• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report — July 24, 2024

WordPress Vulnerability Report — July 24, 2024

In this report, 93 vulnerabilities have been publicly disclosed. Security patches for 72 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 21 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

window[“39c0d6cb_962d_43be_9ee9_c39c33aaaeaf”] = {“blockId”:”39c0d6cb-962d-43be-9ee9-c39c33aaaeaf”,”type”:”warning”,”content”:”

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.”,”className”:””};

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

window[“9ae25210_70b9_4c53_b44d_05f51f78aba0”] = {“blockId”:”9ae25210-70b9-4c53-b44d-05f51f78aba0″,”className”:””,”isOpen”:true};

Table of Contents

  1. 1. WordPress Core
  2. 2. WordPress Plugins — 72 Patched / 15 Unpatched
    1. 2.1
      Timetable and Event Schedule by MotoPress
    2. 2.2
      Smartsupp – live chat, chatbots, AI and lead generation
    3. 2.3
      Pretty Simple Popup Builder
    4. 2.4
      Booking Ultra Pro
    5. 2.5
      Easy Testimonials
    6. 2.6
      Keydatas
    7. 2.7
      Light Poll
    8. 2.8
      ListingPro
    9. 2.9
      ListingPro
    10. 2.10
      ListingPro
    11. 2.11
      ListingPro
    12. 2.12
      RegLevel
    13. 2.13
      SVG Support
    14. 2.14
      Telegram Bot & Channel
    15. 2.15
      Timeline Event History
    16. 2.16
      WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
    17. 2.17
      ElementsKit Elementor addons
    18. 2.18
      Redux Framework
    19. 2.19
      Security Optimizer – The All-In-One Protection Plugin
    20. 2.20
      WPS Hide Login
    21. 2.21
      Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
    22. 2.22
      Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)
    23. 2.23
      Conditional Fields for Contact Form 7
    24. 2.24
      GiveWP – Donation Plugin and Fundraising Platform
    25. 2.25
      Schema & Structured Data for WP & AMP
    26. 2.26
      CTX Feed – WooCommerce Product Feed Manager Plugin
    27. 2.27
      Mercado Pago payments for WooCommerce
    28. 2.28
      HUSKY – Products Filter Professional for WooCommerce
    29. 2.29
      Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce
    30. 2.30
      Brizy – Page Builder
    31. 2.31
      Brizy – Page Builder
    32. 2.32
      AI Engine
    33. 2.33
      Premium Portfolio Features for Phlox theme
    34. 2.34
      Getwid – Gutenberg Blocks
    35. 2.35
      Image Hover Effects – Elementor Addon
    36. 2.36
      RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging
    37. 2.37
      Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
    38. 2.38
      FV Flowplayer Video Player
    39. 2.39
      Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA
    40. 2.40
      WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
    41. 2.41
      WordPress File Upload
    42. 2.42
      Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress
    43. 2.43
      Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress
    44. 2.44
      BSK PDF Manager
    45. 2.45
      CM Popup Plugin for WordPress – Popup Maker
    46. 2.46
      Language Translate Widget for WP – ConveyThis
    47. 2.47
      JetWidgets for Elementor and WooCommerce
    48. 2.48
      Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
    49. 2.49
      MasterStudy LMS WordPress Plugin – for Online Courses and Education
    50. 2.50
      UiPress lite | Effortless custom dashboards, admin themes and pages
    51. 2.51
      Event Manager, Events Calendar, Tickets, Registrations – Eventin
    52. 2.52
      SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
    53. 2.53
      Backup, Restore and Migrate WordPress Sites With the XCloner Plugin
    54. 2.54
      Arconix FAQ
    55. 2.55
      HTML Forms – Simple WordPress Forms Plugin
    56. 2.56
      YITH Essential Kit for WooCommerce #1
    57. 2.57
      Arconix Shortcodes
    58. 2.58
      AI ChatBot for WordPress – WPBot
    59. 2.59
      WP QuickLaTeX
    60. 2.60
      Livemesh Addons for Beaver Builder
    61. 2.61
      Cooked – Recipe Management
    62. 2.62
      Cooked – Recipe Management
    63. 2.63
      AForms — Form Builder for Price Calculator & Cost Estimation
    64. 2.64
      Insert or Embed Articulate Content into WordPress
    65. 2.65
      Addonify – Quick View For WooCommerce
    66. 2.66
      Visual Website Collaboration, Feedback & Project Management – Atarim
    67. 2.67
      Glossary
    68. 2.68
      The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)
    69. 2.69
      Web and WooCommerce Addons for WPBakery Builder
    70. 2.70
      Great Restaurant Menu WP
    71. 2.71
      Duplica – Duplicate Posts, Pages, Custom Posts or Users
    72. 2.72
      WP Fast Total Search – The Power of Indexed Search
    73. 2.73
      MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles
    74. 2.74
      Custom Query Blocks
    75. 2.75
      Filter & Grids
    76. 2.76
      FormLift for Infusionsoft Web Forms
    77. 2.77
      ArtPlacer Widget
    78. 2.78
      ArtPlacer Widget
    79. 2.79
      Bug Library
    80. 2.80
      Community Events
    81. 2.81
      PZ Frontend Manager
    82. 2.82
      Ultimate Addons for WPBakery Page Builder
    83. 2.83
      WP eStore
    84. 2.84
      WP eStore
    85. 2.85
      CopySafe Web Protection
    86. 2.86
      WP GoToWebinar
    87. 2.87
      WPForms User Registration
  3. 3. WordPress Themes — 0 Patched / 6 Unpatched
    1. 3.1
      CoziPress
    2. 3.2
      Himalayas
    3. 3.3
      ListingPro
    4. 3.4
      ListingPro
    5. 3.5
      ListingPro
    6. 3.6
      Zenon Lite

window[“1ce5aa33_66c0_4f0e_9fac_f33ef9ffddc9”] = {“blockId”:”1ce5aa33-66c0-4f0e-9fac-f33ef9ffddc9″,”type”:”notice”,”content”:”

Our WordPress Vulnerability Report\u00a0covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of\u00a0Low,\u00a0Medium,\u00a0High, or\u00a0Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress \u2014 and the web \u2014 more secure.”,”className”:””};

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.6.1 is now available! This minor release features 7 bug fixes in Core and 9 bug fixes for the Block Editor. You can review a summary of the maintenance updates in this release by reading the Release Candidate announcement.

window[“d2b829b5_b9f2_417a_92cb_a1351baeb96d”] = {“blockId”:”d2b829b5-b9f2-417a-92cb-a1351baeb96d”,”text”:”No new core vulnerabilities were disclosed this week.”,”className”:””};

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 72 Patched / 15 Unpatched

Timetable and Event Schedule by MotoPress

Plugin:

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable

Installations
30,000+

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-39630

The vulnerability has not been patched. You should deactivate the plugin.

Smartsupp – live chat, chatbots, AI and lead generation

Plugin:

Smartsupp – live chat, chatbots, AI and lead generation

Plugin Slug:
smartsupp-live-chat

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-38790

The vulnerability has not been patched. You should deactivate the plugin.

Pretty Simple Popup Builder

Plugin:

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-39626

The vulnerability has not been patched. You should deactivate the plugin.

Booking Ultra Pro

Plugin:

Booking Ultra Pro

Plugin Slug:
booking-ultra-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-6175

The vulnerability has not been patched. You should deactivate the plugin.

Easy Testimonials

Plugin:

Easy Testimonials

Plugin Slug:
easy-testimonials

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-2337

The vulnerability has not been patched. You should deactivate the plugin.

Keydatas

Plugin:

Keydatas

Plugin Slug:
keydatas

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-6220

The vulnerability has not been patched. You should deactivate the plugin.

Light Poll

Plugin:

Light Poll

Plugin Slug:
light-poll

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-6720

The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-39621

The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-39620

The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-39619

The vulnerability has not been patched. You should deactivate the plugin.

ListingPro

Plugin:

ListingPro

Plugin Slug:
listingpro-plugin

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-38795

The vulnerability has not been patched. You should deactivate the plugin.

RegLevel

Plugin:

RegLevel

Plugin Slug:
reglevel

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-6705

The vulnerability has not been patched. You should deactivate the plugin.

SVG Support

Plugin:

SVG Support

Plugin Slug:
svg-support

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2023-6708

The vulnerability has not been patched. You should deactivate the plugin.

Telegram Bot & Channel

Plugin:

Telegram Bot & Channel

Plugin Slug:
telegram-bot

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-38789

The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:

Timeline Event History

Plugin Slug:
timeline-event-history

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-5726

The vulnerability has not been patched. You should deactivate the plugin.

WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin

Plugin:

WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin

Plugin Slug:
wp-mail-smtp

Installations
3,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.1.0

Severity Score:
Low

CVE:

2024-6694

The vulnerability has been patched, so you should update to version 4.1.0.

ElementsKit Elementor addons

Plugin:

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite

Installations
1,000,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
3.2.1

Severity Score:
Medium

CVE:

2024-6455

The vulnerability has been patched, so you should update to version 3.2.1.

Redux Framework

Plugin:

Redux Framework

Plugin Slug:
redux-framework

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.4.18

Severity Score:
High

CVE:

2024-6828

The vulnerability has been patched, so you should update to version 4.4.18.

Security Optimizer – The All-In-One Protection Plugin

Plugin:

Security Optimizer – The All-In-One Protection Plugin

Plugin Slug:
sg-security

Installations
1,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5.1

Severity Score:
Medium

CVE:

2024-38774

The vulnerability has been patched, so you should update to version 1.5.1.

WPS Hide Login

Plugin:

WPS Hide Login

Plugin Slug:
wps-hide-login

Installations
1,000,000+

Vulnerability:
Bypass Vulnerability

Patched in Version:
1.9.16.4

Severity Score:
Medium

CVE:

2024-6289

The vulnerability has been patched, so you should update to version 1.9.16.4.

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Plugin:

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Plugin Slug:
nextgen-gallery

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.59.4

Severity Score:
Medium

CVE:

2024-39627

The vulnerability has been patched, so you should update to version 3.59.4.

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)

Plugin:

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows)

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.6.6

Severity Score:
Medium

CVE:

2024-5555

The vulnerability has been patched, so you should update to version 5.6.6.

Conditional Fields for Contact Form 7

Plugin:

Conditional Fields for Contact Form 7

Plugin Slug:
cf7-conditional-fields

Installations
100,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.4.14

Severity Score:
Medium

CVE:

2024-5804

The vulnerability has been patched, so you should update to version 2.4.14.

GiveWP – Donation Plugin and Fundraising Platform

Plugin:

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
3.14.0

Severity Score:
Medium

CVE:

2024-5977

The vulnerability has been patched, so you should update to version 3.14.0.

Schema & Structured Data for WP & AMP

Plugin:

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.34.1

Severity Score:
Medium

CVE:

2024-5582

The vulnerability has been patched, so you should update to version 1.34.1.

CTX Feed – WooCommerce Product Feed Manager Plugin

Plugin:

CTX Feed – WooCommerce Product Feed Manager Plugin

Plugin Slug:
webappick-product-feed-for-woocommerce

Installations
100,000+

Vulnerability:
Privilege Escalation

Patched in Version:
6.5.7

Severity Score:
High

CVE:

2024-38775

The vulnerability has been patched, so you should update to version 6.5.7.

Mercado Pago payments for WooCommerce

Plugin:

Mercado Pago payments for WooCommerce

Plugin Slug:
woocommerce-mercadopago

Installations
100,000+

Vulnerability:
Arbitrary File Download

Patched in Version:
7.6.2

Severity Score:
Medium

CVE:

2024-3934

The vulnerability has been patched, so you should update to version 7.6.2.

HUSKY – Products Filter Professional for WooCommerce

Plugin:

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter

Installations
100,000+

Vulnerability:
SQL Injection

Patched in Version:
1.3.6.1

Severity Score:
Critical

CVE:

2024-6457

The vulnerability has been patched, so you should update to version 1.3.6.1.

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

Plugin:

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

Plugin Slug:
email-subscribers

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.27

Severity Score:
Medium

CVE:

2024-5703

The vulnerability has been patched, so you should update to version 5.7.27.

Brizy – Page Builder

Plugin:

Brizy – Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.4.45

Severity Score:
Critical

CVE:

2024-3242

The vulnerability has been patched, so you should update to version 2.4.45.

Brizy – Page Builder

Plugin:

Brizy – Page Builder

Plugin Slug:
brizy

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.45

Severity Score:
High

CVE:

2024-1937

The vulnerability has been patched, so you should update to version 2.4.45.

AI Engine

Plugin:

AI Engine

Plugin Slug:
ai-engine

Installations
70,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.4.8

Severity Score:
Medium

CVE:

2024-38791

The vulnerability has been patched, so you should update to version 2.4.8.

Premium Portfolio Features for Phlox theme

Plugin:

Premium Portfolio Features for Phlox theme

Plugin Slug:
auxin-portfolio

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium

CVE:

2024-3587

The vulnerability has been patched, so you should update to version 2.3.3.

Getwid – Gutenberg Blocks

Plugin:

Getwid – Gutenberg Blocks

Plugin Slug:
getwid

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.11

Severity Score:
Medium

CVE:

2024-6491

The vulnerability has been patched, so you should update to version 2.0.11.

Image Hover Effects – Elementor Addon

Plugin:

Image Hover Effects – Elementor Addon

Plugin Slug:
image-hover-effects-addon-for-elementor

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.4

Severity Score:
Medium

CVE:

2024-4780

The vulnerability has been patched, so you should update to version 1.4.4.

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

Plugin:

RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging

Plugin Slug:
wp-rss-aggregator

Installations
50,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.23.12

Severity Score:
Medium

CVE:

2024-6621

The vulnerability has been patched, so you should update to version 4.23.12.

Gutenverse – Gutenberg Blocks – Page Builder for Site Editor

Plugin:

Gutenverse – Gutenberg Blocks – Page Builder for Site Editor

Plugin Slug:
gutenverse

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.3

Severity Score:
Medium

CVE:

2024-38785

The vulnerability has been patched, so you should update to version 1.9.3.

FV Flowplayer Video Player

Plugin:

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
20,000+

Vulnerability:
SQL Injection

Patched in Version:
7.5.47.7212

Severity Score:
High

CVE:

2024-6338

The vulnerability has been patched, so you should update to version 7.5.47.7212.

Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA

Plugin:

Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA

Plugin Slug:
icegram

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.1.25

Severity Score:
Medium

CVE:

2024-39625

The vulnerability has been patched, so you should update to version 3.1.25.

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

Plugin:

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

Plugin Slug:
wp-event-manager

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.44

Severity Score:
Medium

CVE:

2024-2691

The vulnerability has been patched, so you should update to version 3.1.44.

WordPress File Upload

Plugin:

WordPress File Upload

Plugin Slug:
wp-file-upload

Installations
20,000+

Vulnerability:
Directory Traversal

Patched in Version:
4.24.8

Severity Score:
Medium

CVE:

2024-5852

The vulnerability has been patched, so you should update to version 4.24.8.

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress

Plugin:

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress

Plugin Slug:
bookingpress-appointment-booking

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.6

Severity Score:
Critical

CVE:

2024-6660

The vulnerability has been patched, so you should update to version 1.1.6.

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress

Plugin:

Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress

Plugin Slug:
bookingpress-appointment-booking

Installations
10,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.6

Severity Score:
High

CVE:

2024-6467

The vulnerability has been patched, so you should update to version 1.1.6.

BSK PDF Manager

Plugin:

BSK PDF Manager

Plugin Slug:
bsk-pdf-manager

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.1

Severity Score:
Medium

CVE:

2024-38767

The vulnerability has been patched, so you should update to version 3.6.1.

CM Popup Plugin for WordPress – Popup Maker

Plugin:

CM Popup Plugin for WordPress – Popup Maker

Plugin Slug:
cm-pop-up-banners

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.6

Severity Score:
Medium

CVE:

2024-5004

The vulnerability has been patched, so you should update to version 1.6.6.

Language Translate Widget for WP – ConveyThis

Plugin:

Language Translate Widget for WP – ConveyThis

Plugin Slug:
conveythis-translate

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
235

Severity Score:
Medium

CVE:

2024-38792

The vulnerability has been patched, so you should update to version 235.

JetWidgets for Elementor and WooCommerce

Plugin:

JetWidgets for Elementor and WooCommerce

Plugin Slug:
jetwoo-widgets-for-elementor

Installations
10,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.1.8

Severity Score:
Medium

CVE:

2024-38772

The vulnerability has been patched, so you should update to version 1.1.8.

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Plugin:

Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)

Plugin Slug:
leaflet-maps-marker

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.12.10

Severity Score:
Medium

CVE:

2024-38782

The vulnerability has been patched, so you should update to version 3.12.10.

MasterStudy LMS WordPress Plugin – for Online Courses and Education

Plugin:

MasterStudy LMS WordPress Plugin – for Online Courses and Education

Plugin Slug:
masterstudy-lms-learning-management-system

Installations
10,000+

Vulnerability:
Privilege Escalation

Patched in Version:
3.3.24

Severity Score:
High

CVE:

2024-5973

The vulnerability has been patched, so you should update to version 3.3.24.

UiPress lite | Effortless custom dashboards, admin themes and pages

Plugin:

UiPress lite | Effortless custom dashboards, admin themes and pages

Plugin Slug:
uipress-lite

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.4.07

Severity Score:
High

CVE:

2024-38788

The vulnerability has been patched, so you should update to version 3.4.07.

Event Manager, Events Calendar, Tickets, Registrations – Eventin

Plugin:

Event Manager, Events Calendar, Tickets, Registrations – Eventin

Plugin Slug:
wp-event-solution

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.5

Severity Score:
Medium

CVE:

2024-6033

The vulnerability has been patched, so you should update to version 4.0.5.

SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher

Plugin:

SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher

Plugin Slug:
wp-scheduled-posts

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
5.1.4

Severity Score:
Medium

CVE:

2024-6557

The vulnerability has been patched, so you should update to version 5.1.4.

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin

Plugin:

Backup, Restore and Migrate WordPress Sites With the XCloner Plugin

Plugin Slug:
xcloner-backup-and-restore

Installations
10,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
4.7.4

Severity Score:
Medium

CVE:

2024-6559

The vulnerability has been patched, so you should update to version 4.7.4.

Arconix FAQ

Plugin:

Arconix FAQ

Plugin Slug:
arconix-faq

Installations
9,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.5

Severity Score:
Medium

CVE:

2024-38783

The vulnerability has been patched, so you should update to version 1.9.5.

HTML Forms – Simple WordPress Forms Plugin

Plugin:

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.33

Severity Score:
Medium

CVE:

2024-6243

The vulnerability has been patched, so you should update to version 1.3.33.

YITH Essential Kit for WooCommerce #1

Plugin:

YITH Essential Kit for WooCommerce #1

Plugin Slug:
yith-essential-kit-for-woocommerce-1

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.35.0

Severity Score:
Medium

CVE:

2024-6799

The vulnerability has been patched, so you should update to version 2.35.0.

Arconix Shortcodes

Plugin:

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.12

Severity Score:
Medium

CVE:

2024-38769

The vulnerability has been patched, so you should update to version 2.1.12.

AI ChatBot for WordPress – WPBot

Plugin:

AI ChatBot for WordPress – WPBot

Plugin Slug:
chatbot

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.8

Severity Score:
Medium

CVE:

2024-6669

The vulnerability has been patched, so you should update to version 5.5.8.

WP QuickLaTeX

Plugin:

WP QuickLaTeX

Plugin Slug:
wp-quicklatex

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.8

Severity Score:
Medium

CVE:

2024-5529

The vulnerability has been patched, so you should update to version 3.8.8.

Livemesh Addons for Beaver Builder

Plugin:

Livemesh Addons for Beaver Builder

Plugin Slug:
addons-for-beaver-builder

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7

Severity Score:
Medium

CVE:

2024-38784

The vulnerability has been patched, so you should update to version 3.7.

Cooked – Recipe Management

Plugin:

Cooked – Recipe Management

Plugin Slug:
cooked

Installations
4,000+

Vulnerability:
Content Injection

Patched in Version:
1.8.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.8.0.

Cooked – Recipe Management

Plugin:

Cooked – Recipe Management

Plugin Slug:
cooked

Installations
4,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.8.0

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.8.0.

AForms — Form Builder for Price Calculator & Cost Estimation

Plugin:

AForms — Form Builder for Price Calculator & Cost Estimation

Plugin Slug:
aforms-form-builder-for-price-calculator-cost-estimation

Installations
3,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.7

Severity Score:
Medium

CVE:

2024-6565

The vulnerability has been patched, so you should update to version 2.2.7.

Insert or Embed Articulate Content into WordPress

Plugin:

Insert or Embed Articulate Content into WordPress

Plugin Slug:
insert-or-embed-articulate-content-into-wordpress

Installations
3,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
4.3000000024

Severity Score:
Critical

CVE:

2024-5630

The vulnerability has been patched, so you should update to version 4.3000000024.

Addonify – Quick View For WooCommerce

Plugin:

Addonify – Quick View For WooCommerce

Plugin Slug:
addonify-quick-view

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.17

Severity Score:
Medium

CVE:

2024-6560

The vulnerability has been patched, so you should update to version 1.2.17.

Visual Website Collaboration, Feedback & Project Management – Atarim

Plugin:

Visual Website Collaboration, Feedback & Project Management – Atarim

Plugin Slug:
atarim-visual-collaboration

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.0.1

Severity Score:
Medium

CVE:

2024-38771

The vulnerability has been patched, so you should update to version 4.0.1.

Glossary

Plugin:

Glossary

Plugin Slug:
glossary-by-codeat

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.2.27

Severity Score:
Medium

CVE:

2024-6570

The vulnerability has been patched, so you should update to version 2.2.27.

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)

Plugin:

The Pack Elementor addons (Header Footer & WooCommerce Builder, Template Library)

Plugin Slug:
the-pack-addon

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.0.8.7

Severity Score:
Medium

CVE:

2024-38768

The vulnerability has been patched, so you should update to version 2.0.8.7.

Web and WooCommerce Addons for WPBakery Builder

Plugin:

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.6

Severity Score:
Medium

CVE:

2024-6579

The vulnerability has been patched, so you should update to version 1.4.6.

Great Restaurant Menu WP

Plugin:

Great Restaurant Menu WP

Plugin Slug:
best-restaurant-menu-by-pricelisto

Installations
1,000+

Vulnerability:
SQL Injection

Patched in Version:
1.4.2

Severity Score:
High

CVE:

2024-38793

The vulnerability has been patched, so you should update to version 1.4.2.

Duplica – Duplicate Posts, Pages, Custom Posts or Users

Plugin:

Duplica – Duplicate Posts, Pages, Custom Posts or Users

Plugin Slug:
duplica

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.7

Severity Score:
Medium

CVE:

2024-5997

The vulnerability has been patched, so you should update to version 0.7.

WP Fast Total Search – The Power of Indexed Search

Plugin:

WP Fast Total Search – The Power of Indexed Search

Plugin Slug:
fulltext-search

Installations
1,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.70.236

Severity Score:
Medium

CVE:

2024-38778

The vulnerability has been patched, so you should update to version 1.70.236.

MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles

Plugin:

MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles

Plugin Slug:
maxi-blocks

Installations
1,000+

Vulnerability:
Arbitrary File Deletion

Patched in Version:
1.9.3

Severity Score:
High

CVE:

2024-6885

The vulnerability has been patched, so you should update to version 1.9.3.

Custom Query Blocks

Plugin:

Custom Query Blocks

Plugin Slug:
post-type-archive-mapping

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.3.0

Severity Score:
Medium

CVE:

2024-38794

The vulnerability has been patched, so you should update to version 5.3.0.

Filter & Grids

Plugin:

Filter & Grids

Plugin Slug:
ymc-smart-filter

Installations
1,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.8.33

Severity Score:
High

CVE:

2024-6164

The vulnerability has been patched, so you should update to version 2.8.33.

FormLift for Infusionsoft Web Forms

Plugin:

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
7.5.18

Severity Score:
Critical

CVE:

2024-38773

The vulnerability has been patched, so you should update to version 7.5.18.

ArtPlacer Widget

Plugin:

ArtPlacer Widget

Plugin Slug:
artplacer-widget

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.21.2

Severity Score:
High

CVE:

2023-7269

The vulnerability has been patched, so you should update to version 2.21.2.

ArtPlacer Widget

Plugin:

ArtPlacer Widget

Plugin Slug:
artplacer-widget

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
2.21.2

Severity Score:
Medium

CVE:

2023-7268

The vulnerability has been patched, so you should update to version 2.21.2.

Bug Library

Plugin:

Bug Library

Plugin Slug:
bug-library

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.2

Severity Score:
Medium

CVE:

2024-5604

The vulnerability has been patched, so you should update to version 2.1.2.

Community Events

Plugin:

Community Events

Plugin Slug:
community-events

Installations
40+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5

Severity Score:
Medium

CVE:

2024-6271

The vulnerability has been patched, so you should update to version 1.5.

PZ Frontend Manager

Plugin:

PZ Frontend Manager

Plugin Slug:
pz-frontend-manager

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium

CVE:

2024-6244

The vulnerability has been patched, so you should update to version 1.0.6.

Ultimate Addons for WPBakery Page Builder

Plugin:

Ultimate Addons for WPBakery Page Builder

Plugin Slug:
ultimate_vc_addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.19.20.1

Severity Score:
Medium

CVE:

2024-5251

The vulnerability has been patched, so you should update to version 3.19.20.1.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
8.5.5

Severity Score:
Medium

CVE:

2024-6075

The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:

WP eStore

Plugin Slug:
wp-cart-for-digital-products

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
8.5.5

Severity Score:
High

CVE:

2024-6072

The vulnerability has been patched, so you should update to version 8.5.5.

CopySafe Web Protection

Plugin:

CopySafe Web Protection

Plugin Slug:
wp-copysafe-web

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0

Severity Score:
High

CVE:

2024-38781

The vulnerability has been patched, so you should update to version 4.0.

WP GoToWebinar

Plugin:

WP GoToWebinar

Plugin Slug:
wp-gotowebinar

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
15.8

Severity Score:
High

CVE:

2024-38776

The vulnerability has been patched, so you should update to version 15.8.

WPForms User Registration

Plugin:

WPForms User Registration

Plugin Slug:
wpforms-user-registration

Vulnerability:
Privilege Escalation

Patched in Version:
2.1.2

Severity Score:
High

CVE:

2023-52209

The vulnerability has been patched, so you should update to version 2.1.2.

WordPress Themes — 0 Patched / 6 Unpatched

CoziPress

Theme:

CoziPress

Theme Slug:
cozipress

Downloads
144,938

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-38786

The vulnerability has not been patched. You should switch themes.

Himalayas

Theme:

Himalayas

Theme Slug:
himalayas

Downloads
334,322

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-39629

The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-39624

The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-39623

The vulnerability has not been patched. You should switch themes.

ListingPro

Theme:

ListingPro

Theme Slug:
listingpro

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-39622

The vulnerability has not been patched. You should switch themes.

Zenon Lite

Theme:

Zenon Lite

Theme Slug:
zenon-lite

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-5964

The vulnerability has not been patched. You should switch themes.

window[“ea1c4c97_fbb2_4c04_a9d2_2e6d4dcee038”] = {“blockId”:”ea1c4c97-fbb2-4c04-a9d2-2e6d4dcee038″,”className”:””,”heading”:”Solid Security is part of Solid Suite \u2014 The best foundation for WordPress websites.”,”text”:”Every WordPress site needs security, backups, and management tools. That\u2019s Solid Suite \u2014 an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy\u2019s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!”,”buttonText”:”Get Solid Security”,”buttonLink”:”\/pricing”,”buttonTarget”:”_self”,”buttonRel”:””};

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — July 24, 2024 appeared first on SolidWP.

Source link

Written by:
Abdul Wahid
Published on:
July 26, 2024

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter