Vulnerable plugins and themes are the #1 reason WordPress websites get hacked. The weekly WordPress Vulnerability Report powered by WPScan covers recent WordPress plugin, theme, and core vulnerabilities and what to do if you run one of the vulnerable plugins or themes on your website.
Each vulnerability will have a severity rating of low, medium, high, or critical. Responsible disclosure and reporting of vulnerabilities is an integral part of keeping the WordPress community safe. Please share this post with your friends to help get the word out and make WordPress safer for everyone!

The Future of Authentication is Passkeys! Login to your WordPress site with Biometrics only available in iThemes Security Pro
The problems of brute force attacks through credential stuffing, phishing attacks, and reused passwords have made our digital lives less secure. We’ve all tried to encourage 2-factor authentication as a protection, but less than 30% of users actually use 2FA. Password-based logins are a problem.
The future of authentication is passkeys, and iThemes Security Pro is the first to bring this breakthrough technology to WordPress sites. Using breakthrough WebAuthn technology based on public/private cryptography, passkeys make passwords obsolete. Now, website admins and end users can have secure logins without the inconvenience of additional two-factor apps, password managers, or complex password requirements.
WordPress Core News
WordPress 6.1.1 was released on November 15, 2022, as a short-cycle maintenance release with 29 bug fixes in Core and 21 bug fixes for the block editor. Because this is a core update, be sure to update to WordPress 6.1.1 as soon as possible! As always, with a major release like this, it makes sense to ensure your site is backed up with BackupBuddy before updating.
Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
WordPress Plugin Vulnerabilities
In this section, the latest WordPress plugin vulnerabilities have been disclosed. Each plugin listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
MonsterInsights
- Plugin Slug
- google-analytics-for-wordpress
- Installations
- 3,000,000+
- Vulnerability
- Stored Cross-Site Scripting via Google Analytics
- Patched in Version
- 8.9.1
- Severity Score
- Medium
Click to Chat
- Plugin Slug
- click-to-chat-for-whatsapp
- Installations
- 400,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.18.1
- Severity Score
- High
Font Awesome
- Plugin Slug
- font-awesome
- Installations
- 300,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 4.3.2
- Severity Score
- High
ProfilePress
- Plugin Slug
- wp-user-avatar
- Installations
- 300,000+
- Vulnerability
- Admin+ Stored Cross-Site Scripting via Form Settings; Admin+ Stored Cross-Site Scripting
- Patched in Version
- 4.5.1
- Severity Score
- Low
Table of Contents Plus
- Plugin Slug
- table-of-contents-plus
- Installations
- 300,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2212
- Severity Score
- High
Anti-Malware Security and Brute-Force Firewall
- Plugin Slug
- gotmls
- Installations
- 200,000+
- Vulnerability
- Admin+ PHP Object Injection
- Patched in Version
- 4.21.86
- Severity Score
- Low
Page Scroll To ID
- Plugin Slug
- page-scroll-to-id
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.7.6
- Severity Score
- High
Real Cookie Banner
- Plugin Slug
- real-cookie-banner
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.4.10
- Severity Score
- High
Mesmerize Companion
- Plugin Slug
- mesmerize-companion
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.6.135
- Severity Score
- High
Slimstat Analytics
- Plugin Slug
- wp-slimstat
- Installations
- 100,000+
- Vulnerability
- Unauthenticated Stored XSS
- Patched in Version
- 4.9.3
- Severity Score
- High
Smash Balloon Social Post Feed
- Plugin Slug
- custom-facebook-feed
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 4.1.6
- Severity Score
- High
WPtouch
- Plugin Slug
- wptouch
- Installations
- 100,000+
- Vulnerability
- Admin+ PHP Object Injection; Admin+ Arbitrary File Upload
- Patched in Version
- 4.3.45
- Severity Score
- Medium
Download Manager
- Plugin Slug
- download-manager
- Installations
- 100,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.2.62
- Severity Score
- High
WOOCS
- Plugin Slug
- woocommerce-currency-switcher
- Installations
- 70,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.3.9.4
- Severity Score
- High
3D FlipBook
- Plugin Slug
- interactive-3d-flipbook-powered-physics-engine
- Installations
- 70,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.13.3
- Severity Score
- High
Carousel, Slider, Gallery by WP Carousel
- Plugin Slug
- wp-carousel-free
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.5.3
- Severity Score
- High
WP Video Lightbox
- Plugin Slug
- wp-video-lightbox
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.9.7
- Severity Score
- High
Simple Membership
- Plugin Slug
- simple-membership
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 4.2.2
- Severity Score
- High
WP Recipe Maker
- Plugin Slug
- wp-recipe-maker
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 8.6.1
- Severity Score
- High
Themify Portfolio Post
- Plugin Slug
- themify-portfolio-post
- Installations
- 50,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 1.2.1
- Severity Score
- High
Metricool
- Plugin Slug
- metricool
- Installations
- 40,000+
- Vulnerability
- Admin+ Stored XSS
- Patched in Version
- 1.18
- Severity Score
- Low
ConvertKit
- Plugin Slug
- convertkit
- Installations
- 40,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.0.5
- Severity Score
- High
Super Socializer
- Plugin Slug
- super-socializer
- Installations
- 40,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 7.13.44
- Severity Score
- High
Real Testimonials
- Plugin Slug
- testimonial-free
- Installations
- 40,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.6.0
- Severity Score
- High
Easy Accordion
- Plugin Slug
- easy-accordion-free
- Installations
- 40,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.2.0
- Severity Score
- High
MashShare
- Plugin Slug
- mashsharer
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 3.8.7
- Severity Score
- High
Seriously Simple Podcasting
- Plugin Slug
- seriously-simple-podcasting
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 2.19.1
- Severity Score
- High
Jetpack CRM
- Plugin Slug
- zero-bs-crm
- Installations
- 30,000+
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- 5.5
- Severity Score
- High
Subscribe2
- Plugin Slug
- subscribe2
- Installations
- 30,000+
- Vulnerability
- User Deletion via CSRF
- Patched in Version
- 10.38
- Severity Score
- High
WCK
- Plugin Slug
- wck-custom-fields-and-custom-post-types-creator
- Installations
- 20,000+
- Vulnerability
- Admin+ Stored XSS
- Patched in Version
- 2.3.3
- Severity Score
- Low
Welcart e-Commerce
- Plugin Slug
- usc-e-shop
- Installations
- 20,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 2.8.9
- Severity Score
- High
Link Library
- Plugin Slug
- link-library
- Installations
- 10,000+
- Vulnerability
- Admin+ Stored XSS
- Patched in Version
- 7.4.1
- Severity Score
- Low
Greenshift – animation and page builder blocks
- Plugin Slug
- greenshift-animation-and-page-builder-blocks
- Installations
- 10,000+
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- 4.8.9
- Severity Score
- High
Tickera
- Plugin Slug
- tickera-event-ticketing-system
- Installations
- 5,000+
- Vulnerability
- Plugin Data Deletion via CSRF
- Patched in Version
- 3.5.1.0
- Severity Score
- Low
WP Spell Check
- Plugin Slug
- wp-spell-check
- Installations
- 3,000+
- Vulnerability
- Ignored Word Deletion via CSRF; Admin+ Stored Cross-Site Scripting
- Patched in Version
- 9.13
- Severity Score
- Medium
Show All Comments
- Plugin Slug
- show-all-comments-in-one-page
- Installations
- 900+
- Vulnerability
- Reflected XSS
- Patched in Version
- 7.0.1
- Severity Score
- High
WordPress Events Calendar Plugin
- Plugin Slug
- connect-daily-web-calendar
- Installations
- 200+
- Vulnerability
- Multiple Reflected XSS
- Patched in Version
- 1.4.5
- Severity Score
- High
Mautic Integration For WooCommerce
- Plugin
- Mautic Integration for WooCommerce
- Plugin Slug
- mautic-integration-for-woocommerce
- Vulnerability
- Arbitrary Options Update via CSRF
- Patched in Version
- 1.0.3
- Severity Score
- High
WordPress Plugin Vulnerabilities – No Known Fix
This section contains plugin vulnerabilities with no known fix. Until a patch is available, immediately uninstall and delete the plugin.
Conditional Payment Methods for WooCommerce
- Plugin Slug
- conditional-payment-methods-for-woocommerce
- Vulnerability
- Admin+ SQLi
- Patched in Version
- No Fix
- Severity Score
- Medium
WP Attachments
- Plugin Slug
- wp-attachments
- Vulnerability
- Admin+ Stored XSS
- Patched in Version
- No Fix
- Severity Score
- Low
Easy Bootstrap Shortcode
- Plugin Slug
- easy-bootstrap-shortcodes
- Vulnerability
- Contributor+ Stored XSS
- Patched in Version
- No Fix
- Severity Score
- High
Images Optimize and Upload CF7
- Plugin Slug
- images-optimize-and-upload-cf7
- Vulnerability
- Unauthenticated Arbitrary File Deletion
- Patched in Version
- No Fix
- Severity Score
- Critical
Fontsy
- Plugin Slug
- fontsy
- Vulnerability
- Multiple Unauthenticated SQLi
- Patched in Version
- No Fix
- Severity Score
- High
User Post Gallery
- Plugin Slug
- wp-upg
- Vulnerability
- Unauthenticated RCE
- Patched in Version
- No Fix
- Severity Score
- Critical
RSSImport
- Plugin Slug
- rss-import
- Vulnerability
- Contributor+ Stored XSS via Shortcode
- Patched in Version
- No Fix
- Severity Score
- High
Sidebar Widgets by CodeLights
- Plugin Slug
- codelights-shortcodes-and-widgets
- Vulnerability
- Contributor+ Stored XSS; Admin+ Stored Cross Site Scripting
- Patched in Version
- No Fix
- Severity Score
- High
WordPress Theme Vulnerabilities
In this section, the latest WordPress theme vulnerabilities have been disclosed. Each theme listing includes the type of vulnerability, the active installations, the version number if patched, the severity rating, and the CVE.
Never worry about running a vulnerable plugin or theme again.
As you can see from this report, lots of new WordPress plugin and theme vulnerabilities are disclosed each week. We know it can be difficult to stay on top of every reported vulnerability disclosure, so the iThemes Security Pro plugin makes it easy to make sure your site isn’t running a theme, plugin, or WordPress core version with a known vulnerability.
Scans Your Website Twice a Day for Vulnerabilities
Your website’s plugins, themes, and WordPress core versions are checked against the WPScan Vulnerability Database for the latest vulnerability disclosures.
Automatically Updates if a Security Fix is Available
Paired with Version Management, iThemes Security will automatically update a plugin, theme, or WordPress core version if it has a vulnerability.
Emails You if Site Scan Detects a Vulnerability
You can receive an email report if your site is running vulnerable versions of a plugin, theme, or WordPress core. Customize the email addresses that receive scan results.
The Best WordPress Security Plugin to Secure & Protect WordPress Sites
WordPress currently powers over 40% of all websites, so it has become an easy target for hackers with malicious intent. The iThemes Security Pro plugin takes the guesswork out of WordPress security to make it easy to secure & protect your WordPress website. It’s like having a full-time security expert on staff who constantly monitors and protects your WordPress site for you.
