll recent post

- Plugin Slug
- vertical-scroll-recent-post
- Installations
- 2,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23862
Product Category Slider for WooCommerce

- Plugin Slug
- woo-category-slider-by-pluginever
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
WP Content Filter – Censor All Offensive Content From Your Site

- Plugin Slug
- wp-content-filter
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23883
BigContact Contact Page

- Plugin
- BigContact Contact Page
- Plugin Slug
- bigcontact
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-22694
Bulk Resize Media

- Plugin
- Bulk Resize Media
- Plugin Slug
- bulk-resize-media
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-46865
JS Job Manager

- Plugin
- JS Job Manager
- Plugin Slug
- js-jobs
- Installations
- 1,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28689
Kanban Boards for WordPress

- Plugin Slug
- kanban
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23884
Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

- Plugin Slug
- post-grid-carousel-ultimate
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
PT Addons for Elementor Lite

- Plugin Slug
- pt-elementor-addons-lite
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
Elementor Addons, Widgets and Enhancements – Stax

- Plugin Slug
- stax-addons-for-elementor
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
Surbma | GDPR Proof Cookie Consent & Notice Bar

- Plugin Slug
- surbma-gdpr-proof-google-analytics
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23894
Challan – PDF Invoice & Packing Slip for WooCommerce

- Plugin Slug
- webappick-pdf-invoice-for-woocommerce
- Installations
- 1,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2022-47150
TreePress – Easy Family Trees & Ancestor Profiles

- Plugin Slug
- treepress
- Installations
- 900+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-23863
VigilanTor
- Plugin
- VigilanTor
- Plugin Slug
- vigilantor
- Installations
- 900+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28695
Backup Bank: WordPress Backup Plugin

- Plugin Slug
- wp-backup-bank
- Installations
- 700+
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28165
Be POPIA Compliant
- Plugin
- Be POPIA Compliant
- Plugin Slug
- be-popia-compliant
- Installations
- 100+
- Vulnerability
- SQL Injection
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2022-47445
Simple Custom Author Profiles

- Plugin Slug
- simple-custom-author-profiles
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-24372
WordPress WP Popup Banners
- Plugin
- WP Popup Banners
- Plugin Slug
- wp-popup-banners
- Vulnerability
- Authenticated (Subscriber+) SQL Injection
- Patched in Version
- No Fix
- Severity Score
- High
- CVE
- 2023-1471
WP Simple Events

- Plugin
- WP Simple Events
- Plugin Slug
- wp-simple-events
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-24376
WordPress Theme Vulnerabilities
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.
Real Estate Directory

- Theme Slug
- real-estate-directory
- Downloads
- 3,569
- Vulnerability
- Authenticated Arbitrary Plugin Activation
- Patched in Version
- 1.0.6
- Severity Score
- Medium
- CVE
- 2023-28532
NewsMag

- Theme
- NewsMag
- Theme Slug
- newsmag
- Downloads
- 338,702
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28493
Mediciti Lite

- Theme
- Mediciti Lite
- Theme Slug
- mediciti-lite
- Downloads
- 20,184
- Vulnerability
- Reflected Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28418
Chankhe

- Theme
- Chankhe
- Theme Slug
- chankhe
- Downloads
- 3,083
- Vulnerability
- Authenticated Arbitrary Plugin Activation
- Patched in Version
- No Fix
- Severity Score
- Medium
- CVE
- 2023-28416
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.