• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – October 4, 2023

WordPress Vulnerability Report – October 4, 2023

Written by

Dan Knauss

on

October 4, 2023

Last Updated on October 4, 2023

Since last week, 97 total vulnerabilities have emerged in public disclosure. They may affect over two million WordPress sites. There are 50 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Table of Contents Plus

Product image for Table of Contents Plus.

Plugin Slug
table-of-contents-plus

Installations
300,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2309

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2309.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.

Plugin Slug
wp-user-avatar

Installations
200,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
4.13.3

Severity Score
High

The vulnerability has been patched, so you should update to version 4.13.3.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.

Plugin Slug
foogallery

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.3.2

Severity Score
High

The vulnerability has been patched, so you should update to version 2.3.2.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.

Plugin Slug
foogallery

Installations
100,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.2.

iframe

Product image for iframe.

Plugin Slug
iframe

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.7.

Advanced Custom Fields: Extended

Product image for Advanced Custom Fields: Extended.

Plugin Slug
acf-extended

Installations
80,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
0.8.9.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 0.8.9.4.

Astra Bulk Edit

Product image for Astra Bulk Edit.

Plugin Slug
astra-bulk-edit

Installations
70,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.8.

Simple Membership

Product image for Simple Membership.

Plugin Slug
simple-membership

Installations
50,000+

Vulnerability
Privilege Escalation

Patched in Version
4.3.5

Severity Score
High

The vulnerability has been patched, so you should update to version 4.3.5.

Simple Membership

Product image for Simple Membership.

Plugin Slug
simple-membership

Installations
50,000+

Vulnerability
Privilege Escalation

Patched in Version
4.3.5

Severity Score
High

The vulnerability has been patched, so you should update to version 4.3.5.

Ditty

Product image for Ditty – Responsive News Tickers, Sliders, and Lists.

Plugin Slug
ditty-news-ticker

Installations
40,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.25

Severity Score
High

The vulnerability has been patched, so you should update to version 3.1.25.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slug
woo-bulk-editor

Installations
30,000+

Vulnerability
Broken Access Control

Patched in Version
1.1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.4.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slug
woo-bulk-editor

Installations
30,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.4.

Abandoned Cart Lite for WooCommerce

Product image for Abandoned Cart Lite for WooCommerce.

Plugin Slug
woocommerce-abandoned-cart

Installations
30,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.16.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.16.0.

WP Job Openings

Product image for WP Job Openings – Job Listing, Career Page and Recruitment Plugin.

Plugin Slug
wp-job-openings

Installations
30,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
3.4.3

Severity Score
Low

The vulnerability has been patched, so you should update to version 3.4.3.

flowpaper

Product image for flowpaper.

Plugin Slug
flowpaper-lite-pdf-flipbook

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.0.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.0.4.

Simple Cloudflare Turnstile

Product image for Simple Cloudflare Turnstile – CAPTCHA Alternative.

Plugin Slug
simple-cloudflare-turnstile

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.23.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.23.2.

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

Product image for WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce.

Plugin Slug
wp-event-manager

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.38

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.1.38.

Inactive Logout

Product image for Inactive Logout.

Plugin Slug
inactive-logout

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
3.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.3.

Modal Window

Product image for Modal Window – create popup modal window.

Plugin Slug
modal-window

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.3.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.3.6.

Options for Twenty Seventeen

Product image for Options for Twenty Seventeen.

Plugin Slug
options-for-twenty-seventeen

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.5.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.5.1.

bbp style pack

Product image for bbp style pack.

Plugin Slug
bbp-style-pack

Installations
8,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.6.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.6.8.

Brands for WooCommerce

Product image for Brands for WooCommerce.

Plugin Slug
brands-for-woocommerce

Installations
6,000+

Vulnerability
Broken Access Control

Patched in Version
3.8.2.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.8.2.3.

WOLF

Product image for WOLF – WordPress Posts Bulk Editor and Manager Professional.

Plugin Slug
bulk-editor

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0.7.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.7.2.

Active Directory Integration / LDAP Integration

Product image for Active Directory Integration / LDAP Integration.

Plugin Slug
ldap-login-for-intranet-sites

Installations
5,000+

Vulnerability
Broken Access Control

Patched in Version
4.2

Severity Score
Low

The vulnerability has been patched, so you should update to version 4.2.

AI ChatBot

Product image for AI ChatBot.

Plugin Slug
chatbot

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
4.7.9

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.7.9.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slug
activitypub

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slug
activitypub

Installations
3,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
1.0.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slug
activitypub

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slug
activitypub

Installations
3,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
1.0.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.0.

Checkfront Online Booking System

Product image for Checkfront Online Booking System.

Plugin Slug
checkfront-wp-booking

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.7.

DoLogin Security

Plugin Slug
dologin

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.7

Severity Score
High

The vulnerability has been patched, so you should update to version 3.7.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slug
import-xml-feed

Installations
3,000+

Vulnerability
Remote Code Execution (RCE)

Patched in Version
2.1.5

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.1.5.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slug
import-xml-feed

Installations
3,000+

Vulnerability
Arbitrary File Upload

Patched in Version
2.1.4

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.1.4.

Track The Click

Product image for Track The Click.

Plugin Slug
track-the-click

Installations
3,000+

Vulnerability
SQL Injection

Patched in Version
0.3.12

Severity Score
High

The vulnerability has been patched, so you should update to version 0.3.12.

Anchor Episodes Index (Spotify for Podcasters)

Product image for Anchor Episodes Index (Spotify for Podcasters).

Plugin Slug
anchor-episodes-index

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.8.

Comment Blacklist Updater

Product image for Comment Blacklist Updater.

Plugin Slug
comment-blacklist-updater

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.0.

Instant CSS

Product image for Instant CSS.

Plugin Slug
instant-css

Installations
2,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.2.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.2.

Pretty Google Calendar

Plugin Slug
pretty-google-calendar

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.6.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.6.0.

OpenHook

Product image for OpenHook.

Plugin Slug
thesis-openhook

Installations
2,000+

Vulnerability
Remote Code Execution (RCE)

Patched in Version
4.3.1

Severity Score
Critical

The vulnerability has been patched, so you should update to version 4.3.1.

BuddyMeet

Product image for BuddyMeet.

Plugin Slug
buddymeet

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.0.

Pre-Publish Checklist

Product image for Pre-Publish Checklist.

Plugin Slug
pre-publish-checklist

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
1.1.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.2.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slug
simple-posts-ticker

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.1.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.6.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slug
simple-posts-ticker

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.1.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.6.

User Avatar – Reloaded

Product image for User Avatar – Reloaded.

Plugin Slug
user-avatar-reloaded

Installations
800+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.2.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.2.

Payment gateway per Product for WooCommerce

Product image for Payment gateway per Product for WooCommerce.

Plugin Slug
woocommerce-product-payments

Installations
500+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.2.8

Severity Score
High

The vulnerability has been patched, so you should update to version 3.2.8.

Staff / Employee Business Directory for Active Directory

Product image for Staff / Employee Business Directory for Active Directory.

Plugin Slug
ldap-ad-staff-employee-directory-search

Installations
10+

Vulnerability
Broken Access Control

Patched in Version
1.3

Severity Score
Low

The vulnerability has been patched, so you should update to version 1.3.

Modern Events Calendar lite

Plugin
Modern Events Calendar Lite

Plugin Slug
modern-events-calendar-lite

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
7.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 7.1.0.

Tiger Forms

Product image for Tiger Forms – Drag and Drop Form Builder.

Plugin Slug
tiger-form

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.0

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.0.

User Activity Log Pro

Plugin
User Activity Log Pro

Plugin Slug
user-activity-log-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.3.4

Severity Score
High

The vulnerability has been patched, so you should update to version 2.3.4.

User Activity Log Pro

Plugin
User Activity Log Pro

Plugin Slug
user-activity-log-pro

Vulnerability
Bypass Vulnerability

Patched in Version
2.3.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Popup Builder

Product image for Popup Builder – Create highly converting, mobile friendly marketing popups..

Plugin Slug
popup-builder

Installations
200,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Unyson

Product image for Unyson.

Plugin Slug
unyson

Installations
200,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Media Library Assistant

Product image for Media Library Assistant.

Plugin Slug
media-library-assistant

Installations
70,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Timthumb Vulnerability Scanner

Plugin Slug
timthumb-vulnerability-scanner

Installations
40,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Mang Board WP

Product image for Mang Board WP.

Plugin Slug
mangboard

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Mediavine Control Panel

Plugin Slug
mediavine-control-panel

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Schema App Structured Data

Product image for Schema App Structured Data.

Plugin Slug
schema-app-structured-data-for-schemaorg

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Block Plugin Update

Product image for Block Plugin Update.

Plugin Slug
block-specific-plugin-updates

Installations
7,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple File List

Plugin Slug
simple-file-list

Installations
5,000+

Vulnerability
Arbitrary File Deletion

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Product image for WP Job Portal – A Complete Job Board.

Plugin Slug
wp-job-portal

Installations
3,000+

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

WP Adminify

Product image for WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders.

Plugin Slug
adminify

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Blocks

Product image for Blocks.

Plugin Slug
blocks

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form

Product image for Contact Form.

Plugin Slug
contact-form-ready

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Timely Booking Button

Product image for Timely Booking Button.

Plugin Slug
timely-booking-button

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Tiny Carousel Horizontal Slider

Product image for Tiny Carousel Horizontal Slider.

Plugin Slug
tiny-carousel-horizontal-slider

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce ESTO

Plugin Slug
woo-esto

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Pages

Plugin Slug
wp-hide-pages

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.

Plugin Slug
popup-contact-form

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.

Plugin Slug
popup-contact-form

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Social Metrics

Plugin Slug
social-metrics

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

The Awesome Feed – Custom Feed

Product image for The Awesome Feed – Custom Feed.

Plugin Slug
wp-facebook-feed

Installations
900+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Onclick Show Popup

Product image for Onclick show popup.

Plugin Slug
onclick-show-popup

Installations
400+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Slideshow, Image Slider by 2J

Plugin
Images Slideshow by 2J

Plugin Slug
2j-slideshow

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Add Shortcodes Actions And Filters

Plugin
Add Shortcodes Actions And Filters

Plugin Slug
add-actions-and-filters

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contractor Contact Form Website to Workflow Tool

Plugin
Contractor Contact Form Website to Workflow Tool

Plugin Slug
contractor-contact-form-website-to-workflow-tool

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cooked

Plugin
Cooked

Plugin Slug
cooked

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CopyRightPro

Plugin
CopyRightPro

Plugin Slug
copyrightpro

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Comments by Startbit

Plugin
Comments by Startbit

Plugin Slug
facebook-comment-by-vivacity

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome Integration

Plugin
Font Awesome Integration

Plugin Slug
font-awesome-integration

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome More Icons

Plugin
Font Awesome More Icons

Plugin Slug
font-awesome-more-icons

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form Form For All

Plugin
Contact form Form For All

Plugin Slug
formforall

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Keap Landing Pages

Plugin
Keap Landing Pages

Plugin Slug
infusionsoft-landing-pages

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Backend Localization

Plugin
Backend Localization

Plugin Slug
kau-boys-backend-localization

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Kv TinyMCE Editor Add Fonts

Plugin
Kv TinyMCE Editor Add Fonts

Plugin Slug
kv-tinymce-editor-fonts

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Magic Action Box

Plugin
Magic Action Box

Plugin Slug
magic-action-box

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Remove slug from custom post type

Plugin
Remove slug from custom post type

Plugin Slug
remove-slug-from-custom-post-type

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Responsive header image slider

Plugin
WP Responsive header image slide

Plugin Slug
responsive-header-image-slider

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Events Rich Snippets for Google

Plugin
Events Rich Snippets for Google

Plugin Slug
rich-snippets-vevents

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Shockingly Simple Favicon

Plugin
Shockingly Simple Favicon

Plugin Slug
shockingly-simple-favicon

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

TM WooCommerce Compare & Wishlist

Plugin
TM WooCommerce Compare & Wishlist

Plugin Slug
tm-woocommerce-compare-wishlist

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Vrm 360 3D Model Viewer

Plugin
Vrm 360 3D Model Viewer

Plugin Slug
vrm360

Vulnerability
Sensitive Data Exposure

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

Plugin
WP Captcha

Plugin Slug
wp-captcha

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

Plugin
WP Captcha

Plugin Slug
wp-captcha

Vulnerability
Bypass Vulnerability

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP GPX Maps

Plugin
WP GPX Map

Plugin Slug
wp-gpx-maps

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Jump Menu

Plugin
WP Jump Menu

Plugin Slug
wp-jump-menu

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Site Protector

Plugin
WP Site Protector

Plugin Slug
wp-site-protector

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WWM Social Share On Image Hover

Plugin
WWM Social Share On Image Hover

Plugin Slug
wwm-social-share-on-image-hover

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

  • No new WordPress theme vulnerabilities were disclosed this week.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
October 8, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (6)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

WordPress: A Powerhouse for Achieving Internet …

Continue Reading about Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter