Since last week, 48 total vulnerabilities have emerged in public disclosure. They may affect over three million WordPress sites. There are 39 plugin vulnerabilities with security patches, so run those updates!
Additionally, there are nine plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
WordPress Core Vulnerabilities — Patched
WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.
These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.
Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.
Website Builder by SeedProd
- Plugin Slug
- coming-soon
- Installations
- 1,000,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 6.15.15.3
- Severity Score
- Medium
Ad Inserter
- Plugin Slug
- ad-inserter
- Installations
- 300,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 2.7.31
- Severity Score
- Medium
Ad Inserter
- Plugin Slug
- ad-inserter
- Installations
- 300,000+
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- 2.7.31
- Severity Score
- Medium
Table of Contents Plus
- Plugin Slug
- table-of-contents-plus
- Installations
- 300,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2309
- Severity Score
- Medium
WPvivid
- Plugin Slug
- wpvivid-backuprestore
- Installations
- 300,000+
- Vulnerability
- Arbitrary File Deletion
- Patched in Version
- 0.9.90
- Severity Score
- High
WPvivid
- Plugin Slug
- wpvivid-backuprestore
- Installations
- 300,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 0.9.90
- Severity Score
- Medium
iframe
- Plugin Slug
- iframe
- Installations
- 100,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 4.7
- Severity Score
- Medium
wpDiscuz
- Plugin Slug
- wpdiscuz
- Installations
- 80,000+
- Vulnerability
- SQL Injection
- Patched in Version
- 7.6.6
- Severity Score
- Critical
Media Library Assistant
- Plugin Slug
- media-library-assistant
- Installations
- 70,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.11
- Severity Score
- Medium
Connect Matomo (WP-Matomo, WP-Piwik)
- Plugin Slug
- wp-piwik
- Installations
- 60,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.0.29
- Severity Score
- Medium
Simple Membership
- Plugin Slug
- simple-membership
- Installations
- 50,000+
- Vulnerability
- Privilege Escalation
- Patched in Version
- 4.3.5
- Severity Score
- High
Simple Membership
- Plugin Slug
- simple-membership
- Installations
- 50,000+
- Vulnerability
- Privilege Escalation
- Patched in Version
- 4.3.5
- Severity Score
- High
Ditty
- Plugin Slug
- ditty-news-ticker
- Installations
- 40,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.1.25
- Severity Score
- High
BEAR
- Plugin Slug
- woo-bulk-editor
- Installations
- 30,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- 1.1.4
- Severity Score
- Medium
BEAR
- Plugin Slug
- woo-bulk-editor
- Installations
- 30,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 1.1.4
- Severity Score
- Medium
Poptin
- Plugin Slug
- poptin
- Installations
- 20,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.3.1
- Severity Score
- Medium
Copy Anything to Clipboard
- Plugin Slug
- copy-the-code
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.6.5
- Severity Score
- Medium
Statify
- Plugin Slug
- extended-evaluation-for-statify
- Installations
- 10,000+
- Vulnerability
- CSV Injection
- Patched in Version
- 2.6.4
- Severity Score
- Medium
Modal Window
- Plugin Slug
- modal-window
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 5.3.6
- Severity Score
- Medium
Options for Twenty Seventeen
- Plugin Slug
- options-for-twenty-seventeen
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.5.1
- Severity Score
- Medium
WP Mailto Links
- Plugin Slug
- wp-mailto-links
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.1.4
- Severity Score
- Medium
Widget Responsive for Youtube
- Plugin Slug
- youtube-widget-responsive
- Installations
- 10,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.6.2
- Severity Score
- Medium
iPanorama 360 – WordPress Virtual Tour Builder
- Plugin Slug
- ipanorama-360-virtual-tour-builder-lite
- Installations
- 7,000+
- Vulnerability
- SQL Injection
- Patched in Version
- 1.8.0
- Severity Score
- High
Drag and Drop Multiple File Upload
- Plugin Slug
- drag-and-drop-multiple-file-upload-for-woocommerce
- Installations
- 4,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.1.1
- Severity Score
- High
DoLogin Security
- Plugin Slug
- dologin
- Installations
- 3,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.7
- Severity Score
- High
Import XML and RSS Feeds
- Plugin Slug
- import-xml-feed
- Installations
- 3,000+
- Vulnerability
- Remote Code Execution (RCE)
- Patched in Version
- 2.1.5
- Severity Score
- Critical
Import XML and RSS Feeds
- Plugin Slug
- import-xml-feed
- Installations
- 3,000+
- Vulnerability
- Arbitrary File Upload
- Patched in Version
- 2.1.4
- Severity Score
- Critical
Pretty Google Calendar
- Plugin Slug
- pretty-google-calendar
- Installations
- 2,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.6.0
- Severity Score
- Medium
WPSchoolPress
- Plugin Slug
- wpschoolpress
- Installations
- 2,000+
- Vulnerability
- Cross Site Request Forgery (CSRF)
- Patched in Version
- 2.2.5
- Severity Score
- Medium
Bit Assist
- Plugin Slug
- bit-assist
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.2
- Severity Score
- Medium
Leaflet Map
- Plugin Slug
- extensions-leaflet-map
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.3.1
- Severity Score
- Medium
Simple Posts Ticker
- Plugin Slug
- simple-posts-ticker
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.1.6
- Severity Score
- Medium
Simple Posts Ticker
- Plugin Slug
- simple-posts-ticker
- Installations
- 1,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.1.6
- Severity Score
- Medium
Funnelforms Free
- Plugin Slug
- funnelforms-free
- Installations
- 800+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 3.4
- Severity Score
- High
User Avatar – Reloaded
- Plugin Slug
- user-avatar-reloaded
- Installations
- 800+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.2.2
- Severity Score
- Medium
Memberlite Shortcodes
- Plugin Slug
- memberlite-shortcodes
- Installations
- 700+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 1.3.9
- Severity Score
- Medium
Serial Codes Generator and Validator with WooCommerce Support
- Plugin Slug
- serial-codes-generator-and-validator
- Installations
- 600+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.4.15
- Severity Score
- Medium
User Activity Log Pro
- Plugin
- User Activity Log Pro
- Plugin Slug
- user-activity-log-pro
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- 2.3.4
- Severity Score
- High
User Activity Log Pro
- Plugin
- User Activity Log Pro
- Plugin Slug
- user-activity-log-pro
- Vulnerability
- Bypass Vulnerability
- Patched in Version
- 2.3.4
- Severity Score
- Medium
WordPress Plugin Vulnerabilities — Unpatched
This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.
Popup Builder
- Plugin Slug
- popup-builder
- Installations
- 200,000+
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
Active Directory Integration / LDAP Integration
- Plugin Slug
- ldap-login-for-intranet-sites
- Installations
- 5,000+
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Low
WP Job Portal
- Plugin Slug
- wp-job-portal
- Installations
- 3,000+
- Vulnerability
- SQL Injection
- Patched in Version
- No Fix
- Severity Score
- Critical
Staff / Employee Business Directory for Active Directory
- Plugin Slug
- ldap-ad-staff-employee-directory-search
- Installations
- 10+
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Low
Easy Registration Forms
- Plugin
- Easy Registration Forms
- Plugin Slug
- easy-registration-forms
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- No Fix
- Severity Score
- Medium
Contact Form by FormGet
- Plugin
- FormGet Contact Form
- Plugin Slug
- formget-contact-form
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
Super Store Finder
- Plugin
- Super Store Finder
- Plugin Slug
- superstorefinder-wp
- Vulnerability
- Broken Access Control
- Patched in Version
- No Fix
- Severity Score
- Medium
Vrm 360 3D Model Viewer
- Plugin
- Vrm 360 3D Model Viewer
- Plugin Slug
- vrm360
- Vulnerability
- Sensitive Data Exposure
- Patched in Version
- No Fix
- Severity Score
- Medium
Charts
- Plugin
- wp-charts
- Plugin Slug
- wp-charts
- Vulnerability
- Cross Site Scripting (XSS)
- Patched in Version
- No Fix
- Severity Score
- Medium
WordPress Theme Vulnerabilities
In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.