• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report – September 6, 2023

WordPress Vulnerability Report – September 6, 2023

Written by

Dan Knauss

on

September 6, 2023

Last Updated on September 6, 2023

Since last week, 95 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 32 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 60 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT SEPT 6TH @ 1:00 P.M. (CT)

Discover essential best practices for safeguarding your WordPress website through proactive security measures. Join WordPress security expert Thomas Raef as he explains the art and science of WordPress security, focusing on three key dimensions: hosting, WordPress configurations, and user management. You’ll also learn how Solid Security equips users with tools that diminish hacking risks, focusing on safeguarding plugins, themes, and user accounts.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

GTranslate

Product image for Translate WordPress with GTranslate.

Plugin Slug
gtranslate

Installations
500,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.0.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.0.4.

Forminator

Product image for Forminator – Contact Form, Payment Form & Custom Form Builder.

Plugin Slug
forminator

Installations
400,000+

Vulnerability
Arbitrary File Upload

Patched in Version
1.25.0

Severity Score
Critical

The vulnerability has been patched, so you should update to version 1.25.0.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder.

Plugin Slug
metform

Installations
200,000+

Vulnerability
Sensitive Data Exposure

Patched in Version
3.3.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.2.

Social Media & Share Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slug
ultimate-social-media-icons

Installations
200,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.8.4

Severity Score
High

The vulnerability has been patched, so you should update to version 2.8.4.

GiveWP

Product image for GiveWP – Donation Plugin and Fundraising Platform.

Plugin Slug
give

Installations
100,000+

Vulnerability
Privilege Escalation

Patched in Version
2.33.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.33.1.

UserFeedback Lite

Product image for User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds.

Plugin Slug
userfeedback-lite

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0.8

Severity Score
High

The vulnerability has been patched, so you should update to version 1.0.8.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slug
wp-slimstat

Installations
100,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
5.0.10

Severity Score
Medium

The vulnerability has been patched, so you should update to version 5.0.10.

Email Encoder

Product image for Email Encoder – Protect Email Addresses and Phone Numbers.

Plugin Slug
email-encoder-bundle

Installations
80,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.1.8

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.1.8.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.

Plugin Slug
folders

Installations
60,000+

Vulnerability
Arbitrary File Upload

Patched in Version
2.9.3

Severity Score
Critical

The vulnerability has been patched, so you should update to version 2.9.3.

Popup Box

Product image for Popup box.

Plugin Slug
ays-popup-box

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.7.2

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.7.2.

GS Logo Slider

Product image for Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.

Plugin Slug
gs-logo-slider

Installations
20,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
3.4.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.4.3.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slug
wedevs-project-manager

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
2.6.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.6.1.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slug
wedevs-project-manager

Installations
10,000+

Vulnerability
SQL Injection

Patched in Version
2.6.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.6.1.

WP Super Minify

Product image for WP Super Minify.

Plugin Slug
wp-super-minify

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.6

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.6.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).

Plugin Slug
post-to-google-my-business

Installations
9,000+

Vulnerability
Broken Access Control

Patched in Version
3.1.15

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.1.15.

SureCart

Product image for WordPress Ecommerce For Creating Fast Online Stores – By SureCart.

Plugin Slug
surecart

Installations
8,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.5.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.5.1.

HollerBox

Product image for Fast & Effective Popups & Lead-Generation for WordPress – HollerBox.

Plugin Slug
holler-box

Installations
5,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.3.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.3.3.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slug
order-tracking

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.3.7

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slug
order-tracking

Installations
4,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.3.7

Severity Score
High

The vulnerability has been patched, so you should update to version 3.3.7.

Leyka

Product image for Leyka.

Plugin Slug
leyka

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
3.30.3

Severity Score
Medium

The vulnerability has been patched, so you should update to version 3.30.3.

WP Search Analytics

Product image for WP Search Analytics.

Plugin Slug
search-analytics

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.4.8

Severity Score
High

The vulnerability has been patched, so you should update to version 1.4.8.

Sitekit

Product image for Sitekit.

Plugin Slug
sitekit

Installations
2,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.4

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.

Prevent files / folders access

Product image for Prevent files / folders access.

Plugin Slug
prevent-file-access

Installations
1,000+

Vulnerability
Arbitrary File Upload

Patched in Version
2.5.2

Severity Score
High

The vulnerability has been patched, so you should update to version 2.5.2.

WP Pipes

Product image for WP Pipes.

Plugin Slug
wp-pipes

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
1.4.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 1.4.1.

Photo Gallery Slideshow & Masonry Tiled Gallery

Product image for Photo Gallery Slideshow & Masonry Tiled Gallery.

Plugin Slug
wp-responsive-photo-gallery

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
1.0.14

Severity Score
High

The vulnerability has been patched, so you should update to version 1.0.14.

RSVPMaker

Product image for RSVPMaker.

Plugin Slug
rsvpmaker

Installations
400+

Vulnerability
SQL Injection

Patched in Version
10.6.7

Severity Score
High

The vulnerability has been patched, so you should update to version 10.6.7.

AffiliateWP

Plugin
AffiliateWP

Plugin Slug
affiliatewp

Vulnerability
Broken Access Control

Patched in Version
2.14.1

Severity Score
Medium

The vulnerability has been patched, so you should update to version 2.14.1.

All-in-One WP Migration Box Extension

Plugin
All-in-One WP Migration Box Extension

Plugin Slug
all-in-one-wp-migration-box-extension

Vulnerability
Broken Access Control

Patched in Version
1.54

Severity Score
High

The vulnerability has been patched, so you should update to version 1.54.

All-in-One WP Migration Dropbox Extension

Plugin
All-in-One WP Migration Dropbox Extension

Plugin Slug
all-in-one-wp-migration-dropbox-extension

Vulnerability
Broken Access Control

Patched in Version
3.76

Severity Score
High

The vulnerability has been patched, so you should update to version 3.76.

All-in-One WP Migration Google Drive Extension

Plugin
All-in-One WP Migration Google Drive Extension

Plugin Slug
all-in-one-wp-migration-gdrive-extension

Vulnerability
Broken Access Control

Patched in Version
2.80

Severity Score
High

The vulnerability has been patched, so you should update to version 2.80.

All-in-One WP Migration OneDrive Extension

Plugin
All-in-One WP Migration OneDrive Extension

Plugin Slug
all-in-one-wp-migration-onedrive-extension

Vulnerability
Broken Access Control

Patched in Version
1.67

Severity Score
High

The vulnerability has been patched, so you should update to version 1.67.

Happy Elementor Addons Pro

Plugin
Happy Elementor Addons Pro

Plugin Slug
happy-elementor-addons-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
2.8.1

Severity Score
High

The vulnerability has been patched, so you should update to version 2.8.1.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

PowerPress Podcasting plugin by Blubrry

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slug
powerpress

Installations
40,000+

Vulnerability
Server Side Request Forgery (SSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Conversion Tracking

Product image for WooCommerce Conversion Tracking.

Plugin Slug
woocommerce-conversion-tracking

Installations
40,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.

Plugin Slug
ultimate-addons-for-contact-form-7

Installations
20,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.

Plugin Slug
directorist

Installations
10,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Export Import Menus

Product image for Export Import Menus.

Plugin Slug
export-import-menus

Installations
10,000+

Vulnerability
Arbitrary File Upload

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

Legal Pages

Product image for Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator.

Plugin Slug
legal-pages

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.

Plugin Slug
mts-url-shortener

Installations
10,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Texty

Product image for Texty – SMS Notification for WordPress, WooCommerce, Dokan and more.

Plugin Slug
texty

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

weMail

Product image for weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin.

Plugin Slug
wemail

Installations
10,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Product image for Better Elementor Addons.

Plugin Slug
better-elementor-addons

Installations
7,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.

Plugin Slug
easy-coming-soon

Installations
7,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Login and Logout Redirect

Product image for Login and Logout Redirect.

Plugin Slug
login-and-logout-redirect

Installations
7,000+

Vulnerability
Open Redirection

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin Slug
authldap

Installations
6,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin Slug
authldap

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.

Plugin Slug
luckywp-scripts-control

Installations
6,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Product image for Multi-column Tag Map.

Plugin Slug
multi-column-tag-map

Installations
6,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Responsive Gallery Grid

Product image for Responsive Gallery Grid.

Plugin Slug
responsive-gallery-grid

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin Slug
social-share-boost

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elementor Inner Sections By BoomDevs

Product image for Unlimited Elementor Inner Sections By BoomDevs.

Plugin Slug
unlimited-elementor-inner-sections-by-boomdevs

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

weDocs – Knowledgebase and Documentation Plugin for WordPress

Product image for weDocs – Knowledgebase and Documentation Plugin for WordPress.

Plugin Slug
wedocs

Installations
6,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).

Plugin Slug
makestories-helper

Installations
5,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

MyCryptoCheckout

Product image for MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce.

Plugin Slug
mycryptocheckout

Installations
5,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Remove/hide Author, Date, Category Like Entry-Meta

Product image for Remove/hide Author, Date, Category Like Entry-Meta.

Plugin Slug
removehide-author-date-category-like-entry-meta

Installations
5,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Surfer

Product image for Surfer – WordPress Plugin.

Plugin Slug
surferseo

Installations
5,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Product image for Leadster.

Plugin Slug
leadster-marketing-conversacional

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Ovic Product Bundle

Product image for Ovic Product Bundle.

Plugin Slug
ovic-product-bundle

Installations
4,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Pricing Deals for WooCommercePricing Deals for WooCommerce

Plugin Slug
pricing-deals-for-woocommerce

Installations
4,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin Slug
wp-users-media

Installations
4,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Migration Plugin DB & Files – WP Synchro

Product image for WP Synchro – WordPress Migration Plugin for Database & Files.

Plugin Slug
wpsynchro

Installations
4,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Live News

Product image for Live News.

Plugin Slug
live-news-lite

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Plugin Slug
realbig-media

Installations
3,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

TelSender

Product image for TelSender – ?ontact form 7, Events, Wpforms  and wooccommerce to telegram bot.

Plugin Slug
telsender

Installations
3,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce PensoPay

Plugin Slug
woo-pensopay

Installations
3,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Hide admin notices – Admin Notification Center

Plugin Slug
wp-admin-notification-center

Installations
2,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WRC Pricing Tables

Product image for WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables.

Plugin Slug
wrc-pricing-tables

Installations
2,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug
bulk-noindex-nofollow-toolkit-by-mad-fish

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Product image for Exclusive Team for Elementor.

Plugin Slug
exclusive-team-for-elementor

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin Slug
goods-catalog

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.

Plugin Slug
olive-one-click-demo-import

Installations
1,000+

Vulnerability
Arbitrary File Upload

Patched in Version
No Fix

Severity Score
Critical

The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Product image for Stock Quotes List.

Plugin Slug
stock-quotes-list

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Product image for Product Category Showcase for WooCommerce.

Plugin Slug
wc-category-showcase

Installations
1,000+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WiserNotify Social Proof

Product image for WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets.

Plugin Slug
wiser-notify

Installations
1,000+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

WP Bannerize Pro

Product image for WP Bannerize Pro.

Plugin Slug
wp-bannerize-pro

Installations
1,000+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Plugin Slug
tilda-publishing

Installations
900+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Newsletter Signups

Product image for Easy Newsletter Signups.

Plugin Slug
easy-newsletter-signups

Installations
800+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Snap Pixel

Product image for Snap Pixel.

Plugin Slug
snap-pixel

Installations
800+

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.

Plugin Slug
wc-support-system

Installations
300+

Vulnerability
Broken Access Control

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.

Plugin Slug
wc-support-system

Installations
300+

Vulnerability
SQL Injection

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

Localize Remote Images

Plugin Slug
localize-remote-images

Installations
10+

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Bridge Core

Plugin
Bridge Core

Plugin Slug
bridge-core

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should deactivate the plugin.

WordPress CTA

Plugin
WordPress CTA

Plugin Slug
easy-sticky-sidebar

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

Plugin
Font Awesome 4 Menus

Plugin Slug
font-awesome-4-menus

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin Slug
guruwalk-affiliates

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched. You should deactivate the plugin.

Maintenance Switch

Plugin
Maintenance Switch

Plugin Slug
maintenance-switch

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sermon’e – Sermons Online

Plugin
Sermon’e – Sermons Online

Plugin Slug
sermone-online-sermons-management

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

SIS Handball

Plugin
SIS Handball

Plugin Slug
sis-handball

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Smarty for WordPress

Plugin
Smarty for WordPress

Plugin Slug
smarty-for-wordpress

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

Plugin
Use Memcached

Plugin Slug
use-memcached

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin
WP-dTree

Plugin Slug
wp-dtree-30

Vulnerability
Cross Site Request Forgery (CSRF)

Patched in Version
No Fix

Severity Score
Medium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

Plugin
WP-dTree

Plugin Slug
wp-dtree-30

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Attorney

Product image for Attorney.

Theme Slug
attorney

Downloads
51,489

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.

Arya Multipurpose Pro

Theme
Arya Multipurpose Pro

Theme Slug
arya-multipurpose-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.

Everest News Pro

Theme
Everest News Pro

Theme Slug
everest-news-pro

Vulnerability
Cross Site Scripting (XSS)

Patched in Version
No Fix

Severity Score
High

The vulnerability has not been patched. You should switch themes.
Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Source link

Written by:
Abdul Wahid
Published on:
September 10, 2023

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter