• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report — December 18, 2024

WordPress Vulnerability Report — December 18, 2024

In this report, 345 vulnerabilities have been publicly disclosed. Security patches for 164 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 181 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

window[“bfaee0c7_200c_49d8_934f_54de478175cf”] = {“blockId”:”bfaee0c7-200c-49d8-934f-54de478175cf”,”type”:”warning”,”content”:”

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.”,”className”:””};

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

window[“50c01be2_1674_45a2_adde_a8dc800635da”] = {“blockId”:”50c01be2-1674-45a2-adde-a8dc800635da”,”className”:””,”isOpen”:true};

Table of Contents

  1. 1. WordPress Core
  2. 2. WordPress Plugins — 156 Patched / 179 Unpatched
    1. 2.1
      WP Mega Menu
    2. 2.2
      WPCargo Track & Trace
    3. 2.3
      Awesome Support – WordPress HelpDesk & Support Plugin
    4. 2.4
      Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch
    5. 2.5
      Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress
    6. 2.6
      EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin
    7. 2.7
      News Ticker for Elementor
    8. 2.8
      WP Menu Image
    9. 2.9
      Smaily for WP
    10. 2.10
      SQL Chart Builder
    11. 2.11
      Job Board Manager
    12. 2.12
      SIP Calculator
    13. 2.13
      LDD Directory Lite
    14. 2.14
      The Permalinker
    15. 2.15
      Nias course | ???? ??? ????
    16. 2.16
      Role Includer
    17. 2.17
      Radius Blocks – WordPress Gutenberg Blocks
    18. 2.18
      WordPress HelpDesk & Support Ticket System Plugin – Octrace Support
    19. 2.19
      WP Cookies Enabler
    20. 2.20
      Advanced Blog Post Block
    21. 2.21
      Poll, Poll Forms – WordPress Poll plugin by Poll Builder
    22. 2.22
      Woocommerce Blocks – Woolook
    23. 2.23
      WP-NERD Toolkit
    24. 2.24
      3D Avatar User Profile
    25. 2.25
      Add image to Post
    26. 2.26
      Advance Menu Manager
    27. 2.27
      Advanced Data Table For Elementor
    28. 2.28
      Advanced Fancybox
    29. 2.29
      Advanced What should we write next about
    30. 2.30
      AI Post Generator | AutoWriter
    31. 2.31
      Zita Site Builder
    32. 2.32
      Amazon Product Price
    33. 2.33
      Animated Counters
    34. 2.34
      Aphorismus
    35. 2.35
      AppMaps
    36. 2.36
      Appsplate
    37. 2.37
      Arabic Webfonts
    38. 2.38
      Arena.IM – Live Blogging for real-time events
    39. 2.39
      Arena.IM – Live Blogging for real-time events
    40. 2.40
      Firebase OTP Authentication
    41. 2.41
      Banner System
    42. 2.42
      Bet sport Free
    43. 2.43
      Better WP Login Page
    44. 2.44
      Bootstrap Buttons
    45. 2.45
      Buk
    46. 2.46
      Caldera SMTP Mailer
    47. 2.47
      Mollie for Contact Form 7
    48. 2.48
      ??????
    49. 2.49
      CK and SyntaxHighlighter
    50. 2.50
      Code Generator Pro
    51. 2.51
      Comments On Feed
    52. 2.52
      Companion Portfolio
    53. 2.53
      Connatix Video Embed
    54. 2.54
      CoSchool LMS
    55. 2.55
      Crafthemes Demo Import
    56. 2.56
      Cricket Live Score
    57. 2.57
      Critical Site Intel
    58. 2.58
      CRUDLab Google Plus Button
    59. 2.59
      CSV to html
    60. 2.60
      Custom Skins Contact Form 7
    61. 2.61
      Ultimate Endpoints With Rest Api
    62. 2.62
      Mimoos
    63. 2.63
      Display Future Posts
    64. 2.64
      Dr Affiliate
    65. 2.65
      DTC Documents
    66. 2.66
      Easy Site Importer
    67. 2.67
      ECT Product Carousel
    68. 2.68
      ECT Social Share
    69. 2.69
      EELV Newsletter
    70. 2.70
      Mandrill WP
    71. 2.71
      eTemplates
    72. 2.72
      Evernote Sync
    73. 2.73
      Feedpress Generator
    74. 2.74
      Flaming Forms
    75. 2.75
      Flash News / Post (Responsive)
    76. 2.76
      Floating Video Player
    77. 2.77
      Gaxx Keywords
    78. 2.78
      Geoportail Shortcode
    79. 2.79
      Get Post Content Shortcode
    80. 2.80
      GitSync
    81. 2.81
      glomex oEmbed
    82. 2.82
      Go Animate
    83. 2.83
      Grid Plus
    84. 2.84
      Gutensee
    85. 2.85
      Opt-In Downloads
    86. 2.86
      Hello In All Languages
    87. 2.87
      Horizontal scroll image slideshow
    88. 2.88
      HostFact bestelformulier integratie
    89. 2.89
      HQ Rental Software
    90. 2.90
      IDer Login
    91. 2.91
      Image Mapper
    92. 2.92
      Increase Sociability
    93. 2.93
      Insertify
    94. 2.94
      Instant Appointment
    95. 2.95
      jCarousel
    96. 2.96
      Jet Footer Code
    97. 2.97
      KH Easy User Settings
    98. 2.98
      Kredeum NFTs
    99. 2.99
      kvCORE IDX
    100. 2.100
      LaunchPage.app Importer
    101. 2.101
      Leader
    102. 2.102
      LeaderBoard Plugin
    103. 2.103
      Library Management System
    104. 2.104
      Like in Vk.com
    105. 2.105
      Category of Posts
    106. 2.106
      ListApp Mobile Manager
    107. 2.107
      LionScripts: Site Maintenance & Noindex Nofollow Plugin
    108. 2.108
      MDC Comment Toolbar
    109. 2.109
      Metrika
    110. 2.110
      Minterpress
    111. 2.111
      Multiple Admin Emails
    112. 2.112
      My IDX Home Search
    113. 2.113
      addWeather
    114. 2.114
      Nabz Image Gallery
    115. 2.115
      Navayan CSV Export
    116. 2.116
      Newsletter Subscriptions
    117. 2.117
      Onlywire Multi Autosubmitter
    118. 2.118
      Order Delivery & Pickup Location Date Time
    119. 2.119
      phZoom
    120. 2.120
      PixProof
    121. 2.121
      Popup Surveys & Polls for WordPress (Mare.io)
    122. 2.122
      Portfolio – Filterable Masonry Portfolio Gallery for Professionals
    123. 2.123
      Post Carousel & Slider
    124. 2.124
      Posts and Products Views for WooCommerce
    125. 2.125
      Posts Date Ranges
    126. 2.126
      PowerFormBuilder
    127. 2.127
      Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart
    128. 2.128
      Quietly Insights
    129. 2.129
      Share Buttons – Social Media
    130. 2.130
      Saksh Escrow System
    131. 2.131
      Saoshyant Element
    132. 2.132
      SeedProd Pro
    133. 2.133
      SeedProd Pro
    134. 2.134
      SeedProd Pro
    135. 2.135
      Service
    136. 2.136
      Sign In With Google
    137. 2.137
      Simple Booking Widget
    138. 2.138
      Slope Widgets
    139. 2.139
      Social Media Sharing
    140. 2.140
      SOPA Blackout
    141. 2.141
      WP Simple Pay Lite Manager
    142. 2.142
      Surbma | SalesAutopilot Shortcode
    143. 2.143
      SVG Shortcode
    144. 2.144
      TagGator
    145. 2.145
      TCBD Popover
    146. 2.146
      Tidy Up
    147. 2.147
      TPG Get Posts
    148. 2.148
      TSB Occasion Editor
    149. 2.149
      Ui Slider Filter By Price
    150. 2.150
      Utech World Time
    151. 2.151
      vBSSO-lite
    152. 2.152
      Visual Recent Posts
    153. 2.153
      Visualmodo Elements
    154. 2.154
      Website Toolbox Community
    155. 2.155
      WooCommerce Cart Count Shortcode
    156. 2.156
      WooCommerce Basic Ordernumbers
    157. 2.157
      WordPress Filter
    158. 2.158
      Wovax IDX
    159. 2.159
      WP-Ban-User
    160. 2.160
      WP Fiddle
    161. 2.161
      WP Flipkart Importer
    162. 2.162
      WP-HideThat
    163. 2.163
      Wp Login with Ajax
    164. 2.164
      WP Controller
    165. 2.165
      Wp NssUser Register
    166. 2.166
      Wp photo text slider 50
    167. 2.167
      WP Service Payment Form With Authorize.net
    168. 2.168
      Tithe.ly Giving Button
    169. 2.169
      WP?????
    170. 2.170
      WPBookit
    171. 2.171
      Admin Customization
    172. 2.172
      Wr Age Verification
    173. 2.173
      Wr Age Verification
    174. 2.174
      XML Multilanguage Sitemap Generator
    175. 2.175
      XPD Reduce Image Filesize
    176. 2.176
      YDS Support Ticket System
    177. 2.177
      States Map US
    178. 2.178
      YooBar
    179. 2.179
      Youtube Video Grid
    180. 2.180
      WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
    181. 2.181
      MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
    182. 2.182
      Ninja Forms – The Contact Form Builder That Grows With You
    183. 2.183
      The Events Calendar
    184. 2.184
      User Role Editor
    185. 2.185
      Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    186. 2.186
      Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    187. 2.187
      SiteOrigin Widgets Bundle
    188. 2.188
      Gutenberg Blocks with AI by Kadence WP – Page Builder Features
    189. 2.189
      Members – Membership & User Role Editor Plugin
    190. 2.190
      Popup Builder – Create highly converting, mobile friendly marketing popups.
    191. 2.191
      Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
    192. 2.192
      Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
    193. 2.193
      Beaver Builder – WordPress Page Builder
    194. 2.194
      Image Widget
    195. 2.195
      LuckyWP Table of Contents
    196. 2.196
      Web Stories
    197. 2.197
      LearnPress – WordPress LMS Plugin
    198. 2.198
      LearnPress – WordPress LMS Plugin
    199. 2.199
      AI Engine
    200. 2.200
      Ajax Search Lite – Live Search & Filter
    201. 2.201
      Bold Page Builder
    202. 2.202
      Calculated Fields Form
    203. 2.203
      Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
    204. 2.204
      Ultimate Blocks – WordPress Blocks Plugin
    205. 2.205
      Greenshift – animation and page builder blocks
    206. 2.206
      ?????? ????? ??????? Persian WooCommerce SMS
    207. 2.207
      FULL – Cliente
    208. 2.208
      NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar
    209. 2.209
      PPWP – Password Protect Pages
    210. 2.210
      New User Approve
    211. 2.211
      Rate My Post – Star Rating Plugin by FeedbackWP
    212. 2.212
      Minify HTML
    213. 2.213
      s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
    214. 2.214
      Simple Side Tab
    215. 2.215
      Essential Real Estate
    216. 2.216
      Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent
    217. 2.217
      MyParcel
    218. 2.218
      Events Addon for Elementor
    219. 2.219
      PowerPack Lite for Beaver Builder
    220. 2.220
      Primary Addon for Elementor
    221. 2.221
      Notibar – Notification Bar for WordPress
    222. 2.222
      Notibar – Notification Bar for WordPress
    223. 2.223
      Vimeography: Vimeo Video Gallery WordPress Plugin
    224. 2.224
      OAuth Single Sign On – SSO (OAuth Client)
    225. 2.225
      Coupon Affiliates – Affiliate Plugin for WooCommerce
    226. 2.226
      WPMobile.App — Android and iOS Mobile Application
    227. 2.227
      ElementsReady Addons for Elementor
    228. 2.228
      EventPrime – Events Calendar, Bookings and Tickets
    229. 2.229
      GEO my WP
    230. 2.230
      MStore API – Create Native Android & iOS Apps On The Cloud
    231. 2.231
      WP Crowdfunding
    232. 2.232
      WP Crowdfunding
    233. 2.233
      Hash Form – Drag & Drop Form Builder
    234. 2.234
      Cognito Forms
    235. 2.235
      Falcon – WordPress Optimizations & Tweaks
    236. 2.236
      Online Booking & Scheduling Calendar for WordPress by vcita
    237. 2.237
      Active Products Tables for WooCommerce. Use constructor to create tables 
    238. 2.238
      Responsive Filterable Portfolio
    239. 2.239
      Restaurant & Cafe Addon for Elementor
    240. 2.240
      Restrict – membership, site, content and user access restrictions for WordPress
    241. 2.241
      Simple Link Directory
    242. 2.242
      WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin
    243. 2.243
      360 Javascript Viewer
    244. 2.244
      Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.
    245. 2.245
      FormFacade – WordPress plugin for Google Forms
    246. 2.246
      ForumWP – Forum & Discussion Board
    247. 2.247
      ImageRecycle pdf & image compression
    248. 2.248
      Memberful – Membership Plugin
    249. 2.249
      Posti Shipping
    250. 2.250
      Simple Restrict
    251. 2.251
      RapidLoad – Optimize Web Vitals Automatically
    252. 2.252
      NiceJob
    253. 2.253
      Property Hive Mortgage Calculator
    254. 2.254
      Property Hive Stamp Duty Calculator
    255. 2.255
      WPC Order Notes for WooCommerce
    256. 2.256
      Quran multilanguage Text & Audio
    257. 2.257
      Waymark
    258. 2.258
      WP Pipes
    259. 2.259
      AR for WordPress
    260. 2.260
      Car Dealer (Dealership) and Vehicle sales
    261. 2.261
      Device Detector
    262. 2.262
      Last Viewed Posts by WPBeginner
    263. 2.263
      Out of the Block: OpenStreetMap
    264. 2.264
      AIcomments – ??????????? ? ?????? ChatGPT
    265. 2.265
      CM Answers – Powerful WordPress Forum Plugin
    266. 2.266
      Cryptocurrency Price Widget
    267. 2.267
      iChart – Easy Charts and Graphs
    268. 2.268
      Mark New Posts
    269. 2.269
      WP Email Log – PostBox
    270. 2.270
      Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
    271. 2.271
      Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
    272. 2.272
      Themify Store Locator
    273. 2.273
      WooCommerce Additional Fees On Checkout (Free)
    274. 2.274
      Gutenberg Blocks and Page Layouts – Attire Blocks
    275. 2.275
      Projectopia – WordPress Project Management
    276. 2.276
      Payment Gateway Per Product for WooCommerce
    277. 2.277
      Check Pincode For Woocommerce
    278. 2.278
      Currency Converter Widget ? PRO
    279. 2.279
      NewsmanApp
    280. 2.280
      Print Science Designer
    281. 2.281
      Stop Registration Spam
    282. 2.282
      WP BASE Booking of Appointments, Services and Events
    283. 2.283
      WP Mailster
    284. 2.284
      AutoWP – AI Content Writer & Rewriter
    285. 2.285
      Booking System Trafft
    286. 2.286
      dejure.org Vernetzungsfunktion
    287. 2.287
      Email Reminders
    288. 2.288
      J&T Express Malaysia
    289. 2.289
      Revi.io – Customer & Products Reviews
    290. 2.290
      WordPress Post Grid Layouts with Pagination – Sogrid
    291. 2.291
      WordPress Post Grid Layouts with Pagination – Sogrid
    292. 2.292
      Staggs – Product Configurator Toolkit
    293. 2.293
      Lifetime free Drag & Drop Contact Form Builder for WordPress VForm
    294. 2.294
      Video & Photo Gallery for Ultimate Member
    295. 2.295
      Gou Manage My Account Menu – User Roles
    296. 2.296
      ICDSoft Reseller Store
    297. 2.297
      Ksher
    298. 2.298
      Media Downloader
    299. 2.299
      CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout
    300. 2.300
      Invoice Payment for WooCommerce
    301. 2.301
      Seraphinite Bulk Discounts for WooCommerce
    302. 2.302
      Hurrakify
    303. 2.303
      SMS for WooCommerce
    304. 2.304
      Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress
    305. 2.305
      Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress
    306. 2.306
      AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot
    307. 2.307
      LabelGrid Tools
    308. 2.308
      Simple Payment
    309. 2.309
      CarDealerPress
    310. 2.310
      CE21 Suite
    311. 2.311
      EduAdmin Booking
    312. 2.312
      Hack-Info
    313. 2.313
      FloristPress – Customize your Woo store for your Florist
    314. 2.314
      CleverNode Related Content
    315. 2.315
      Connect Contact Form 7 to Constant Contact V3
    316. 2.316
      Fancy Roller Scroller
    317. 2.317
      I Plant A Tree
    318. 2.318
      ImmoToolBox Connect
    319. 2.319
      Newsletter, Email Marketing, Email Subscriber – Mail Picker
    320. 2.320
      Simple Presenter
    321. 2.321
      SMSify
    322. 2.322
      UNIVERSAM
    323. 2.323
      WP Currency Exchange Rates
    324. 2.324
      WP Quick Shop
    325. 2.325
      DX Dark Site
    326. 2.326
      FooGallery Premium
    327. 2.327
      GeoFlickr
    328. 2.328
      Hello Event Widgets For Elementor
    329. 2.329
      WP SuperBackup
    330. 2.330
      Kundgenerator
    331. 2.331
      Quran Phrases About Most People Shortcodes
    332. 2.332
      Responsive Google Maps | by imbaa
    333. 2.333
      Termin-Kalender
    334. 2.334
      WooCommerce PDF Vouchers
    335. 2.335
      WP All Import Pro
  3. 3. WordPress Themes — 8 Patched / 2 Unpatched
    1. 3.1
      Olivia
    2. 3.2
      Zerif Lite
    3. 3.3
      Barter
    4. 3.4
      Bicycleshop
    5. 3.5
      Brand
    6. 3.6
      hmd
    7. 3.7
      Plain Post
    8. 3.8
      Avada
    9. 3.9
      Woffice
    10. 3.10
      WoodMart

window[“5692f671_f1b2_412a_a76c_ceb9a9396d4e”] = {“blockId”:”5692f671-f1b2-412a-a76c-ceb9a9396d4e”,”type”:”notice”,”content”:”

Our WordPress Vulnerability Report\u00a0covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of\u00a0Low,\u00a0Medium,\u00a0High, or\u00a0Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress \u2014 and the web \u2014 more secure.”,”className”:””};

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

window[“c8539d2c_4fc0_432d_8df0_94a80820d5df”] = {“blockId”:”c8539d2c-4fc0-432d-8df0-94a80820d5df”,”text”:”No new core vulnerabilities were disclosed this week.”,”className”:””};

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 156 Patched / 179 Unpatched

WP Mega Menu

Plugin:

WP Mega Menu

Plugin Slug:
wp-megamenu

Installations
10,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54282

The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin:

WPCargo Track & Trace

Plugin Slug:
wpcargo

Installations
10,000+

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54271

The vulnerability has not been patched. You should deactivate the plugin.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin:

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54289

The vulnerability has not been patched. You should deactivate the plugin.

Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch

Plugin:

Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch

Plugin Slug:
axeptio-sdk-integration

Installations
7,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54270

The vulnerability has not been patched. You should deactivate the plugin.

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress

Plugin:

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress

Plugin Slug:
radio-player

Installations
6,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54385

The vulnerability has not been patched. You should deactivate the plugin.

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin

Plugin:

EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin

Plugin Slug:
eazydocs

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54376

The vulnerability has not been patched. You should deactivate the plugin.

News Ticker for Elementor

Plugin:

News Ticker for Elementor

Plugin Slug:
news-ticker-for-elementor

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54278

The vulnerability has not been patched. You should deactivate the plugin.

WP Menu Image

Plugin:

WP Menu Image

Plugin Slug:
wp-menu-image

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-52485

The vulnerability has not been patched. You should deactivate the plugin.

Smaily for WP

Plugin:

Smaily for WP

Plugin Slug:
smaily-for-wp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54286

The vulnerability has not been patched. You should deactivate the plugin.

SQL Chart Builder

Plugin:

SQL Chart Builder

Plugin Slug:
sql-chart-builder

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11430

The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin:

Job Board Manager

Plugin Slug:
job-board-manager

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55993

The vulnerability has not been patched. You should deactivate the plugin.

SIP Calculator

Plugin:

SIP Calculator

Plugin Slug:
sip-calculator

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12555

The vulnerability has not been patched. You should deactivate the plugin.

LDD Directory Lite

Plugin:

LDD Directory Lite

Plugin Slug:
ldd-directory-lite

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54288

The vulnerability has not been patched. You should deactivate the plugin.

The Permalinker

Plugin:

The Permalinker

Plugin Slug:
the-permalinker

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11894

The vulnerability has not been patched. You should deactivate the plugin.

Nias course | ???? ??? ????

Plugin:

Nias course | ???? ??? ????

Plugin Slug:
nias-course

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54277

The vulnerability has not been patched. You should deactivate the plugin.

Role Includer

Plugin:

Role Includer

Plugin Slug:
role-includer

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54290

The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks – WordPress Gutenberg Blocks

Plugin:

Radius Blocks – WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54272

The vulnerability has not been patched. You should deactivate the plugin.

WordPress HelpDesk & Support Ticket System Plugin – Octrace Support

Plugin:

WordPress HelpDesk & Support Ticket System Plugin – Octrace Support

Plugin Slug:
octrace-support

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54274

The vulnerability has not been patched. You should deactivate the plugin.

WP Cookies Enabler

Plugin:

WP Cookies Enabler

Plugin Slug:
wp-cookies-enabler

Installations
30+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54380

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Blog Post Block

Plugin:

Advanced Blog Post Block

Plugin Slug:
advanced-blog-post-block

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54287

The vulnerability has not been patched. You should deactivate the plugin.

Poll, Poll Forms – WordPress Poll plugin by Poll Builder

Plugin:

Poll, Poll Forms – WordPress Poll plugin by Poll Builder

Plugin Slug:
poll-builder

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54276

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Blocks – Woolook

Plugin:

Woocommerce Blocks – Woolook

Plugin Slug:
woolook

Installations
10+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54375

The vulnerability has not been patched. You should deactivate the plugin.

WP-NERD Toolkit

Plugin:

WP-NERD Toolkit

Plugin Slug:
wp-nerd-toolkit

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54279

The vulnerability has not been patched. You should deactivate the plugin.

3D Avatar User Profile

Plugin:

3D Avatar User Profile

Plugin Slug:
3d-avatar-user-profile

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54358

The vulnerability has not been patched. You should deactivate the plugin.

Add image to Post

Plugin:

Add image to Post

Plugin Slug:
add-image-to-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54428

The vulnerability has not been patched. You should deactivate the plugin.

Advance Menu Manager

Plugin:

Advance Menu Manager

Plugin Slug:
advance-menu-manager

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54381

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Data Table For Elementor

Plugin:

Advanced Data Table For Elementor

Plugin Slug:
advanced-data-table-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54443

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Fancybox

Plugin:

Advanced Fancybox

Plugin Slug:
advanced-fancybox

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54401

The vulnerability has not been patched. You should deactivate the plugin.

Advanced What should we write next about

Plugin:

Advanced What should we write next about

Plugin Slug:
advanced-what-should-we-write-about-next

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55987

The vulnerability has not been patched. You should deactivate the plugin.

AI Post Generator | AutoWriter

Plugin:

AI Post Generator | AutoWriter

Plugin Slug:
ai-post-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11709

The vulnerability has not been patched. You should deactivate the plugin.

Zita Site Builder

Plugin:

Zita Site Builder

Plugin Slug:
ai-site-builder

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54369

The vulnerability has not been patched. You should deactivate the plugin.

Amazon Product Price

Plugin:

Amazon Product Price

Plugin Slug:
amazon-product-price

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54439

The vulnerability has not been patched. You should deactivate the plugin.

Animated Counters

Plugin:

Animated Counters

Plugin Slug:
animated-counters

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11905

The vulnerability has not been patched. You should deactivate the plugin.

Aphorismus

Plugin:

Aphorismus

Plugin Slug:
aphorismus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54429

The vulnerability has not been patched. You should deactivate the plugin.

AppMaps

Plugin:

AppMaps

Plugin Slug:
appmaps

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54400

The vulnerability has not been patched. You should deactivate the plugin.

Appsplate

Plugin:

Appsplate

Plugin Slug:
appsplate

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54292

The vulnerability has not been patched. You should deactivate the plugin.

Arabic Webfonts

Plugin:

Arabic Webfonts

Plugin Slug:
arabic-webfonts

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54402

The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM – Live Blogging for real-time events

Plugin:

Arena.IM – Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12526

The vulnerability has not been patched. You should deactivate the plugin.

Arena.IM – Live Blogging for real-time events

Plugin:

Arena.IM – Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12463

The vulnerability has not been patched. You should deactivate the plugin.

Firebase OTP Authentication

Plugin:

Firebase OTP Authentication

Plugin Slug:
authentication-via-otp-using-firebase

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54294

The vulnerability has not been patched. You should deactivate the plugin.

Banner System

Plugin:

Banner System

Plugin Slug:
banner-system

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54359

The vulnerability has not been patched. You should deactivate the plugin.

Bet sport Free

Plugin:

Bet sport Free

Plugin Slug:
bet-sport-free

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54396

The vulnerability has not been patched. You should deactivate the plugin.

Better WP Login Page

Plugin:

Better WP Login Page

Plugin Slug:
better-wp-login-page

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54442

The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Buttons

Plugin:

Bootstrap Buttons

Plugin Slug:
bootstrap-buttons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-49677

The vulnerability has not been patched. You should deactivate the plugin.

Buk

Plugin:

Buk

Plugin Slug:
buk-appointments

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11869

The vulnerability has not been patched. You should deactivate the plugin.

Caldera SMTP Mailer

Plugin:

Caldera SMTP Mailer

Plugin Slug:
caldera-smtp-mailer

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-56003

The vulnerability has not been patched. You should deactivate the plugin.

Mollie for Contact Form 7

Plugin:

Mollie for Contact Form 7

Plugin Slug:
cf7-mollie

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55990

The vulnerability has not been patched. You should deactivate the plugin.

??????

Plugin:

??????

Plugin Slug:
changyan

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55994

The vulnerability has not been patched. You should deactivate the plugin.

CK and SyntaxHighlighter

Plugin:

CK and SyntaxHighlighter

Plugin Slug:
ck-and-syntaxhighlighter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54407

The vulnerability has not been patched. You should deactivate the plugin.

Code Generator Pro

Plugin:

Code Generator Pro

Plugin Slug:
code-generator-pro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55978

The vulnerability has not been patched. You should deactivate the plugin.

Comments On Feed

Plugin:

Comments On Feed

Plugin Slug:
comments-on-feed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54406

The vulnerability has not been patched. You should deactivate the plugin.

Companion Portfolio

Plugin:

Companion Portfolio

Plugin Slug:
companion-portfolio

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11867

The vulnerability has not been patched. You should deactivate the plugin.

Connatix Video Embed

Plugin:

Connatix Video Embed

Plugin Slug:
connatix-video-embed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11883

The vulnerability has not been patched. You should deactivate the plugin.

CoSchool LMS

Plugin:

CoSchool LMS

Plugin Slug:
coschool

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54296

The vulnerability has not been patched. You should deactivate the plugin.

Crafthemes Demo Import

Plugin:

Crafthemes Demo Import

Plugin Slug:
crafthemes-demo-import

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-9698

The vulnerability has not been patched. You should deactivate the plugin.

Cricket Live Score

Plugin:

Cricket Live Score

Plugin Slug:
cricket-score

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11877

The vulnerability has not been patched. You should deactivate the plugin.

Critical Site Intel

Plugin:

Critical Site Intel

Plugin Slug:
critical-site-intel-stats

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55976

The vulnerability has not been patched. You should deactivate the plugin.

CRUDLab Google Plus Button

Plugin:

CRUDLab Google Plus Button

Plugin Slug:
crudlab-google-plus

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54399

The vulnerability has not been patched. You should deactivate the plugin.

CSV to html

Plugin:

CSV to html

Plugin Slug:
csv-to-html

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54275

The vulnerability has not been patched. You should deactivate the plugin.

Custom Skins Contact Form 7

Plugin:

Custom Skins Contact Form 7

Plugin Slug:
custom-skins-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12341

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Endpoints With Rest Api

Plugin:

Ultimate Endpoints With Rest Api

Plugin Slug:
custom-wp-rest-api

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12260

The vulnerability has not been patched. You should deactivate the plugin.

Mimoos

Plugin:

Mimoos

Plugin Slug:
devoluciones-packback

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55974

The vulnerability has not been patched. You should deactivate the plugin.

Display Future Posts

Plugin:

Display Future Posts

Plugin Slug:
display-future-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54413

The vulnerability has not been patched. You should deactivate the plugin.

Dr Affiliate

Plugin:

Dr Affiliate

Plugin Slug:
dr-affiliate

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55975

The vulnerability has not been patched. You should deactivate the plugin.

DTC Documents

Plugin:

DTC Documents

Plugin Slug:
dtc-documents

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54418

The vulnerability has not been patched. You should deactivate the plugin.

Easy Site Importer

Plugin:

Easy Site Importer

Plugin Slug:
easy-site-importer

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-56004

The vulnerability has not been patched. You should deactivate the plugin.

ECT Product Carousel

Plugin:

ECT Product Carousel

Plugin Slug:
ect-product-carousel

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54412

The vulnerability has not been patched. You should deactivate the plugin.

ECT Social Share

Plugin:

ECT Social Share

Plugin Slug:
ect-social-share

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54405

The vulnerability has not been patched. You should deactivate the plugin.

EELV Newsletter

Plugin:

EELV Newsletter

Plugin Slug:
eelv-newsletter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54430

The vulnerability has not been patched. You should deactivate the plugin.

Mandrill WP

Plugin:

Mandrill WP

Plugin Slug:
email-form-under-post

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54394

The vulnerability has not been patched. You should deactivate the plugin.

eTemplates

Plugin:

eTemplates

Plugin Slug:
etemplates

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55972

The vulnerability has not been patched. You should deactivate the plugin.

Evernote Sync

Plugin:

Evernote Sync

Plugin Slug:
evernote-sync

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54422

The vulnerability has not been patched. You should deactivate the plugin.

Feedpress Generator

Plugin:

Feedpress Generator

Plugin Slug:
feedpress-generator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54364

The vulnerability has not been patched. You should deactivate the plugin.

Flaming Forms

Plugin:

Flaming Forms

Plugin Slug:
flaming-forms

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54398

The vulnerability has not been patched. You should deactivate the plugin.

Flash News / Post (Responsive)

Plugin:

Flash News / Post (Responsive)

Plugin Slug:
flashnews-fading-effect-pearlbells

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-56012

The vulnerability has not been patched. You should deactivate the plugin.

Floating Video Player

Plugin:

Floating Video Player

Plugin Slug:
floating-player

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54421

The vulnerability has not been patched. You should deactivate the plugin.

Gaxx Keywords

Plugin:

Gaxx Keywords

Plugin Slug:
gaxx-keywords

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54438

The vulnerability has not been patched. You should deactivate the plugin.

Geoportail Shortcode

Plugin:

Geoportail Shortcode

Plugin Slug:
geoportail-shortcode

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54414

The vulnerability has not been patched. You should deactivate the plugin.

Get Post Content Shortcode

Plugin:

Get Post Content Shortcode

Plugin Slug:
get-post-content-shortcode

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12447

The vulnerability has not been patched. You should deactivate the plugin.

GitSync

Plugin:

GitSync

Plugin Slug:
git-sync

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54368

The vulnerability has not been patched. You should deactivate the plugin.

glomex oEmbed

Plugin:

glomex oEmbed

Plugin Slug:
glomex-oembed

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11873

The vulnerability has not been patched. You should deactivate the plugin.

Go Animate

Plugin:

Go Animate

Plugin Slug:
goanimate

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54397

The vulnerability has not been patched. You should deactivate the plugin.

Grid Plus

Plugin:

Grid Plus

Plugin Slug:
grid-plus

Vulnerability:
Arbitrary Code Execution

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-10910

The vulnerability has not been patched. You should deactivate the plugin.

Gutensee

Plugin:

Gutensee

Plugin Slug:
gutensee

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54360

The vulnerability has not been patched. You should deactivate the plugin.

Opt-In Downloads

Plugin:

Opt-In Downloads

Plugin Slug:
halfdata-optin-downloads

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-10590

The vulnerability has not been patched. You should deactivate the plugin.

Hello In All Languages

Plugin:

Hello In All Languages

Plugin Slug:
hello-in-all-languages

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12572

The vulnerability has not been patched. You should deactivate the plugin.

Horizontal scroll image slideshow

Plugin:

Horizontal scroll image slideshow

Plugin Slug:
horizontal-scroll-image-slideshow

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11442

The vulnerability has not been patched. You should deactivate the plugin.

HostFact bestelformulier integratie

Plugin:

HostFact bestelformulier integratie

Plugin Slug:
hostfact-bestelformulier-integratie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11413

The vulnerability has not been patched. You should deactivate the plugin.

HQ Rental Software

Plugin:

HQ Rental Software

Plugin Slug:
hq-rental-software

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11689

The vulnerability has not been patched. You should deactivate the plugin.

IDer Login

Plugin:

IDer Login

Plugin Slug:
ider-login

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11888

The vulnerability has not been patched. You should deactivate the plugin.

Image Mapper

Plugin:

Image Mapper

Plugin Slug:
image-mapper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-56016

The vulnerability has not been patched. You should deactivate the plugin.

Increase Sociability

Plugin:

Increase Sociability

Plugin Slug:
increase-sociability

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54395

The vulnerability has not been patched. You should deactivate the plugin.

Insertify

Plugin:

Insertify

Plugin Slug:
insertify

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54372

The vulnerability has not been patched. You should deactivate the plugin.

Instant Appointment

Plugin:

Instant Appointment

Plugin Slug:
instant-appointment

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54361

The vulnerability has not been patched. You should deactivate the plugin.

jCarousel

Plugin:

jCarousel

Plugin Slug:
jcarousel-for-wordpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54437

The vulnerability has not been patched. You should deactivate the plugin.

Jet Footer Code

Plugin:

Jet Footer Code

Plugin Slug:
jet-footer-code

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54436

The vulnerability has not been patched. You should deactivate the plugin.

KH Easy User Settings

Plugin:

KH Easy User Settings

Plugin Slug:
kh-easy-user-settings

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54365

The vulnerability has not been patched. You should deactivate the plugin.

Kredeum NFTs

Plugin:

Kredeum NFTs

Plugin Slug:
kredeum-nfts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11876

The vulnerability has not been patched. You should deactivate the plugin.

kvCORE IDX

Plugin:

kvCORE IDX

Plugin Slug:
kvcore-idx

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11723

The vulnerability has not been patched. You should deactivate the plugin.

LaunchPage.app Importer

Plugin:

LaunchPage.app Importer

Plugin Slug:
launchpage-app-importer

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55977

The vulnerability has not been patched. You should deactivate the plugin.

Leader

Plugin:

Leader

Plugin Slug:
leader

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-56007

The vulnerability has not been patched. You should deactivate the plugin.

LeaderBoard Plugin

Plugin:

LeaderBoard Plugin

Plugin Slug:
leaderboard-lite

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54426

The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:

Library Management System

Plugin Slug:
library-management-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12406

The vulnerability has not been patched. You should deactivate the plugin.

Like in Vk.com

Plugin:

Like in Vk.com

Plugin Slug:
like-on-vkontakte

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54424

The vulnerability has not been patched. You should deactivate the plugin.

Category of Posts

Plugin:

Category of Posts

Plugin Slug:
list-one-category-of-posts

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54427

The vulnerability has not been patched. You should deactivate the plugin.

ListApp Mobile Manager

Plugin:

ListApp Mobile Manager

Plugin Slug:
listapp-mobile-manager

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54295

The vulnerability has not been patched. You should deactivate the plugin.

LionScripts: Site Maintenance & Noindex Nofollow Plugin

Plugin:

LionScripts: Site Maintenance & Noindex Nofollow Plugin

Plugin Slug:
maintenance-and-noindex-nofollow

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54425

The vulnerability has not been patched. You should deactivate the plugin.

MDC Comment Toolbar

Plugin:

MDC Comment Toolbar

Plugin Slug:
mdc-comment-toolbar

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54404

The vulnerability has not been patched. You should deactivate the plugin.

Metrika

Plugin:

Metrika

Plugin Slug:
metrika

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54420

The vulnerability has not been patched. You should deactivate the plugin.

Minterpress

Plugin:

Minterpress

Plugin Slug:
minterpress

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54379

The vulnerability has not been patched. You should deactivate the plugin.

Multiple Admin Emails

Plugin:

Multiple Admin Emails

Plugin Slug:
multiple-admin-emails

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54388

The vulnerability has not been patched. You should deactivate the plugin.

My IDX Home Search

Plugin:

My IDX Home Search

Plugin Slug:
my-idx-home-search

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12502

The vulnerability has not been patched. You should deactivate the plugin.

addWeather

Plugin:

addWeather

Plugin Slug:
myweather

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54389

The vulnerability has not been patched. You should deactivate the plugin.

Nabz Image Gallery

Plugin:

Nabz Image Gallery

Plugin Slug:
nabz-image-gallery

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55981

The vulnerability has not been patched. You should deactivate the plugin.

Navayan CSV Export

Plugin:

Navayan CSV Export

Plugin Slug:
navayan-csv-export

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55988

The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Subscriptions

Plugin:

Newsletter Subscriptions

Plugin Slug:
newsletter-subscriptions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11683

The vulnerability has not been patched. You should deactivate the plugin.

Onlywire Multi Autosubmitter

Plugin:

Onlywire Multi Autosubmitter

Plugin Slug:
onlywire-multi-autosubmitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54435

The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery & Pickup Location Date Time

Plugin:

Order Delivery & Pickup Location Date Time

Plugin Slug:
order-delivery-pickup-location-date-time-free-version

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55997

The vulnerability has not been patched. You should deactivate the plugin.

phZoom

Plugin:

phZoom

Plugin Slug:
phzoom

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54434

The vulnerability has not been patched. You should deactivate the plugin.

PixProof

Plugin:

PixProof

Plugin Slug:
pixproof

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54417

The vulnerability has not been patched. You should deactivate the plugin.

Popup Surveys & Polls for WordPress (Mare.io)

Plugin:

Popup Surveys & Polls for WordPress (Mare.io)

Plugin Slug:
popup-surveys

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55998

The vulnerability has not been patched. You should deactivate the plugin.

Portfolio – Filterable Masonry Portfolio Gallery for Professionals

Plugin:

Portfolio – Filterable Masonry Portfolio Gallery for Professionals

Plugin Slug:
portfolio-pro

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11900

The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel & Slider

Plugin:

Post Carousel & Slider

Plugin Slug:
post-types-carousel-slider

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11770

The vulnerability has not been patched. You should deactivate the plugin.

Posts and Products Views for WooCommerce

Plugin:

Posts and Products Views for WooCommerce

Plugin Slug:
posts-and-products-views

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12448

The vulnerability has not been patched. You should deactivate the plugin.

Posts Date Ranges

Plugin:

Posts Date Ranges

Plugin Slug:
posts-date-ranges

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54387

The vulnerability has not been patched. You should deactivate the plugin.

PowerFormBuilder

Plugin:

PowerFormBuilder

Plugin Slug:
power-forms-builder

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55983

The vulnerability has not been patched. You should deactivate the plugin.

Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart

Plugin:

Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart

Plugin Slug:
push-monkey-desktop-push-notifications

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54386

The vulnerability has not been patched. You should deactivate the plugin.

Quietly Insights

Plugin:

Quietly Insights

Plugin Slug:
quietly-insights

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54378

The vulnerability has not been patched. You should deactivate the plugin.

Share Buttons – Social Media

Plugin:

Share Buttons – Social Media

Plugin Slug:
rich-web-share-button

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55982

The vulnerability has not been patched. You should deactivate the plugin.

Saksh Escrow System

Plugin:

Saksh Escrow System

Plugin Slug:
saksh-escrow-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55984

The vulnerability has not been patched. You should deactivate the plugin.

Saoshyant Element

Plugin:

Saoshyant Element

Plugin Slug:
saoshyant-element

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-51646

The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54285

The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54284

The vulnerability has not been patched. You should deactivate the plugin.

SeedProd Pro

Plugin:

SeedProd Pro

Plugin Slug:
seedprod-coming-soon-pro-5

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54283

The vulnerability has not been patched. You should deactivate the plugin.

Service

Plugin:

Service

Plugin Slug:
service

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55986

The vulnerability has not been patched. You should deactivate the plugin.

Sign In With Google

Plugin:

Sign In With Google

Plugin Slug:
sign-in-with-google

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-11015

The vulnerability has not been patched. You should deactivate the plugin.

Simple Booking Widget

Plugin:

Simple Booking Widget

Plugin Slug:
simple-booking-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54433

The vulnerability has not been patched. You should deactivate the plugin.

Slope Widgets

Plugin:

Slope Widgets

Plugin Slug:
slope-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11902

The vulnerability has not been patched. You should deactivate the plugin.

Social Media Sharing

Plugin:

Social Media Sharing

Plugin Slug:
social-media-sharing

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54423

The vulnerability has not been patched. You should deactivate the plugin.

SOPA Blackout

Plugin:

SOPA Blackout

Plugin Slug:
sopa-blackout

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54410

The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Pay Lite Manager

Plugin:

WP Simple Pay Lite Manager

Plugin Slug:
stripe-manager

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55989

The vulnerability has not been patched. You should deactivate the plugin.

Surbma | SalesAutopilot Shortcode

Plugin:

Surbma | SalesAutopilot Shortcode

Plugin Slug:
surbma-salesautopilot-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11433

The vulnerability has not been patched. You should deactivate the plugin.

SVG Shortcode

Plugin:

SVG Shortcode

Plugin Slug:
svg-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12574

The vulnerability has not been patched. You should deactivate the plugin.

TagGator

Plugin:

TagGator

Plugin Slug:
taggator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54390

The vulnerability has not been patched. You should deactivate the plugin.

TCBD Popover

Plugin:

TCBD Popover

Plugin Slug:
tcbd-popover

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11751

The vulnerability has not been patched. You should deactivate the plugin.

Tidy Up

Plugin:

Tidy Up

Plugin Slug:
tidy-up

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-56015

The vulnerability has not been patched. You should deactivate the plugin.

TPG Get Posts

Plugin:

TPG Get Posts

Plugin Slug:
tpg-get-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11906

The vulnerability has not been patched. You should deactivate the plugin.

TSB Occasion Editor

Plugin:

TSB Occasion Editor

Plugin Slug:
tsb-occasion-editor

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55973

The vulnerability has not been patched. You should deactivate the plugin.

Ui Slider Filter By Price

Plugin:

Ui Slider Filter By Price

Plugin Slug:
ui-slider-filter-by-price

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54419

The vulnerability has not been patched. You should deactivate the plugin.

Utech World Time

Plugin:

Utech World Time

Plugin Slug:
utech-world-time-for-wp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54441

The vulnerability has not been patched. You should deactivate the plugin.

vBSSO-lite

Plugin:

vBSSO-lite

Plugin Slug:
vbsso-lite

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54297

The vulnerability has not been patched. You should deactivate the plugin.

Visual Recent Posts

Plugin:

Visual Recent Posts

Plugin Slug:
visual-recent-posts

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54403

The vulnerability has not been patched. You should deactivate the plugin.

Visualmodo Elements

Plugin:

Visualmodo Elements

Plugin Slug:
visualmodo-elements

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11095

The vulnerability has not been patched. You should deactivate the plugin.

Website Toolbox Community

Plugin:

Website Toolbox Community

Plugin Slug:
website-toolbox-forums

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12338

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Cart Count Shortcode

Plugin:

WooCommerce Cart Count Shortcode

Plugin Slug:
woo-cart-count-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12517

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Basic Ordernumbers

Plugin:

WooCommerce Basic Ordernumbers

Plugin Slug:
woocommerce-basic-ordernumbers

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55992

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Filter

Plugin:

WordPress Filter

Plugin Slug:
wordpress-filter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54391

The vulnerability has not been patched. You should deactivate the plugin.

Wovax IDX

Plugin:

Wovax IDX

Plugin Slug:
wovax-idx

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-56013

The vulnerability has not been patched. You should deactivate the plugin.

WP-Ban-User

Plugin:

WP-Ban-User

Plugin Slug:
wp-ban-user

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54440

The vulnerability has not been patched. You should deactivate the plugin.

WP Fiddle

Plugin:

WP Fiddle

Plugin Slug:
wp-fiddle

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54393

The vulnerability has not been patched. You should deactivate the plugin.

WP Flipkart Importer

Plugin:

WP Flipkart Importer

Plugin Slug:
wp-flipkart-importer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54432

The vulnerability has not been patched. You should deactivate the plugin.

WP-HideThat

Plugin:

WP-HideThat

Plugin Slug:
wp-hide-that

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54415

The vulnerability has not been patched. You should deactivate the plugin.

Wp Login with Ajax

Plugin:

Wp Login with Ajax

Plugin Slug:
wp-login-with-ajax

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54416

The vulnerability has not been patched. You should deactivate the plugin.

WP Controller

Plugin:

WP Controller

Plugin Slug:
wp-management-controller

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54411

The vulnerability has not been patched. You should deactivate the plugin.

Wp NssUser Register

Plugin:

Wp NssUser Register

Plugin Slug:
wp-nssuser-register

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54363

The vulnerability has not been patched. You should deactivate the plugin.

Wp photo text slider 50

Plugin:

Wp photo text slider 50

Plugin Slug:
wp-photo-text-slider-50

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11884

The vulnerability has not been patched. You should deactivate the plugin.

WP Service Payment Form With Authorize.net

Plugin:

WP Service Payment Form With Authorize.net

Plugin Slug:
wp-service-payment-form-with-authorizenet

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12258

The vulnerability has not been patched. You should deactivate the plugin.

Tithe.ly Giving Button

Plugin:

Tithe.ly Giving Button

Plugin Slug:
wp-tithely

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11841

The vulnerability has not been patched. You should deactivate the plugin.

WP?????

Plugin:

WP?????

Plugin Slug:
wp-weixin-robot

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54392

The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:

WPBookit

Plugin Slug:
wpbookit

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54280

The vulnerability has not been patched. You should deactivate the plugin.

Admin Customization

Plugin:

Admin Customization

Plugin Slug:
wpp-customization

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54431

The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:

Wr Age Verification

Plugin Slug:
wr-age-verification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55979

The vulnerability has not been patched. You should deactivate the plugin.

Wr Age Verification

Plugin:

Wr Age Verification

Plugin Slug:
wr-age-verification

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-55980

The vulnerability has not been patched. You should deactivate the plugin.

XML Multilanguage Sitemap Generator

Plugin:

XML Multilanguage Sitemap Generator

Plugin Slug:
xml-multilanguage-sitemap-generator

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-55999

The vulnerability has not been patched. You should deactivate the plugin.

XPD Reduce Image Filesize

Plugin:

XPD Reduce Image Filesize

Plugin Slug:
xpd-reduce-image-filesize

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54409

The vulnerability has not been patched. You should deactivate the plugin.

YDS Support Ticket System

Plugin:

YDS Support Ticket System

Plugin Slug:
yds-support-ticket-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-55985

The vulnerability has not been patched. You should deactivate the plugin.

States Map US

Plugin:

States Map US

Plugin Slug:
ymc-states-map

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12523

The vulnerability has not been patched. You should deactivate the plugin.

YooBar

Plugin:

YooBar

Plugin Slug:
yoo-bar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11410

The vulnerability has not been patched. You should deactivate the plugin.

Youtube Video Grid

Plugin:

Youtube Video Grid

Plugin Slug:
youmax-channel-embeds-for-youtube-businesses

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54408

The vulnerability has not been patched. You should deactivate the plugin.

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

Plugin:

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

Plugin Slug:
wpforms-lite

Installations
6,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.2.2

Severity Score:
High

CVE:

2024-11205

The vulnerability has been patched, so you should update to version 1.9.2.2.

MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites

Plugin:

MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites

Plugin Slug:
mainwp-child

Installations
700,000+

Vulnerability:
Privilege Escalation

Patched in Version:
5.3

Severity Score:
High

CVE:

2024-10783

The vulnerability has been patched, so you should update to version 5.3.

Ninja Forms – The Contact Form Builder That Grows With You

Plugin:

Ninja Forms – The Contact Form Builder That Grows With You

Plugin Slug:
ninja-forms

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.20

Severity Score:
High

CVE:

2024-11052

The vulnerability has been patched, so you should update to version 3.8.20.

The Events Calendar

Plugin:

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.8.2.1

Severity Score:
Medium

CVE:

2024-5333

The vulnerability has been patched, so you should update to version 6.8.2.1.

User Role Editor

Plugin:

User Role Editor

Plugin Slug:
user-role-editor

Installations
700,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.64.4

Severity Score:
Critical

CVE:

2024-12293

The vulnerability has been patched, so you should update to version 4.64.4.

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin:

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin Slug:
fluentform

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.7

Severity Score:
High

CVE:

2024-10646

The vulnerability has been patched, so you should update to version 5.2.7.

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin:

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin Slug:
fluentform

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.1

Severity Score:
Medium

CVE:

2024-9651

The vulnerability has been patched, so you should update to version 5.2.1.

SiteOrigin Widgets Bundle

Plugin:

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle

Installations
500,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.64.1

Severity Score:
Medium

CVE:

2024-54268

The vulnerability has been patched, so you should update to version 1.64.1.

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin:

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.54

Severity Score:
Medium

CVE:

2024-10637

The vulnerability has been patched, so you should update to version 3.2.54.

Members – Membership & User Role Editor Plugin

Plugin:

Members – Membership & User Role Editor Plugin

Plugin Slug:
members

Installations
300,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.11

Severity Score:
Medium

CVE:

2024-11008

The vulnerability has been patched, so you should update to version 3.2.11.

Popup Builder – Create highly converting, mobile friendly marketing popups.

Plugin:

Popup Builder – Create highly converting, mobile friendly marketing popups.

Plugin Slug:
popup-builder

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.3.5

Severity Score:
Medium

CVE:

2024-9428

The vulnerability has been patched, so you should update to version 4.3.5.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin:

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin Slug:
unlimited-elements-for-elementor

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.127

Severity Score:
Medium

CVE:

2024-10784

The vulnerability has been patched, so you should update to version 1.5.127.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Plugin:

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.15

Severity Score:
Medium

CVE:

2024-10517

The vulnerability has been patched, so you should update to version 4.15.15.

Beaver Builder – WordPress Page Builder

Plugin:

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.5.3

Severity Score:
Medium

CVE:

2024-11832

The vulnerability has been patched, so you should update to version 2.8.5.3.

Image Widget

Plugin:

Image Widget

Plugin Slug:
image-widget

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.11

Severity Score:
Medium

CVE:

2024-10939

The vulnerability has been patched, so you should update to version 4.4.11.

LuckyWP Table of Contents

Plugin:

LuckyWP Table of Contents

Plugin Slug:
luckywp-table-of-contents

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.7

Severity Score:
Medium

CVE:

2024-9641

The vulnerability has been patched, so you should update to version 2.1.7.

Web Stories

Plugin:

Web Stories

Plugin Slug:
web-stories

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.38.0

Severity Score:
Medium

CVE:

2024-54317

The vulnerability has been patched, so you should update to version 1.38.0.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.7.2

Severity Score:
Medium

CVE:

2024-10010

The vulnerability has been patched, so you should update to version 4.2.7.2.

LearnPress – WordPress LMS Plugin

Plugin:

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress

Installations
90,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.2.7.4

Severity Score:
Medium

CVE:

2024-11868

The vulnerability has been patched, so you should update to version 4.2.7.4.

AI Engine

Plugin:

AI Engine

Plugin Slug:
ai-engine

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
2.6.5

Severity Score:
High

CVE:

2024-10499

The vulnerability has been patched, so you should update to version 2.6.5.

Ajax Search Lite – Live Search & Filter

Plugin:

Ajax Search Lite – Live Search & Filter

Plugin Slug:
ajax-search-lite

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.12.4

Severity Score:
Medium

CVE:

2024-10568

The vulnerability has been patched, so you should update to version 4.12.4.

Bold Page Builder

Plugin:

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Path Traversal

Patched in Version:
5.1.6

Severity Score:
Medium

CVE:

2024-54382

The vulnerability has been patched, so you should update to version 5.1.6.

Calculated Fields Form

Plugin:

Calculated Fields Form

Plugin Slug:
calculated-fields-form

Installations
50,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
5.2.64

Severity Score:
Medium

CVE:

2024-12601

The vulnerability has been patched, so you should update to version 5.2.64.

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Plugin:

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy

Plugin Slug:
easy-digital-downloads

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.3.5

Severity Score:
Low

CVE:

2024-9654

The vulnerability has been patched, so you should update to version 3.3.5.

Ultimate Blocks – WordPress Blocks Plugin

Plugin:

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.4

Severity Score:
Medium

CVE:

2024-10678

The vulnerability has been patched, so you should update to version 3.2.4.

Greenshift – animation and page builder blocks

Plugin:

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks

Installations
40,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
9.9.9.4

Severity Score:
Medium

CVE:

2024-11181

The vulnerability has been patched, so you should update to version 9.9.9.4.

?????? ????? ??????? Persian WooCommerce SMS

Plugin:

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.0.6

Severity Score:
High

CVE:

2024-54312

The vulnerability has been patched, so you should update to version 7.0.6.

FULL – Cliente

Plugin:

FULL – Cliente

Plugin Slug:
full-customer

Installations
30,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.1.26

Severity Score:
Medium

CVE:

2024-54313

The vulnerability has been patched, so you should update to version 3.1.26.

NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar

Plugin:

NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar

Plugin Slug:
notificationx

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.9.4

Severity Score:
Medium

CVE:

2024-11727

The vulnerability has been patched, so you should update to version 2.9.4.

PPWP – Password Protect Pages

Plugin:

PPWP – Password Protect Pages

Plugin Slug:
password-protect-page

Installations
30,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.9.6

Severity Score:
Medium

CVE:

2024-11280

The vulnerability has been patched, so you should update to version 1.9.6.

New User Approve

Plugin:

New User Approve

Plugin Slug:
new-user-approve

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.4

Severity Score:
Medium

CVE:

2024-54323

The vulnerability has been patched, so you should update to version 2.6.4.

Rate My Post – Star Rating Plugin by FeedbackWP

Plugin:

Rate My Post – Star Rating Plugin by FeedbackWP

Plugin Slug:
rate-my-post

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.5

Severity Score:
Medium

CVE:

2024-12309

The vulnerability has been patched, so you should update to version 4.2.5.

Minify HTML

Plugin:

Minify HTML

Plugin Slug:
minify-html-markup

Installations
10,000+

Vulnerability:
Denial of Service Attack

Patched in Version:
2.1.11

Severity Score:
High

CVE:

2024-12579

The vulnerability has been patched, so you should update to version 2.1.11.

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

Plugin:

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

Plugin Slug:
s2member

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
241216

Severity Score:
High

CVE:

2024-8326

The vulnerability has been patched, so you should update to version 241216.

Simple Side Tab

Plugin:

Simple Side Tab

Plugin Slug:
simple-side-tab

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium

CVE:

2024-11183

The vulnerability has been patched, so you should update to version 2.2.0.

Essential Real Estate

Plugin:

Essential Real Estate

Plugin Slug:
essential-real-estate

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.7

Severity Score:
Medium

CVE:

2024-12329

The vulnerability has been patched, so you should update to version 5.1.7.

Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent

Plugin:

Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent

Plugin Slug:
gdpr-cookie-consent

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.6.6

Severity Score:
Medium

CVE:

2024-11724

The vulnerability has been patched, so you should update to version 3.6.6.

MyParcel

Plugin:

MyParcel

Plugin Slug:
woocommerce-myparcel

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.24.2

Severity Score:
High

CVE:

2024-9608

The vulnerability has been patched, so you should update to version 4.24.2.

Events Addon for Elementor

Plugin:

Events Addon for Elementor

Plugin Slug:
events-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium

CVE:

2024-54315

The vulnerability has been patched, so you should update to version 2.2.3.

PowerPack Lite for Beaver Builder

Plugin:

PowerPack Lite for Beaver Builder

Plugin Slug:
powerpack-addon-for-beaver-builder

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
High

CVE:

2024-12239

The vulnerability has been patched, so you should update to version 1.3.1.

Primary Addon for Elementor

Plugin:

Primary Addon for Elementor

Plugin Slug:
primary-addon-for-elementor

Installations
8,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.2

Severity Score:
Medium

CVE:

2024-54314

The vulnerability has been patched, so you should update to version 1.6.2.

Notibar – Notification Bar for WordPress

Plugin:

Notibar – Notification Bar for WordPress

Plugin Slug:
notibar

Installations
7,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
2.1.5

Severity Score:
Medium

CVE:

2024-11012

The vulnerability has been patched, so you should update to version 2.1.5.

Notibar – Notification Bar for WordPress

Plugin:

Notibar – Notification Bar for WordPress

Plugin Slug:
notibar

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.5

Severity Score:
Medium

CVE:

2024-54269

The vulnerability has been patched, so you should update to version 2.1.5.

Vimeography: Vimeo Video Gallery WordPress Plugin

Plugin:

Vimeography: Vimeo Video Gallery WordPress Plugin

Plugin Slug:
vimeography

Installations
7,000+

Vulnerability:
Full Path Disclosure (FPD)

Patched in Version:
2.4.5

Severity Score:
Medium

CVE:

2024-54366

The vulnerability has been patched, so you should update to version 2.4.5.

OAuth Single Sign On – SSO (OAuth Client)

Plugin:

OAuth Single Sign On – SSO (OAuth Client)

Plugin Slug:
miniorange-login-with-eve-online-google-facebook

Installations
6,000+

Vulnerability:
Broken Authentication

Patched in Version:
6.26.4

Severity Score:
High

CVE:

2024-10111

The vulnerability has been patched, so you should update to version 6.26.4.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin:

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage

Installations
5,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
5.16.7.2

Severity Score:
Medium

CVE:

2024-12421

The vulnerability has been patched, so you should update to version 5.16.7.2.

WPMobile.App — Android and iOS Mobile Application

Plugin:

WPMobile.App — Android and iOS Mobile Application

Plugin Slug:
wpappninja

Installations
5,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
11.53

Severity Score:
Medium

CVE:

2024-12420

The vulnerability has been patched, so you should update to version 11.53.

ElementsReady Addons for Elementor

Plugin:

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
4,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
6.4.9

Severity Score:
Medium

CVE:

2024-10356

The vulnerability has been patched, so you should update to version 6.4.9.

EventPrime – Events Calendar, Bookings and Tickets

Plugin:

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.6.0

Severity Score:
High

CVE:

2024-12024

The vulnerability has been patched, so you should update to version 4.0.6.0.

GEO my WP

Plugin:

GEO my WP

Plugin Slug:
geo-my-wp

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.5.1

Severity Score:
Medium

CVE:

2024-54326

The vulnerability has been patched, so you should update to version 4.5.1.

MStore API – Create Native Android & iOS Apps On The Cloud

Plugin:

MStore API – Create Native Android & iOS Apps On The Cloud

Plugin Slug:
mstore-api

Installations
4,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.16.5

Severity Score:
Medium

CVE:

2024-12042

The vulnerability has been patched, so you should update to version 4.16.5.

WP Crowdfunding

Plugin:

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.13

Severity Score:
Medium

CVE:

2024-11910

The vulnerability has been patched, so you should update to version 2.1.13.

WP Crowdfunding

Plugin:

WP Crowdfunding

Plugin Slug:
wp-crowdfunding

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.13

Severity Score:
Medium

CVE:

2024-11911

The vulnerability has been patched, so you should update to version 2.1.13.

Hash Form – Drag & Drop Form Builder

Plugin:

Hash Form – Drag & Drop Form Builder

Plugin Slug:
hash-form

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.2

Severity Score:
Medium

CVE:

2024-12201

The vulnerability has been patched, so you should update to version 1.2.2.

Cognito Forms

Plugin:

Cognito Forms

Plugin Slug:
cognito-forms

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
Medium

CVE:

2024-10182

The vulnerability has been patched, so you should update to version 2.0.8.

Falcon – WordPress Optimizations & Tweaks

Plugin:

Falcon – WordPress Optimizations & Tweaks

Plugin Slug:
falcon

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.4

Severity Score:
Medium

CVE:

2024-54384

The vulnerability has been patched, so you should update to version 2.8.4.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin:

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.5.2

Severity Score:
Medium

CVE:

2024-54356

The vulnerability has been patched, so you should update to version 4.5.2.

Active Products Tables for WooCommerce. Use constructor to create tables 

Plugin:

Active Products Tables for WooCommerce. Use constructor to create tables 

Plugin Slug:
profit-products-tables-for-woocommerce

Installations
2,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.0.6.6

Severity Score:
High

CVE:

2024-10959

The vulnerability has been patched, so you should update to version 1.0.6.6.

Responsive Filterable Portfolio

Plugin:

Responsive Filterable Portfolio

Plugin Slug:
responsive-filterable-portfolio

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
1.0.9

Severity Score:
Critical

CVE:

2019-25221

The vulnerability has been patched, so you should update to version 1.0.9.

Restaurant & Cafe Addon for Elementor

Plugin:

Restaurant & Cafe Addon for Elementor

Plugin Slug:
restaurant-cafe-addon-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.9

Severity Score:
Medium

CVE:

2024-54316

The vulnerability has been patched, so you should update to version 1.5.9.

Restrict – membership, site, content and user access restrictions for WordPress

Plugin:

Restrict – membership, site, content and user access restrictions for WordPress

Plugin Slug:
restricted-content

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.9

Severity Score:
Medium

CVE:

2024-11351

The vulnerability has been patched, so you should update to version 2.2.9.

Simple Link Directory

Plugin:

Simple Link Directory

Plugin Slug:
simple-link-directory

Installations
2,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
8.4.1

Severity Score:
Medium

CVE:

2024-12417

The vulnerability has been patched, so you should update to version 8.4.1.

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin

Plugin:

WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin

Plugin Slug:
timetics

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.28

Severity Score:
Medium

CVE:

2024-11275

The vulnerability has been patched, so you should update to version 1.0.28.

360 Javascript Viewer

Plugin:

360 Javascript Viewer

Plugin Slug:
360deg-javascript-viewer

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.30

Severity Score:
Medium

CVE:

2024-12271

The vulnerability has been patched, so you should update to version 1.7.30.

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin:

Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.

Plugin Slug:
barcode-scanner-lite-pos-to-manage-products-inventory-and-orders

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.7

Severity Score:
High

CVE:

2024-54265

The vulnerability has been patched, so you should update to version 1.6.7.

FormFacade – WordPress plugin for Google Forms

Plugin:

FormFacade – WordPress plugin for Google Forms

Plugin Slug:
formfacade

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
High

CVE:

2024-54301

The vulnerability has been patched, so you should update to version 1.3.7.

ForumWP – Forum & Discussion Board

Plugin:

ForumWP – Forum & Discussion Board

Plugin Slug:
forumwp

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.1.1

Severity Score:
Critical

CVE:

2024-54367

The vulnerability has been patched, so you should update to version 2.1.1.

ImageRecycle pdf & image compression

Plugin:

ImageRecycle pdf & image compression

Plugin Slug:
imagerecycle-pdf-image-compression

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.17

Severity Score:
High

CVE:

2024-54266

The vulnerability has been patched, so you should update to version 3.1.17.

Memberful – Membership Plugin

Plugin:

Memberful – Membership Plugin

Plugin Slug:
memberful-wp

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.74.0

Severity Score:
Medium

CVE:

2024-11294

The vulnerability has been patched, so you should update to version 1.74.0.

Posti Shipping

Plugin:

Posti Shipping

Plugin Slug:
posti-shipping

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.10.4

Severity Score:
Medium

CVE:

2024-56005

The vulnerability has been patched, so you should update to version 3.10.4.

Simple Restrict

Plugin:

Simple Restrict

Plugin Slug:
simple-restrict

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.8

Severity Score:
Medium

CVE:

2024-11106

The vulnerability has been patched, so you should update to version 1.2.8.

RapidLoad – Optimize Web Vitals Automatically

Plugin:

RapidLoad – Optimize Web Vitals Automatically

Plugin Slug:
unusedcss

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.3

Severity Score:
High

CVE:

2024-11840

The vulnerability has been patched, so you should update to version 2.4.3.

NiceJob

Plugin:

NiceJob

Plugin Slug:
nicejob

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.2

Severity Score:
Medium

CVE:

2024-54318

The vulnerability has been patched, so you should update to version 3.7.2.

Property Hive Mortgage Calculator

Plugin:

Property Hive Mortgage Calculator

Plugin Slug:
property-hive-mortgage-calculator

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-11940

The vulnerability has been patched, so you should update to version 1.0.7.

Property Hive Stamp Duty Calculator

Plugin:

Property Hive Stamp Duty Calculator

Plugin Slug:
property-hive-stamp-duty-calculator

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.23

Severity Score:
Medium

CVE:

2024-12465

The vulnerability has been patched, so you should update to version 1.0.23.

WPC Order Notes for WooCommerce

Plugin:

WPC Order Notes for WooCommerce

Plugin Slug:
woo-order-notes

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.3

Severity Score:
High

CVE:

2024-12004

The vulnerability has been patched, so you should update to version 1.5.3.

Quran multilanguage Text & Audio

Plugin:

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High

CVE:

2024-11973

The vulnerability has been patched, so you should update to version 2.3.22.

Waymark

Plugin:

Waymark

Plugin Slug:
waymark

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High

CVE:

2024-12325

The vulnerability has been patched, so you should update to version 1.4.2.

WP Pipes

Plugin:

WP Pipes

Plugin Slug:
wp-pipes

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High

CVE:

2024-12283

The vulnerability has been patched, so you should update to version 1.4.2.

AR for WordPress

Plugin:

AR for WordPress

Plugin Slug:
ar-for-wordpress

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
7.4

Severity Score:
Low

CVE:

2024-12300

The vulnerability has been patched, so you should update to version 7.4.

Car Dealer (Dealership) and Vehicle sales

Plugin:

Car Dealer (Dealership) and Vehicle sales

Plugin Slug:
cardealer

Installations
600+

Vulnerability:
Broken Access Control

Patched in Version:
4.48

Severity Score:
Medium

CVE:

2024-54298

The vulnerability has been patched, so you should update to version 4.48.

Device Detector

Plugin:

Device Detector

Plugin Slug:
device-detector

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.1

Severity Score:
High

CVE:

2024-56010

The vulnerability has been patched, so you should update to version 4.2.1.

Last Viewed Posts by WPBeginner

Plugin:

Last Viewed Posts by WPBeginner

Plugin Slug:
last-viewed-posts

Installations
600+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.2

Severity Score:
Medium

CVE:

2024-12294

The vulnerability has been patched, so you should update to version 1.0.2.

Out of the Block: OpenStreetMap

Plugin:

Out of the Block: OpenStreetMap

Plugin Slug:
ootb-openstreetmap

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4

Severity Score:
Medium

CVE:

2024-11827

The vulnerability has been patched, so you should update to version 2.8.4.

AIcomments – ??????????? ? ?????? ChatGPT

Plugin:

AIcomments – ??????????? ? ?????? ChatGPT

Plugin Slug:
aicomments

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.2

Severity Score:
Medium

CVE:

2024-54307

The vulnerability has been patched, so you should update to version 1.4.2.

CM Answers – Powerful WordPress Forum Plugin

Plugin:

CM Answers – Powerful WordPress Forum Plugin

Plugin Slug:
cm-answers

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
3.2.7

Severity Score:
Medium

CVE:

2024-54267

The vulnerability has been patched, so you should update to version 3.2.7.

Cryptocurrency Price Widget

Plugin:

Cryptocurrency Price Widget

Plugin Slug:
cryptocurrency-price-widget

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
Medium

CVE:

2024-54308

The vulnerability has been patched, so you should update to version 1.2.4.

iChart – Easy Charts and Graphs

Plugin:

iChart – Easy Charts and Graphs

Plugin Slug:
ichart

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium

CVE:

2024-11928

The vulnerability has been patched, so you should update to version 2.1.4.

Mark New Posts

Plugin:

Mark New Posts

Plugin Slug:
mark-new-posts

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
7.6

Severity Score:
Medium

CVE:

2024-54311

The vulnerability has been patched, so you should update to version 7.6.

WP Email Log – PostBox

Plugin:

WP Email Log – PostBox

Plugin Slug:
postbox-email-logs

Installations
500+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.0.5

Severity Score:
Medium

CVE:

2024-54309

The vulnerability has been patched, so you should update to version 1.0.5.

Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate

Plugin:

Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate

Plugin Slug:
spreadr-for-woocomerce

Installations
500+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
1.0.5

Severity Score:
High

CVE:

2024-56008

The vulnerability has been patched, so you should update to version 1.0.5.

Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate

Plugin:

Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate

Plugin Slug:
spreadr-for-woocomerce

Installations
500+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.5

Severity Score:
Medium

CVE:

2024-56009

The vulnerability has been patched, so you should update to version 1.0.5.

Themify Store Locator

Plugin:

Themify Store Locator

Plugin Slug:
themify-store-locator

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2.0

Severity Score:
Medium

CVE:

2024-12414

The vulnerability has been patched, so you should update to version 1.2.0.

WooCommerce Additional Fees On Checkout (Free)

Plugin:

WooCommerce Additional Fees On Checkout (Free)

Plugin Slug:
woo-additional-fees-on-checkout-wordpress

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.8

Severity Score:
High

CVE:

2024-12395

The vulnerability has been patched, so you should update to version 1.4.8.

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin:

Gutenberg Blocks and Page Layouts – Attire Blocks

Plugin Slug:
attire-blocks

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.6

Severity Score:
Medium

CVE:

2024-11914

The vulnerability has been patched, so you should update to version 1.9.6.

Projectopia – WordPress Project Management

Plugin:

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core

Installations
400+

Vulnerability:
Broken Authentication

Patched in Version:
5.1.8

Severity Score:
High

CVE:

2024-54336

The vulnerability has been patched, so you should update to version 5.1.8.

Payment Gateway Per Product for WooCommerce

Plugin:

Payment Gateway Per Product for WooCommerce

Plugin Slug:
woocommerce-product-payments

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
3.5.9

Severity Score:
Medium

CVE:

2024-55996

The vulnerability has been patched, so you should update to version 3.5.9.

Check Pincode For Woocommerce

Plugin:

Check Pincode For Woocommerce

Plugin Slug:
check-pincode-for-woocommerce

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2

Severity Score:
High

CVE:

2024-54333

The vulnerability has been patched, so you should update to version 1.2.

Currency Converter Widget ? PRO

Plugin:

Currency Converter Widget ? PRO

Plugin Slug:
currency-converter-widget-pro

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-11760

The vulnerability has been patched, so you should update to version 1.0.7.

NewsmanApp

Plugin:

NewsmanApp

Plugin Slug:
newsmanapp

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.7

Severity Score:
Medium

CVE:

2024-11767

The vulnerability has been patched, so you should update to version 2.7.7.

Print Science Designer

Plugin:

Print Science Designer

Plugin Slug:
print-science-designer

Installations
300+

Vulnerability:
PHP Object Injection

Patched in Version:
1.3.153

Severity Score:
Critical

CVE:

2024-12312

The vulnerability has been patched, so you should update to version 1.3.153.

Stop Registration Spam

Plugin:

Stop Registration Spam

Plugin Slug:
stop-registration-spam

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.24

Severity Score:
High

CVE:

2024-56017

The vulnerability has been patched, so you should update to version 1.24.

WP BASE Booking of Appointments, Services and Events

Plugin:

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.9.2

Severity Score:
High

CVE:

2024-12469

The vulnerability has been patched, so you should update to version 4.9.2.

WP Mailster

Plugin:

WP Mailster

Plugin Slug:
wp-mailster

Installations
300+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.18.0

Severity Score:
Medium

CVE:

2024-54355

The vulnerability has been patched, so you should update to version 1.8.18.0.

AutoWP – AI Content Writer & Rewriter

Plugin:

AutoWP – AI Content Writer & Rewriter

Plugin Slug:
autowp-ai-content-writer-rewriter

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.0.9

Severity Score:
Medium

CVE:

2024-54300

The vulnerability has been patched, so you should update to version 2.0.9.

Booking System Trafft

Plugin:

Booking System Trafft

Plugin Slug:
booking-system-trafft

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-11754

The vulnerability has been patched, so you should update to version 1.0.7.

dejure.org Vernetzungsfunktion

Plugin:

dejure.org Vernetzungsfunktion

Plugin Slug:
dejureorg-vernetzungsfunktion

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.98.0

Severity Score:
High

CVE:

2024-11417

The vulnerability has been patched, so you should update to version 1.98.0.

Email Reminders

Plugin:

Email Reminders

Plugin Slug:
email-reminders

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium

CVE:

2024-11945

The vulnerability has been patched, so you should update to version 2.0.5.

J&T Express Malaysia

Plugin:

J&T Express Malaysia

Plugin Slug:
jt-express

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.15

Severity Score:
High

CVE:

2024-54305

The vulnerability has been patched, so you should update to version 2.0.15.

Revi.io – Customer & Products Reviews

Plugin:

Revi.io – Customer & Products Reviews

Plugin Slug:
revi-io-customer-and-product-reviews

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.8.0

Severity Score:
High

CVE:

2024-54299

The vulnerability has been patched, so you should update to version 5.8.0.

WordPress Post Grid Layouts with Pagination – Sogrid

Plugin:

WordPress Post Grid Layouts with Pagination – Sogrid

Plugin Slug:
sogrid

Installations
200+

Vulnerability:
Local File Inclusion

Patched in Version:
1.5.7

Severity Score:
High

CVE:

2024-54374

The vulnerability has been patched, so you should update to version 1.5.7.

WordPress Post Grid Layouts with Pagination – Sogrid

Plugin:

WordPress Post Grid Layouts with Pagination – Sogrid

Plugin Slug:
sogrid

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.5

Severity Score:
High

CVE:

2024-54352

The vulnerability has been patched, so you should update to version 1.5.5.

Staggs – Product Configurator Toolkit

Plugin:

Staggs – Product Configurator Toolkit

Plugin Slug:
staggs

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
High

CVE:

2024-54342

The vulnerability has been patched, so you should update to version 2.1.0.

Lifetime free Drag & Drop Contact Form Builder for WordPress VForm

Plugin:

Lifetime free Drag & Drop Contact Form Builder for WordPress VForm

Plugin Slug:
v-form

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.1

Severity Score:
High

CVE:

2024-54302

The vulnerability has been patched, so you should update to version 3.0.1.

Video & Photo Gallery for Ultimate Member

Plugin:

Video & Photo Gallery for Ultimate Member

Plugin Slug:
gallery-for-ultimate-member

Installations
100+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.1

Severity Score:
Critical

CVE:

2024-54370

The vulnerability has been patched, so you should update to version 1.1.1.

Gou Manage My Account Menu – User Roles

Plugin:

Gou Manage My Account Menu – User Roles

Plugin Slug:
gou-wc-account-tabs

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.1.9

Severity Score:
Medium

CVE:

2024-54310

The vulnerability has been patched, so you should update to version 1.0.1.9.

ICDSoft Reseller Store

Plugin:

ICDSoft Reseller Store

Plugin Slug:
icdsoft-reseller-store

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.0

Severity Score:
High

CVE:

2024-54320

The vulnerability has been patched, so you should update to version 2.5.0.

Ksher

Plugin:

Ksher

Plugin Slug:
ksher-payment

Installations
100+

Vulnerability:
Settings Change

Patched in Version:
1.1.2

Severity Score:
Medium

CVE:

2024-56001

The vulnerability has been patched, so you should update to version 1.1.2.

Media Downloader

Plugin:

Media Downloader

Plugin Slug:
media-downloader

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.4.7.5

Severity Score:
High

CVE:

2024-54322

The vulnerability has been patched, so you should update to version 0.4.7.5.

CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout

Plugin:

CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout

Plugin Slug:
support-x

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium

CVE:

2024-12443

The vulnerability has been patched, so you should update to version 1.1.7.

Invoice Payment for WooCommerce

Plugin:

Invoice Payment for WooCommerce

Plugin Slug:
invoice-payment-for-woocommerce

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.0

Severity Score:
High

CVE:

2024-54328

The vulnerability has been patched, so you should update to version 2.0.0.

Seraphinite Bulk Discounts for WooCommerce

Plugin:

Seraphinite Bulk Discounts for WooCommerce

Plugin Slug:
seraphinite-discount-for-woocommerce

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.7

Severity Score:
High

CVE:

2024-12160

The vulnerability has been patched, so you should update to version 2.4.7.

Hurrakify

Plugin:

Hurrakify

Plugin Slug:
hurrakify

Installations
80+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
8.0.1

Severity Score:
High

CVE:

2024-54330

The vulnerability has been patched, so you should update to version 8.0.1.

SMS for WooCommerce

Plugin:

SMS for WooCommerce

Plugin Slug:
wc-sms

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.1.1

Severity Score:
High

CVE:

2024-12220

The vulnerability has been patched, so you should update to version 2.8.1.1.

Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress

Plugin:

Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress

Plugin Slug:
hive-support

Installations
70+

Vulnerability:
SQL Injection

Patched in Version:
1.1.3

Severity Score:
High

CVE:

2024-54304

The vulnerability has been patched, so you should update to version 1.1.3.

Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress

Plugin:

Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress

Plugin Slug:
hive-support

Installations
70+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.3

Severity Score:
Medium

CVE:

2024-54321

The vulnerability has been patched, so you should update to version 1.1.3.

AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot

Plugin:

AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot

Plugin Slug:
ai-seo-translator

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.6.3

Severity Score:
Medium

CVE:

2024-54306

The vulnerability has been patched, so you should update to version 1.6.3.

LabelGrid Tools

Plugin:

LabelGrid Tools

Plugin Slug:
label-grid-tools

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.59

Severity Score:
High

CVE:

2024-54341

The vulnerability has been patched, so you should update to version 1.3.59.

Simple Payment

Plugin:

Simple Payment

Plugin Slug:
simple-payment

Installations
60+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
High

CVE:

2024-54303

The vulnerability has been patched, so you should update to version 2.3.8.

CarDealerPress

Plugin:

CarDealerPress

Plugin Slug:
cardealerpress

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.7.2411.00

Severity Score:
High

CVE:

2024-54325

The vulnerability has been patched, so you should update to version 6.7.2411.00.

CE21 Suite

Plugin:

CE21 Suite

Plugin Slug:
ce21-suite

Installations
30+

Vulnerability:
Privilege Escalation

Patched in Version:
2.2.1

Severity Score:
Critical

CVE:

2024-54293

The vulnerability has been patched, so you should update to version 2.2.1.

EduAdmin Booking

Plugin:

EduAdmin Booking

Plugin Slug:
eduadmin-booking

Installations
30+

Vulnerability:
Local File Inclusion

Patched in Version:
5.3.0

Severity Score:
High

CVE:

2024-54373

The vulnerability has been patched, so you should update to version 5.3.0.

Hack-Info

Plugin:

Hack-Info

Plugin Slug:
hack-info

Installations
30+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.18

Severity Score:
High

CVE:

2024-54353

The vulnerability has been patched, so you should update to version 3.18.

FloristPress – Customize your Woo store for your Florist

Plugin:

FloristPress – Customize your Woo store for your Florist

Plugin Slug:
bakkbone-florist-companion

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.3.0

Severity Score:
High

CVE:

2024-54347

The vulnerability has been patched, so you should update to version 7.3.0.

CleverNode Related Content

Plugin:

CleverNode Related Content

Plugin Slug:
clevernode-related-content

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.6

Severity Score:
High

CVE:

2024-54329

The vulnerability has been patched, so you should update to version 1.1.6.

Connect Contact Form 7 to Constant Contact V3

Plugin:

Connect Contact Form 7 to Constant Contact V3

Plugin Slug:
connect-contact-form-7-to-constant-contact-v3

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
High

CVE:

2024-54343

The vulnerability has been patched, so you should update to version 1.5.

Fancy Roller Scroller

Plugin:

Fancy Roller Scroller

Plugin Slug:
fancy-roller-scroller

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.1

Severity Score:
High

CVE:

2024-54351

The vulnerability has been patched, so you should update to version 1.4.1.

I Plant A Tree

Plugin:

I Plant A Tree

Plugin Slug:
i-plant-a-tree

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.7.4

Severity Score:
High

CVE:

2024-54331

The vulnerability has been patched, so you should update to version 1.7.4.

ImmoToolBox Connect

Plugin:

ImmoToolBox Connect

Plugin Slug:
immotoolbox-connect

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.0

Severity Score:
High

CVE:

2024-54335

The vulnerability has been patched, so you should update to version 1.4.0.

Newsletter, Email Marketing, Email Subscriber – Mail Picker

Plugin:

Newsletter, Email Marketing, Email Subscriber – Mail Picker

Plugin Slug:
mail-picker

Installations
10+

Vulnerability:
PHP Object Injection

Patched in Version:
1.0.15

Severity Score:
Critical

CVE:

2024-54273

The vulnerability has been patched, so you should update to version 1.0.15.

Simple Presenter

Plugin:

Simple Presenter

Plugin Slug:
simple-presenter

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.2

Severity Score:
High

CVE:

2024-54340

The vulnerability has been patched, so you should update to version 1.5.2.

SMSify

Plugin:

SMSify

Plugin Slug:
smsify

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.1.0

Severity Score:
High

CVE:

2024-54324

The vulnerability has been patched, so you should update to version 6.1.0.

UNIVERSAM

Plugin:

UNIVERSAM

Plugin Slug:
universam-demo

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.59

Severity Score:
High

CVE:

2024-54327

The vulnerability has been patched, so you should update to version 8.59.

WP Currency Exchange Rates

Plugin:

WP Currency Exchange Rates

Plugin Slug:
wp-currency-exchange-rates

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.0

Severity Score:
High

CVE:

2024-54332

The vulnerability has been patched, so you should update to version 1.3.0.

WP Quick Shop

Plugin:

WP Quick Shop

Plugin Slug:
wp-quick-shop

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
High

CVE:

2024-54344

The vulnerability has been patched, so you should update to version 1.3.2.

DX Dark Site

Plugin:

DX Dark Site

Plugin Slug:
devrix-dark-site

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.1.1

Severity Score:
High

CVE:

2024-54337

The vulnerability has been patched, so you should update to version 1.1.1.

FooGallery Premium

Plugin:

FooGallery Premium

Plugin Slug:
foogallery-premium

Vulnerability:
Directory Traversal

Patched in Version:
2.4.27

Severity Score:
High

CVE:

2023-6947

The vulnerability has been patched, so you should update to version 2.4.27.

GeoFlickr

Plugin:

GeoFlickr

Plugin Slug:
geoflickr

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4

Severity Score:
High

CVE:

2024-54339

The vulnerability has been patched, so you should update to version 1.4.

Hello Event Widgets For Elementor

Plugin:

Hello Event Widgets For Elementor

Plugin Slug:
hello-event-widgets-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium

CVE:

2024-54338

The vulnerability has been patched, so you should update to version 1.1.0.

WP SuperBackup

Plugin:

WP SuperBackup

Plugin Slug:
indeed-wp-superbackup

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4

Severity Score:
Critical

CVE:

2024-9290

The vulnerability has been patched, so you should update to version 2.4.

Kundgenerator

Plugin:

Kundgenerator

Plugin Slug:
kundgenerator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
High

CVE:

2024-54319

The vulnerability has been patched, so you should update to version 1.0.7.

Quran Phrases About Most People Shortcodes

Plugin:

Quran Phrases About Most People Shortcodes

Plugin Slug:
quran-phrases-about-most-people-shortcodes

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
Medium

CVE:

2024-54334

The vulnerability has been patched, so you should update to version 1.5.

Responsive Google Maps | by imbaa

Plugin:

Responsive Google Maps | by imbaa

Plugin Slug:
responsive-google-maps

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.7

Severity Score:
Medium

CVE:

2024-56011

The vulnerability has been patched, so you should update to version 1.2.7.

Termin-Kalender

Plugin:

Termin-Kalender

Plugin Slug:
termin-kalender

Vulnerability:
Broken Access Control

Patched in Version:
1.00.04

Severity Score:
Medium

CVE:

2024-54354

The vulnerability has been patched, so you should update to version 1.00.04.

WooCommerce PDF Vouchers

Plugin:

WooCommerce PDF Vouchers

Plugin Slug:
woocommerce-pdf-vouchers

Vulnerability:
Privilege Escalation

Patched in Version:
4.9.9

Severity Score:
Critical

CVE:

2024-54383

The vulnerability has been patched, so you should update to version 4.9.9.

WP All Import Pro

Plugin:

WP All Import Pro

Plugin Slug:
wp-all-import-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
4.9.4

Severity Score:
Medium

CVE:

2024-9624

The vulnerability has been patched, so you should update to version 4.9.4.

WordPress Themes — 8 Patched / 2 Unpatched

Olivia

Theme:

Olivia

Theme Slug:
olivia

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-56014

The vulnerability has not been patched. You should switch themes.

Zerif Lite

Theme:

Zerif Lite

Theme Slug:
zerif-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

The vulnerability has not been patched. You should switch themes.

Barter

Theme:

Barter

Theme Slug:
barter

Downloads
7,610

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7

Severity Score:
Medium

CVE:

2024-54346

The vulnerability has been patched, so you should update to version 1.7.

Bicycleshop

Theme:

Bicycleshop

Theme Slug:
bicycleshop

Downloads
9,127

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium

CVE:

2024-54345

The vulnerability has been patched, so you should update to version 1.6.

Brand

Theme:

Brand

Theme Slug:
brand

Downloads
32,921

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium

CVE:

2024-54348

The vulnerability has been patched, so you should update to version 1.1.7.

hmd

Theme:

hmd

Theme Slug:
hmd

Downloads
892

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
High

CVE:

2024-54350

The vulnerability has been patched, so you should update to version 2.2.

Plain Post

Theme:

Plain Post

Theme Slug:
plain-post

Downloads
1,459

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.4

Severity Score:
Medium

CVE:

2024-54349

The vulnerability has been patched, so you should update to version 1.0.4.

Avada

Theme:

Avada

Theme Slug:
avada

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
7.11.11

Severity Score:
Medium

CVE:

2024-54357

The vulnerability has been patched, so you should update to version 7.11.11.

Woffice

Theme:

Woffice

Theme Slug:
woffice

Vulnerability:
Broken Authentication

Patched in Version:
5.4.15

Severity Score:
Critical

CVE:

2024-43234

The vulnerability has been patched, so you should update to version 5.4.15.

WoodMart

Theme:

WoodMart

Theme Slug:
woodmart

Vulnerability:
Arbitrary Code Execution

Patched in Version:
8.0.4

Severity Score:
Medium

CVE:

2024-12333

The vulnerability has been patched, so you should update to version 8.0.4.

window[“91949fd6_d510_43bc_8fec_16f2a437a0ed”] = {“blockId”:”91949fd6-d510-43bc-8fec-16f2a437a0ed”,”className”:””,”heading”:”Solid Security is part of Solid Suite \u2014 The best foundation for WordPress websites.”,”text”:”Every WordPress site needs security, backups, and management tools. That\u2019s Solid Suite \u2014 an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy\u2019s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!”,”buttonText”:”Get Solid Security”,”buttonLink”:”\/pricing”,”buttonTarget”:”_self”,”buttonRel”:””};

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — December 18, 2024 appeared first on SolidWP.

Source link

Written by:
Abdul Wahid
Published on:
December 24, 2024

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter