WordPress Vulnerability Report

WordPress Vulnerability Report – September 13, 2023

Since last week, 136 total vulnerabilities emerged in public disclosure. They may affect over four million WordPress sites. There are 76 plugin vulnerabilities and two theme vulnerabilities with security patches, so run those updates! Additionally, there are 55 plugin vulnerabilities and three theme vulnerabilities with no patch available yet.

Dan Knauss

Since last week, 136 total vulnerabilities emerged in public disclosure. They may affect over four million WordPress sites. There are 76 plugin vulnerabilities and two theme vulnerabilities with security patches, so run those updates!

Additionally, there are 55 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WEBINAR REPLAY NOW AVAILABLE

Discover a streamlined approach to WordPress logins with Passkeys and Solid Security Pro (the new name for iThemes Security Pro). Passkeys are compatible with leading browsers such as Chrome, Firefox, and Safari, as well as biometric logins like Face ID, Touch ID, and Windows Hello. Say goodbye to the hassle of extra two-factor apps, password managers, or intricate password requirements, as website administrators and end users can now enjoy secure logins effortlessly.

Powered by the WebAuthn protocol, these cutting-edge login methods redefine passwordless login experiences, setting the stage for the future of safeguarding sensitive online information, including accessing WordPress sites. Timothy Jacobs, Lead Developer for SolidWP, gives an in-depth exploration of how this innovative technology enhances the WordPress login process for both you and your clients.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Activity Log

Plugin Slug:
aryo-activity-log
Installations:
200,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

Slimstat Analytics

Plugin Slug:
wp-slimstat
Installations:
100,000+
Vulnerability:
SQL Injection
Patched in Version:
5.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.10.

Backup Migration

Plugin Slug:
backup-backup
Installations:
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations:
70,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.10.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.88.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.88.5.

Simple Membership

Plugin Slug:
simple-membership
Installations:
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.6.
Plugin Slug:
carousel-slider
Installations:
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.

Meks Easy Photo Feed Widget

Plugin Slug:
meks-easy-instagram-widget
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Meks Simple Flickr Widget

Plugin Slug:
meks-simple-flickr-widget
Installations:
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Meks Easy Ads Widget

Plugin Slug:
meks-easy-ads-widget
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Meks Smart Author Widget

Plugin Slug:
meks-smart-author-widget
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.4.

Meks ThemeForest Smart Widget

Plugin Slug:
meks-themeforest-smart-widget
Installations:
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

WP Accessibility Helper (WAH)

Plugin Slug:
wp-accessibility-helper
Installations:
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.2.5.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.6.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.15.

Meks Time Ago

Plugin Slug:
meks-time-ago
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

SAML Single Sign On – SSO Login

Plugin Slug:
miniorange-saml-20-single-sign-on
Installations:
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.5.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce
Installations:
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.20.1.

Post to Google My Business (Google Business Profile)

Plugin Slug:
post-to-google-my-business
Installations:
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.15.
Plugin Slug:
automatic-youtube-gallery
Installations:
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

Poll Maker

Plugin Slug:
poll-maker
Installations:
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.1.

Posts Like Dislike

Plugin Slug:
posts-like-dislike
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Slider Pro

Plugin:
Slider Pro
Plugin Slug:
sliderpro
Installations:
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.7.

WP Crowdfunding

Plugin Slug:
wp-crowdfunding
Installations:
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Meks Video Importer

Plugin Slug:
meks-video-importer
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

WooCommerce PensoPay

Plugin Slug:
woo-pensopay
Installations:
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.2.

Locatoraid Store Locator

Plugin Slug:
locatoraid
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.24.

Meks Audio Player

Plugin Slug:
meks-audio-player
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

StagTools

Plugin:
StagTools
Plugin Slug:
stagtools
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.8.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations:
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.51
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.51.

CP Blocks

Plugin:
CP Blocks
Plugin Slug:
cp-blocks
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.21.

Laposta Signup Basic

Plugin Slug:
laposta-signup-basic
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

Meks Easy Maps

Plugin Slug:
meks-easy-maps
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

Notice Bar

Plugin:
Notice Bar
Plugin Slug:
notice-bar
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

POEditor

Plugin:
POEditor
Plugin Slug:
poeditor
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.5.

User Private Files

Plugin Slug:
user-private-files
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

BitPay Checkout for WooCommerce

Plugin Slug:
bitpay-checkout-for-woocommerce
Installations:
900+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Swifty Bar, sticky bar by WPGens

Plugin Slug:
swifty-bar
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.11.
Plugin Slug:
cookie-notice-consent
Installations:
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations:
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Laposta Signup Embed

Plugin Slug:
laposta-signup-embed
Installations:
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Laposta Signup Embed

Plugin Slug:
laposta-signup-embed
Installations:
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

RSVPMaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations:
400+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
10.6.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 10.6.7.

PeproDev CF7 Database

Plugin Slug:
pepro-cf7-database
Installations:
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Staff / Employee Business Directory for Active Directory

Plugin Slug:
ldap-ad-staff-employee-directory-search
Installations:
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Premium Starter Templates

Plugin Slug:
astra-pro-sites
Vulnerability:
Broken Access Control
Patched in Version:
3.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.6.

Premium Starter Templates

Plugin Slug:
astra-pro-sites
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Newsletter

Plugin Slug:
email-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.9.0.

My Account Page Editor

Plugin Slug:
my-account-page-editor
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.2.

VS Contact Form

Plugin Slug:
very-simple-contact-form
Vulnerability:
Broken Authentication
Patched in Version:
14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WooCommerce Conversion Tracking

Plugin Slug:
woocommerce-conversion-tracking
Installations:
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailMunch – Grow your Email List

Plugin Slug:
mailmunch
Installations:
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elementor Inner Sections By BoomDevs

Plugin Slug:
unlimited-elementor-inner-sections-by-boomdevs
Installations:
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Plugin Slug:
order-delivery-date
Installations:
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WP e-Commerce

Plugin Slug:
order-delivery-date
Installations:
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
outbound-link-manager
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post Template

Plugin Slug:
wp-custom-post-template
Installations:
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Plugin:
Leadster
Plugin Slug:
leadster-marketing-conversacional
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin Slug:
sendpress
Installations:
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin Slug:
sendpress
Installations:
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Cleaner

Plugin Slug:
easy-wp-cleaner
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live News

Plugin:
Live News
Plugin Slug:
live-news-lite
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Plugin Slug:
realbig-media
Installations:
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes
Installations:
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide admin notices – Admin Notification Center

Plugin Slug:
wp-admin-notification-center
Installations:
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Back To The Top Button

Plugin Slug:
back-to-the-top-button
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Plugin Slug:
click-to-tweet
Installations:
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Click To Tweet

Plugin Slug:
click-to-tweet
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Plugin Slug:
exclusive-team-for-elementor
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin Slug:
goods-catalog
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Plugin Slug:
stock-quotes-list
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sunshine Photo Cart

Plugin Slug:
sunshine-photo-cart
Installations:
1,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Travel Map

Plugin:
Travel Map
Plugin Slug:
travelmap-blog
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
uniconsent-cmp
Installations:
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Plugin Slug:
wc-category-showcase
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP iCal Availability

Plugin Slug:
wp-ical-availability
Installations:
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Insert Estimated Reading Time

Plugin Slug:
insert-estimated-reading-time
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wordpress publish post email notification

Plugin Slug:
publish-post-email-notification
Installations:
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Plugin Slug:
tilda-publishing
Installations:
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Locations

Plugin:
Locations
Plugin Slug:
locations
Installations:
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Plugin Slug:
wc-support-system
Installations:
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Plugin Slug:
wc-support-system
Installations:
300+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin Slug:
all-in-one-b2b-for-woocommerce
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

All in One B2B for WooCommerce

Plugin Slug:
all-in-one-b2b-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crayon Syntax Highlighter

Plugin Slug:
crayon-syntax-highlighter
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress CTA

Plugin Slug:
easy-sticky-sidebar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin Slug:
email-posts-to-subscribers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Email posts to subscribers

Plugin Slug:
email-posts-to-subscribers
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Export Import Menus

Plugin Slug:
export-import-menus
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

Plugin Slug:
font-awesome-4-menus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Maps Plugin by Intergeo

Plugin Slug:
intergeo-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JQuery Accordion Menu Widget

Plugin Slug:
jquery-vertical-accordion-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Regpack

Plugin:
Regpack
Plugin Slug:
regpack
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SIS Handball

Plugin Slug:
sis-handball
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

Plugin Slug:
use-memcached
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Social Login

Plugin Slug:
wordpress-social-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wpCentral

Plugin:
wpCentral
Plugin Slug:
wp-central
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin:
WP-dTree
Plugin Slug:
wp-dtree-30
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.
Plugin Slug:
wp-gallery-metabox
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Wishful Blog

Theme Slug:
wishful-blog
Downloads:
79,101
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Attorney

Theme:
Attorney
Theme Slug:
attorney
Downloads:
51,491
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Raise Mag

Theme:
Raise Mag
Theme Slug:
raise-mag
Downloads:
12,709
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Flatsome

Theme:
Flatsome
Theme Slug:
flatsome
Vulnerability:
PHP Object Injection
Patched in Version:
3.17.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.17.6.

Woodmart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security