Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Solid Foundations
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

WordPress Vulnerability Report – September 13, 2023

Written by Dan Knauss on September 13, 2023

Last Updated on September 13, 2023

Since last week, 136 total vulnerabilities emerged in public disclosure. They may affect over four million WordPress sites. There are 76 plugin vulnerabilities and two theme vulnerabilities with security patches, so run those updates!

Additionally, there are 55 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WEBINAR REPLAY NOW AVAILABLE

Discover a streamlined approach to WordPress logins with Passkeys and Solid Security Pro (the new name for iThemes Security Pro). Passkeys are compatible with leading browsers such as Chrome, Firefox, and Safari, as well as biometric logins like Face ID, Touch ID, and Windows Hello. Say goodbye to the hassle of extra two-factor apps, password managers, or intricate password requirements, as website administrators and end users can now enjoy secure logins effortlessly.

Powered by the WebAuthn protocol, these cutting-edge login methods redefine passwordless login experiences, setting the stage for the future of safeguarding sensitive online information, including accessing WordPress sites. Timothy Jacobs, Lead Developer for SolidWP, gives an in-depth exploration of how this innovative technology enhances the WordPress login process for both you and your clients.

Watch the replay

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.


WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

Contents of the September 13, 2023 Report
  1. WEBINAR REPLAY NOW AVAILABLE
  2. WordPress Core News
  3. WordPress Core Vulnerabilities – Patched
  4. WordPress Plugin Vulnerabilities – Patched
    1. Starter Templates
    2. Starter Templates
    3. Fluent Forms
    4. Activity Log
    5. ProfilePress
    6. ProfilePress
    7. GiveWP
    8. Modula
    9. UserFeedback Lite
    10. Slimstat Analytics
    11. Backup Migration
    12. Media Library Assistant
    13. Form Maker by 10Web
    14. MapPress Maps for WordPress
    15. Simple Membership
    16. Carousel Slider
    17. Super Socializer
    18. Analytify
    19. Meks Easy Photo Feed Widget
    20. Meks Simple Flickr Widget
    21. GS Logo Slider
    22. Meks Easy Ads Widget
    23. Meks Smart Author Widget
    24. Meks ThemeForest Smart Widget
    25. User Submitted Posts
    26. WP Accessibility Helper (WAH)
    27. Auto Amazon Links
    28. rtMedia for WordPress, BuddyPress and bbPress
    29. Directorist
    30. Directorist
    31. Meks Time Ago
    32. SAML Single Sign On – SSO Login
    33. Order Delivery Date for WooCommerce
    34. WP Project Manager
    35. WP Project Manager
    36. weMail
    37. Post to Google My Business (Google Business Profile)
    38. AcyMailing
    39. Classifieds
    40. Automatic YouTube Gallery
    41. MyCryptoCheckout
    42. Poll Maker
    43. Posts Like Dislike
    44. Slider Pro
    45. WP Crowdfunding
    46. Meks Video Importer
    47. WooCommerce PensoPay
    48. Locatoraid Store Locator
    49. Meks Audio Player
    50. StagTools
    51. WP Directory Kit
    52. WRC Pricing Tables
    53. Bulk NoIndex & NoFollow Toolkit
    54. CP Blocks
    55. Laposta Signup Basic
    56. Meks Easy Maps
    57. Notice Bar
    58. POEditor
    59. User Private Files
    60. WiserNotify Social Proof
    61. WP Pipes
    62. BitPay Checkout for WooCommerce
    63. Swifty Bar, sticky bar by WPGens
    64. Cookie Notice & Consent
    65. Simple Download Counter
    66. Laposta Signup Embed
    67. Laposta Signup Embed
    68. RSVPMaker
    69. PeproDev CF7 Database
    70. iFolders
    71. Staff / Employee Business Directory for Active Directory
    72. Premium Starter Templates
    73. Premium Starter Templates
    74. Newsletter
    75. My Account Page Editor
    76. VS Contact Form
  5. WordPress Plugin Vulnerabilities – Unpatched
    1. FileOrganizer
    2. WooCommerce Conversion Tracking
    3. Legal Pages
    4. MailMunch – Grow your Email List
    5. Texty
    6. Unlimited Elementor Inner Sections By BoomDevs
    7. Order Delivery Date for WP e-Commerce
    8. Order Delivery Date for WP e-Commerce
    9. weDocs – Knowledgebase and Documentation Plugin for WordPress
    10. Outbound Link Manager
    11. WP Custom Post Template
    12. Leadster
    13. SendPress Newsletters
    14. SendPress Newsletters
    15. Easy WP Cleaner
    16. Live News
    17. Realbig
    18. TelSender
    19. Rescue Shortcodes
    20. Restrict
    21. Hide admin notices – Admin Notification Center
    22. Back To The Top Button
    23. Click To Tweet
    24. Click To Tweet
    25. Exclusive Team for Elementor
    26. Goods Catalog
    27. Stock Quotes List
    28. Sunshine Photo Cart
    29. Travel Map
    30. UniConsent Cookie Consent CMP for GDPR / CCPA
    31. Product Category Showcase for WooCommerce
    32. WP iCal Availability
    33. Insert Estimated Reading Time
    34. wordpress publish post email notification
    35. Tilda Publishing
    36. Locations
    37. Woocommerce Support System
    38. Woocommerce Support System
    39. All in One B2B for WooCommerce
    40. All in One B2B for WooCommerce
    41. Crayon Syntax Highlighter
    42. WordPress CTA
    43. Email posts to subscribers
    44. Email posts to subscribers
    45. Export Import Menus
    46. Font Awesome 4 Menus
    47. Google Maps Plugin by Intergeo
    48. JQuery Accordion Menu Widget
    49. Regpack
    50. SIS Handball
    51. Use Memcached
    52. WordPress Social Login
    53. wpCentral
    54. WP-dTree
    55. WP Gallery Metabox
  6. WordPress Theme Vulnerabilities
    1. Wishful Blog
    2. Attorney
    3. Raise Mag
    4. Flatsome
    5. Woodmart
  7. The Best WordPress Security Plugin to Secure & Protect WordPress Sites

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
Subscribe now

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Starter Templates

Product image for Starter Templates — Elementor, WordPress & Beaver Builder Templates.
Plugin
Starter Templates — Elementor, WordPress & Beaver Builder Templates
Plugin Slug
astra-sites
Installations
1,000,000+
Vulnerability
Broken Access Control
Patched in Version
3.2.6
Severity Score
Medium
CVE
2023-41805
The vulnerability has been patched, so you should update to version 3.2.6.

Starter Templates

Product image for Starter Templates — Elementor, WordPress & Beaver Builder Templates.
Plugin
Starter Templates — Elementor, WordPress & Beaver Builder Templates
Plugin Slug
astra-sites
Installations
1,000,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
3.2.5
Severity Score
High
CVE
2023-41804
The vulnerability has been patched, so you should update to version 3.2.5.

Fluent Forms

Product image for Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms.
Plugin
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms
Plugin Slug
fluentform
Installations
300,000+
Vulnerability
Broken Access Control
Patched in Version
5.0.9
Severity Score
Medium
CVE
2023-41952
The vulnerability has been patched, so you should update to version 5.0.9.

Activity Log

Product image for Activity Log.
Plugin
Activity Log
Plugin Slug
aryo-activity-log
Installations
200,000+
Vulnerability
Bypass Vulnerability
Patched in Version
2.8.8
Severity Score
Medium
CVE
2023-4281
The vulnerability has been patched, so you should update to version 2.8.8.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.
Plugin
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Plugin Slug
wp-user-avatar
Installations
200,000+
Vulnerability
Privilege Escalation
Patched in Version
4.13.2
Severity Score
High
CVE
2023-41954
The vulnerability has been patched, so you should update to version 4.13.2.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.
Plugin
Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Plugin Slug
wp-user-avatar
Installations
200,000+
Vulnerability
Broken Access Control
Patched in Version
4.13.2
Severity Score
Medium
CVE
2023-41953
The vulnerability has been patched, so you should update to version 4.13.2.

GiveWP

Product image for GiveWP – Donation Plugin and Fundraising Platform.
Plugin
GiveWP – Donation Plugin and Fundraising Platform
Plugin Slug
give
Installations
100,000+
Vulnerability
Privilege Escalation
Patched in Version
2.33.1
Severity Score
High
CVE
2023-41665
The vulnerability has been patched, so you should update to version 2.33.1.

Modula

Product image for Customizable WordPress Gallery Plugin – Modula Image Gallery.
Plugin
Customizable WordPress Gallery Plugin – Modula Image Gallery
Plugin Slug
modula-best-grid-gallery
Installations
100,000+
Vulnerability
Broken Access Control
Patched in Version
2.7.5
Severity Score
Low
The vulnerability has been patched, so you should update to version 2.7.5.

UserFeedback Lite

Product image for User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds.
Plugin
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
Plugin Slug
userfeedback-lite
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.8
Severity Score
High
CVE
2023-39308
The vulnerability has been patched, so you should update to version 1.0.8.

Slimstat Analytics

Product image for Slimstat Analytics.
Plugin
Slimstat Analytics
Plugin Slug
wp-slimstat
Installations
100,000+
Vulnerability
SQL Injection
Patched in Version
5.0.10
Severity Score
High
CVE
2023-4598
The vulnerability has been patched, so you should update to version 5.0.10.

Backup Migration

Product image for BackupBliss – Backup Migration Staging.
Plugin
BackupBliss – Backup Migration Staging
Plugin Slug
backup-backup
Installations
90,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.3.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Media Library Assistant

Product image for Media Library Assistant.
Plugin
Media Library Assistant
Plugin Slug
media-library-assistant
Installations
70,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.10
Severity Score
Critical
CVE
2023-4634
The vulnerability has been patched, so you should update to version 3.10.

Form Maker by 10Web

Product image for Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder.
Plugin
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Plugin Slug
form-maker
Installations
60,000+
Vulnerability
Arbitrary File Upload
Patched in Version
1.15.20
Severity Score
Critical
The vulnerability has been patched, so you should update to version 1.15.20.

MapPress Maps for WordPress

Product image for MapPress Maps for WordPress.
Plugin
MapPress Maps for WordPress
Plugin Slug
mappress-google-maps-for-wordpress
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.88.5
Severity Score
Medium
CVE
2023-4840
The vulnerability has been patched, so you should update to version 2.88.5.

Simple Membership

Product image for Simple Membership.
Plugin
Simple Membership
Plugin Slug
simple-membership
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.3.6
Severity Score
High
CVE
2023-4719
The vulnerability has been patched, so you should update to version 4.3.6.

Carousel Slider

Product image for Carousel Slider.
Plugin
Carousel Slider
Plugin Slug
carousel-slider
Installations
40,000+
Vulnerability
Broken Access Control
Patched in Version
2.2.3
Severity Score
Medium
CVE
2023-41848
The vulnerability has been patched, so you should update to version 2.2.3.

Super Socializer

Product image for Social Share, Social Login and Social Comments Plugin – Super Socializer.
Plugin
Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin Slug
super-socializer
Installations
40,000+
Vulnerability
Broken Access Control
Patched in Version
7.13.55
Severity Score
Medium
CVE
2023-41802
The vulnerability has been patched, so you should update to version 7.13.55.

Analytify

Product image for Analytify – Google Analytics Dashboard For WordPress (GA4 made easy).
Plugin
Analytify – Google Analytics Dashboard For WordPress (GA4 made easy)
Plugin Slug
wp-analytify
Installations
40,000+
Vulnerability
Broken Access Control
Patched in Version
5.1.1
Severity Score
Low
CVE
2023-41695
The vulnerability has been patched, so you should update to version 5.1.1.

Meks Easy Photo Feed Widget

Product image for Meks Easy Photo Feed Widget.
Plugin
Meks Easy Photo Feed Widget
Plugin Slug
meks-easy-instagram-widget
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.2.8
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.2.8.

Meks Simple Flickr Widget

Product image for Meks Simple Flickr Widget.
Plugin
Meks Simple Flickr Widget
Plugin Slug
meks-simple-flickr-widget
Installations
30,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.3
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.3.

GS Logo Slider

Product image for Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.
Plugin
Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation
Plugin Slug
gs-logo-slider
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
3.4.3
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 3.4.3.

Meks Easy Ads Widget

Product image for Meks Easy Ads Widget.
Plugin
Meks Easy Ads Widget
Plugin Slug
meks-easy-ads-widget
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.0.8
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 2.0.8.

Meks Smart Author Widget

Product image for Meks Smart Author Widget.
Plugin
Meks Smart Author Widget
Plugin Slug
meks-smart-author-widget
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.1.4
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.1.4.

Meks ThemeForest Smart Widget

Product image for Meks ThemeForest Smart Widget.
Plugin
Meks ThemeForest Smart Widget
Plugin Slug
meks-themeforest-smart-widget
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.5
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.5.

User Submitted Posts

Product image for User Submitted Posts – Enable Users to Submit Posts from the Front End.
Plugin
User Submitted Posts – Enable Users to Submit Posts from the Front End
Plugin Slug
user-submitted-posts
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
20230902
Severity Score
Medium
CVE
2023-41696
The vulnerability has been patched, so you should update to version 20230902.

WP Accessibility Helper (WAH)

Product image for WP Accessibility Helper (WAH).
Plugin
WP Accessibility Helper (WAH)
Plugin Slug
wp-accessibility-helper
Installations
20,000+
Vulnerability
Broken Access Control
Patched in Version
0.6.2.5
Severity Score
Medium
CVE
2023-41869
The vulnerability has been patched, so you should update to version 0.6.2.5.

Auto Amazon Links

Product image for Auto Amazon Links – Amazon Associates Affiliate Plugin.
Plugin
Auto Amazon Links – Amazon Associates Affiliate Plugin
Plugin Slug
amazon-auto-links
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.3.2
Severity Score
Medium
CVE
2023-4482
The vulnerability has been patched, so you should update to version 5.3.2.

rtMedia for WordPress, BuddyPress and bbPress

Product image for rtMedia for WordPress, BuddyPress and bbPress.
Plugin
rtMedia for WordPress, BuddyPress and bbPress
Plugin Slug
buddypress-media
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
4.6.15
Severity Score
Medium
CVE
2023-41951
The vulnerability has been patched, so you should update to version 4.6.15.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.
Plugin
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
Plugin Slug
directorist
Installations
10,000+
Vulnerability
CSV Injection
Patched in Version
7.7.2
Severity Score
Medium
CVE
2023-41798
The vulnerability has been patched, so you should update to version 7.7.2.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.
Plugin
Directorist – WordPress Business Directory Plugin with Classified Ads Listings
Plugin Slug
directorist
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
7.7.2
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 7.7.2.

Meks Time Ago

Product image for Meks Time Ago.
Plugin
Meks Time Ago
Plugin Slug
meks-time-ago
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.1.7
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.1.7.

SAML Single Sign On – SSO Login

Product image for SAML Single Sign On – SSO Login.
Plugin
SAML Single Sign On – SSO Login
Plugin Slug
miniorange-saml-20-single-sign-on
Installations
10,000+
Vulnerability
Broken Access Control
Patched in Version
5.0.5
Severity Score
Medium
CVE
2023-41873
The vulnerability has been patched, so you should update to version 5.0.5.

Order Delivery Date for WooCommerce

Product image for Order Delivery Date for WooCommerce.
Plugin
Order Delivery Date for WooCommerce
Plugin Slug
order-delivery-date-for-woocommerce
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.20.1
Severity Score
High
CVE
2023-41874
The vulnerability has been patched, so you should update to version 3.20.1.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.
Plugin
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts
Plugin Slug
wedevs-project-manager
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.6.1
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 2.6.1.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.
Plugin
WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts
Plugin Slug
wedevs-project-manager
Installations
10,000+
Vulnerability
SQL Injection
Patched in Version
2.6.1
Severity Score
High
CVE
2023-34383
The vulnerability has been patched, so you should update to version 2.6.1.

weMail

Product image for weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin.
Plugin
weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin
Plugin Slug
wemail
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.14.2
Severity Score
Medium
CVE
2022-47150
The vulnerability has been patched, so you should update to version 1.14.2.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).
Plugin
Post to Google My Business (Google Business Profile)
Plugin Slug
post-to-google-my-business
Installations
9,000+
Vulnerability
Broken Access Control
Patched in Version
3.1.15
Severity Score
Medium
CVE
2023-41689
The vulnerability has been patched, so you should update to version 3.1.15.

AcyMailing

Product image for AcyMailing – Newsletter & mailing automation for WordPress.
Plugin
AcyMailing – Newsletter & mailing automation for WordPress
Plugin Slug
acymailing
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
8.6.3
Severity Score
High
CVE
2023-41867
The vulnerability has been patched, so you should update to version 8.6.3.

Classifieds

Product image for WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds.
Plugin
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds
Plugin Slug
another-wordpress-classifieds-plugin
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.3.1
Severity Score
Medium
CVE
2023-41801
The vulnerability has been patched, so you should update to version 4.3.1.

Automatic YouTube Gallery

Product image for Automatic YouTube Gallery.
Plugin
Automatic YouTube Gallery
Plugin Slug
automatic-youtube-gallery
Installations
6,000+
Vulnerability
Broken Access Control
Patched in Version
2.3.5
Severity Score
Medium
CVE
2023-41866
The vulnerability has been patched, so you should update to version 2.3.5.

MyCryptoCheckout

Product image for MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce.
Plugin
MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce
Plugin Slug
mycryptocheckout
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.126
Severity Score
Medium
CVE
2023-41693
The vulnerability has been patched, so you should update to version 2.126.

Poll Maker

Product image for Poll Maker – Best WordPress Poll Plugin.
Plugin
Poll Maker – Best WordPress Poll Plugin
Plugin Slug
poll-maker
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.7.1
Severity Score
High
CVE
2023-41871
The vulnerability has been patched, so you should update to version 4.7.1.

Posts Like Dislike

Product image for Posts Like Dislike.
Plugin
Posts Like Dislike
Plugin Slug
posts-like-dislike
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
1.1.1
Severity Score
Medium
CVE
2023-41849
The vulnerability has been patched, so you should update to version 1.1.1.

Slider Pro

Product image for Slider Pro.
Plugin
Slider Pro
Plugin Slug
sliderpro
Installations
5,000+
Vulnerability
Broken Access Control
Patched in Version
4.8.7
Severity Score
Medium
CVE
2023-41865
The vulnerability has been patched, so you should update to version 4.8.7.

WP Crowdfunding

Product image for WP Crowdfunding.
Plugin
WP Crowdfunding
Plugin Slug
wp-crowdfunding
Installations
4,000+
Vulnerability
Broken Access Control
Patched in Version
2.1.6
Severity Score
Medium
CVE
2023-41870
The vulnerability has been patched, so you should update to version 2.1.6.

Meks Video Importer

Product image for Meks Video Importer.
Plugin
Meks Video Importer
Plugin Slug
meks-video-importer
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.0.11
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.0.11.

WooCommerce PensoPay

Plugin
WooCommerce PensoPay
Plugin Slug
woo-pensopay
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.3.2
Severity Score
High
CVE
2023-41691
The vulnerability has been patched, so you should update to version 6.3.2.

Locatoraid Store Locator

Product image for Locatoraid Store Locator.
Plugin
Locatoraid Store Locator
Plugin Slug
locatoraid
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.9.24
Severity Score
High
CVE
2023-4476
The vulnerability has been patched, so you should update to version 3.9.24.

Meks Audio Player

Product image for Meks Audio Player.
Plugin
Meks Audio Player
Plugin Slug
meks-audio-player
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.3
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 1.3.

StagTools

Product image for StagTools.
Plugin
StagTools
Plugin Slug
stagtools
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.8
Severity Score
High
CVE
2023-41868
The vulnerability has been patched, so you should update to version 2.3.8.

WP Directory Kit

Product image for WP Directory Kit.
Plugin
WP Directory Kit
Plugin Slug
wpdirectorykit
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
1.2.7
Severity Score
Medium
CVE
2023-41875
The vulnerability has been patched, so you should update to version 1.2.7.

WRC Pricing Tables

Product image for WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables.
Plugin
WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables
Plugin Slug
wrc-pricing-tables
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
2.3.8
Severity Score
Medium
CVE
2023-32293
The vulnerability has been patched, so you should update to version 2.3.8.

Bulk NoIndex & NoFollow Toolkit

Plugin
Bulk NoIndex & NoFollow Toolkit
Plugin Slug
bulk-noindex-nofollow-toolkit-by-mad-fish
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
1.51
Severity Score
Medium
CVE
2023-41688
The vulnerability has been patched, so you should update to version 1.51.

CP Blocks

Product image for CP Blocks.
Plugin
CP Blocks
Plugin Slug
cp-blocks
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.0.21
Severity Score
Medium
CVE
2023-41732
The vulnerability has been patched, so you should update to version 1.0.21.

Laposta Signup Basic

Product image for Laposta Signup Basic.
Plugin
Laposta Signup Basic
Plugin Slug
laposta-signup-basic
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.4.2
Severity Score
Medium
CVE
2023-41950
The vulnerability has been patched, so you should update to version 1.4.2.

Meks Easy Maps

Product image for Meks Easy Maps.
Plugin
Meks Easy Maps
Plugin Slug
meks-easy-maps
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.1.4
Severity Score
Medium
CVE
2023-25989
The vulnerability has been patched, so you should update to version 2.1.4.

Notice Bar

Product image for Notice Bar.
Plugin
Notice Bar
Plugin Slug
notice-bar
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.1
Severity Score
Medium
CVE
2023-41847
The vulnerability has been patched, so you should update to version 3.1.1.

POEditor

Product image for POEditor.
Plugin
POEditor
Plugin Slug
poeditor
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
0.9.5
Severity Score
Medium
CVE
2023-32091
The vulnerability has been patched, so you should update to version 0.9.5.

User Private Files

Product image for WordPress File Sharing Plugin.
Plugin
WordPress File Sharing Plugin
Plugin Slug
user-private-files
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.4
Severity Score
Medium
CVE
2023-4636
The vulnerability has been patched, so you should update to version 2.0.4.

WiserNotify Social Proof

Product image for WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets.
Plugin
WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets
Plugin Slug
wiser-notify
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
2.6
Severity Score
Medium
CVE
2023-41690
The vulnerability has been patched, so you should update to version 2.6.

WP Pipes

Product image for WP Pipes.
Plugin
WP Pipes
Plugin Slug
wp-pipes
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.4.1
Severity Score
Medium
CVE
2023-40009
The vulnerability has been patched, so you should update to version 1.4.1.

BitPay Checkout for WooCommerce

Product image for BitPay Checkout for WooCommerce.
Plugin
BitPay Checkout for WooCommerce
Plugin Slug
bitpay-checkout-for-woocommerce
Installations
900+
Vulnerability
Broken Access Control
Patched in Version
5.0.0
Severity Score
Medium
CVE
2023-41803
The vulnerability has been patched, so you should update to version 5.0.0.

Swifty Bar, sticky bar by WPGens

Product image for Swifty Bar, sticky bar by WPGens.
Plugin
Swifty Bar, sticky bar by WPGens
Plugin Slug
swifty-bar
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.11
Severity Score
Medium
CVE
2023-41737
The vulnerability has been patched, so you should update to version 1.2.11.

Cookie Notice & Consent

Product image for Cookie Notice & Consent.
Plugin
Cookie Notice & Consent
Plugin Slug
cookie-notice-consent
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.1
Severity Score
Medium
CVE
2023-41948
The vulnerability has been patched, so you should update to version 1.6.1.

Simple Download Counter

Plugin
Simple Download Counter
Plugin Slug
simple-download-counter
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.1
Severity Score
Medium
CVE
2023-4838
The vulnerability has been patched, so you should update to version 1.6.1.

Laposta Signup Embed

Product image for Laposta Signup Embed.
Plugin
Laposta Signup Embed
Plugin Slug
laposta-signup-embed
Installations
400+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
1.1.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Laposta Signup Embed

Product image for Laposta Signup Embed.
Plugin
Laposta Signup Embed
Plugin Slug
laposta-signup-embed
Installations
400+
Vulnerability
Broken Access Control
Patched in Version
1.1.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

RSVPMaker

Product image for RSVPMaker.
Plugin
RSVPMaker
Plugin Slug
rsvpmaker
Installations
400+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
10.6.7
Severity Score
Critical
CVE
2023-25054
The vulnerability has been patched, so you should update to version 10.6.7.

PeproDev CF7 Database

Product image for PeproDev CF7 Database.
Plugin
PeproDev CF7 Database
Plugin Slug
pepro-cf7-database
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.0
Severity Score
High
CVE
2023-41863
The vulnerability has been patched, so you should update to version 1.8.0.

iFolders

Product image for iFolders – Ultimate Folder Manager for Media, Pages, Posts & etc.
Plugin
iFolders – Ultimate Folder Manager for Media, Pages, Posts & etc
Plugin Slug
ifolders
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.1
Severity Score
Medium
CVE
2023-41949
The vulnerability has been patched, so you should update to version 1.5.1.

Staff / Employee Business Directory for Active Directory

Product image for Staff / Employee Business Directory for Active Directory.
Plugin
Staff / Employee Business Directory for Active Directory
Plugin Slug
ldap-ad-staff-employee-directory-search
Installations
10+
Vulnerability
Broken Access Control
Patched in Version
1.2.3
Severity Score
Medium
CVE
2023-4757
The vulnerability has been patched, so you should update to version 1.2.3.

Premium Starter Templates

Plugin
Premium Starter Templates
Plugin Slug
astra-pro-sites
Vulnerability
Broken Access Control
Patched in Version
3.2.6
Severity Score
Medium
CVE
2023-41805
The vulnerability has been patched, so you should update to version 3.2.6.

Premium Starter Templates

Plugin
Premium Starter Templates
Plugin Slug
astra-pro-sites
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
3.2.5
Severity Score
High
CVE
2023-41804
The vulnerability has been patched, so you should update to version 3.2.5.

Newsletter

Plugin
Email Newsletter
Plugin Slug
email-newsletter
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.9.0
Severity Score
Medium
CVE
2023-4772
The vulnerability has been patched, so you should update to version 7.9.0.

My Account Page Editor

Plugin
My Account Page Editor for Woocommerce
Plugin Slug
my-account-page-editor
Vulnerability
Arbitrary File Upload
Patched in Version
1.3.2
Severity Score
Critical
CVE
2023-4536
The vulnerability has been patched, so you should update to version 1.3.2.

VS Contact Form

Plugin
VS Contact Form
Plugin Slug
very-simple-contact-form
Vulnerability
Broken Authentication
Patched in Version
14.0
Severity Score
Medium
CVE
2023-41862
The vulnerability has been patched, so you should update to version 14.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

FileOrganizer

Product image for FileOrganizer – Manage WordPress and Website Files.
Plugin
FileOrganizer – Manage WordPress and Website Files
Plugin Slug
fileorganizer
Installations
90,000+
Vulnerability
Arbitrary File Download
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-3664
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Conversion Tracking

Product image for WooCommerce Conversion Tracking.
Plugin
WooCommerce Conversion Tracking
Plugin Slug
woocommerce-conversion-tracking
Installations
40,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Legal Pages

Product image for Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator.
Plugin
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
Plugin Slug
legal-pages
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

MailMunch – Grow your Email List

Product image for MailMunch – Grow your Email List.
Plugin
MailMunch – Grow your Email List
Plugin Slug
mailmunch
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41852
The vulnerability has not been patched. You should deactivate the plugin.

Texty

Product image for Texty – SMS Notification for WordPress, WooCommerce, Dokan and more.
Plugin
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
Plugin Slug
texty
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elementor Inner Sections By BoomDevs

Product image for Unlimited Elementor Inner Sections By BoomDevs.
Plugin
Unlimited Elementor Inner Sections By BoomDevs
Plugin Slug
unlimited-elementor-inner-sections-by-boomdevs
Installations
7,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Plugin
Order Delivery Date for WP e-Commerce
Plugin Slug
order-delivery-date
Installations
6,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41859
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Plugin
Order Delivery Date for WP e-Commerce
Plugin Slug
order-delivery-date
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41858
The vulnerability has not been patched. You should deactivate the plugin.

weDocs – Knowledgebase and Documentation Plugin for WordPress

Product image for weDocs – Knowledgebase and Documentation Plugin for WordPress.
Plugin
weDocs – Knowledgebase and Documentation Plugin for WordPress
Plugin Slug
wedocs
Installations
6,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Outbound Link Manager

Plugin
Outbound Link Manager
Plugin Slug
outbound-link-manager
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41850
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post Template

Plugin
WP Custom Post Template
Plugin Slug
wp-custom-post-template
Installations
5,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41851
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Product image for Leadster.
Plugin
Leadster
Plugin Slug
leadster-marketing-conversacional
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41668
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.
Plugin
SendPress Newsletters
Plugin Slug
sendpress
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41730
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.
Plugin
SendPress Newsletters
Plugin Slug
sendpress
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41729
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Cleaner

Product image for Easy WP Cleaner.
Plugin
Easy WP Cleaner
Plugin Slug
easy-wp-cleaner
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41697
The vulnerability has not been patched. You should deactivate the plugin.

Live News

Product image for Live News.
Plugin
Live News
Plugin Slug
live-news-lite
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41669
The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Plugin
Realbig For WordPress
Plugin Slug
realbig-media
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41694
The vulnerability has not been patched. You should deactivate the plugin.

TelSender

Product image for TelSender – ?ontact form 7, Events, Wpforms  and wooccommerce to telegram bot.
Plugin
TelSender – ?ontact form 7, Events, Wpforms and wooccommerce to telegram bot
Plugin Slug
telsender
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41683
The vulnerability has not been patched. You should deactivate the plugin.

Rescue Shortcodes

Product image for Rescue Shortcodes.
Plugin
Rescue Shortcodes
Plugin Slug
rescue-shortcodes
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41728
The vulnerability has not been patched. You should deactivate the plugin.

Restrict

Product image for Restrict – membership, site, content and user access restrictions for WordPress.
Plugin
Restrict – membership, site, content and user access restrictions for WordPress
Plugin Slug
restricted-content
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41861
The vulnerability has not been patched. You should deactivate the plugin.

Hide admin notices – Admin Notification Center

Plugin
Hide admin notices – Admin Notification Center
Plugin Slug
wp-admin-notification-center
Installations
2,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41672
The vulnerability has not been patched. You should deactivate the plugin.

Back To The Top Button

Product image for Back To The Top Button.
Plugin
Back To The Top Button
Plugin Slug
back-to-the-top-button
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41733
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Product image for Click To Tweet.
Plugin
Click To Tweet
Plugin Slug
click-to-tweet
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41857
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Product image for Click To Tweet.
Plugin
Click To Tweet
Plugin Slug
click-to-tweet
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41856
The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Product image for Exclusive Team for Elementor.
Plugin
Exclusive Team for Elementor
Plugin Slug
exclusive-team-for-elementor
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin
Goods Catalog
Plugin Slug
goods-catalog
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41687
The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Product image for Stock Quotes List.
Plugin
Stock Quotes List
Plugin Slug
stock-quotes-list
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41666
The vulnerability has not been patched. You should deactivate the plugin.

Sunshine Photo Cart

Product image for Sunshine Photo Cart.
Plugin
Sunshine Photo Cart
Plugin Slug
sunshine-photo-cart
Installations
1,000+
Vulnerability
Insecure Direct Object References (IDOR)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41796
The vulnerability has not been patched. You should deactivate the plugin.

Travel Map

Product image for Travel Map.
Plugin
Travel Map
Plugin Slug
travelmap-blog
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41860
The vulnerability has not been patched. You should deactivate the plugin.

UniConsent Cookie Consent CMP for GDPR / CCPA

Product image for UniConsent CMP for GDPR CPRA GPP TCF.
Plugin
UniConsent CMP for GDPR CPRA GPP TCF
Plugin Slug
uniconsent-cmp
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41800
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Product image for Product Category Showcase for WooCommerce.
Plugin
Product Category Showcase for WooCommerce
Plugin Slug
wc-category-showcase
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched. You should deactivate the plugin.

WP iCal Availability

Plugin
WP iCal Availability
Plugin Slug
wp-ical-availability
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41853
The vulnerability has not been patched. You should deactivate the plugin.

Insert Estimated Reading Time

Plugin
Insert Estimated Reading Time
Plugin Slug
insert-estimated-reading-time
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41734
The vulnerability has not been patched. You should deactivate the plugin.

wordpress publish post email notification

Plugin
wordpress publish post email notification
Plugin Slug
publish-post-email-notification
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41731
The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Plugin
Tilda Publishing
Plugin Slug
tilda-publishing
Installations
900+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-31234
The vulnerability has not been patched. You should deactivate the plugin.

Locations

Product image for Locations.
Plugin
Locations
Plugin Slug
locations
Installations
800+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41797
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.
Plugin
Woocommerce Support System
Plugin Slug
wc-support-system
Installations
300+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41686
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.
Plugin
Woocommerce Support System
Plugin Slug
wc-support-system
Installations
300+
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
CVE
2023-41685
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin
All in One B2B for WooCommerce
Plugin Slug
all-in-one-b2b-for-woocommerce
Vulnerability
Privilege Escalation
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-4703
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin
All in One B2B for WooCommerce
Plugin Slug
all-in-one-b2b-for-woocommerce
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-3547
The vulnerability has not been patched. You should deactivate the plugin.

Crayon Syntax Highlighter

Plugin
Crayon Syntax Highlighter
Plugin Slug
crayon-syntax-highlighter
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4893
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress CTA

Plugin
WordPress CTA
Plugin Slug
easy-sticky-sidebar
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2022-47150
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin
Email posts to subscribers
Plugin Slug
email-posts-to-subscribers
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41736
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin
Email posts to subscribers
Plugin Slug
email-posts-to-subscribers
Vulnerability
Sensitive Data Exposure
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41735
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Export Import Menus

Plugin
Export Import Menus
Plugin Slug
export-import-menus
Vulnerability
Arbitrary File Upload
Patched in Version
No Fix
Severity Score
Critical
CVE
2023-34385
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

Plugin
Font Awesome 4 Menus
Plugin Slug
font-awesome-4-menus
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4718
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Maps Plugin by Intergeo

Plugin
Google Maps Plugin by Intergeo
Plugin Slug
intergeo-maps
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4887
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JQuery Accordion Menu Widget

Plugin
JQuery Accordion Menu Widget
Plugin Slug
jquery-vertical-accordion-menu
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4890
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Regpack

Plugin
Regpack
Plugin Slug
regpack
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41855
The vulnerability has not been patched. You should deactivate the plugin.

SIS Handball

Plugin
SIS Handball
Plugin Slug
sis-handball
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41684
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

Plugin
Use Memcached
Plugin Slug
use-memcached
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41670
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Social Login

Plugin
WordPress Social Login
Plugin Slug
wordpress-social-login
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-4773
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wpCentral

Plugin
wpCentral
Plugin Slug
wp-central
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41854
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin
WP-dTree
Plugin Slug
wp-dtree-30
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41667
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Gallery Metabox

Plugin
WP Gallery Metabox
Plugin Slug
wp-gallery-metabox
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
CVE
2023-41876
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Wishful Blog

Product image for Wishful Blog.
Theme
Wishful Blog
Theme Slug
wishful-blog
Downloads
79,101
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-28621
The vulnerability has not been patched. You should switch themes.

Attorney

Product image for Attorney.
Theme
Attorney
Theme Slug
attorney
Downloads
51,491
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-41692
The vulnerability has not been patched. You should switch themes.

Raise Mag

Product image for Raise Mag.
Theme
Raise Mag
Theme Slug
raise-mag
Downloads
12,709
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
CVE
2023-28621
The vulnerability has not been patched. You should switch themes.

Flatsome

Theme
Flatsome
Theme Slug
flatsome
Vulnerability
PHP Object Injection
Patched in Version
3.17.6
Severity Score
High
CVE
2023-40555
The vulnerability has been patched, so you should update to version 3.17.6.

Woodmart

Theme
WoodMart
Theme Slug
woodmart
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.2.5
Severity Score
High
CVE
2023-41872
The vulnerability has been patched, so you should update to version 7.2.5.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.

Scans Your Website Twice a Day for Vulnerabilities

Your website’s plugins, themes, and WordPress core versions are checked against the Patchstack Vulnerability Database for the latest vulnerability disclosures.

Automatically Updates if a Security Fix is Available

Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.

Emails You a Warning if Site Scan Detects a Vulnerability

You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.

iThemes Security Pro

The Best WordPress Security Plugin to Secure & Protect WordPress Sites

WordPress currently powers over 40% of all websites, so it has become a popular target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.

Buy iThemes Security Pro


Dan Knauss
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
WordPress Vulnerability Report
WordPress Vulnerability Report – September 6, 2023
wordpress vulnerability report - security
WordPress Vulnerability Report – August 30, 2023
WordPress Vulnerability Report
WordPress Vulnerability Report – August 23, 2023
A computer riddled with security issue alerts. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – August 16, 2023

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.
No spam. Unsubscribe anytime.