• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – April 19, 2023

WordPress Vulnerability Report – April 19, 2023

Written by

Dan Knauss

on

April 19, 2023

Last Updated on April 19, 2023

This week, 116 vulnerabilities may affect over 6 million WordPress sites. There are 67 plugin vulnerabilities and 2 themes with security patches available, so run those updates if you use these plugins! Additionally, there are 45 plugin vulnerabilities and 2 theme vulnerabilities with no patch available yet. At least three of these have been closed and dropped from the wordpress.org plugin directory so far. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable plugin or theme has been closed, you should consider deactivation and removal in favor of alternative solutions.

For reference, these reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

WordPress Core News

WordPress 6.2 is the first major release of 2023, with over 900 enhancements and fixes. You’ll notice a reimagined Site Editor, blocks get even better, and new tools and improvements in WordPress 6.2. As always, with a major release like this, ensure your site is backed up with BackupBuddy before updating.

If your WordPress sites have enabled automatic background updates, they should have upgraded to 6.2 automatically. You can download WordPress 6.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates,” and then click the “Update Now” button, which will appear when any core updates are available. For more information, check out the version 6.2 HelpHub documentation page.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities with Patches

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

All In One WP Security & Firewall

Product image for All-In-One Security (AIOS) – Security and Firewall.

Plugin Slug
all-in-one-wp-security-and-firewall

Installations
1,000,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.1.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.1.5.

WP Fastest Cache

Product image for WP Fastest Cache.

Plugin Slug
wp-fastest-cache

Installations
1,000,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.1.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.3.

WP Fastest Cache

Product image for WP Fastest Cache.

Plugin Slug
wp-fastest-cache

Installations
1,000,000+

Vulnerability
Broken Access Control

Patched in Version
1.1.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.3.

Limit Login Attempts

Plugin Slug
limit-login-attempts

Installations
600,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.7.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.7.2.

Forminator

Product image for Forminator – Contact Form, Payment Form & Custom Form Builder.

Plugin Slug
forminator

Installations
400,000+

Vulnerability
Broken Access Control

Patched in Version
1.23.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.23.3.

FluentForm

Product image for Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms.

Plugin Slug
fluentform

Installations
300,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.3.25

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.3.25.

Shortlinks by Pretty Links

Product image for Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin.

Plugin Slug
pretty-link

Installations
300,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.4.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.4.1.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.

Plugin Slug
foogallery

Installations
200,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.2.41

Severity Score
High

The vulnerability has been patched, so you should update to version 2.2.41.

Photo Gallery by 10Web

Product image for Photo Gallery by 10Web – Mobile-Friendly Image Gallery.

Plugin Slug
photo-gallery

Installations
200,000+

Vulnerability
Directory Traversal

Patched in Version
1.8.15

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.15.

Photo Gallery by 10Web

Product image for Photo Gallery by 10Web – Mobile-Friendly Image Gallery.

Plugin Slug
photo-gallery

Installations
200,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.8.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.3.

Blocksy Companion

Product image for Blocksy Companion.

Plugin Slug
blocksy-companion

Installations
100,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
1.8.82

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.82.

Cyr to Lat

Plugin Slug
cyr3lat

Installations
100,000+

Vulnerability
SQL Injection

Patched in Version
3.7

Severity Score
High

The vulnerability has been patched, so you should update to version 3.7.

Download Manager Pro

Product image for Download Manager.

Plugin Slug
download-manager

Installations
100,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
6.3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.3.0.

Hummingbird

Product image for Hummingbird – Optimize Speed, Enable Cache, Minify CSS & Defer Critical JS.

Plugin Slug
hummingbird-performance

Installations
100,000+

Vulnerability
Path Traversal

Patched in Version
3.4.2

Severity Score
High

The vulnerability has been patched, so you should update to version 3.4.2.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slug
wp-slimstat

Installations
100,000+

Vulnerability
SQL Injection

Patched in Version
4.9.4

Severity Score
High

The vulnerability has been patched, so you should update to version 4.9.4.

Easy Forms for MailChimp

Product image for Easy Forms for Mailchimp.

Plugin Slug
yikes-inc-easy-mailchimp-extender

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
6.8.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.8.7.

Easy Forms for MailChimp

Product image for Easy Forms for Mailchimp.

Plugin Slug
yikes-inc-easy-mailchimp-extender

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
6.8.7

Severity Score
High

The vulnerability has been patched, so you should update to version 6.8.7.

PowerPress Podcasting plugin by Blubrry

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slug
powerpress

Installations
50,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
10.0.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 10.0.2.

PowerPress

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slug
powerpress

Installations
50,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
10.0.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 10.0.1.

Site Reviews

Product image for Site Reviews.

Plugin Slug
site-reviews

Installations
50,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
6.7.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 6.7.1.

Quiz And Survey Master

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.

Plugin Slug
quiz-master-next

Installations
40,000+

Vulnerability
SQL Injection

Patched in Version
8.1.5

Severity Score
Critical

The vulnerability has been patched, so you should update to version 8.1.5.

Klaviyo

Plugin Slug
klaviyo

Installations
30,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.0.10

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.10.

Redirection

Product image for Redirection.

Plugin Slug
redirect-redirection

Installations
20,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.1.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.5.

Easy Appointments

Product image for Easy Appointments.

Plugin Slug
easy-appointments

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.11.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.11.1.

Gallery by BestWebSoft

Product image for Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress.

Plugin Slug
gallery-plugin

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.7.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.7.0.

Gallery by BestWebSoft

Product image for Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress.

Plugin Slug
gallery-plugin

Installations
20,000+

Vulnerability
SQL Injection

Patched in Version
4.7.0

Severity Score
High

The vulnerability has been patched, so you should update to version 4.7.0.

SupportCandy

Product image for SupportCandy – Helpdesk & Support Ticket System.

Plugin Slug
supportcandy

Installations
10,000+

Vulnerability
SQL Injection

Patched in Version
3.1.5

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.1.5.

WP VR

Product image for WP VR – 360 Panorama and Virtual Tour Builder For WordPress.

Plugin Slug
wpvr

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
8.2.9

Severity Score
High

The vulnerability has been patched, so you should update to version 8.2.9.

Better Search

Product image for Better Search – Relevant search results for WordPress.

Plugin Slug
better-search

Installations
8,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.2.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.2.0.

LearnPress Export Import

Product image for LearnPress Export Import – WordPress extension for LearnPress.

Plugin Slug
learnpress-import-export

Installations
8,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.0.3

Severity Score
High

The vulnerability has been patched, so you should update to version 4.0.3.

Product Catalog Feed by PixelYourSite

Product image for Product Catalog Feed by PixelYourSite.

Plugin Slug
product-catalog-feed

Installations
8,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.1.

MyCryptoCheckout

Product image for MyCryptoCheckout – Bitcoin, Ethereum, and 175+ altcoins for WooCommerce.

Plugin Slug
mycryptocheckout

Installations
6,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.124

Severity Score
High

The vulnerability has been patched, so you should update to version 2.124.

Watu Quiz

Product image for Watu Quiz.

Plugin Slug
watu

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.3.9.3

Severity Score
High

The vulnerability has been patched, so you should update to version 3.3.9.3.

Vimeotheque

Product image for Vimeotheque / Vimeo.

Plugin Slug
codeflavors-vimeo-video-post-lite

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.2.2

Severity Score
High

The vulnerability has been patched, so you should update to version 2.2.2.

Ultimate Noindex Nofollow Tool II

Plugin Slug
ultimate-noindex-nofollow-tool-ii

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.3.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.4.

WooCommerce Easy Duplicate Product

Plugin Slug
woo-easy-duplicate-product

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
0.3.0.1

Severity Score
High

The vulnerability has been patched, so you should update to version 0.3.0.1.

Thumbnail carousel slider

Product image for Thumbnail carousel slider.

Plugin Slug
wp-responsive-thumbnail-slider

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.1.10

Severity Score
High

The vulnerability has been patched, so you should update to version 1.1.10.

Email Subscription Popup

Product image for Email Subscription Popup.

Plugin Slug
email-subscribe

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.2.17

Severity Score
High

The vulnerability has been patched, so you should update to version 1.2.17.

Woo Bulk Price Update

Product image for Bulk Price Update for Woocommerce.

Plugin Slug
woo-bulk-price-update

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.2.2

Severity Score
High

The vulnerability has been patched, so you should update to version 2.2.2.

Coupon Affiliates

Product image for Coupon Affiliates – WooCommerce Affiliate Plugin.

Plugin Slug
woo-coupon-usage

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.4.6

Severity Score
High

The vulnerability has been patched, so you should update to version 5.4.6.

Featured Post Creative

Product image for Featured Post Creative.

Plugin Slug
featured-post-creative

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
1.2.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.2.8.

Groundhogg

Product image for WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg.

Plugin Slug
groundhogg

Installations
2,000+

Vulnerability
SQL Injection

Patched in Version
2.7.9.4

Severity Score
High

The vulnerability has been patched, so you should update to version 2.7.9.4.

Locatoraid Store Locator

Product image for Locatoraid Store Locator.

Plugin Slug
locatoraid

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.9.15

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.9.15.

WP Inventory Manager

Product image for WP Inventory Manager.

Plugin Slug
wp-inventory-manager

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.0.12

Severity Score
High

The vulnerability has been patched, so you should update to version 2.1.0.12.

MDTF

Product image for MDTF – Meta Data and Taxonomies Filter.

Plugin Slug
wp-meta-data-filter-and-taxonomy-filter

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.3.1

Severity Score
High

The vulnerability has been patched, so you should update to version 1.3.1.

Contact Form to DB by BestWebSoft

Product image for Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.

Plugin Slug
contact-form-to-db

Installations
1,000+

Vulnerability
SQL Injection

Patched in Version
1.7.1

Severity Score
High

The vulnerability has been patched, so you should update to version 1.7.1.

Contact Form to DB

Product image for Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress.

Plugin Slug
contact-form-to-db

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.7.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.7.1.

Simple Giveaways

Product image for Simple Giveaways – Grow your business, email lists and traffic with contests.

Plugin Slug
giveasap

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.45.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.45.1.

Simple Giveaways

Product image for Simple Giveaways – Grow your business, email lists and traffic with contests.

Plugin Slug
giveasap

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.45.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.45.1.

ShiftController Employee Shift Scheduling

Plugin Slug
shiftcontroller

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.9.26

Severity Score
High

The vulnerability has been patched, so you should update to version 4.9.26.

MC Woocommerce Wishlist

Product image for WooCommerce Wishlist by MC + (Free Elementor & Email Marketing Automation).

Plugin Slug
smart-wishlist-for-more-convert

Installations
900+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.5.5

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.5.5.

Scheduled Announcements Widget

Product image for Scheduled Announcements Widget.

Plugin Slug
scheduled-announcements-widget

Installations
300+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.0.

Photo Gallery by 10Web

Plugin Slug
1-jquery-photo-gallery-slideshow-flash

Installations
200+

Vulnerability
Path Traversal

Patched in Version
1.8.15

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.8.15.

a3 Portfolio

Product image for a3 Portfolio.

Plugin Slug
a3-portfolio

Installations
100+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.1.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.1.1.

Auto Rename Media On Upload

Product image for Auto Rename Media On Upload.

Plugin Slug
auto-rename-media-on-upload

Installations
100+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.1.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.1.0.

Time Sheets

Product image for Time Sheets.

Plugin Slug
time-sheets

Installations
100+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.29.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.29.3.

Zyrex Popup

Plugin Slug
popup-zyrex

Installations
10+

Vulnerability
Arbitrary File Upload

Patched in Version
1.1

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.1.

AI ChatBot

Product image for Blog Navigator Chatbot by Xatkit.

Plugin Slug
xatkit-chatbot-connector

Installations
10+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
4.5.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 4.5.1.

Drag and Drop Multiple File Upload PRO

Plugin
Drag and Drop Multiple File Upload PRO

Plugin Slug
drag-n-drop-upload-cf7-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.0.6.4

Severity Score
High

The vulnerability has been patched, so you should update to version 5.0.6.4.

JetEngine

Plugin
JetEngine

Plugin Slug
jet-engine

Vulnerability
Remote Code Execution (RCE)

Patched in Version
3.1.3.1

Severity Score
Critical

The vulnerability has been patched, so you should update to version 3.1.3.1.

Responsive WordPress Slideshows

Plugin
Meta Slider

Plugin Slug
ml-slider1

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.29.1

Severity Score
High

The vulnerability has been patched, so you should update to version 3.29.1.

Pricing Tables For WPBakery Page Builder

Plugin
Pricing Tables For WPBakery Page Builder

Plugin Slug
pricing-tables-for-wpbakery-page-builder

Vulnerability
Local File Inclusion

Patched in Version
3.0

Severity Score
High

The vulnerability has been patched, so you should update to version 3.0.

Pricing Tables For WPBakery Page Builder

Plugin
Pricing Tables For WPBakery Page Builder

Plugin Slug
pricing-tables-for-wpbakery-page-builder

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.0

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.

Ruby Help Desk

Product image for Ruby Help Desk.

Plugin Slug
ruby-help-desk

Vulnerability
Insecure Direct Object References (IDOR)

Patched in Version
1.3.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.3.4.

Stylish Cost Calculator Premium

Plugin
Stylish Cost Calculator Premium

Plugin Slug
stylish-cost-calculator-premium

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
7.9.0

Severity Score
High

The vulnerability has been patched, so you should update to version 7.9.0.

W4 Post List

Plugin
W4 Post List

Plugin Slug
w4-post-list

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.4.6

Severity Score
High

The vulnerability has been patched, so you should update to version 2.4.6.

W4 Post List

Plugin
W4 Post List

Plugin Slug
w4-post-list

Vulnerability
Sensitive Data Exposure

Patched in Version
2.4.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.4.6.

WordPress Plugin Vulnerabilities – No Known Fix

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Shortcodes by Angie Makes

Product image for Shortcodes by Angie Makes.

Plugin Slug
wc-shortcodes

Installations
30,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Custom Order Numbers for WooCommerce

Product image for Custom Order Numbers for WooCommerce.

Plugin Slug
custom-order-numbers-for-woocommerce

Installations
20,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Enable Accessibility

Product image for Enable Accessibility.

Plugin Slug
enable-accessibility

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Optima Express + MarketBoost IDX Plugin

Product image for Optima Express + MarketBoost IDX Plugin.

Plugin Slug
optima-express

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

ReviewX

Product image for ReviewX – Multi-criteria Rating & Reviews for WooCommerce.

Plugin Slug
reviewx

Installations
10,000+

Vulnerability
CSV Injection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

CoSchedule

Product image for CoSchedule.

Plugin Slug
coschedule-by-todaymade

Installations
8,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Fantastic Content Protector Free

Product image for Fantastic Content Protector Free.

Plugin Slug
fantastic-content-protector-free

Installations
6,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Links Lite

Product image for Affiliate Links Lite.

Plugin Slug
affiliate-links

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Neshan Maps

Product image for Neshan Maps.

Plugin Slug
neshan-maps

Installations
3,000+

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Newsletters

Product image for Newsletters.

Plugin Slug
newsletters-lite

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP EasyPay – Square for WordPress

Product image for WP EasyPay – Square for WordPress.

Plugin Slug
wp-easy-pay

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Stamped.io Product Reviews & UGC for WooCommerce

Product image for Stamped.io Product Reviews & UGC for WooCommerce.

Plugin Slug
stampedio-product-reviews

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

AdFoxly – Ad Manager, AdSense Ads & Ads.txt

Product image for AdFoxly – Ad Manager, AdSense Ads & Ads.txt.

Plugin Slug
adfoxly

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Booqable Rental Plugin

Product image for Booqable Rental Plugin.

Plugin Slug
booqable-rental-reservations

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Database Collation Fix

Plugin Slug
database-collation-fix

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Simple PopUp

Plugin Slug
simple-popup

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Landing Page Builder – Free Landing Page Templates

Product image for Landing Page Builder – Free Landing Page Templates.

Plugin Slug
ultimate-landing-page

Installations
1,000+

Vulnerability
Local File Inclusion

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Paytm Payment Donation

Plugin Slug
paytm-donation

Installations
600+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WP Roles at Registration

Product image for WP Roles at Registration.

Plugin Slug
wp-roles-at-registration

Installations
400+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

External Videos

Product image for External Videos.

Plugin Slug
external-videos

Installations
100+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Motor Racing League

Plugin Slug
motor-racing-league

Installations
90+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Pickup | Delivery | Dine-in date time

Plugin Slug
restaurant-pickup-delivery-dine-in

Installations
70+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

hiWeb Migration Simple

Product image for hiWeb Migration Simple.

Plugin Slug
hiweb-migration-simple

Installations
20+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Electric Studio Client Login

Product image for Electric Studio Client Login.

Plugin Slug
electric-studio-client-login

Installations
10+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin Slug
userplus

Installations
10+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

AFFILIATE Solution

Product image for AFFILIATE Solution.

Plugin Slug
affiliate-solution

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Amr Ical Events Lists

Plugin
Amr Ical Events Lists

Plugin Slug
amr-ical-events-list

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Article Directory

Plugin
Article Directory

Plugin Slug
article-directory

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Article Directory Redux

Plugin
Article Directory Redux

Plugin Slug
article-directory-redux

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cloud Manager

Plugin
Cloud Manager

Plugin Slug
cloud-manager

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Post Type and Taxonomy GUI Manager

Plugin
Custom Post Type and Taxonomy GUI Manager

Plugin Slug
custom-post-type-cpt-cusom-taxonomy-ct-manager

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Events Made Easy

Plugin
Events Made Easy

Plugin Slug
events-made-easy

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

InPost Gallery

Plugin
InPost Gallery

Plugin Slug
inpost-gallery

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

MS-Reviews

Plugin
MS-Reviews

Plugin Slug
ms-reviews

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Random Text

Plugin
Random Text

Plugin Slug
randomtext

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Video Central

Plugin
Video Central

Plugin Slug
video-central

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Waiting: One-click Countdowns

Plugin
Waiting: One-click countdowns

Plugin Slug
waiting

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP FEvents Book

Plugin
WP FEvents Book

Plugin Slug
wp-fevents-book

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Reroute Email

Plugin
WP Reroute Email

Plugin Slug
wp-reroute-email

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Reroute Email

Plugin
WP Reroute Email

Plugin Slug
wp-reroute-email

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Steveas WP Live Chat Shoutbox

Plugin
Steveas WP Live Chat Shoutbox

Plugin Slug
wp-shoutbox-live-chat

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Steveas WP Live Chat Shoutbox

Plugin
Steveas WP Live Chat Shoutbox

Plugin Slug
wp-shoutbox-live-chat

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Tiles

Plugin
WP Tiles

Plugin Slug
wp-tiles

Vulnerability
Sensitive Data Exposure

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Tiles

Plugin
WP Tiles

Plugin Slug
wp-tiles

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

ZM Ajax Login & Register

Plugin
ZM Ajax Login & Register

Plugin Slug
zm-ajax-login-register

Vulnerability
Broken Authentication

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

Square

Product image for Square.

Theme Slug
square

Downloads
468,498

Vulnerability
Broken Access Control

Patched in Version
2.0.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.0.1.

BeTheme

Theme
Betheme

Theme Slug
betheme

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
26.8

Severity Score
High

The vulnerability has been patched, so you should update to version 26.8.

Educenter

Product image for Educenter.

Theme Slug
educenter

Downloads
136,704

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should switch themes.

Blogger Buzz

Product image for Blogger Buzz.

Theme Slug
blogger-buzz

Downloads
47,897

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should switch themes.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
April 20, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter