Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – March 8, 2023

Written by iThemes Editorial Team on March 8, 2023

Last Updated on March 8, 2023

Vulnerable plugins and themes are some of the most common vectors for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, now powered by Patchstack, covers new WordPress plugins, themes, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging vulnerabilities and help you decide what to do if you are using one of these vulnerable plugins or themes on your website. For a deeper analysis of trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Please note the Metform Elementor Contact Form Builder plugin has an important update that patches two recently disclosed vulnerabilities. One is a high-risk XSS vulnerability. Update Metform to version 3.2.3 as soon as possible.

Contents of the March 8, 2023 Report
  1. The Future of Authentication is Passkeys! Log into your WordPress site with Biometrics only available in iThemes Security Pro.
  2. WordPress Core News
    1. WordPress 6.2 Beta 5
  3. WordPress Plugin Vulnerabilities
    1. WordPress Yoast SEO plugin
    2. WordPress Cookie Notice & Compliance for GDPR / CCPA plugin
    3. WordPress WPCode plugin
    4. WordPress Popup Builder by OptinMonster plugin
    5. WordPress Smart Slider 3 plugin
    6. WordPress Shortcodes Ultimate plugin
    7. WordPress Metform Elementor Contact Form Builder plugin
    8. WordPress FluentSMTP plugin
    9. WordPress Paid Memberships Pro plugin
    10. WordPress VK All in One Expansion Unit plugin
    11. WordPress Slimstat Analytics plugin
    12. WordPress Auto Featured Image plugin
    13. WordPress Calculated Fields Form plugin
    14. WordPress Dokan plugin
    15. WordPress Quiz And Survey Master plugin
    16. WordPress Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation plugin
    17. WordPress GN Publisher plugin
    18. WordPress Rife Elementor Extensions & Templates plugin
    19. WordPress When Last Login plugin
    20. WordPress WP Meteor Page Speed Optimization Topping plugin
    21. WordPress Gallery Blocks with Lightbox plugin
    22. WordPress Wholesale Suite plugin
    23. WordPress Yasr – Yet Another Stars Rating plugin
    24. WordPress Admin CSS MU plugin
    25. WordPress Maspik – Spam blacklist plugin
    26. WordPress GTmetrix for WordPress plugin
    27. WordPress HT Slider For Elementor plugin
    28. WordPress 10WebMapBuilder plugin
    29. WordPress WP SMS plugin
    30. WordPress WP SMS plugin
    31. WordPress YITH WooCommerce Product Slider Carousel plugin
    32. WordPress JCH Optimize plugin
    33. WordPress LWS Tools plugin
    34. WordPress ProfileGrid plugin
    35. WordPress Add Expires Headers & Optimized Minify plugin
    36. WordPress Button Generator plugin
    37. WordPress WpStream plugin
    38. WordPress Dashboard Widgets Suite plugin
    39. WordPress Publish to Schedule plugin
    40. WordPress Simple File List plugin
    41. WordPress Watu Quiz plugin
    42. WordPress WP OAuth Server plugin
    43. WordPress Pie Register plugin
    44. WordPress Pie Register plugin
    45. WordPress We're Open! plugin
    46. WordPress Search in Place plugin
    47. WordPress WP Plugin Manager plugin
    48. WordPress DeepL API translation
    49. WordPress Cart Lift
    50. WordPress CP Contact Form with PayPal
    51. WordPress Simple Slug Translate plugin
    52. WordPress DecaLog plugin
    53. WordPress Easy Testimonial Slider and Form
    54. WordPress Event Espresso 4 Decaf plugin
    55. WordPress Sheets To WP Table Live Sync
    56. WordPress Total Poll Lite
    57. WordPress WP Time Slots Booking Form
    58. WordPress Donation Block For PayPal
    59. WordPress Namaste! LMS plugin
    60. WordPress Namaste! LMS plugin
    61. WordPress real.Kit plugin
    62. WordPress Custom Login Admin Front-end CSS
    63. WordPress HT Portfolio plugin
    64. WordPress WooCommerce Checkout Field Manager plugin
    65. WordPress GS Insever Portfolio plugin
    66. WordPress WC Sales Notification plugin
    67. WordPress Debug Assistant plugin
    68. WordPress Debug Assistant plugin
    69. WordPress Preview Link Generator plugin
    70. WordPress Replyable plugin
    71. WordPress Toolset Types plugin
  4. WordPress Plugin Vulnerabilities – No Known Fix
    1. WordPress Instant Images
    2. WordPress Rus-To-Lat plugin
    3. WordPress WP Social Bookmarking Light plugin
    4. WordPress clickfunnels plugin
    5. WordPress WP Translitera plugin
    6. WordPress WP TFeed plugin
    7. WordPress Custom Content Shortcode plugin
    8. WordPress Custom Content Shortcode plugin
    9. WordPress menu shortcode plugin
    10. WordPress Smart YouTube PRO plugin
    11. WordPress Styles plugin
    12. WordPress Video Background plugin
    13. WordPress WP Clean Up plugin
    14. WordPress XML Sitemap Generator for Google plugin
    15. WordPress FareHarbor for WordPress plugin
    16. WordPress Blog Floating Button plugin
    17. WordPress Classic Editor and Classic Widgets plugin
    18. WordPress CPO Content Types plugin
    19. WordPress Resize at Upload Plus plugin
    20. WordPress Advanced Text Widget plugin
    21. WordPress Advanced Text Widget plugin
    22. WordPress New Adman plugin
    23. WordPress New Adman plugin
    24. WordPress WP No External Links plugin
    25. WordPress Simple CSV/XLS Exporter plugin
    26. WordPress Social Auto Poster plugin
    27. WordPress Elegant Custom Fonts plugin
    28. WordPress About Me 3000 widget plugin
    29. WordPress Leyka plugin
    30. WordPress Leyka plugin
    31. WordPress Wpopal Core Features plugin
    32. WordPress Simple Vimeo Shortcode
    33. WordPress Sales Report Email for WooCommerce
    34. WordPress WP Google Tag Manager plugin
    35. WordPress Ever Compare plugin
    36. WordPress React Webcam plugin
    37. WordPress User Activity plugin
    38. WordPress GoToWP plugin
    39. WordPress WP Repost plugin
    40. WordPress WP Repost plugin
    41. WordPress wp2syslog plugin
    42. WordPress CSS Adder By Agene-Press
    43. WordPress AMP Toolbox plugin
    44. WordPress Start plugin
    45. WordPress Manage Upload Limit plugin
    46. WordPress DupeOff plugin
    47. WordPress Shipyaari Shipping Management
    48. WordPress Advanced Recent Posts plugin
    49. WordPress Confirm Data plugin
    50. WordPress Correos Oficial plugin
    51. WordPress Custom Add User plugin
    52. WordPress Download Attachments plugin
    53. WordPress GigPress plugin
    54. WordPress i2 Pros & Cons plugin
    55. WordPress PHPFreeChat plugin
    56. WordPress Product GTIN (EAN, UPC, ISBN) for WooCommerce plugin
    57. WordPress Page Builder – Qards
    58. WordPress Resume Builder plugin
    59. WordPress Saan World Clock plugin
    60. WordPress Smart Logo Showcase Lite plugin
    61. WordPress Synved Shortcodes plugin
    62. WordPress Theme Minifier plugin
    63. WordPress UpQode Google Maps plugin
    64. WordPress Galleries by Angie Makes
    65. WordPress WooSupply plugin
    66. WordPress WooVIP plugin
    67. WordPress WooVirtualWallet plugin
    68. WordPress AMO for WP plugin
    69. WordPress WPaudio MP3 Player plugin
    70. WordPress WPB Advanced FAQ plugin
  5. WordPress Theme Vulnerabilities
    1. WordPress OceanWP theme
    2. WordPress Total theme
    3. WordPress Big Store theme
    4. WordPress darcie theme
    5. WordPress Houzez theme
    6. WordPress Real Estate 7 theme
    7. WordPress Real Estate 7 theme
  6. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

The Future of Authentication is Passkeys! Log into your WordPress site with Biometrics only available in iThemes Security Pro.

Credential stuffing, phishing, and brute force attacks using stolen, guessable, or reused passwords have made our digital lives less secure. Two-Factor Authentication (2FA) offers some protection but at the cost of usability and accessibility. Fewer than 30% of all online account holders actually use 2FA. Password-based logins are broken.

The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.

Learn More About Passkeys

WordPress Core News

WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, ensure your site is backed up with BackupBuddy before updating.

WordPress 6.2 Beta 5

The first release candidate (RC1) for the WordPress 6.2 development cycle has been postponed two days, to Thursday, March 9, and an additional fifth Beta release came out on Tuesday, March 7. Additional time and testing were needed to deal with a regression that came to light last week. The project is still on track for the final release of WordPress 6.2 on March 28. You can get a preview of what’s coming in 6.2 thanks to Anne McCarthy and Rich Tabor, who hosted a live demo. Anne has also written a detailed overview.

  • No new WordPress core vulnerabilities were disclosed this week.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

WordPress Yoast SEO plugin

Product image for Yoast SEO.
Plugin
Yoast SEO
Plugin Slug
wordpress-seo
Installations
5,000,000+
Vulnerability
Authenticated (Contributor+) DOM-Based Cross-Site Scripting
Patched in Version
20.2.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 20.2.1.

WordPress Cookie Notice & Compliance for GDPR / CCPA plugin

Product image for Cookie Notice & Compliance for GDPR / CCPA.
Plugin
Cookie Notice & Compliance for GDPR / CCPA
Plugin Slug
cookie-notice
Installations
1,000,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.7
Severity Score
Medium
CVE
2023-24400
The vulnerability has been patched, so you should update to version 2.4.7.

WordPress WPCode plugin

Product image for WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager.
Plugin
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
Plugin Slug
insert-headers-and-footers
Installations
1,000,000+
Vulnerability
Contributor+ WPCode Library Auth Key Update/Deletion
Patched in Version
2.0.7
Severity Score
Medium
CVE
2023-0328
The vulnerability has been patched, so you should update to version 2.0.7.

WordPress Popup Builder by OptinMonster plugin

Product image for Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation.
Plugin
Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation
Plugin Slug
optinmonster
Installations
1,000,000+
Vulnerability
Subscriber+ Arbitrary Post Content Disclosure
Patched in Version
2.12.2
Severity Score
Medium
CVE
2023-0772
The vulnerability has been patched, so you should update to version 2.12.2.

WordPress Smart Slider 3 plugin

Product image for Smart Slider 3.
Plugin
Smart Slider 3
Plugin Slug
smart-slider-3
Installations
900,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.1.14
Severity Score
Medium
CVE
2023-0660
The vulnerability has been patched, so you should update to version 3.5.1.14.

WordPress Shortcodes Ultimate plugin

Product image for WordPress Shortcodes Plugin — Shortcodes Ultimate.
Plugin
WordPress Shortcodes Plugin — Shortcodes Ultimate
Plugin Slug
shortcodes-ultimate
Installations
700,000+
Vulnerability
Subscriber+ User Meta Disclosure
Patched in Version
5.12.8
Severity Score
Medium
CVE
2023-0911
The vulnerability has been patched, so you should update to version 5.12.8.

WordPress Metform Elementor Contact Form Builder plugin

Product image for Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress.
Plugin
Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress
Plugin Slug
metform
Installations
200,000+
Vulnerability
reCaptcha Protection Bypass Vulnerability
Patched in Version
3.2.2
Severity Score
Medium
CVE
2023-0085
The vulnerability has been patched, so you should update to version 3.2.2.

WordPress FluentSMTP plugin

Product image for FluentSMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin.
Plugin
FluentSMTP – WP Mail SMTP, Amazon SES, SendGrid, MailGun and Any SMTP Connector Plugin
Plugin Slug
fluent-smtp
Installations
100,000+
Vulnerability
Stored XSS via Email Logs
Patched in Version
2.2.3
Severity Score
Medium
CVE
2023-0219
The vulnerability has been patched, so you should update to version 2.2.3.

WordPress Paid Memberships Pro plugin

Product image for Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions.
Plugin
Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions
Plugin Slug
paid-memberships-pro
Installations
100,000+
Vulnerability
SQL Injection
Patched in Version
2.9.12
Severity Score
High
CVE
2023-0631
The vulnerability has been patched, so you should update to version 2.9.12.

WordPress VK All in One Expansion Unit plugin

Product image for VK All in One Expansion Unit.
Plugin
VK All in One Expansion Unit
Plugin Slug
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
9.86.0.0
Severity Score
Medium
CVE
2023-0230
The vulnerability has been patched, so you should update to version 9.86.0.0.

WordPress Slimstat Analytics plugin

Product image for Slimstat Analytics.
Plugin
Slimstat Analytics
Plugin Slug
wp-slimstat
Installations
100,000+
Vulnerability
SQL Injection
Patched in Version
4.9.3.3
Severity Score
High
CVE
2023-0630
The vulnerability has been patched, so you should update to version 4.9.3.3.

WordPress Auto Featured Image plugin

Product image for Auto Featured Image (Auto Post Thumbnail).
Plugin
Auto Featured Image (Auto Post Thumbnail)
Plugin Slug
auto-post-thumbnail
Installations
80,000+
Vulnerability
Author+ Arbitrary File Upload
Patched in Version
3.9.16
Severity Score
Critical
CVE
2023-0477
The vulnerability has been patched, so you should update to version 3.9.16.

WordPress Calculated Fields Form plugin

Product image for Calculated Fields Form.
Plugin
Calculated Fields Form
Plugin Slug
calculated-fields-form
Installations
60,000+
Vulnerability
Missing Authorization Leading To Feedback Submission
Patched in Version
1.1.121
Severity Score
Medium
CVE
2023-26523
The vulnerability has been patched, so you should update to version 1.1.121.

WordPress Dokan plugin

Product image for Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.
Plugin
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
Plugin Slug
dokan-lite
Installations
60,000+
Vulnerability
SQL Injection
Patched in Version
3.7.13
Severity Score
High
CVE
2023-26525
The vulnerability has been patched, so you should update to version 3.7.13.

WordPress Quiz And Survey Master plugin

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.
Plugin
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
Plugin Slug
quiz-master-next
Installations
40,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
8.1.0
Severity Score
Medium
CVE
2023-26524
The vulnerability has been patched, so you should update to version 8.1.0.

WordPress Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation plugin

Product image for Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation.
Plugin
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
Plugin Slug
zero-bs-crm
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.5.0
Severity Score
Medium
CVE
2023-27429
The vulnerability has been patched, so you should update to version 5.5.0.

WordPress GN Publisher plugin

Product image for GN Publisher: Google News Compatible RSS Feeds.
Plugin
GN Publisher: Google News Compatible RSS Feeds
Plugin Slug
gn-publisher
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.6
Severity Score
High
CVE
2023-1080
The vulnerability has been patched, so you should update to version 1.5.6.

WordPress Rife Elementor Extensions & Templates plugin

Product image for Rife Elementor Extensions & Templates.
Plugin
Rife Elementor Extensions & Templates
Plugin Slug
rife-elementor-extensions
Installations
30,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.0
Severity Score
Medium
CVE
2023-27454
The vulnerability has been patched, so you should update to version 1.2.0.

WordPress When Last Login plugin

Product image for When Last Login.
Plugin
When Last Login
Plugin Slug
when-last-login
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.2.2
Severity Score
Medium
CVE
2023-27461
The vulnerability has been patched, so you should update to version 1.2.2.

WordPress WP Meteor Page Speed Optimization Topping plugin

Product image for WP Meteor Page Speed Optimization Topping.
Plugin
WP Meteor Page Speed Optimization Topping
Plugin Slug
wp-meteor
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.1.5
Severity Score
Medium
CVE
2023-26543
The vulnerability has been patched, so you should update to version 3.1.5.

WordPress Gallery Blocks with Lightbox plugin

Product image for Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery.
Plugin
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery
Plugin Slug
simply-gallery-block
Installations
20,000+
Vulnerability
Missing Authorization in pgc_sgb_add_dashboard_widget
Patched in Version
3.0.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.0.8.

WordPress Wholesale Suite plugin

Product image for Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.
Plugin
Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More
Plugin Slug
woocommerce-wholesale-prices
Installations
20,000+
Vulnerability
Settings Change
Patched in Version
2.1.5.1
Severity Score
Medium
CVE
2022-34344
The vulnerability has been patched, so you should update to version 2.1.5.1.

WordPress Yasr – Yet Another Stars Rating plugin

Product image for Yasr – Yet Another Stars Rating.
Plugin
Yasr – Yet Another Stars Rating
Plugin Slug
yet-another-stars-rating
Installations
20,000+
Vulnerability
XSS & Arbitrary Shortcode Execution
Patched in Version
3.1.3
Severity Score
Medium
CVE
2022-40699
The vulnerability has been patched, so you should update to version 3.1.3.

WordPress Admin CSS MU plugin

Product image for Admin CSS MU.
Plugin
Admin CSS MU
Plugin Slug
admin-css-mu
Installations
10,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
2.7
Severity Score
High
CVE
2022-40700
The vulnerability has been patched, so you should update to version 2.7.

WordPress Maspik – Spam blacklist plugin

Product image for Maspik – Spam blacklist.
Plugin
Maspik – Spam blacklist
Plugin Slug
contact-forms-anti-spam
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
0.7.9
Severity Score
Medium
CVE
2023-24008
The vulnerability has been patched, so you should update to version 0.7.9.

WordPress GTmetrix for WordPress plugin

Product image for GTmetrix for WordPress.
Plugin
GTmetrix for WordPress
Plugin Slug
gtmetrix-for-wordpress
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.4.6
Severity Score
Low
CVE
2023-23677
The vulnerability has been patched, so you should update to version 0.4.6.

WordPress HT Slider For Elementor plugin

Product image for HT Slider For Elementor.
Plugin
HT Slider For Elementor
Plugin Slug
ht-slider-for-elementor
Installations
10,000+
Vulnerability
Arbitrary Plugin Activation via CSRF
Patched in Version
1.4.0
Severity Score
Medium
CVE
2023-0495
The vulnerability has been patched, so you should update to version 1.4.0.

WordPress 10WebMapBuilder plugin

Product image for 10Web Map Builder for Google Maps.
Plugin
10Web Map Builder for Google Maps
Plugin Slug
wd-google-maps
Installations
10,000+
Vulnerability
SQL Injection
Patched in Version
1.0.73
Severity Score
High
CVE
2023-0037
The vulnerability has been patched, so you should update to version 1.0.73.

WordPress WP SMS plugin

Product image for WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.
Plugin
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc
Plugin Slug
wp-sms
Installations
9,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
6.0.4.1
Severity Score
Medium
CVE
2023-27447
The vulnerability has been patched, so you should update to version 6.0.4.1.

WordPress WP SMS plugin

Product image for WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc.
Plugin
WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc
Plugin Slug
wp-sms
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.4.13
Severity Score
Medium
CVE
2021-24561
The vulnerability has been patched, so you should update to version 5.4.13.

WordPress YITH WooCommerce Product Slider Carousel plugin

Product image for YITH WooCommerce Product Slider Carousel.
Plugin
YITH WooCommerce Product Slider Carousel
Plugin Slug
yith-woocommerce-product-slider-carousel
Installations
9,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.16.1
Severity Score
Medium
CVE
2022-44630
The vulnerability has been patched, so you should update to version 1.16.1.

WordPress JCH Optimize plugin

Product image for JCH Optimize.
Plugin
JCH Optimize
Plugin Slug
jch-optimize
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.2.3
Severity Score
Medium
CVE
2023-25491
The vulnerability has been patched, so you should update to version 3.2.3.

WordPress LWS Tools plugin

Product image for LWS Tools.
Plugin
LWS Tools
Plugin Slug
lws-tools
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.4
Severity Score
Medium
CVE
2023-27453
The vulnerability has been patched, so you should update to version 2.4.

WordPress ProfileGrid plugin

Product image for ProfileGrid – User Profiles, Memberships, Groups and Communities.
Plugin
ProfileGrid – User Profiles, Memberships, Groups and Communities
Plugin Slug
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability
Subscriber+ Arbitrary Password Reset
Patched in Version
5.3.1
Severity Score
High
CVE
2023-0940
The vulnerability has been patched, so you should update to version 5.3.1.

WordPress Add Expires Headers & Optimized Minify plugin

Product image for Add Expires Headers & Optimized Minify.
Plugin
Add Expires Headers & Optimized Minify
Plugin Slug
add-expires-headers
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.7.1
Severity Score
Medium
CVE
2023-27457
The vulnerability has been patched, so you should update to version 2.7.1.

WordPress Button Generator plugin

Product image for Button Generator – easily Button Builder.
Plugin
Button Generator – easily Button Builder
Plugin Slug
button-generation
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.4
Severity Score
Medium
CVE
2023-27452
The vulnerability has been patched, so you should update to version 2.3.4.

WordPress WpStream plugin

Product image for WpStream – Live Streaming, Video on Demand, Pay Per View.
Plugin
WpStream – Live Streaming, Video on Demand, Pay Per View
Plugin Slug
wpstream
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.4.10.6
Severity Score
Medium
CVE
2023-27458
The vulnerability has been patched, so you should update to version 4.4.10.6.

WordPress Dashboard Widgets Suite plugin

Product image for Dashboard Widgets Suite.
Plugin
Dashboard Widgets Suite
Plugin Slug
dashboard-widgets-suite
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.2.2
Severity Score
Medium
CVE
2023-26517
The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Publish to Schedule plugin

Product image for Publish to Schedule.
Plugin
Publish to Schedule
Plugin Slug
publish-to-schedule
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.5.5
Severity Score
Medium
CVE
2023-26519
The vulnerability has been patched, so you should update to version 4.5.5.

WordPress Simple File List plugin

Plugin
Simple File List
Plugin Slug
simple-file-list
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.0.10
Severity Score
Medium
CVE
2023-1025
The vulnerability has been patched, so you should update to version 6.0.10.

WordPress Watu Quiz plugin

Product image for Watu Quiz.
Plugin
Watu Quiz
Plugin Slug
watu
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.9.1
Severity Score
High
CVE
2023-0968
The vulnerability has been patched, so you should update to version 3.3.9.1.

WordPress WP OAuth Server plugin

Product image for WP OAuth Server (OAuth Authentication).
Plugin
WP OAuth Server (OAuth Authentication)
Plugin Slug
oauth2-provider
Installations
4,000+
Vulnerability
Subscriber+ Arbitrary Client Deletion
Patched in Version
4.3.0
Severity Score
Medium
CVE
2022-4148
The vulnerability has been patched, so you should update to version 4.3.0.

WordPress Pie Register plugin

Product image for Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction.
Plugin
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction
Plugin Slug
pie-register
Installations
4,000+
Vulnerability
Arbitrary Content Deletion
Patched in Version
3.8.1.3
Severity Score
High
CVE
2022-4024
The vulnerability has been patched, so you should update to version 3.8.1.3.

WordPress Pie Register plugin

Product image for Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction.
Plugin
Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction
Plugin Slug
pie-register
Installations
4,000+
Vulnerability
Open Redirection
Patched in Version
3.8.2.3
Severity Score
Medium
CVE
2023-0552
The vulnerability has been patched, so you should update to version 3.8.2.3.

WordPress We’re Open! plugin

Product image for We’re Open!.
Plugin
We’re Open!
Plugin Slug
opening-hours
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.47
Severity Score
Medium
CVE
2023-25964
The vulnerability has been patched, so you should update to version 1.47.

WordPress Search in Place plugin

Product image for Search in Place.
Plugin
Search in Place
Plugin Slug
search-in-place
Installations
3,000+
Vulnerability
Missing Authorization Leading To Feedback Submission
Patched in Version
1.0.105
Severity Score
Medium
CVE
2023-26521
The vulnerability has been patched, so you should update to version 1.0.105.

WordPress WP Plugin Manager plugin

Product image for WP Plugin Manager – Deactivate plugins per page.
Plugin
WP Plugin Manager – Deactivate plugins per page
Plugin Slug
wp-plugin-manager
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.1.8
Severity Score
Medium
CVE
2023-1088
The vulnerability has been patched, so you should update to version 1.1.8.

WordPress DeepL API translation

Plugin
DeepL API translation plugin
Plugin Slug
wpdeepl
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.1.5
Severity Score
Medium
CVE
2023-27446
The vulnerability has been patched, so you should update to version 2.1.5.

WordPress Cart Lift

Product image for Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD.
Plugin
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
Plugin Slug
cart-lift
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.6
Severity Score
High
CVE
2022-47449
The vulnerability has been patched, so you should update to version 3.1.6.

WordPress CP Contact Form with PayPal

Product image for CP Contact Form with PayPal.
Plugin
CP Contact Form with PayPal
Plugin Slug
cp-contact-form-with-paypal
Installations
2,000+
Vulnerability
Missing Authorization Leading To Feedback Submission
Patched in Version
1.3.35
Severity Score
Medium
CVE
2023-27460
The vulnerability has been patched, so you should update to version 1.3.35.

WordPress Simple Slug Translate plugin

Product image for Simple Slug Translate.
Plugin
Simple Slug Translate
Plugin Slug
simple-slug-translate
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.7.3
Severity Score
Medium
CVE
2023-26515
The vulnerability has been patched, so you should update to version 2.7.3.

WordPress DecaLog plugin

Plugin
DecaLog
Plugin Slug
decalog
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.7.1
Severity Score
Medium
CVE
2023-27444
The vulnerability has been patched, so you should update to version 3.7.1.

WordPress Easy Testimonial Slider and Form

Product image for Easy Testimonial Slider and Form.
Plugin
Easy Testimonial Slider and Form
Plugin Slug
easy-testimonial-rotator
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.16
Severity Score
High
CVE
2022-46799
The vulnerability has been patched, so you should update to version 1.0.16.

WordPress Event Espresso 4 Decaf plugin

Product image for Event Espresso 4 Decaf – Event Registration Event Ticketing.
Plugin
Event Espresso 4 Decaf – Event Registration Event Ticketing
Plugin Slug
event-espresso-decaf
Installations
1,000+
Vulnerability
Bypass Vulnerability
Patched in Version
4.10.45.decaf
Severity Score
Low
CVE
2023-27437
The vulnerability has been patched, so you should update to version 4.10.45.decaf.

WordPress Sheets To WP Table Live Sync

Product image for Sheets To WP Table Live Sync.
Plugin
Sheets To WP Table Live Sync
Plugin Slug
sheets-to-wp-table-live-sync
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.13.0
Severity Score
Medium
CVE
2023-26535
The vulnerability has been patched, so you should update to version 2.13.0.

WordPress Total Poll Lite

Product image for Total Poll Lite.
Plugin
Total Poll Lite
Plugin Slug
totalpoll-lite
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
4.8.7
Severity Score
Medium
CVE
2023-27449
The vulnerability has been patched, so you should update to version 4.8.7.

WordPress WP Time Slots Booking Form

Product image for WP Time Slots Booking Form.
Plugin
WP Time Slots Booking Form
Plugin Slug
wp-time-slots-booking-form
Installations
1,000+
Vulnerability
Missing Authorization Leading To Feedback Submission
Patched in Version
1.1.77
Severity Score
Medium
CVE
2022-41790
The vulnerability has been patched, so you should update to version 1.1.77.

WordPress Donation Block For PayPal

Product image for Donation Block For PayPal.
Plugin
Donation Block For PayPal
Plugin Slug
donations-block
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.0
Severity Score
Medium
CVE
2023-0535
The vulnerability has been patched, so you should update to version 2.1.0.

WordPress Namaste! LMS plugin

Product image for Namaste! LMS.
Plugin
Namaste! LMS
Plugin Slug
namaste-lms
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.6
Severity Score
Medium
CVE
2023-0844
The vulnerability has been patched, so you should update to version 2.6.

WordPress Namaste! LMS plugin

Product image for Namaste! LMS.
Plugin
Namaste! LMS
Plugin Slug
namaste-lms
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5.9.4
Severity Score
Medium
CVE
2023-0548
The vulnerability has been patched, so you should update to version 2.5.9.4.

WordPress real.Kit plugin

Plugin
real.Kit
Plugin Slug
real-kit
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.1.1
Severity Score
Medium
CVE
2023-0364
The vulnerability has been patched, so you should update to version 5.1.1.

WordPress Custom Login Admin Front-end CSS

Product image for Custom Login Admin Front-end CSS.
Plugin
Custom Login Admin Front-end CSS
Plugin Slug
custom-login-admin-front-end-css-with-multisite-support
Installations
500+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
1.5
Severity Score
High
CVE
2022-40700
The vulnerability has been patched, so you should update to version 1.5.

WordPress HT Portfolio plugin

Product image for HT Portfolio – WordPress Portfolio Plugin for Elementor.
Plugin
HT Portfolio – WordPress Portfolio Plugin for Elementor
Plugin Slug
ht-portfolio
Installations
300+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.1.6
Severity Score
Medium
CVE
2023-0497
The vulnerability has been patched, so you should update to version 1.1.6.

WordPress WooCommerce Checkout Field Manager plugin

Product image for WooCommerce Checkout Field Manager.
Plugin
WooCommerce Checkout Field Manager
Plugin Slug
n-media-woocommerce-checkout-fields
Installations
200+
Vulnerability
Arbitrary File Upload
Patched in Version
18.0
Severity Score
Critical
CVE
2022-4328
The vulnerability has been patched, so you should update to version 18.0.

WordPress GS Insever Portfolio plugin

Product image for GS Insever Portfolio.
Plugin
GS Insever Portfolio
Plugin Slug
gs-instagram-portfolio
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.5
Severity Score
Medium
CVE
2023-0539
The vulnerability has been patched, so you should update to version 1.4.5.

WordPress WC Sales Notification plugin

Product image for WC Sales Notification.
Plugin
WC Sales Notification
Plugin Slug
wc-sales-notification
Installations
100+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.2.3
Severity Score
Medium
CVE
2023-1087
The vulnerability has been patched, so you should update to version 1.2.3.

WordPress Debug Assistant plugin

Plugin
Debug Assistant
Plugin Slug
debug-assistant
Installations
80+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.5
Severity Score
High
CVE
2023-26516
The vulnerability has been patched, so you should update to version 1.5.

WordPress Debug Assistant plugin

Plugin
Debug Assistant
Plugin Slug
debug-assistant
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5
Severity Score
Medium
CVE
2023-26527
The vulnerability has been patched, so you should update to version 1.5.

WordPress Preview Link Generator plugin

Product image for Preview Link Generator.
Plugin
Preview Link Generator
Plugin Slug
preview-link-generator
Installations
10+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.0.4
Severity Score
Medium
CVE
2023-1086
The vulnerability has been patched, so you should update to version 1.0.4.

WordPress Replyable plugin

Plugin
Postmatic
Plugin Slug
postmatic
Vulnerability
PHP Object Injection
Patched in Version
2.2.10
Severity Score
High
CVE
2022-4265
The vulnerability has been patched, so you should update to version 2.2.10.

WordPress Toolset Types plugin

Plugin
Types
Plugin Slug
types
Vulnerability
Arbitrary File Upload
Patched in Version
3.4.18
Severity Score
High
CVE
2023-27440
The vulnerability has been patched, so you should update to version 3.4.18.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WordPress Instant Images

Product image for Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels.
Plugin
Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels
Plugin Slug
instant-images
Installations
100,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2023-27451
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Rus-To-Lat plugin

Plugin
Rus-To-Lat
Plugin Slug
rustolat
Installations
90,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25470
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Social Bookmarking Light plugin

Plugin
WP Social Bookmarking Light
Plugin Slug
wp-social-bookmarking-light
Installations
60,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25029
The vulnerability has not been patched. You should deactivate the plugin.

WordPress clickfunnels plugin

Product image for ClickFunnels.
Plugin
ClickFunnels
Plugin Slug
clickfunnels
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47152
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Translitera plugin

Plugin
WP Translitera
Plugin Slug
wp-translitera
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27438
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP TFeed plugin

Product image for WP TFeed.
Plugin
WP TFeed
Plugin Slug
accesspress-twitter-feed
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26518
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Custom Content Shortcode plugin

Product image for Custom Content Shortcode.
Plugin
Custom Content Shortcode
Plugin Slug
custom-content-shortcode
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0273
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Custom Content Shortcode plugin

Product image for Custom Content Shortcode.
Plugin
Custom Content Shortcode
Plugin Slug
custom-content-shortcode
Installations
10,000+
Vulnerability
Local File Inclusion
Patched in Version
No Fix
Severity Score
High
CVE
2023-0340
The vulnerability has not been patched. You should deactivate the plugin.

WordPress menu shortcode plugin

Plugin
menu shortcode
Plugin Slug
menu-shortcode
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0395
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Smart YouTube PRO plugin

Product image for Smart YouTube PRO.
Plugin
Smart YouTube PRO
Plugin Slug
smart-youtube
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25475
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Styles plugin

Product image for Styles.
Plugin
Styles
Plugin Slug
styles
Installations
10,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Video Background plugin

Product image for Video Background.
Plugin
Video Background
Plugin Slug
video-background
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4652
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Clean Up plugin

Plugin
WP Clean Up
Plugin Slug
wp-clean-up
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25034
The vulnerability has not been patched. You should deactivate the plugin.

WordPress XML Sitemap Generator for Google plugin

Product image for Google XML Sitemaps Generator.
Plugin
Google XML Sitemaps Generator
Plugin Slug
xml-sitemap-generator-for-google
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26514
The vulnerability has not been patched. You should deactivate the plugin.

WordPress FareHarbor for WordPress plugin

Product image for FareHarbor for WordPress.
Plugin
FareHarbor for WordPress
Plugin Slug
fareharbor
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25021
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Blog Floating Button plugin

Product image for Blog Floating Button.
Plugin
Blog Floating Button
Plugin Slug
blog-floating-button
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27445
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Classic Editor and Classic Widgets plugin

Product image for Classic Editor and Classic Widgets.
Plugin
Classic Editor and Classic Widgets
Plugin Slug
classic-editor-and-classic-widgets
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27434
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CPO Content Types plugin

Product image for CPO Content Types.
Plugin
CPO Content Types
Plugin Slug
cpo-content-types
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25451
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Resize at Upload Plus plugin

Plugin
Resize at Upload Plus
Plugin Slug
resize-at-upload-plus
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25467
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Advanced Text Widget plugin

Product image for Advanced Text Widget.
Plugin
Advanced Text Widget
Plugin Slug
advanced-text-widget
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26520
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Advanced Text Widget plugin

Product image for Advanced Text Widget.
Plugin
Advanced Text Widget
Plugin Slug
advanced-text-widget
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26539
The vulnerability has not been patched. You should deactivate the plugin.

WordPress New Adman plugin

Plugin
New Adman
Plugin Slug
new-adman
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27439
The vulnerability has not been patched. You should deactivate the plugin.

WordPress New Adman plugin

Plugin
New Adman
Plugin Slug
new-adman
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27441
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP No External Links plugin

Product image for WP No External Links.
Plugin
WP No External Links
Plugin Slug
no-external-links
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26537
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple CSV/XLS Exporter plugin

Product image for Simple CSV/XLS Exporter.
Plugin
Simple CSV/XLS Exporter
Plugin Slug
simple-csv-xls-exporter
Installations
6,000+
Vulnerability
CSV Injection
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-42882
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Social Auto Poster plugin

Product image for Social Auto Poster.
Plugin
Social Auto Poster
Plugin Slug
accesspress-facebook-auto-post
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26532
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Elegant Custom Fonts plugin

Product image for Elegant Custom Fonts.
Plugin
Elegant Custom Fonts
Plugin Slug
elegant-custom-fonts
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27436
The vulnerability has not been patched. You should deactivate the plugin.

WordPress About Me 3000 widget plugin

Product image for About Me 3000 widget.
Plugin
About Me 3000 widget
Plugin Slug
about-me-3000
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25474
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Leyka plugin

Product image for Leyka.
Plugin
Leyka
Plugin Slug
leyka
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-27450
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Leyka plugin

Product image for Leyka.
Plugin
Leyka
Plugin Slug
leyka
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27442
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Wpopal Core Features plugin

Product image for Wpopal Core Features.
Plugin
Wpopal Core Features
Plugin Slug
wpopal-core-features
Installations
2,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple Vimeo Shortcode

Plugin
Simple Vimeo Shortcode
Plugin Slug
the-very-simple-vimeo-shortcode
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-27443
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Sales Report Email for WooCommerce

Product image for Sales Report Email for WooCommerce.
Plugin
Sales Report Email for WooCommerce
Plugin Slug
woo-advanced-sales-report-email
Installations
1,000+
Vulnerability
Other Vulnerability Type
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-38141
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Google Tag Manager plugin

Product image for WP Google Tag Manager.
Plugin
WP Google Tag Manager
Plugin Slug
wp-google-tag-manager
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-22693
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Ever Compare plugin

Product image for Ever Compare – Products Compare Plugin for WooCommerce.
Plugin
Ever Compare – Products Compare Plugin for WooCommerce
Plugin Slug
ever-compare
Installations
800+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0505
The vulnerability has not been patched. You should deactivate the plugin.

WordPress React Webcam plugin

Product image for React Webcam.
Plugin
React Webcam
Plugin Slug
react-webcam
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0365
The vulnerability has not been patched. You should deactivate the plugin.

WordPress User Activity plugin

Product image for User Activity.
Plugin
User Activity
Plugin Slug
user-activity
Installations
300+
Vulnerability
Content Spoofing
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4550
The vulnerability has not been patched. You should deactivate the plugin.

WordPress GoToWP plugin

Product image for GoToWP.
Plugin
GoToWP
Plugin Slug
gotowp
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0369
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Repost plugin

Plugin
WP Repost
Plugin Slug
wp-repost
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26534
The vulnerability has not been patched. You should deactivate the plugin.

WordPress WP Repost plugin

Plugin
WP Repost
Plugin Slug
wp-repost
Installations
200+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26522
The vulnerability has not been patched. You should deactivate the plugin.

WordPress wp2syslog plugin

Plugin
wp2syslog
Plugin Slug
wp2syslog
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25974
The vulnerability has not been patched. You should deactivate the plugin.

WordPress CSS Adder By Agene-Press

Plugin
CSS Adder By Agence-Press
Plugin Slug
css-adder-by-agence-press
Installations
60+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched. You should deactivate the plugin.

WordPress AMP Toolbox plugin

Plugin
AMP Toolbox
Plugin Slug
amp-toolbox
Installations
50+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Start plugin

Product image for WordPress Start.
Plugin
WordPress Start
Plugin Slug
iksweb
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-25972
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Manage Upload Limit plugin

Product image for Manage Upload Limit.
Plugin
Manage Upload Limit
Plugin Slug
wpsimpletools-upload-limit
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-27432
The vulnerability has not been patched. You should deactivate the plugin.

WordPress DupeOff plugin

Plugin
DupeOff
Plugin Slug
dupeoff
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26529
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Shipyaari Shipping Management

Product image for Shipyaari Shipping Management.
Plugin
Shipyaari Shipping Management
Plugin Slug
manage-shipyaari-shipping
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-26528
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Advanced Recent Posts plugin

Plugin
Advanced Recent Posts
Plugin Slug
advanced-recent-posts
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0212
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Confirm Data plugin

Product image for Confirm Data.
Plugin
Confirm Data
Plugin Slug
confirm-data
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Correos Oficial plugin

Plugin
Correos Oficial
Plugin Slug
correosoficial
Vulnerability
Arbitrary File Download
Patched in Version
No Fix
Severity Score
High
CVE
2023-0331
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Custom Add User plugin

Plugin
Custom Add User
Plugin Slug
custom-add-user
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-0043
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Download Attachments plugin

Plugin
Download Attachments
Plugin Slug
download-attachments
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0076
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress GigPress plugin

Plugin
GigPress
Plugin Slug
gigpress
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2023-0381
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress i2 Pros & Cons plugin

Plugin
i2 Pros & Cons
Plugin Slug
i2-pro-cons
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0065
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress PHPFreeChat plugin

Plugin
PHPFreeChat
Plugin Slug
phpfreechat
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Product GTIN (EAN, UPC, ISBN) for WooCommerce plugin

Plugin
Product GTIN (EAN, UPC, ISBN) for WooCommerce
Plugin Slug
product-gtin-ean-upc-isbn-for-woocommerce
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0068
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Page Builder – Qards

Plugin
WordPress Page Builder – Qards
Plugin Slug
qards-free
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Resume Builder plugin

Plugin
Resume Builder
Plugin Slug
resume-builder
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0078
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Saan World Clock plugin

Plugin
Saan World Clock
Plugin Slug
saan-world-clock
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0145
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Smart Logo Showcase Lite plugin

Plugin
Smart Logo Showcase Lite
Plugin Slug
smart-logo-showcase-lite
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0175
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Synved Shortcodes plugin

Plugin
Synved Shortcodes
Plugin Slug
synved-shortcodes
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0063
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Minifier plugin

Plugin
Theme Minifier
Plugin Slug
theme-minifier
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress UpQode Google Maps plugin

Plugin
UpQode Google Maps
Plugin Slug
upqode-google-maps
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0094
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Galleries by Angie Makes

Plugin
Galleries by Angie Makes
Plugin Slug
wc-gallery
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-4795
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress WooSupply plugin

Plugin
WooSupply – Suppliers, Supply Orders and Stock Management
Plugin Slug
woosupply
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress WooVIP plugin

Plugin
WooVIP – Membership plugin for WordPress and WooCommerce
Plugin Slug
woovip
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress WooVirtualWallet plugin

Plugin
WooVirtualWallet – A virtual wallet for WooCommerce
Plugin Slug
woovirtualwallet
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress AMO for WP plugin

Plugin
AMO for WP – Membership Management
Plugin Slug
wp-amo
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
High
CVE
2022-40700
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress WPaudio MP3 Player plugin

Plugin
WPaudio MP3 Player
Plugin Slug
wpaudio-mp3-player
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0069
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress WPB Advanced FAQ plugin

Plugin
WPB Advanced FAQ
Plugin Slug
wpb-advanced-faq
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-0370
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

WordPress OceanWP theme

Product image for OceanWP.
Theme
OceanWP
Theme Slug
oceanwp
Downloads
5,985,364
Vulnerability
Local File Inclusion
Patched in Version
3.4.2
Severity Score
High
CVE
2023-23700
The vulnerability has been patched, so you should update to version 3.4.2.

WordPress Total theme

Product image for Total.
Theme
Total
Theme Slug
total
Downloads
956,513
Vulnerability
Broken Authentication
Patched in Version
2.1.20
Severity Score
Medium
CVE
2023-27456
The vulnerability has been patched, so you should update to version 2.1.20.

WordPress Big Store theme

Product image for Big Store.
Theme
Big Store
Theme Slug
big-store
Downloads
104,293
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.9.4
Severity Score
Medium
CVE
2023-27431
The vulnerability has been patched, so you should update to version 1.9.4.

WordPress darcie theme

Product image for Darcie.
Theme
Darcie
Theme Slug
darcie
Downloads
14,911
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.6
Severity Score
High
CVE
2023-25961
The vulnerability has been patched, so you should update to version 1.1.6.

WordPress Houzez theme

Theme
Houzez
Theme Slug
houzez
Vulnerability
Privilege Escalation
Patched in Version
2.7.2
Severity Score
Critical
CVE
2023-26540
The vulnerability has been patched, so you should update to version 2.7.2.

WordPress Real Estate 7 theme

Theme
Real Estate 7
Theme Slug
realestate-7
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.3.5
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.3.5.

WordPress Real Estate 7 theme

Theme
Real Estate 7
Theme Slug
realestate-7
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.5
Severity Score
High
The vulnerability has been patched, so you should update to version 3.3.5.

Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


iThemes Team
iThemes Editorial Team

Each week, the team at iThemes team publishes new WordPress tutorials and resources, including the Weekly WordPress Vulnerability Report. Since 2008, iThemes has been dedicated to helping you build, maintain, and secure WordPress sites for yourself or for clients. Our mission? Make People’s Lives Awesome.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
denial of service
What is a Denial of Service (DoS)?
WordPress Vulnerability Report
WordPress Vulnerability Report – March 1, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – February 22, 2023
botnets
Botnets: What are They and How do They Operate

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.