• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report — February 28, 2024

WordPress Vulnerability Report — February 28, 2024

In this report, 73 vulnerabilities have been publicly disclosed. Security patches for 48 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 25 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the reasons why WordPress websites get hacked. (See our Annual Vulnerability Report for 2022.) Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Table of Contents

  1. 1. WordPress Core
  2. 2. WordPress Plugins — 46 Patched / 25 Unpatched
    1. 2.1
      Addon Library
    2. 2.2
      Admin side data storage for Contact Form 7
    3. 2.3
      Admin side data storage for Contact Form 7
    4. 2.4
      Admin side data storage for Contact Form 7
    5. 2.5
      Admin side data storage for Contact Form 7
    6. 2.6
      Adsmonetizer
    7. 2.7
      BeePress
    8. 2.8
      Configure SMTP
    9. 2.9
      Download Media
    10. 2.10
      Duitku Payment Gateway
    11. 2.11
      Fontific | Google Fonts
    12. 2.12
      Gestpay for WooCommerce
    13. 2.13
      Marketo Forms and Tracking
    14. 2.14
      Media Alt Renamer
    15. 2.15
      WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit
    16. 2.16
      PayU India
    17. 2.17
      Play.ht
    18. 2.18
      postMash – custom post order
    19. 2.19
      Rolo Slider
    20. 2.20
      Slivery Extender
    21. 2.21
      SoundCloud Shortcode
    22. 2.22
      Tabs Shortcode and Widget
    23. 2.23
      Tainacan
    24. 2.24
      User Shortcodes Plus
    25. 2.25
      Watermark RELOADED
    26. 2.26
      LiteSpeed Cache
    27. 2.27
      LiteSpeed Cache
    28. 2.28
      Premium Addons for Elementor
    29. 2.29
      BackWPup – WordPress Backup Plugin
    30. 2.30
      Page Builder: Pagelayer – Drag and Drop website builder
    31. 2.31
      Page Builder: Pagelayer – Drag and Drop website builder
    32. 2.32
      Orbit Fox by ThemeIsle
    33. 2.33
      Orbit Fox by ThemeIsle
    34. 2.34
      Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
    35. 2.35
      User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
    36. 2.36
      Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
    37. 2.37
      Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
    38. 2.38
      Elementor Addon Elements
    39. 2.39
      Elementor Addon Elements
    40. 2.40
      Elementor Addon Elements
    41. 2.41
      Colibri Page Builder
    42. 2.42
      Colibri Page Builder
    43. 2.43
      Brizy – Page Builder
    44. 2.44
      Brizy – Page Builder
    45. 2.45
      Brizy – Page Builder
    46. 2.46
      Brizy – Page Builder
    47. 2.47
      Event Tickets and Registration
    48. 2.48
      Sydney Toolbox
    49. 2.49
      Enhanced Text Widget
    50. 2.50
      NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor
    51. 2.51
      WP Dashboard Notes
    52. 2.52
      Restrict User Access – Ultimate Membership & Content Protection
    53. 2.53
      WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
    54. 2.54
      YML for Yandex Market
    55. 2.55
      Smart Forms – when you need more than just a contact form
    56. 2.56
      Maintenance Page
    57. 2.57
      Maintenance Page
    58. 2.58
      SMS Alert Order Notifications – WooCommerce
    59. 2.59
      Thank You Page Customizer for WooCommerce – Increase Your Sales
    60. 2.60
      Thank You Page Customizer for WooCommerce – Increase Your Sales
    61. 2.61
      Spiffy Calendar
    62. 2.62
      Academy LMS – eLearning and online course solution for WordPress
    63. 2.63
      Archivist – Custom Archive Templates
    64. 2.64
      Comments Extra Fields For Post,Pages and CPT
    65. 2.65
      Comments Extra Fields For Post,Pages and CPT
    66. 2.66
      KODO Qiniu
    67. 2.67
      Backup
    68. 2.68
      Elementor Pro
    69. 2.69
      JobSearch
    70. 2.70
      JobSearch
    71. 2.71
      WP Social Widget
  3. 3. WordPress Themes — 2 Patched /0 Unpatched
    1. 3.1
      Colibri WP
    2. 3.2
      Socialdriver

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.4.3 was released on January 30, 2024, as a short-cycle maintenance and security release with five bug fixes in Core and 16 bug fixes for the Block Editor. It is recommended that you update your sites immediately.

The next major release will be version 6.5, planned for March 26, 2024.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 25 Unpatched

Plugin:

Addon Library

Plugin Slug:
addon-library

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Admin side data storage for Contact Form 7

Plugin Slug:
admin-side-data-storage-for-contact-form-7

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Adsmonetizer

Plugin Slug:
adsensei-b30

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

BeePress

Plugin Slug:
beepress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Configure SMTP

Plugin Slug:
configure-smtp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Download Media

Plugin Slug:
download-media

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Duitku Payment Gateway

Plugin Slug:
duitku-social-payment-gateway

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Fontific | Google Fonts

Plugin Slug:
fontific

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Marketo Forms and Tracking

Plugin Slug:
marketo-forms-and-tracking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Media Alt Renamer

Plugin Slug:
media-alt-renamer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit

Plugin Slug:
myshopkit-popup-smartbar-slidein

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

PayU India

Plugin Slug:
payu-india

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Play.ht

Plugin Slug:
play-ht

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

Plugin:

postMash – custom post order

Plugin Slug:
postmash

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Rolo Slider

Plugin Slug:
rolo-slider

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
High

Plugin:

Slivery Extender

Plugin Slug:
slivery-extender

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
High

Plugin:

SoundCloud Shortcode

Plugin Slug:
soundcloud-shortcode

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tabs Shortcode and Widget

Plugin Slug:
tabs-shortcode-and-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

User Shortcodes Plus

Plugin Slug:
user-shortcodes-plus

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

Plugin:

Watermark RELOADED

Plugin Slug:
watermark-reloaded

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
litespeed-cache

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.7.0.1

Severity Score:
High

Plugin Slug:
premium-addons-for-elementor

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.19

Severity Score:
Medium

Plugin Slug:
backwpup

Installations
600,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.0.3

Severity Score:
Low

Plugin Slug:
pagelayer

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.1

Severity Score:
Medium

Plugin Slug:
pagelayer

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.3

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.32

Severity Score:
Medium

Plugin Slug:
themeisle-companion

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.10.31

Severity Score:
Medium

Plugin Slug:
ultimate-member

Installations
200,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.3

Severity Score:
Critical

Plugin Slug:
userfeedback-lite

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.14

Severity Score:
High

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.1

Severity Score:
Medium

Plugin Slug:
wp-user-avatar

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.15.1

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.13

Severity Score:
Medium

Plugin Slug:
addon-elements-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.13

Severity Score:
High

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.260

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Directory Traversal

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.41

Severity Score:
Critical

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.41

Severity Score:
Medium

Plugin Slug:
event-tickets

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.8.2

Severity Score:
Medium

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26

Severity Score:
Medium

Plugin Slug:
enhanced-text-widget

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium

Plugin Slug:
notificationx

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
2.8.3

Severity Score:
Critical

Plugin Slug:
wp-dashboard-notes

Installations
30,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.0.11

Severity Score:
Medium

Plugin Slug:
restrict-user-access

Installations
20,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.6

Severity Score:
Medium

Plugin Slug:
wp-event-manager

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.42

Severity Score:
High

Plugin Slug:
yml-for-yandex-market

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.2.4

Severity Score:
High

Plugin Slug:
smart-forms

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.87

Severity Score:
Medium

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.9

Severity Score:
Medium

Plugin Slug:
maintenance-page

Installations
5,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.0.9

Severity Score:
Medium

Plugin Slug:
sms-alert

Installations
5,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.7.0

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
woo-thank-you-page-customizer

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.1.3

Severity Score:
Medium

Plugin Slug:
spiffy-calendar

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.9.9

Severity Score:
Medium

Plugin Slug:
academy

Installations
1,000+

Vulnerability:
Privilege Escalation

Patched in Version:
1.9.20

Severity Score:
High

Plugin Slug:
archivist-custom-archive-templates

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.7.6

Severity Score:
High

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.1

Severity Score:
Medium

Plugin Slug:
wp-comment-fields

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1

Severity Score:
Medium

Plugin Slug:
kodo-qiniu

Installations
400+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium

Plugin:

Backup

Plugin Slug:
backup2

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.9.9

Severity Score:
High

Plugin:

Elementor Pro

Plugin Slug:
elementor-pro

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.19.3

Severity Score:
Medium

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

JobSearch

Plugin Slug:
wp-jobsearch

Vulnerability:
Broken Authentication

Patched in Version:
2.3.4

Severity Score:
Critical

Plugin:

WP Social Widget

Plugin Slug:
wp-social-widget

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.6

Severity Score:
Medium

WordPress Themes — 2 Patched /0 Unpatched

Theme Slug:
colibri-wp

Downloads
1,232,050

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.101

Severity Score:
Medium

Theme:

Socialdriver

Theme Slug:
socialdriver

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024

Severity Score:
High

Source link

Written by:
Abdul Wahid
Published on:
March 4, 2024

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (6)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

WordPress: A Powerhouse for Achieving Internet …

Continue Reading about Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter