• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report — May 22, 2024

WordPress Vulnerability Report — May 22, 2024

In this report, 153 vulnerabilities have been publicly disclosed. Security patches for 119 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 34 plugin and themes vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

window[“587c405a_dfaa_41a6_88a0_cfee675cbc8b”] = {“blockId”:”587c405a-dfaa-41a6-88a0-cfee675cbc8b”,”type”:”warning”,”content”:”

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.”,”className”:””};

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

window[“11f6da05_c970_4d05_89f8_e32f555bf151”] = {“blockId”:”11f6da05-c970-4d05-89f8-e32f555bf151″,”className”:””,”isOpen”:true};

Table of Contents

  1. 1. WordPress Core
  2. 2. WordPress Plugins — 109 Patched / 33 Unpatched
    1. 2.1
      Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer
    2. 2.2
      Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
    3. 2.3
      Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More
    4. 2.4
      reCAPTCHA Jetpack
    5. 2.5
      reCAPTCHA Jetpack
    6. 2.6
      UnGallery
    7. 2.7
      Add Custom CSS and JS
    8. 2.8
      WP Stacker
    9. 2.9
      AdFoxly – Ad Manager, AdSense Ads & Ads.txt
    10. 2.10
      Base64 Encoder/Decoder
    11. 2.11
      Base64 Encoder/Decoder
    12. 2.12
      Base64 Encoder/Decoder
    13. 2.13
      Crafthemes Demo Import
    14. 2.14
      Dextaz Ping
    15. 2.15
      Elegant Blocks
    16. 2.16
      Fast Custom Social Share by CodeBard
    17. 2.17
      HL Twitter
    18. 2.18
      HL Twitter
    19. 2.19
      LetterPress
    20. 2.20
      Newsletter Popup
    21. 2.21
      Popup4Phone
    22. 2.22
      Popup4Phone
    23. 2.23
      PopupAlly
    24. 2.24
      Praison SEO WordPress
    25. 2.25
      Simple Popup Manager
    26. 2.26
      SP Project & Document Manager
    27. 2.27
      SP Project & Document Manager
    28. 2.28
      Tainacan
    29. 2.29
      Tainacan
    30. 2.30
      WP Backpack
    31. 2.31
      WP Next Post Navi
    32. 2.32
      WP Prayer
    33. 2.33
      WPB Elementor Addons
    34. 2.34
      Elementor Website Builder – More than Just a Page Builder
    35. 2.35
      Yoast SEO
    36. 2.36
      Jetpack – WP Security, Backup, Speed, & Growth
    37. 2.37
      Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
    38. 2.38
      Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders
    39. 2.39
      Rank Math SEO with AI Best SEO Tools
    40. 2.40
      Elementor Header & Footer Builder
    41. 2.41
      Elementor Header & Footer Builder
    42. 2.42
      Page Builder by SiteOrigin
    43. 2.43
      The Events Calendar
    44. 2.44
      WP Shortcodes Plugin — Shortcodes Ultimate
    45. 2.45
      WP Shortcodes Plugin — Shortcodes Ultimate
    46. 2.46
      NextGEN Gallery – Create an Amazing Photo Gallery in Seconds
    47. 2.47
      Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
    48. 2.48
      Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
    49. 2.49
      Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
    50. 2.50
      Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
    51. 2.51
      Happy Addons for Elementor
    52. 2.52
      Happy Addons for Elementor
    53. 2.53
      Gutenberg Blocks with AI by Kadence WP – Page Builder Features
    54. 2.54
      Gutenberg Blocks with AI by Kadence WP – Page Builder Features
    55. 2.55
      Password Protected – Ultimate Plugin to Protect WordPress Site, Pages & WooCommerce Store
    56. 2.56
      Royal Elementor Addons and Templates
    57. 2.57
      Menu Icons by ThemeIsle
    58. 2.58
      Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF
    59. 2.59
      Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
    60. 2.60
      GiveWP – Donation Plugin and Fundraising Platform
    61. 2.61
      HT Mega – Absolute Addons For Elementor
    62. 2.62
      HT Mega – Absolute Addons For Elementor
    63. 2.63
      ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)
    64. 2.64
      ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)
    65. 2.65
      ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)
    66. 2.66
      Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce
    67. 2.67
      iframe
    68. 2.68
      Master Slider – Responsive Touch Slider
    69. 2.69
      Import and export users and customers
    70. 2.70
      Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
    71. 2.71
      Sydney Toolbox
    72. 2.72
      Tutor LMS – eLearning and online course solution
    73. 2.73
      Tutor LMS – eLearning and online course solution
    74. 2.74
      Tutor LMS – eLearning and online course solution
    75. 2.75
      Visual Portfolio, Photo Gallery & Post Grid
    76. 2.76
      Exclusive Addons for Elementor
    77. 2.77
      WP Table Builder – WordPress Table Plugin
    78. 2.78
      Order Export & Order Import for WooCommerce
    79. 2.79
      Ultimate Blocks – WordPress Blocks Plugin
    80. 2.80
      DethemeKit For Elementor
    81. 2.81
      DethemeKit For Elementor
    82. 2.82
      Piotnet Addons For Elementor
    83. 2.83
      Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks
    84. 2.84
      Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor
    85. 2.85
      Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
    86. 2.86
      Visualizer: Tables and Charts Manager for WordPress
    87. 2.87
      All-in-One Video Gallery
    88. 2.88
      Envo Extra
    89. 2.89
      Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin
    90. 2.90
      Post Grid Elementor Addon
    91. 2.91
      WPZOOM Addons for Elementor (Templates, Widgets)
    92. 2.92
      BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin
    93. 2.93
      Mega Elements – Addons for Elementor
    94. 2.94
      Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages
    95. 2.95
      ReviewX – Multi-criteria Rating & Reviews for WooCommerce
    96. 2.96
      Simple Basic Contact Form
    97. 2.97
      140+ Widgets | Best Addons For Elementor – FREE
    98. 2.98
      YITH WooCommerce Gift Cards
    99. 2.99
      Alt Text AI – Automatically generate image alt text for SEO and accessibility
    100. 2.100
      WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc
    101. 2.101
      VikBooking Hotel Booking Engine & PMS
    102. 2.102
      Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
    103. 2.103
      WP Compress – Image Optimizer [All-In-One]
    104. 2.104
      WP Compress – Image Optimizer [All-In-One]
    105. 2.105
      Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg
    106. 2.106
      Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg
    107. 2.107
      JCH Optimize
    108. 2.108
      Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress
    109. 2.109
      Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )
    110. 2.110
      Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid
    111. 2.111
      Move Addons for Elementor
    112. 2.112
      YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress
    113. 2.113
      Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
    114. 2.114
      Debug Log – Manger Tool
    115. 2.115
      FundEngine – Donation and Crowdfunding Platform
    116. 2.116
      Kognetiks Chatbot for WordPress
    117. 2.117
      Copymatic – AI Content Writer & Generator
    118. 2.118
      Custom Post Type Attachment
    119. 2.119
      Fastly
    120. 2.120
      Fastly
    121. 2.121
      Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table
    122. 2.122
      Save as PDF Plugin by Pdfcrowd
    123. 2.123
      ShiftController Employee Shift Scheduling
    124. 2.124
      Popup Builder
    125. 2.125
      Picture Gallery – Frontend Image Uploads, AJAX Photo List
    126. 2.126
      Popup – Popup More Popups
    127. 2.127
      Builder for WooCommerce product reviews shortcodes – ReviewShort
    128. 2.128
      Bulk Posts Editing For WordPress
    129. 2.129
      Bulk Posts Editing For WordPress
    130. 2.130
      month name translation benaceur
    131. 2.131
      Advanced Custom Fields PRO
    132. 2.132
      Advanced Custom Fields PRO
    133. 2.133
      ConvertPlus
    134. 2.134
      Cost Calculator Builder Pro
    135. 2.135
      ElementsKit Pro
    136. 2.136
      Penci Soledad Data Migrator
    137. 2.137
      Swift Framework Page Builder
    138. 2.138
      Tutor LMS Pro
    139. 2.139
      Tutor LMS Pro
    140. 2.140
      Tutor LMS Pro
    141. 2.141
      Uber Menu
    142. 2.142
      Automatic
  3. 3. WordPress Themes — 10 Patched / 1 Unpatched
    1. 3.1
      ImageMagick Sharpen Resized Images
    2. 3.2
      Blocksy
    3. 3.3
      ChaosTheory
    4. 3.4
      Consus
    5. 3.5
      EmpowerWP
    6. 3.6
      Ketos
    7. 3.7
      Mindscape
    8. 3.8
      Niveau
    9. 3.9
      Oasis
    10. 3.10
      Skyline WP
    11. 3.11
      Zeka

window[“df8d7e80_ec24_4a89_8904_30b2c3f63cb7”] = {“blockId”:”df8d7e80-ec24-4a89-8904-30b2c3f63cb7″,”type”:”notice”,”content”:”

Our WordPress Vulnerability Report\u00a0covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of\u00a0Low,\u00a0Medium,\u00a0High, or\u00a0Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress \u2014 and the web \u2014 more secure.”,”className”:””};

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.5.3 was released on May 7, 2024, as a short-cycle maintenance release. This release features 12 bug fixes on Core and 9 bug fixes for the Block editor.

The next major release will be version 6.6 planned for July 2024.

window[“0307515b_74c4_4623_adaa_9f93addf5eb0”] = {“blockId”:”0307515b-74c4-4623-adaa-9f93addf5eb0″,”text”:”No new core vulnerabilities were disclosed this week.”,”className”:””};

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 109 Patched / 33 Unpatched

Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer

Plugin:

Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer

Plugin Slug:
clearfy

Installations
80,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34806

The vulnerability has not been patched. You should deactivate the plugin.

Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds

Plugin:

Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds

Plugin Slug:
tagembed-widget

Installations
8,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34804

The vulnerability has not been patched. You should deactivate the plugin.

Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More

Plugin:

Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More

Plugin Slug:
popup-maker-wp

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34770

The vulnerability has not been patched. You should deactivate the plugin.

reCAPTCHA Jetpack

Plugin:

reCAPTCHA Jetpack

Plugin Slug:
recaptcha-jetpack

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-3941

The vulnerability has not been patched. You should deactivate the plugin.

reCAPTCHA Jetpack

Plugin:

reCAPTCHA Jetpack

Plugin Slug:
recaptcha-jetpack

Installations
700+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3940

The vulnerability has not been patched. You should deactivate the plugin.

UnGallery

Plugin:

UnGallery

Plugin Slug:
ungallery

Installations
50+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-3582

The vulnerability has not been patched. You should deactivate the plugin.

Add Custom CSS and JS

Plugin:

Add Custom CSS and JS

Plugin Slug:
add-custom-css-and-js

Installations
10+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-3903

The vulnerability has not been patched. You should deactivate the plugin.

WP Stacker

Plugin:

WP Stacker

Plugin Slug:
wp-stacker

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-5003

The vulnerability has not been patched. You should deactivate the plugin.

AdFoxly – Ad Manager, AdSense Ads & Ads.txt

Plugin:

AdFoxly – Ad Manager, AdSense Ads & Ads.txt

Plugin Slug:
adfoxly

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34802

The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3824

The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3823

The vulnerability has not been patched. You should deactivate the plugin.

Base64 Encoder/Decoder

Plugin:

Base64 Encoder/Decoder

Plugin Slug:
base64-encoderdecoder

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-3822

The vulnerability has not been patched. You should deactivate the plugin.

Crafthemes Demo Import

Plugin:

Crafthemes Demo Import

Plugin Slug:
crafthemes-demo-import

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-34800

The vulnerability has not been patched. You should deactivate the plugin.

Dextaz Ping

Plugin:

Dextaz Ping

Plugin Slug:
dextaz-ping

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-34792

The vulnerability has not been patched. You should deactivate the plugin.

Elegant Blocks

Plugin:

Elegant Blocks

Plugin Slug:
elegant-blocks

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34769

The vulnerability has not been patched. You should deactivate the plugin.

Fast Custom Social Share by CodeBard

Plugin:

Fast Custom Social Share by CodeBard

Plugin Slug:
fast-custom-social-share-by-codebard

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34807

The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:

HL Twitter

Plugin Slug:
hl-twitter

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3630

The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:

HL Twitter

Plugin Slug:
hl-twitter

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3629

The vulnerability has not been patched. You should deactivate the plugin.

LetterPress

Plugin:

LetterPress

Plugin Slug:
letterpress

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3590

The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:

Newsletter Popup

Plugin Slug:
newsletter-popup

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3644

The vulnerability has not been patched. You should deactivate the plugin.

Popup4Phone

Plugin:

Popup4Phone

Plugin Slug:
popup4phone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3580

The vulnerability has not been patched. You should deactivate the plugin.

Popup4Phone

Plugin:

Popup4Phone

Plugin Slug:
popup4phone

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-3231

The vulnerability has not been patched. You should deactivate the plugin.

PopupAlly

Plugin:

PopupAlly

Plugin Slug:
popupally

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34796

The vulnerability has not been patched. You should deactivate the plugin.

Praison SEO WordPress

Plugin:

Praison SEO WordPress

Plugin Slug:
seo-wordpress

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34801

The vulnerability has not been patched. You should deactivate the plugin.

Simple Popup Manager

Plugin:

Simple Popup Manager

Plugin Slug:
simple-popup-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34797

The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3748

The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:

SP Project & Document Manager

Plugin Slug:
sp-client-document-manager

Vulnerability:
Directory Traversal

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-1693

The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34795

The vulnerability has not been patched. You should deactivate the plugin.

Tainacan

Plugin:

Tainacan

Plugin Slug:
tainacan

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-34794

The vulnerability has not been patched. You should deactivate the plugin.

WP Backpack

Plugin:

WP Backpack

Plugin Slug:
wp-backpack

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-4756

The vulnerability has not been patched. You should deactivate the plugin.

WP Next Post Navi

Plugin:

WP Next Post Navi

Plugin Slug:
wp-next-post-navi

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34793

The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:

WP Prayer

Plugin Slug:
wp-prayer

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-3405

The vulnerability has not been patched. You should deactivate the plugin.

WPB Elementor Addons

Plugin:

WPB Elementor Addons

Plugin Slug:
wpb-elementor-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34791

The vulnerability has not been patched. You should deactivate the plugin.

Elementor Website Builder – More than Just a Page Builder

Plugin:

Elementor Website Builder – More than Just a Page Builder

Plugin Slug:
elementor

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.21.6

Severity Score:
Medium

CVE:

2024-4619

The vulnerability has been patched, so you should update to version 3.21.6.

Yoast SEO

Plugin:

Yoast SEO

Plugin Slug:
wordpress-seo

Installations
5,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
22.7

Severity Score:
Medium

CVE:

2024-4984

The vulnerability has been patched, so you should update to version 22.7.

Jetpack – WP Security, Backup, Speed, & Growth

Plugin:

Jetpack – WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
13.4

Severity Score:
Medium

CVE:

2024-4392

The vulnerability has been patched, so you should update to version 13.4.

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin:

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.16

Severity Score:
Medium

CVE:

2024-34764

The vulnerability has been patched, so you should update to version 5.9.16.

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin:

Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders

Plugin Slug:
essential-addons-for-elementor-lite

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.9.21

Severity Score:
Medium

CVE:

2024-4624

The vulnerability has been patched, so you should update to version 5.9.21.

Rank Math SEO with AI Best SEO Tools

Plugin:

Rank Math SEO with AI Best SEO Tools

Plugin Slug:
seo-by-rank-math

Installations
2,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.219-beta

Severity Score:
Medium

CVE:

2024-4617

The vulnerability has been patched, so you should update to version 1.0.219-beta.

Elementor Header & Footer Builder

Plugin:

Elementor Header & Footer Builder

Plugin Slug:
header-footer-elementor

Installations
1,000,000+

Vulnerability:
Content Injection

Patched in Version:
1.6.27

Severity Score:
Medium

CVE:

2024-2619

The vulnerability has been patched, so you should update to version 1.6.27.

Elementor Header & Footer Builder

Plugin:

Elementor Header & Footer Builder

Plugin Slug:
header-footer-elementor

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.29

Severity Score:
Medium

CVE:

2024-4634

The vulnerability has been patched, so you should update to version 1.6.29.

Page Builder by SiteOrigin

Plugin:

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.29.16

Severity Score:
Medium

CVE:

2024-4361

The vulnerability has been patched, so you should update to version 2.29.16.

The Events Calendar

Plugin:

The Events Calendar

Plugin Slug:
the-events-calendar

Installations
700,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.0.1

Severity Score:
High

CVE:

2024-4180

The vulnerability has been patched, so you should update to version 6.4.0.1.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin:

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.6

Severity Score:
Medium

CVE:

2024-4553

The vulnerability has been patched, so you should update to version 7.1.6.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin:

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate

Installations
600,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.1.2

Severity Score:
Medium

CVE:

2024-3548

The vulnerability has been patched, so you should update to version 7.1.2.

NextGEN Gallery – Create an Amazing Photo Gallery in Seconds

Plugin:

NextGEN Gallery – Create an Amazing Photo Gallery in Seconds

Plugin Slug:
nextgen-gallery

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.59.1

Severity Score:
Medium

CVE:

2024-2744

The vulnerability has been patched, so you should update to version 3.59.1.

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin:

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin Slug:
fluentform

Installations
400,000+

Vulnerability:
Privilege Escalation

Patched in Version:
5.1.17

Severity Score:
Critical

CVE:

2024-2771

The vulnerability has been patched, so you should update to version 5.1.17.

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin:

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin Slug:
fluentform

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.1.17

Severity Score:
High

CVE:

2024-2782

The vulnerability has been patched, so you should update to version 5.1.17.

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin:

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin Slug:
fluentform

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.14

Severity Score:
Medium

CVE:

2024-2772

The vulnerability has been patched, so you should update to version 5.1.14.

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin:

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder

Plugin Slug:
fluentform

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1.17

Severity Score:
Medium

CVE:

2024-4709

The vulnerability has been patched, so you should update to version 5.1.17.

Happy Addons for Elementor

Plugin:

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.9

Severity Score:
Medium

CVE:

2024-4865

The vulnerability has been patched, so you should update to version 3.10.9.

Happy Addons for Elementor

Plugin:

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.10.8

Severity Score:
Medium

CVE:

2024-4478

The vulnerability has been patched, so you should update to version 3.10.8.

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin:

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.37

Severity Score:
Medium

CVE:

2024-4057

The vulnerability has been patched, so you should update to version 3.2.37.

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin:

Gutenberg Blocks with AI by Kadence WP – Page Builder Features

Plugin Slug:
kadence-blocks

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.38

Severity Score:
Medium

CVE:

2024-3189

The vulnerability has been patched, so you should update to version 3.2.38.

Password Protected – Ultimate Plugin to Protect WordPress Site, Pages & WooCommerce Store

Plugin:

Password Protected – Ultimate Plugin to Protect WordPress Site, Pages & WooCommerce Store

Plugin Slug:
password-protected

Installations
400,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.6.7

Severity Score:
Medium

CVE:

2024-0437

The vulnerability has been patched, so you should update to version 2.6.7.

Royal Elementor Addons and Templates

Plugin:

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons

Installations
300,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.975

Severity Score:
Medium

CVE:

2024-3887

The vulnerability has been patched, so you should update to version 1.3.975.

Menu Icons by ThemeIsle

Plugin:

Menu Icons by ThemeIsle

Plugin Slug:
menu-icons

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
0.13.14

Severity Score:
Medium

CVE:

2024-4635

The vulnerability has been patched, so you should update to version 0.13.14.

Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF

Plugin:

Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF

Plugin Slug:
optimole-wp

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.13.0

Severity Score:
Medium

CVE:

2024-4636

The vulnerability has been patched, so you should update to version 3.13.0.

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates

Plugin:

Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates

Plugin Slug:
essential-blocks

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.13

Severity Score:
Medium

CVE:

2024-4891

The vulnerability has been patched, so you should update to version 4.5.13.

GiveWP – Donation Plugin and Fundraising Platform

Plugin:

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.11.0

Severity Score:
Medium

CVE:

2024-3714

The vulnerability has been patched, so you should update to version 3.11.0.

HT Mega – Absolute Addons For Elementor

Plugin:

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.3

Severity Score:
Medium

CVE:

2024-4876

The vulnerability has been patched, so you should update to version 2.5.3.

HT Mega – Absolute Addons For Elementor

Plugin:

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.3

Severity Score:
Medium

CVE:

2024-4875

The vulnerability has been patched, so you should update to version 2.5.3.

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin:

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin Slug:
woolentor-addons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.9

Severity Score:
Medium

CVE:

2024-3345

The vulnerability has been patched, so you should update to version 2.8.9.

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin:

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin Slug:
woolentor-addons

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.9

Severity Score:
High

CVE:

2024-4566

The vulnerability has been patched, so you should update to version 2.8.9.

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin:

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor)

Plugin Slug:
woolentor-addons

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.8

Severity Score:
Medium

CVE:

2024-34767

The vulnerability has been patched, so you should update to version 2.8.8.

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

Plugin:

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

Plugin Slug:
email-subscribers

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.7.20

Severity Score:
High

CVE:

2024-4010

The vulnerability has been patched, so you should update to version 5.7.20.

iframe

Plugin:

iframe

Plugin Slug:
iframe

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.1

Severity Score:
Medium

CVE:

2024-34805

The vulnerability has been patched, so you should update to version 5.1.

Master Slider – Responsive Touch Slider

Plugin:

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider

Installations
90,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.10

Severity Score:
Medium

CVE:

2024-4470

The vulnerability has been patched, so you should update to version 3.9.10.

Import and export users and customers

Plugin:

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26.7

Severity Score:
Medium

CVE:

2024-4656

The vulnerability has been patched, so you should update to version 1.26.7.

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor

Plugin:

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor

Plugin Slug:
post-and-page-builder

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.26.5

Severity Score:
Medium

CVE:

2024-4400

The vulnerability has been patched, so you should update to version 1.26.5.

Sydney Toolbox

Plugin:

Sydney Toolbox

Plugin Slug:
sydney-toolbox

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.32

Severity Score:
Medium

CVE:

2024-4473

The vulnerability has been patched, so you should update to version 1.32.

Tutor LMS – eLearning and online course solution

Plugin:

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.7.1

Severity Score:
High

CVE:

2024-4223

The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS – eLearning and online course solution

Plugin:

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
2.7.1

Severity Score:
Medium

CVE:

2024-4279

The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS – eLearning and online course solution

Plugin:

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor

Installations
80,000+

Vulnerability:
SQL Injection

Patched in Version:
2.7.1

Severity Score:
High

CVE:

2024-4318

The vulnerability has been patched, so you should update to version 2.7.1.

Visual Portfolio, Photo Gallery & Post Grid

Plugin:

Visual Portfolio, Photo Gallery & Post Grid

Plugin Slug:
visual-portfolio

Installations
70,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.3

Severity Score:
Medium

CVE:

2024-4363

The vulnerability has been patched, so you should update to version 3.3.3.

Exclusive Addons for Elementor

Plugin:

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9.7

Severity Score:
Medium

CVE:

2024-4618

The vulnerability has been patched, so you should update to version 2.6.9.7.

WP Table Builder – WordPress Table Plugin

Plugin:

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.15

Severity Score:
Medium

CVE:

2024-4700

The vulnerability has been patched, so you should update to version 1.4.15.

Order Export & Order Import for WooCommerce

Plugin:

Order Export & Order Import for WooCommerce

Plugin Slug:
order-import-export-for-woocommerce

Installations
50,000+

Vulnerability:
PHP Object Injection

Patched in Version:
2.5.0

Severity Score:
Medium

CVE:

2024-34751

The vulnerability has been patched, so you should update to version 2.5.0.

Ultimate Blocks – WordPress Blocks Plugin

Plugin:

Ultimate Blocks – WordPress Blocks Plugin

Plugin Slug:
ultimate-blocks

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.7

Severity Score:
Medium

CVE:

2024-3241

The vulnerability has been patched, so you should update to version 3.1.7.

DethemeKit For Elementor

Plugin:

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium

CVE:

2024-4374

The vulnerability has been patched, so you should update to version 2.1.4.

DethemeKit For Elementor

Plugin:

DethemeKit For Elementor

Plugin Slug:
dethemekit-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.3

Severity Score:
Medium

CVE:

2024-34575

The vulnerability has been patched, so you should update to version 2.1.3.

Piotnet Addons For Elementor

Plugin:

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.28

Severity Score:
Medium

CVE:

2024-4432

The vulnerability has been patched, so you should update to version 2.4.28.

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks

Plugin:

Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks

Plugin Slug:
post-grid

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.81

Severity Score:
Medium

CVE:

2024-3155

The vulnerability has been patched, so you should update to version 2.2.81.

Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor

Plugin:

Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor

Plugin Slug:
master-addons

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.6.1

Severity Score:
Medium

CVE:

2024-3134

The vulnerability has been patched, so you should update to version 2.0.6.1.

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

Plugin:

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin

Plugin Slug:
simply-schedule-appointments

Installations
30,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.7.18

Severity Score:
Medium

CVE:

2024-4288

The vulnerability has been patched, so you should update to version 1.6.7.18.

Visualizer: Tables and Charts Manager for WordPress

Plugin:

Visualizer: Tables and Charts Manager for WordPress

Plugin Slug:
visualizer

Installations
30,000+

Vulnerability:
SQL Injection

Patched in Version:
3.11.0

Severity Score:
High

CVE:

2024-3750

The vulnerability has been patched, so you should update to version 3.11.0.

All-in-One Video Gallery

Plugin:

All-in-One Video Gallery

Plugin Slug:
all-in-one-video-gallery

Installations
20,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.7.0

Severity Score:
High

CVE:

2024-4670

The vulnerability has been patched, so you should update to version 3.7.0.

Envo Extra

Plugin:

Envo Extra

Plugin Slug:
envo-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.17

Severity Score:
Medium

CVE:

2024-4385

The vulnerability has been patched, so you should update to version 1.8.17.

Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin

Plugin:

Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider WordPress Plugin

Plugin Slug:
logo-slider-wp

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.0.0

Severity Score:
Medium

CVE:

2024-3288

The vulnerability has been patched, so you should update to version 4.0.0.

Post Grid Elementor Addon

Plugin:

Post Grid Elementor Addon

Plugin Slug:
post-grid-elementor-addon

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.17

Severity Score:
Medium

CVE:

2024-34789

The vulnerability has been patched, so you should update to version 2.0.17.

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin:

WPZOOM Addons for Elementor (Templates, Widgets)

Plugin Slug:
wpzoom-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.37

Severity Score:
Medium

CVE:

2024-4370

The vulnerability has been patched, so you should update to version 1.1.37.

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin

Plugin:

BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin

Plugin Slug:
bookingpress-appointment-booking

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.0.83

Severity Score:
Medium

CVE:

2024-34799

The vulnerability has been patched, so you should update to version 1.0.83.

Mega Elements – Addons for Elementor

Plugin:

Mega Elements – Addons for Elementor

Plugin Slug:
mega-elements-addons-for-elementor

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.2

Severity Score:
Medium

CVE:

2024-4702

The vulnerability has been patched, so you should update to version 1.2.2.

Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages

Plugin:

Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages

Plugin Slug:
page-builder-add

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.1.9

Severity Score:
High

CVE:

2024-34752

The vulnerability has been patched, so you should update to version 1.5.1.9.

ReviewX – Multi-criteria Rating & Reviews for WooCommerce

Plugin:

ReviewX – Multi-criteria Rating & Reviews for WooCommerce

Plugin Slug:
reviewx

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.28

Severity Score:
Medium

CVE:

2024-3609

The vulnerability has been patched, so you should update to version 1.6.28.

Simple Basic Contact Form

Plugin:

Simple Basic Contact Form

Plugin Slug:
simple-basic-contact-form

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
20240511

Severity Score:
Medium

CVE:

2024-4144

The vulnerability has been patched, so you should update to version 20240511.

140+ Widgets | Best Addons For Elementor – FREE

Plugin:

140+ Widgets | Best Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.3.1

Severity Score:
Medium

CVE:

2024-4440

The vulnerability has been patched, so you should update to version 1.4.3.1.

YITH WooCommerce Gift Cards

Plugin:

YITH WooCommerce Gift Cards

Plugin Slug:
yith-woocommerce-gift-cards

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
4.13.0

Severity Score:
Medium

CVE:

2024-0870

The vulnerability has been patched, so you should update to version 4.13.0.

Alt Text AI – Automatically generate image alt text for SEO and accessibility

Plugin:

Alt Text AI – Automatically generate image alt text for SEO and accessibility

Plugin Slug:
alttext-ai

Installations
9,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.0

Severity Score:
High

CVE:

2024-4847

The vulnerability has been patched, so you should update to version 1.5.0.

WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc

Plugin:

WP SMS – Messaging, SMS & MMS Notifications, 2FA & OTP for WordPress, WooCommerce, GravityForms, etc

Plugin Slug:
wp-sms

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.5.2

Severity Score:
Medium

CVE:

2024-34811

The vulnerability has been patched, so you should update to version 6.5.2.

VikBooking Hotel Booking Engine & PMS

Plugin:

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking

Installations
8,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.6.8

Severity Score:
Medium

CVE:

2024-2441

The vulnerability has been patched, so you should update to version 1.6.8.

Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms

Plugin:

Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms

Plugin Slug:
cf7-hubspot

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.3.2

Severity Score:
Medium

CVE:

2024-34756

The vulnerability has been patched, so you should update to version 1.3.2.

WP Compress – Image Optimizer [All-In-One]

Plugin:

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.20.02

Severity Score:
Medium

CVE:

2024-4445

The vulnerability has been patched, so you should update to version 6.20.02.

WP Compress – Image Optimizer [All-In-One]

Plugin:

WP Compress – Image Optimizer [All-In-One]

Plugin Slug:
wp-compress-image-optimizer

Installations
7,000+

Vulnerability:
Open Redirection

Patched in Version:
6.20.02

Severity Score:
Medium

CVE:

2023-6812

The vulnerability has been patched, so you should update to version 6.20.02.

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin:

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin Slug:
borderless

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
Medium

CVE:

2024-34757

The vulnerability has been patched, so you should update to version 1.5.4.

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin:

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin Slug:
borderless

Installations
6,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.4

Severity Score:
Medium

CVE:

2024-4666

The vulnerability has been patched, so you should update to version 1.5.4.

JCH Optimize

Plugin:

JCH Optimize

Plugin Slug:
jch-optimize

Installations
6,000+

Vulnerability:
Path Traversal

Patched in Version:
4.2.1

Severity Score:
Medium

CVE:

2024-34808

The vulnerability has been patched, so you should update to version 4.2.1.

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress

Plugin:

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress

Plugin Slug:
radio-player

Installations
6,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.0.74

Severity Score:
Medium

CVE:

2024-34753

The vulnerability has been patched, so you should update to version 2.0.74.

Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )

Plugin:

Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )

Plugin Slug:
magical-addons-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.38

Severity Score:
Medium

CVE:

2024-2923

The vulnerability has been patched, so you should update to version 1.1.38.

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Plugin:

Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid

Plugin Slug:
magazine-blocks

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium

CVE:

2024-34760

The vulnerability has been patched, so you should update to version 1.3.7.

Move Addons for Elementor

Plugin:

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium

CVE:

2024-4695

The vulnerability has been patched, so you should update to version 1.3.2.

YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress

Plugin:

YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress

Plugin Slug:
youtube-showcase

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
3.4.0

Severity Score:
Medium

CVE:

2024-3268

The vulnerability has been patched, so you should update to version 3.4.0.

Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Plugin:

Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Plugin Slug:
cf7-salesforce

Installations
2,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.4.0

Severity Score:
Medium

CVE:

2024-34755

The vulnerability has been patched, so you should update to version 1.4.0.

Debug Log – Manger Tool

Plugin:

Debug Log – Manger Tool

Plugin Slug:
debug-log-config-tool

Installations
2,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.5

Severity Score:
Medium

CVE:

2024-34798

The vulnerability has been patched, so you should update to version 1.5.

FundEngine – Donation and Crowdfunding Platform

Plugin:

FundEngine – Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.7.0

Severity Score:
Medium

CVE:

2024-34758

The vulnerability has been patched, so you should update to version 1.7.0.

Kognetiks Chatbot for WordPress

Plugin:

Kognetiks Chatbot for WordPress

Plugin Slug:
chatbot-chatgpt

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
2.0.1

Severity Score:
Critical

CVE:

2024-32700

The vulnerability has been patched, so you should update to version 2.0.1.

Copymatic – AI Content Writer & Generator

Plugin:

Copymatic – AI Content Writer & Generator

Plugin Slug:
copymatic

Installations
1,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.7

Severity Score:
Critical

CVE:

2024-31351

The vulnerability has been patched, so you should update to version 1.7.

Custom Post Type Attachment

Plugin:

Custom Post Type Attachment

Plugin Slug:
custom-post-type-pdf-attachment

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.6

Severity Score:
Medium

CVE:

2024-4546

The vulnerability has been patched, so you should update to version 3.4.6.

Fastly

Plugin:

Fastly

Plugin Slug:
fastly

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.26

Severity Score:
Medium

CVE:

2024-34803

The vulnerability has been patched, so you should update to version 1.2.26.

Fastly

Plugin:

Fastly

Plugin Slug:
fastly

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.26

Severity Score:
Medium

CVE:

2024-34768

The vulnerability has been patched, so you should update to version 1.2.26.

Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table

Plugin:

Contact Form Widget – Contact Query, Contact Page, Form Maker, Query Table

Plugin Slug:
new-contact-form-widget

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.4.0

Severity Score:
Medium

CVE:

2024-34754

The vulnerability has been patched, so you should update to version 1.4.0.

Save as PDF Plugin by Pdfcrowd

Plugin:

Save as PDF Plugin by Pdfcrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.0

Severity Score:
Medium

CVE:

2023-5971

The vulnerability has been patched, so you should update to version 3.2.0.

ShiftController Employee Shift Scheduling

Plugin:

ShiftController Employee Shift Scheduling

Plugin Slug:
shiftcontroller

Installations
1,000+

Vulnerability:
PHP Object Injection

Patched in Version:
4.9.58

Severity Score:
High

CVE:

2024-4733

The vulnerability has been patched, so you should update to version 4.9.58.

Popup Builder

Plugin:

Popup Builder

Plugin Slug:
easy-notify-lite

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.30

Severity Score:
Medium

CVE:

2024-34567

The vulnerability has been patched, so you should update to version 1.1.30.

Picture Gallery – Frontend Image Uploads, AJAX Photo List

Plugin:

Picture Gallery – Frontend Image Uploads, AJAX Photo List

Plugin Slug:
picture-gallery

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.12

Severity Score:
Medium

CVE:

2024-34759

The vulnerability has been patched, so you should update to version 1.5.12.

Popup – Popup More Popups

Plugin:

Popup – Popup More Popups

Plugin Slug:
popup-more

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium

CVE:

2024-32800

The vulnerability has been patched, so you should update to version 2.3.3.

Builder for WooCommerce product reviews shortcodes – ReviewShort

Plugin:

Builder for WooCommerce product reviews shortcodes – ReviewShort

Plugin Slug:
woo-product-reviews-shortcode

Installations
300+

Vulnerability:
Broken Access Control

Patched in Version:
1.01.6

Severity Score:
Medium

CVE:

2024-34763

The vulnerability has been patched, so you should update to version 1.01.6.

Bulk Posts Editing For WordPress

Plugin:

Bulk Posts Editing For WordPress

Plugin Slug:
ithemeland-bulk-posts-editing-lite

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
4.2.4

Severity Score:
Medium

CVE:

2024-4204

The vulnerability has been patched, so you should update to version 4.2.4.

Bulk Posts Editing For WordPress

Plugin:

Bulk Posts Editing For WordPress

Plugin Slug:
ithemeland-bulk-posts-editing-lite

Installations
200+

Vulnerability:
Broken Access Control

Patched in Version:
4.2.4

Severity Score:
Medium

CVE:

2024-4199

The vulnerability has been patched, so you should update to version 4.2.4.

month name translation benaceur

Plugin:

month name translation benaceur

Plugin Slug:
month-name-translation-benaceur

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.8

Severity Score:
Medium

CVE:

2024-3634

The vulnerability has been patched, so you should update to version 2.3.8.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Arbitrary Code Execution

Patched in Version:
6.2.10

Severity Score:
High

CVE:

2024-34761

The vulnerability has been patched, so you should update to version 6.2.10.

Advanced Custom Fields PRO

Plugin:

Advanced Custom Fields PRO

Plugin Slug:
advanced-custom-fields-pro

Vulnerability:
Local File Inclusion

Patched in Version:
6.2.10

Severity Score:
Critical

CVE:

2024-34762

The vulnerability has been patched, so you should update to version 6.2.10.

ConvertPlus

Plugin:

ConvertPlus

Plugin Slug:
convertplug

Vulnerability:
PHP Object Injection

Patched in Version:
3.5.26.1

Severity Score:
High

CVE:

2024-4838

The vulnerability has been patched, so you should update to version 3.5.26.1.

Cost Calculator Builder Pro

Plugin:

Cost Calculator Builder Pro

Plugin Slug:
cost-calculator-builder-pro

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
3.1.73

Severity Score:
Medium

CVE:

2024-4789

The vulnerability has been patched, so you should update to version 3.1.73.

ElementsKit Pro

Plugin:

ElementsKit Pro

Plugin Slug:
elementskit

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.2

Severity Score:
Medium

CVE:

2024-4452

The vulnerability has been patched, so you should update to version 3.6.2.

Penci Soledad Data Migrator

Plugin:

Penci Soledad Data Migrator

Plugin Slug:
penci-data-migrator

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.1

Severity Score:
Critical

CVE:

2024-3551

The vulnerability has been patched, so you should update to version 1.3.1.

Swift Framework Page Builder

Plugin:

Swift Framework Page Builder

Plugin Slug:
socialdriver-framework

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2024.0.0

Severity Score:
Medium

CVE:

2024-2697

The vulnerability has been patched, so you should update to version 2024.0.0.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.7.1

Severity Score:
High

CVE:

2024-4352

The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Broken Access Control

Patched in Version:
2.7.1

Severity Score:
High

CVE:

2024-4222

The vulnerability has been patched, so you should update to version 2.7.1.

Tutor LMS Pro

Plugin:

Tutor LMS Pro

Plugin Slug:
tutor-pro

Vulnerability:
Privilege Escalation

Patched in Version:
2.7.1

Severity Score:
High

CVE:

2024-4351

The vulnerability has been patched, so you should update to version 2.7.1.

Uber Menu

Plugin:

Uber Menu

Plugin Slug:
ubermenu

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.3

Severity Score:
Medium

CVE:

2024-4710

The vulnerability has been patched, so you should update to version 3.8.3.

Automatic

Plugin:

Automatic

Plugin Slug:
wp-automatic

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.95.0

Severity Score:
Medium

CVE:

2024-4849

The vulnerability has been patched, so you should update to version 3.95.0.

WordPress Themes — 10 Patched / 1 Unpatched

ImageMagick Sharpen Resized Images

Theme:

ImageMagick Sharpen Resized Images

Theme Slug:
imagemagick-sharpen-resized-images

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-34790

The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,200,500

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.47

Severity Score:
Medium

CVE:

2024-4943

The vulnerability has been patched, so you should update to version 2.0.47.

ChaosTheory

Theme:

ChaosTheory

Theme Slug:
chaostheory

Downloads
441,334

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.2

Severity Score:
Medium

CVE:

2024-34766

The vulnerability has been patched, so you should update to version 1.3.2.

Consus

Theme:

Consus

Theme Slug:
consus

Downloads
16,413

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.7.

EmpowerWP

Theme:

EmpowerWP

Theme Slug:
empowerwp

Downloads
219,617

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.22

Severity Score:
Medium

CVE:

2024-34809

The vulnerability has been patched, so you should update to version 1.0.22.

Ketos

Theme:

Ketos

Theme Slug:
ketos

Downloads
28,821

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.6

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.6.

Mindscape

Theme:

Mindscape

Theme Slug:
mindscape

Downloads
42,404

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.23

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.23.

Niveau

Theme:

Niveau

Theme Slug:
niveau

Downloads
16,949

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.9

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.9.

Oasis

Theme:

Oasis

Theme Slug:
oasis

Downloads
69,561

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.13

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.13.

Skyline WP

Theme:

Skyline WP

Theme Slug:
skyline-wp

Downloads
169,826

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.11

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.11.

Zeka

Theme:

Zeka

Theme Slug:
zeka

Downloads
20,361

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.0.10

Severity Score:
Medium

CVE:

2024-34810

The vulnerability has been patched, so you should update to version 1.0.10.

window[“98929d30_4e56_4573_ada9_2473c5bdf5a9”] = {“blockId”:”98929d30-4e56-4573-ada9-2473c5bdf5a9″,”className”:””,”heading”:”Solid Security is part of Solid Suite \u2014 The best foundation for WordPress websites.”,”text”:”Every WordPress site needs security, backups, and management tools. That\u2019s Solid Suite \u2014 an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy\u2019s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!”,”buttonText”:”Get Solid Security”,”buttonLink”:”\/pricing”,”buttonTarget”:”_self”,”buttonRel”:””};

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — May 22, 2024 appeared first on SolidWP.

Source link

Written by:
Abdul Wahid
Published on:
May 23, 2024

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (6)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

WordPress: A Powerhouse for Achieving Internet …

Continue Reading about Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter