WordPress Vulnerability Report – July 27, 2023

>>> Shared from Original Post iThemes

Since last week, 329 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 209 plugin vulnerabilities and 18 theme vulnerabilities with security patches, so run those updates!

Additionally, there are 66 plugin vulnerabilities and 36 theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

Such an unusually high number of vulnerability reports is due to outdated versions of many plugins and themes that may use a common third-party dependency, Freemius’ WordPress SDK 2.5.9. Please see the Freemius WordPress SDK 2.5.9 Security Disclosure for more details.

New Today: Patchstack lists multiple high-severity vulnerabilities in the Ninja Forms plugin, potentially affecting 900k active WordPress sites. These vulnerabilities include a POST-based reflected XSS and broken access control on the form submissions export feature. Please update to version 3.6.26.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Essential Addons For Elementor

Product image for Essential Addons for Elementor.
Plugin Slug
essential-addons-for-elementor-lite
Installations
1,000,000+
Vulnerability
Sensitive Data Exposure
Patched in Version
5.8.2
Severity Score
Medium
The vulnerability has been patched, so you should update to version 5.8.2.

The Events Calendar

Product image for The Events Calendar.
Plugin Slug
the-events-calendar
Installations
800,000+
Vulnerability
Broken Access Control
Patched in Version
6.1.3
Severity Score
Medium
The vulnerability has been patched, so you should update to version 6.1.3.

The Events Calendar

Product image for The Events Calendar.
Plugin Slug
the-events-calendar
Installations
800,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.1.0
Severity Score
High
The vulnerability has been patched, so you should update to version 6.1.0.

NextGEN Gallery

Product image for WordPress Gallery Plugin – NextGEN Gallery.
Plugin Slug
nextgen-gallery
Installations
600,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4.7
Severity Score
High
The vulnerability has been patched, so you should update to version 3.4.7.

WP Activity Log

Product image for WP Activity Log.
Plugin Slug
wp-security-audit-log
Installations
200,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.4.3
Severity Score
High
The vulnerability has been patched, so you should update to version 4.4.3.

Elementor Addon Elements

Product image for Elementor Addon Elements.
Plugin Slug
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.12
Severity Score
High
The vulnerability has been patched, so you should update to version 1.12.

CAPTCHA 4WP

Product image for CAPTCHA 4WP.
Plugin Slug
advanced-nocaptcha-recaptcha
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
7.0.6
Severity Score
High
The vulnerability has been patched, so you should update to version 7.0.6.

Blocksy Companion

Product image for Blocksy Companion.
Plugin Slug
blocksy-companion
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.47
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.47.

Meta Tag Manager

Product image for Meta Tag Manager.
Plugin Slug
meta-tag-manager
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.

Pods

Product image for Pods – Custom Content Types and Fields.
Plugin Slug
pods
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.8.23
Severity Score
High
The vulnerability has been patched, so you should update to version 2.8.23.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.
Plugin Slug
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.7.0.

Asset CleanUp: Page Speed Booster

Product image for Asset CleanUp: Page Speed Booster.
Plugin Slug
wp-asset-clean-up
Installations
100,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.5.5
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.5.5.

AnyWhere Elementor

Product image for AnyWhere Elementor.
Plugin Slug
anywhere-elementor
Installations
90,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.8.

Event Tickets

Product image for Event Tickets and Registration.
Plugin Slug
event-tickets
Installations
70,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
5.6.0
Severity Score
High
The vulnerability has been patched, so you should update to version 5.6.0.

Easy Watermark

Product image for Easy Watermark.
Plugin Slug
easy-watermark
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.7
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.7.

Simple Author Box

Product image for Simple Author Box.
Plugin Slug
simple-author-box
Installations
60,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4
Severity Score
High
The vulnerability has been patched, so you should update to version 2.4.

Preloader Plus – WordPress Loading Screen Plugin

Product image for Preloader Plus – WordPress Loading Screen Plugin.
Plugin Slug
preloader-plus
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.

Stop User Enumeration

Product image for Stop User Enumeration.
Plugin Slug
stop-user-enumeration
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.0.

Mail Bank – #1 Mail SMTP Plugin for WordPress

Product image for Mail Bank – #1 Mail SMTP Plugin for WordPress.
Plugin Slug
wp-mail-bank
Installations
40,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.13
Severity Score
High
The vulnerability has been patched, so you should update to version 3.0.13.

Gutenberg Block Editor Toolkit

Product image for Gutenberg Block Editor Toolkit – EditorsKit.
Plugin Slug
block-options
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.17
Severity Score
High
The vulnerability has been patched, so you should update to version 1.17.

Divi Contact Form 7

Product image for Contact Form 7 Module For Divi Builder.
Plugin Slug
cf7-styler-for-divi
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.3.

Cost Calculator Builder

Product image for Cost Calculator Builder.
Plugin Slug
cost-calculator-builder
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.3
Severity Score
High
The vulnerability has been patched, so you should update to version 2.3.3.

Image Photo Gallery Final Tiles Grid

Product image for Image Photo Gallery Final Tiles Grid.
Plugin Slug
final-tiles-grid-gallery-lite
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.8
Severity Score
High
The vulnerability has been patched, so you should update to version 3.5.8.

Hide Admin Bar Based on User Roles

Product image for Hide Admin Bar Based on User Roles.
Plugin Slug
hide-admin-bar-based-on-user-roles
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.

Divi Carousel Lite

Plugin Slug
wow-carousel-for-divi-lite
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.12
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.12.

WP Google Review Slider

Product image for WP Google Review Slider.
Plugin Slug
wp-google-places-review-slider
Installations
30,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
12.6
Severity Score
High
The vulnerability has been patched, so you should update to version 12.6.

DiviTorque – Divi Theme, Divi Builder and Extra Theme

Product image for Divi Torque Lite.
Plugin Slug
addons-for-divi
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.6.0.

Contact Form 7 Skins

Product image for CF7 Skins for Contact Form 7.
Plugin Slug
contact-form-7-skins
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.1.

Greenshift – animation and page builder blocks

Product image for Greenshift – animation and page builder blocks.
Plugin Slug
greenshift-animation-and-page-builder-blocks
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.8.1
Severity Score
High
The vulnerability has been patched, so you should update to version 4.8.1.

New User Approve

Product image for New User Approve.
Plugin Slug
new-user-approve
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.5.1.

HP Everywhere

Product image for PHP Everywhere.
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.
Plugin Slug
php-everywhere
Installations
20,000+
Vulnerability
Remote Code Execution (RCE)
Patched in Version
3.0.0
Severity Score
Critical
The vulnerability has been patched, so you should update to version 3.0.0.

Redirect 404 Error Page to Homepage or Custom Page with Logs

Plugin Slug
redirect-404-error-page-to-homepage-or-custom-page
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.0.

Media Library Categories

Product image for Media Library Categories.
Plugin Slug
wp-media-library-categories
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP to Twitter

Product image for WP to Twitter.
Plugin Slug
wp-to-twitter
Installations
20,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.3.0.

DeMomentSomTres WordPress Export Posts With Images

Product image for DeMomentSomTres WordPress Export Posts With Images.
Plugin Slug
demomentsomtres-wp-export
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
20200610
Severity Score
High
The vulnerability has been patched, so you should update to version 20200610.

Enjoy Social Feed plugin for WordPress website

Product image for Enjoy Social Feed plugin for WordPress website.
Plugin Slug
enjoy-instagram-instagram-responsive-images-gallery-and-carousel
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 6.2.1.

eRoom – Zoom Meetings & Webinar

Product image for eRoom – Zoom Meetings & Webinars.
Plugin Slug
eroom-zoom-meetings-webinar
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.4.

PowerPack Lite for Beaver Builder

Product image for PowerPack Lite for Beaver Builder.
Plugin Slug
powerpack-addon-for-beaver-builder
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.9.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.9.3.

Seo Optimized Images

Product image for Seo Optimized Images.
Plugin Slug
seo-optimized-images
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.

WP News and Scrolling Widgets

Product image for WP News and Scrolling Widgets.
Plugin Slug
sp-news-and-widget
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.2
Severity Score
High
The vulnerability has been patched, so you should update to version 4.2.

Stop WP Emails Going to Spam

Plugin Slug
stop-wp-emails-going-to-spam
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Tiered Price Table

Product image for Tiered Pricing Table for WooCommerce.
Plugin Slug
tier-pricing-table
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.5.1
Severity Score
High
The vulnerability has been patched, so you should update to version 3.5.1.

WP Review Slider

Product image for WP Review Slider.
Plugin Slug
wp-facebook-reviews
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6
Severity Score
High
The vulnerability has been patched, so you should update to version 3.6.

WP Mail Log

Product image for WP Mail Log.
Plugin Slug
wp-mail-log
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.1.

ACF Frontend – Add and edit posts, pages, users and more all from the frontend

Plugin Slug
acf-frontend-form-element
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.8.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.8.0.

HuCommerce | Magyar WooCommerce kiegészítések

Product image for HuCommerce | Magyar WooCommerce kiegészítések.
Plugin Slug
surbma-magyar-woocommerce
Installations
9,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2022.0.3
Severity Score
High
The vulnerability has been patched, so you should update to version 2022.0.3.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).
Plugin Slug
post-to-google-my-business
Installations
8,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.14
Severity Score
High
The vulnerability has been patched, so you should update to version 3.1.14.

Salon booking system

Product image for Salon booking system.
Plugin Slug
salon-booking-system
Installations
7,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
8.4.9
Severity Score
High
The vulnerability has been patched, so you should update to version 8.4.9.

Easy Photography Portfolio

Product image for Easy Photography Portfolio.
Plugin Slug
photography-portfolio
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.9
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.9.

Quiz Cat

Product image for Quiz Cat – WordPress Quiz Plugin.
Plugin Slug
quiz-cat
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.0.

WooCommerce Google Ads Dynamic Remarketing

Product image for WooCommerce Google Ads Dynamic Remarketing.
Plugin Slug
woocommerce-google-dynamic-retargeting-tag
Installations
5,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.17
Severity Score
High
The vulnerability has been patched, so you should update to version 1.7.17.

ACF-VC Integrator

Product image for ACF-VC Integrator.
Plugin Slug
acf-vc-integrator
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.1.

AnyComment

Product image for AnyComment.
Plugin Slug
anycomment
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.0.99
Severity Score
High
The vulnerability has been patched, so you should update to version 0.0.99.

Search Console

Product image for Search Console.
Plugin Slug
search-console
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.2.2
Severity Score
High
The vulnerability has been patched, so you should update to version 2.2.2.

Discussion Board

Product image for Discussion Board – WordPress Forum Plugin.
Plugin Slug
wp-discussion-board
Installations
3,000+
Vulnerability
Content Injection
Patched in Version
2.4.9
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

Photo Engine

Product image for Photo Engine (Media Organizer & Lightroom).
Plugin Slug
wplr-sync
Installations
3,000+
Vulnerability
Insecure Direct Object References (IDOR)
Patched in Version
6.2.6
Severity Score
Medium
The vulnerability has been patched, so you should update to version 6.2.6.

Image Carousel For Divi

Product image for Image Carousel For Divi.
Plugin Slug
image-carousel-for-divi
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.6.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.6.1.

Market Exporter

Product image for Market Exporter.
Plugin Slug
market-exporter
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.19
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.19.

Multiple Page Generator Plugin – MPG

Product image for Multiple Page Generator Plugin – MPG.
Plugin Slug
multiple-pages-generator-by-porthas
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.0.0.

Share This Image

Product image for Share This Image.
Plugin Slug
share-this-image
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.81
Severity Score
High
The vulnerability has been patched, so you should update to version 1.81.

Spanish Market Enhancements for WooCommerce

Product image for Spanish Market Enhancements for WooCommerce.
Plugin Slug
woocommerce-es
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.

Pay For Post with WooCommerce

Product image for Pay For Post with WooCommerce.
Plugin Slug
woocommerce-pay-per-post
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.1.11
Severity Score
High
The vulnerability has been patched, so you should update to version 3.1.11.

360 Javascript Viewer

Product image for 360 Javascript Viewer.
Plugin Slug
360deg-javascript-viewer
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.5.3.

Activity Log For MainWP

Product image for Activity Log For MainWP.
Plugin Slug
activity-log-mainwp
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

Message Filter for Contact Form 7

Plugin Slug
cf7-message-filter
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.3.

Church Admin

Product image for Church Admin.
Plugin Slug
church-admin
Installations
1,000+
Vulnerability
Server Side Request Forgery (SSRF)
Patched in Version
3.8.0
Severity Score
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

TempTool [Show Current Template Info]

Product image for TempTool  [Show Current Template Info].
Plugin Slug
current-template-name
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.10
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.10.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.
Plugin Slug
remove-duplicate-posts
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.

WP Required Taxonomies – Categories and Tags Mandatory

Plugin Slug
required-taxonomies
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.8.

SV Proven Expert

Product image for SV Proven Expert.
Plugin Slug
sv-provenexpert
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

SV Tracking Manager

Product image for SV Tracking Manager.
Plugin Slug
sv-tracking-manager
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

Live Sales Notification for Woocommerce – Woomotiv

Product image for Live Sales Notification for Woocommerce – Woomotiv.
Plugin Slug
woomotiv
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.4
Severity Score
High
The vulnerability has been patched, so you should update to version 3.4.

Integration for WooCommerce and QuickBooks

Product image for Integration for WooCommerce and QuickBooks.
Plugin Slug
wp-woocommerce-quickbooks
Installations
1,000+
Vulnerability
Open Redirection
Patched in Version
1.2.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

wpShopGermany IT-RECHT KANZLEI

Plugin Slug
wpshopgermany-it-recht-kanzlei
Installations
900+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 1.8.

GraphComment Comment system

Product image for GraphComment Comment system.
Plugin Slug
graphcomment-comment-system
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.5
Severity Score
High
The vulnerability has been patched, so you should update to version 2.3.5.

Terms & Conditions Per Product

Product image for Terms & Conditions Per Product.
Plugin Slug
terms-and-conditions-per-product
Installations
700+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.6.

Chamber Dashboard Business Directory

Product image for Chamber Dashboard Business Directory.
Plugin Slug
chamber-dashboard-business-directory
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.2
Severity Score
High
The vulnerability has been patched, so you should update to version 3.3.2.

Embed Video Thumbnail

Product image for Embed Video Thumbnail.
Plugin Slug
embed-video-thumbnail
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.1.

WordPress Form Builder Plugin – Gutenberg Forms

Product image for Gutenberg Forms – WordPress Form Builder Plugin.
Plugin Slug
forms-gutenberg
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.0.

FormsCRM

Product image for FormsCRM.
Plugin
FormsCRM
Plugin Slug
formscrm
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.6
Severity Score
High
The vulnerability has been patched, so you should update to version 3.6.

WZ Followed Posts – Display what visitors are reading

Product image for WZ Followed Posts – Display what visitors are reading.
Plugin Slug
where-did-they-go-from-here
Installations
600+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.0.

WPEventPartners Demo Import

Plugin Slug
wep-demo-import
Installations
500+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.4.

Display WP Admin Pages in the Frontend – WP Frontend Admin

Product image for WP Frontend Admin – Display WP Admin Pages in the Frontend.
Plugin Slug
display-admin-page-on-frontend
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.21.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.21.1.

Product Filter Widget for Elementor

Plugin Slug
product-filter-widget-for-elementor
Installations
400+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.2.

what3words Address Field

Product image for what3words Address Field.
Plugin Slug
3-word-address-validation-field
Installations
300+
Vulnerability
Sensitive Data Exposure
Patched in Version
4.0.1
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

BuddyForms Ultimate Member

Product image for BuddyForms Ultimate Member.
Plugin Slug
buddyforms-ultimate-member
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.8.

Gift Message for WooCommerce

Product image for Gift Message for WooCommerce.
Plugin Slug
gift-message-for-woocommerce
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.5
Severity Score
High
The vulnerability has been patched, so you should update to version 1.7.5.

Ultimate LinkedIn Integration

Product image for Ultimate LinkedIn Integration.
Plugin Slug
linkedin-login
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.

Shipping for Nova Poshta

Product image for Shipping for Nova Poshta.
Plugin Slug
nova-poshta-ttn
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.1.

Spice Blocks

Plugin Slug
spice-blocks
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.

WooCommerce Country Catalogs – Product Country Restrictions

Plugin Slug
woo-country-restrictions-advanced
Installations
300+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.14.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.14.3.

2MB Autocode

Plugin Slug
2mb-autocode
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.6.

Checkbox

Product image for Checkbox.
Plugin
Checkbox
Plugin Slug
checkbox
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.8.5
Severity Score
High
The vulnerability has been patched, so you should update to version 0.8.5.

Content Blocks Builder

Product image for Content Blocks Builder.
Plugin Slug
content-blocks-builder
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.3.17
Severity Score
High
The vulnerability has been patched, so you should update to version 2.3.17.

Joli FAQ SEO – WordPress FAQ Plugin

Product image for Joli FAQ SEO – WordPress FAQ Plugin.
Plugin Slug
joli-faq-seo
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.1.

RSS Control

Product image for RSS Control.
Plugin Slug
rss-control
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.8
Severity Score
High
The vulnerability has been patched, so you should update to version 3.0.8.

Simple Tour Guide

Plugin Slug
simple-tour-guide
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.6.

Coming Soon Pages for WordPress – Coming Soon Booster

Product image for Coming Soon Pages for WordPress – Coming Soon Booster.
Plugin Slug
wp-coming-soon-booster
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.7
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.7.

WP SPID Italia

Product image for WP SPID Italia.
Plugin Slug
wp-spid-italia
Installations
200+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.5
Severity Score
High
The vulnerability has been patched, so you should update to version 2.5.

Coming Soon Master

Product image for Coming Soon Master.
Plugin Slug
coming-soon-master
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.

EthereumICO

Plugin Slug
ethereumico
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.4
Severity Score
High
The vulnerability has been patched, so you should update to version 2.4.4.

Files Download Delay

Plugin Slug
files-download-delay
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.9.

Bulk Landing Page Creator for WordPress – LPagery

Product image for Bulk Landing Page Creator for WordPress – LPagery.
Plugin Slug
lpagery
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.6.

Mobile App Editor – WordPress to Android App Builder

Product image for Mobile App Editor – WordPress to Android App Builder.
Plugin Slug
mobile-app-editor
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.0.

Search Field for Gravity Forms

Product image for Search Field for Gravity Forms.
Plugin Slug
search-field-for-gravity-forms
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.6
Severity Score
High
The vulnerability has been patched, so you should update to version 0.6.

Stellar Places

Product image for Stellar Places.
Plugin Slug
stellar-places
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.

Subaccounts for WooCommerce

Product image for Subaccounts for WooCommerce.
Plugin Slug
subaccounts-for-woocommerce
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.0.

WN Flipbox Pro

Product image for WN Flipbox Pro.
Plugin Slug
wn-flipbox-pro
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 2.1.

Bing Custom Search for WordPress

Product image for Bing Custom Search for WordPress.
Plugin Slug
wp-bing-search
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.6.3
Severity Score
High
The vulnerability has been patched, so you should update to version 2.6.3.

WP Tools Divi Blog Carousel

Product image for WP Tools Divi Blog Carousel.
Plugin Slug
wp-tools-divi-blog-carousel
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.1.

Ultimate Custom ScrollBar

Product image for Ultimate Custom ScrollBar.
Plugin Slug
ultimate-custom-scrollbar
Installations
90+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.

WPGutenBlog Demo Import

Plugin Slug
layouts-importer
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.3.

SV100 Companion

Product image for SV100 Companion.
Plugin Slug
sv100-companion
Installations
80+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

Blocks Product Editor for WooCommerce

Plugin Slug
blocks-product-editor-for-woocommerce
Installations
70+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.2.

Variable Inspector

Product image for Variable Inspector.
Plugin Slug
variable-inspector
Installations
70+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.4.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.4.0.

Stripe Express

Product image for Stripe Express.
Plugin Slug
wp-stripe-express
Installations
60+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.12.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.12.1.

BuddyForms Form Elements for WooCommerce

Product image for BuddyForms Form Elements for WooCommerce.
Plugin Slug
buddyforms-woocommerce-form-elements
Installations
50+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.3.

Order Redirects for WooCommerce

Product image for Order Redirects for WooCommerce.
Plugin Slug
order-redirects-for-woocommerce
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.8.1
Severity Score
High
The vulnerability has been patched, so you should update to version 0.8.1.

Simple blueprint installer

Product image for Simple blueprint installer.
Plugin Slug
simple-blueprint-installer
Installations
40+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.2.

BuddyForms Moderation ( Former: Review Logic )

Product image for BuddyForms Moderation ( Former: Review Logic ).
Plugin Slug
buddyforms-review
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.8.

Import Holded for WooCommerce or Easy Digital Downloads

Product image for Connect WooCommerce Holded.
Plugin Slug
import-holded-products-woocommerce
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.

Order Picking For WooCommerce

Product image for Order Picking For WooCommerce.
Plugin Slug
order-picking-for-woocommerce
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.2.

ShortcodeHub – MultiPurpose Shortcode Builder

Product image for ShortcodeHub – MultiPurpose Shortcode Builder.
Plugin Slug
shortcodehub
Installations
30+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.4.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.4.0.

CO2ok: carbon offsetting for e-commerce

Product image for ClimateClick: Climate Action for all.
Plugin Slug
co2ok-for-woocommerce
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.4
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.4.

SV Forms

Product image for SV Forms.
Plugin
SV Forms
Plugin Slug
sv-forms
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.02
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.02.

SV Posts

Product image for SV Posts.
Plugin
SV Posts
Plugin Slug
sv-posts
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

Video Analytics for Cloudflare Stream

Plugin Slug
video-analytics-for-cloudflare-stream
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.

WP Table Pixie

Product image for WP Table Pixie.
Plugin Slug
wp-table-pixie
Installations
20+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.0.

CF7 ReCaptcha Mine

Product image for CF7 ReCaptcha Mine.
Plugin Slug
cf7-recaptcha-mine
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

Convoworks WP

Product image for Convoworks WP.
Plugin Slug
convoworks-wp
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.22.15
Severity Score
High
The vulnerability has been patched, so you should update to version 0.22.15.

Custom Welcome Guide

Plugin Slug
custom-welcome-guide
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.9.

DeMomentSomTres Gravity Forms Improvements

Product image for DeMomentSomTres Gravity Forms Improvements.
Plugin Slug
demomentsomtres-gravity-forms-improvements
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
201805021810
Severity Score
High
The vulnerability has been patched, so you should update to version 201805021810.

Fast Custom Social Share by CodeBard

Product image for Fast Custom Social Share by CodeBard.
Plugin Slug
fast-custom-social-share-by-codebard
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.0.

Contact form builder for Gutenberg – Formello

Product image for Contact form builder for Gutenberg – Formello.
Plugin Slug
formello
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.3.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.3.1.

SV Columns Manager

Product image for SV Columns Manager.
Plugin Slug
sv-columns-manager
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

Divi Testimonial Plus

Product image for Divi Testimonial Plus.
Plugin Slug
website-testimonials
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
6.1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 6.1.1.

WP Signals

Product image for WP Signals.
Plugin Slug
wp-signals
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

BuddyForms Anonymous Author

Plugin
BuddyForms Anonymous Author
Plugin Slug
buddyforms-anonymous-author
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.

BuddyForms Attach Post with Group

Plugin
BuddyForms Attach Post with Group
Plugin Slug
buddyforms-attach-posts-to-groups-extension
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.3.

BuddyForms Hierarchical Posts

Plugin
BuddyForms Hierarchical Posts
Plugin Slug
buddyforms-hierarchical-posts
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.4.

BuddyForms Posts 2 Posts

Plugin
BuddyForms Posts 2 Posts
Plugin Slug
buddyforms-posts-to-posts-integration
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.

BuddyForms Remote

Plugin
BuddyForms Remote
Plugin Slug
buddyforms-remote
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.5
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.5.

Caldera Forms

Plugin
Caldera Forms
Plugin Slug
caldera-forms
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.7.5.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.7.5.1.

Simple Freemius Shop

Plugin
Simple Freemius Shop
Plugin Slug
checkout-freemius-rewamped
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

Convert Pro

Plugin
Convert Pro
Plugin Slug
convertpro
Vulnerability
Broken Access Control
Patched in Version
1.7.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.7.6.

DeMomentSomTres Subscribe

Plugin
DeMomentSomTres Subscribe
Plugin Slug
demomentsomtres-mailchimp-subscribe
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.201903272301
Severity Score
High
The vulnerability has been patched, so you should update to version 3.201903272301.

DEV.LAND

Product image for DEV.LAND.
Plugin
DEV.LAND
Plugin Slug
dev-land
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.0.5
Severity Score
High
The vulnerability has been patched, so you should update to version 3.0.5.

DokoBuilder : DIY Product Bundle for WooCommerce

Plugin Slug
doko-box-builder
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.1.

Expandable Paywall

Product image for Expandable Paywall.
Plugin Slug
expandable-paywall
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.17
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.17.

External Media Upload

Plugin
External Media Upload
Plugin Slug
external-media-upload
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.4
Severity Score
High
The vulnerability has been patched, so you should update to version 0.4.

Frontend Admin – Add and edit posts, pages, users and more all from the frontend

Plugin
Frontend Admin – Add and edit posts, pages, users and more all from the frontend
Plugin Slug
frontend-admin
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.8.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.8.0.

Gallery Bank

Plugin
Gallery Bank
Plugin Slug
gallery-bank
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
4.0.19
Severity Score
High
The vulnerability has been patched, so you should update to version 4.0.19.

Map Plugin alternative to Google Maps using MapQuest, with directions

Plugin
Map Plugin alternative to Google Maps using MapQuest, with directions
Plugin Slug
get-directions
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.16.2
Severity Score
High
The vulnerability has been patched, so you should update to version 2.16.2.

Information for help

Plugin
Information for help
Plugin Slug
information-for-help
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
0.0.3
Severity Score
High
The vulnerability has been patched, so you should update to version 0.0.3.

Google Maps Plugin by Intergeo

Plugin
Google Maps Plugin by Intergeo
Plugin Slug
intergeo-maps
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.6.

Oxygen Builder

Plugin
Oxygen Builder
Plugin Slug
oxygen
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
4.4
Severity Score
Medium
The vulnerability has been patched, so you should update to version 4.4.

Popups

Plugin
Popups
Plugin Slug
popups
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.

Remove WP Update Nags

Plugin
Remove WP Update Nags
Plugin Slug
remove-wp-update-nags
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.5.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.5.0.

SV Media Library

Product image for SV Media Library.
Plugin Slug
sv-media-library
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.00
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.00.

BuddyPress Groups Integration for WooCommerce

Plugin
BuddyPress Groups Integration for WooCommerce
Plugin Slug
wc4bp-groups
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.1.

WP Cloud Server

Plugin
WP Cloud Server
Plugin Slug
wp-cloud-server
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.0
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.0.

WP Native Articles – Instant Articles Plugin for WordPress

Plugin
WP Native Articles – Instant Articles Plugin for WordPress
Plugin Slug
wp-native-articles
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.0.

Schema Pro

Plugin
Schema Pro
Plugin Slug
wp-schema-pro
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
2.7.8
Severity Score
Medium
The vulnerability has been patched, so you should update to version 2.7.8.

WP Scrive by Webbstart

Plugin
WP Scrive by Webbstart
Plugin Slug
wp-scrive
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.4.

WPCasa Mail Alert

Plugin
WPCasa Mail Alert
Plugin Slug
wpcasa-mail-alert
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
3.3.0
Severity Score
High
The vulnerability has been patched, so you should update to version 3.3.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

WPS Limit Login

Product image for WPS Limit Login.
Plugin Slug
wps-limit-login
Installations
60,000+
Vulnerability
Race Condition
Patched in Version
No Fix
Severity Score
Low
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Product image for Custom Field Template.
Plugin Slug
custom-field-template
Installations
50,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Icons & Social Share Buttons

Product image for Social Share Icons & Social Share Buttons.
Plugin Slug
ultimate-social-media-plus
Installations
30,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-CopyProtect [Protect your blog posts]

Product image for WP-CopyProtect [Protect your blog posts].
Plugin Slug
wp-copyprotect
Installations
20,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elastic Email Sender

Product image for Elastic Email Sender.
Plugin Slug
elastic-email-sender
Installations
10,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GTmetrix for WordPress

Product image for GTmetrix for WordPress.
Plugin Slug
gtmetrix-for-wordpress
Installations
10,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Art Decoration Shortcode

Product image for Art Decoration Shortcode.
Plugin Slug
art-decoration-shortcode
Installations
4,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Product image for Banner Management For WooCommerce.
Plugin Slug
banner-management-for-woocommerce
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Product image for Fraud Prevention For Woocommerce.
Plugin Slug
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
Installations
4,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google Map Shortcode

Plugin Slug
google-map-shortcode
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Product image for MultiParcels Shipping For WooCommerce.
Plugin Slug
multiparcels-shipping-for-woocommerce
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Server Info

Product image for Server Info.
Plugin Slug
server-info
Installations
3,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Language

Product image for WordPress Language.
Plugin Slug
wordpress-language
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Emoji One

Product image for WP Emoji One.
Plugin Slug
wp-emoji-one
Installations
3,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Product image for WP Quick Post Duplicator.
Plugin Slug
wp-quick-post-duplicator
Installations
3,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booster Elementor Addons

Product image for Booster Elementor Addons.
Plugin Slug
booster-for-elementor
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Instant CSS

Product image for Instant CSS.
Plugin Slug
instant-css
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeBard’s Patron Button and Widgets for Patreon

Product image for CodeBard's Patron Button and Widgets for Patreon.
Plugin Slug
patron-button-and-widgets-by-codebard
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Googlebot Visit

Product image for Simple Googlebot Visit.
Plugin Slug
simple-googlebot-visit
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QR code MeCard/vCard generator

Product image for QR code MeCard/vCard generator.
Plugin Slug
wp-qrcode-me-v-card
Installations
2,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WRC Pricing Tables

Product image for WRC Pricing Tables.
Plugin Slug
wrc-pricing-tables
Installations
2,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Audio Player with Playlist Ultimate

Product image for Audio Player with Playlist Ultimate.
Plugin Slug
audio-player-with-playlist-ultimate
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Client Portal : SuiteDash Direct Login

Product image for Client Portal : SuiteDash Direct Login.
Plugin Slug
client-portal-suitedash-login
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Go Fetch Jobs (for WP Job Manager)

Product image for Go Fetch Jobs (for WP Job Manager).
Plugin Slug
go-fetch-jobs-wp-job-manager
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Product image for Mobile Address Bar Changer.
Plugin Slug
mobile-address-bar-changer
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Perelink Pro

Plugin Slug
perelink
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post List With Featured Image

Plugin Slug
post-list-with-featured-image
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Product image for Post Affiliate Pro.
Plugin Slug
postaffiliatepro
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.
Plugin Slug
remove-duplicate-posts
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Donations Made Easy – Smart Donations

Product image for Donations Made Easy – Smart Donations.
Plugin Slug
smart-donations
Installations
1,000+
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Taboola

Product image for Taboola.
Plugin
Taboola
Plugin Slug
taboola
Installations
1,000+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Exifography

Product image for Exifography.
Plugin Slug
thesography
Installations
1,000+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Connector

Product image for Post Connector.
Plugin Slug
post-connector
Installations
100+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smarty for WordPress

Plugin Slug
smarty-for-wordpress
Installations
100+
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gestion-Pymes

Product image for Gestion-Pymes.
Plugin Slug
gestion-pymes
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Delivery Date Premium

Product image for Woocommerce Delivery Date Premium.
Plugin Slug
woocommerce-delivery-date
Installations
10+
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

bbResolutions

Plugin
bbResolutions
Plugin Slug
bbresolutions
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BlogPost – BlogPost Widgets – Amazing Blog Layouts

Plugin
BlogPost – BlogPost Widgets – Amazing Blog Layouts
Plugin Slug
blogpost-widgets
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CF7 Constant Contact Fields Mapping

Plugin
CF7 Constant Contact Fields Mapping
Plugin Slug
cf7-constant-contact-fields-mapping
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

Plugin
WP Clone Menu
Plugin Slug
clone-menu
Vulnerability
Broken Access Control
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DancePress (TRWA)

Plugin
DancePress (TRWA)
Plugin Slug
dancepress-trwa
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DeMomentSomTres Immediate Send

Plugin
DeMomentSomTres Immediate Send
Plugin Slug
demomentsomtres-mailchimp-immediate-send
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Disabler

Plugin
Disabler
Plugin Slug
disabler
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Easy Call Now Button by elixirs.io

Plugin
WordPress Easy Call Now Button by elixirs.io
Plugin Slug
easy-call-now-button
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Extend Filter Products By Price Widget

Plugin
Extend Filter Products By Price Widget
Plugin Slug
extend-filter-products-by-price-widget
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Easy Responsive Pricing Tables

Plugin
Easy Responsive Pricing Tables
Plugin Slug
fullworks-pricing-tables
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Jupiter X Core

Plugin
JupiterX Core
Plugin Slug
jupiterx-core
Vulnerability
Arbitrary File Download
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Logger

Product image for WP Logger.
Plugin
WP Logger
Plugin Slug
lite-wp-logger
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

LWS Affiliation

Plugin
LWS Affiliation
Plugin Slug
lws-affiliation
Vulnerability
Local File Inclusion
Patched in Version
No Fix
Severity Score
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Menu Item Scheduler

Plugin
Menu Item Scheduler
Plugin Slug
menu-item-scheduler
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Protect Uploads with Login – Protect Your Uploads

Plugin
Protect Uploads with Login – Protect Your Uploads
Plugin Slug
protect-uploads-with-login-page
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

Plugin
Quasar form
Plugin Slug
quasar-form
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Role Based Bulk Quantity Pricing

Plugin Slug
role-based-bulk-quantity-pricing
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Page Builder for Gutenberg – StarterBlocks

Plugin
Page Builder for Gutenberg – StarterBlocks
Plugin Slug
starterblocks
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Subscribe to Category

Plugin
Subscribe to Category
Plugin Slug
subscribe-to-category
Vulnerability
SQL Injection
Patched in Version
No Fix
Severity Score
Critical
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

Plugin
tagDiv Composer
Plugin Slug
td-composer
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultra Elementor Addons

Plugin
Ultra Elementor Addons
Plugin Slug
ultra-elementor-addons
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Auto SEO Plugin – Upfiv SEO Wizard

Plugin
WordPress Auto SEO Plugin – Upfiv SEO Wizard
Plugin Slug
upfiv-complete-all-in-one-seo-wizard
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

Plugin
User Email Verification for WooCommerce
Plugin Slug
woo-confirmation-email
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-FlyBox

Plugin
WP-FlyBox
Plugin Slug
wp-flybox
Vulnerability
Cross Site Request Forgery (CSRF)
Patched in Version
No Fix
Severity Score
Medium
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WooCommerce Sync for Google Sheet

Plugin
WordPress WooCommerce Sync for Google Sheet
Plugin Slug
wp-woo-commerce-sync-for-g-sheet
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bootstrap Blog

Product image for Bootstrap Blog.
Theme Slug
bootstrap-blog
Downloads
87,177
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.2.3
Severity Score
High
The vulnerability has been patched, so you should update to version 10.2.3.

Ona

Product image for Ona.
Theme
Ona
Theme Slug
ona
Downloads
86,847
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.18.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.18.3.

Yuki

Product image for Yuki.
Theme
Yuki
Theme Slug
yuki
Downloads
74,316
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Techism

Product image for Techism.
Theme
Techism
Theme Slug
techism
Downloads
58,069
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Chic Lifestyle

Product image for Chic Lifestyle.
Theme Slug
chic-lifestyle
Downloads
57,532
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.0.8
Severity Score
High
The vulnerability has been patched, so you should update to version 10.0.8.

Lifestyle Magazine

Product image for Lifestyle Magazine.
Theme Slug
lifestyle-magazine
Downloads
49,638
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
10.2.1
Severity Score
High
The vulnerability has been patched, so you should update to version 10.2.1.

SalesZone

Product image for SalesZone.
Theme Slug
saleszone
Downloads
45,813
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Travel Tour

Product image for Travel Tour.
Theme Slug
travel-tour
Downloads
39,431
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.0
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.0.

Brand

Product image for Brand.
Theme
Brand
Theme Slug
brand
Downloads
32,911
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

WP Sierra

Product image for WP Sierra.
Theme Slug
wp-sierra
Downloads
31,861
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Eighteen tags

Product image for Eighteen tags.
Theme Slug
eighteen-tags
Downloads
26,056
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Hasium

Product image for Hasium.
Theme
Hasium
Theme Slug
hasium
Downloads
23,338
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Broadcast Lite

Product image for Broadcast Lite.
Theme Slug
broadcast-lite
Downloads
21,268
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.0.8
Severity Score
High
The vulnerability has been patched, so you should update to version 2.0.8.

Salzburg Blog

Product image for Salzburg Blog.
Theme Slug
salzburg-blog
Downloads
21,114
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Everse

Product image for Everse.
Theme
Everse
Theme Slug
everse
Downloads
19,143
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.8.12
Severity Score
High
The vulnerability has been patched, so you should update to version 1.8.12.

Speculor

Product image for Speculor.
Theme Slug
speculor
Downloads
17,306
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Meridia

Product image for Meridia.
Theme
Meridia
Theme Slug
meridia
Downloads
16,976
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
2.2.8
Severity Score
High
The vulnerability has been patched, so you should update to version 2.2.8.

Aquarella Lite

Product image for Aquarella Lite.
Theme Slug
aquarella-lite
Downloads
16,673
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Consultpress Lite

Product image for ConsultPress Lite.
Theme Slug
consultpress-lite
Downloads
15,868
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Topcat Lite

Product image for Topcat Lite.
Theme Slug
topcat-lite
Downloads
15,747
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Shuban

Product image for Shuban.
Theme
Shuban
Theme Slug
shuban
Downloads
13,783
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Purus

Product image for Purus.
Theme
Purus
Theme Slug
purus
Downloads
13,561
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Elation

Product image for Elation.
Theme
Elation
Theme Slug
elation
Downloads
13,250
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

GutenBook

Product image for GutenBook.
Theme Slug
gutenbook
Downloads
13,216
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Chained

Product image for Chained.
Theme
Chained
Theme Slug
chained
Downloads
12,157
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Elasta

Product image for Elasta.
Theme
Elasta
Theme Slug
elasta
Downloads
11,744
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.9.

Purosa

Product image for Purosa.
Theme
Purosa
Theme Slug
purosa
Downloads
11,224
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.3.

LearnMore

Product image for LearnMore.
Theme Slug
learnmore
Downloads
9,915
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

WPCake

Product image for WPCake.
Theme
WPCake
Theme Slug
wpcake
Downloads
8,708
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Nokke

Product image for Nokke.
Theme
Nokke
Theme Slug
nokke
Downloads
8,472
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.4
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.4.

Arendelle

Product image for Arendelle.
Theme Slug
arendelle
Downloads
8,463
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.13
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.13.

PixiGo

Product image for PixiGo.
Theme
PixiGo
Theme Slug
pixigo
Downloads
7,670
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

WP Moose

Product image for WP Moose.
Theme Slug
wp-moose
Downloads
7,516
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

G Blog

Product image for G Blog.
Theme
G Blog
Theme Slug
g-blog
Downloads
6,993
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

NicheBase

Product image for NicheBase.
Theme Slug
nichebase
Downloads
6,985
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.2.3
Severity Score
High
The vulnerability has been patched, so you should update to version 1.2.3.

Cuisine Palace

Product image for Cuisine Palace.
Theme Slug
cuisine-palace
Downloads
6,091
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Amela

Product image for Amela.
Theme
Amela
Theme Slug
amela
Downloads
6,063
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.14
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.14.

Agncy

Product image for Agncy.
Theme
Agncy
Theme Slug
agncy
Downloads
6,032
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Travel Agency Booking

Product image for Travel Agency Booking.
Theme Slug
travel-agency-booking
Downloads
5,703
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Bootstrap Fitness

Product image for Bootstrap Fitness.
Theme Slug
bootstrap-fitness
Downloads
5,569
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.6
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.6.

Bootstrap Coach

Product image for Bootstrap Coach.
Theme Slug
bootstrap-coach
Downloads
5,146
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.2
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.2.

Blockst

Product image for Blockst.
Theme
Blockst
Theme Slug
blockst
Downloads
3,309
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.0.9
Severity Score
High
The vulnerability has been patched, so you should update to version 1.0.9.

Relax Spa

Product image for Relax Spa.
Theme Slug
relax-spa
Downloads
2,572
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
1.1.1
Severity Score
High
The vulnerability has been patched, so you should update to version 1.1.1.

Villar

Product image for Villar.
Theme
Villar
Theme Slug
villar
Downloads
3,995
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

BlogHub

Product image for BlogHub.
Theme
BlogHub
Theme Slug
bloghub
Downloads
3,575
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Viralike

Product image for Viralike.
Theme Slug
viralike
Downloads
3,245
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

NewsHit

Product image for NewsHit.
Theme
NewsHit
Theme Slug
newshit
Downloads
3,073
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Simplifii

Product image for Simplifii.
Theme Slug
simplifii
Downloads
2,700
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Roven Blog

Product image for Roven Blog.
Theme Slug
roven-blog
Downloads
2,598
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Krste

Product image for Krste.
Theme
Krste
Theme Slug
krste
Downloads
2,526
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Unakit

Product image for Unakit.
Theme
Unakit
Theme Slug
unakit
Downloads
2,259
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Temp Mail X

Product image for Temp Mail X.
Theme Slug
temp-mail-x
Downloads
2,215
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Rovenstart

Product image for Rovenstart.
Theme Slug
rovenstart
Downloads
1,845
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.

Bani

Theme
Bani
Theme Slug
bani
Vulnerability
Cross Site Scripting (XSS)
Patched in Version
No Fix
Severity Score
High
The vulnerability has not been patched. You should switch themes.


Never worry about running a vulnerable plugin or theme again.

As you can see from this report, new WordPress plugin and theme vulnerabilities are disclosed every week. We know it can be difficult to stay on top of every reported vulnerability disclosure that matters to you, so the Themes Security Pro plugin makes it easy to ensure your site isn’t running a vulnerable theme, plugin, or version of WordPress core.


The post WordPress Vulnerability Report – July 27, 2023 appeared first on iThemes.

>>> Read the Full Story at iThemes