WordPress Vulnerability Report – July 19, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON JULY 19, 2023
Last Updated on July 19, 2023
Since last week, 80 total vulnerabilities emerged in public disclosure. They may affect over 5 million WordPress sites. There are 55 plugin vulnerabilities with security patches available, so run those updates!
Additionally, there are 23 plugin vulnerabilities and two theme vulnerabilities with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- Rank Math SEO
- All In One WP Security
- Spectra
- Spectra
- FluentForm
- Post SMTP
- HT Mega Absolute Addons for Elementor
- ARPP – Yet Another Related Posts Plugin
- kk Star Ratings
- Media Library Assistant
- Advanced AJAX Product Filters
- HTTP Headers
- HTTP Headers
- Quiz And Survey Master
- Super Socializer
- JetFormBuilder
- IP2Location Country Blocker
- Yasr – Yet Another Stars Rating
- Booking Package SAASPROJECT
- User Activity Log
- Variation Swatches for WooCommerce
- Zippy
- Restaurant Menu and Food Ordering by Five Star
- Variation Images Gallery for WooCommerce
- BookingPress
- Buy Me a Coffee – Button and Widget Plugin
- Buy Me a Coffee – Button and Widget Plugin
- WooCommerce Product Stock Alert
- WooCommerce Product Stock Alert
- AnsPress – Question and answer
- WPFunnels
- WPFunnels
- Integrate Google Drive
- ARMember
- Authors List
- Integration for Contact Form 7 and Salesforce
- Gift Cards
- KB Support – WordPress Help Desk
- Short URL
- BuddyBuilder BuddyPress Builder for Elementor
- Checkout with Zelle on Woocommerce
- Custom Field For WP Job Manager
- DirectoryPress
- Falang multilanguage
- MF Gig Calendar
- WP Social AutoConnect
- MailArchiver
- CartFlows Pro
- Grid Kit Premium
- Premium Addons PRO
- Premium Addons PRO
- WooCommerce GoCardless Gateway
- WooCommerce Ship to Multiple Addresses
- WooCommerce Ship to Multiple Addresses
- WooCommerce Warranty Requests
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- Chat Button
- Coming Soon Chop Chop
- Slider a SlidersPack
- Exit Popups & Onsite Retargeting by OptiMonk
- Social Media Icons Widget
- Easyship WooCommerce Shipping Rates
- WPSchoolPress
- WPAdmin AWS CDN
- Contact Form Generator
- Contact Form to Any API
- Shortcode IMDB
- Radio Forge Muses Player with Skins
- Replace Word
- Art Direction
- WPBulky
- ShopConstruct
- Dovetail
- YourMembership Single Sign On
- YourMembership Single Sign On
- Twittee Text Tweet
- Mail Control
- PDQ CSV
- WP Default Feature Image
WordPress Plugin Vulnerabilities – Patched

1 - Rank Math SEO
Plugin -
Plugin Slug -
seo-by-rank-math
Installations -
2,000,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.0.119.1
Severity -
Medium
CVE Code -

2 - All-In-One Security (AIOS) – Security and Firewall
Plugin -
All-In-One Security (AIOS) – Security and Firewall
Plugin Slug -
all-in-one-wp-security-and-firewall
Installations -
1,000,000+
Vulnerability -
Sensitive Data Exposure of Plaintext Credentials
Patched In Version -
5.2.0
Severity -
Medium

3 - Spectra – WordPress Gutenberg Blocks
Plugin -
Spectra – WordPress Gutenberg Blocks
Plugin Slug -
ultimate-addons-for-gutenberg
Installations -
500,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
2.6.7
Severity -
High
CVE Code -

4 - Spectra – WordPress Gutenberg Blocks
Plugin -
Spectra – WordPress Gutenberg Blocks
Plugin Slug -
ultimate-addons-for-gutenberg
Installations -
500,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.6.7
Severity -
Medium
CVE Code -

5 - Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms
Plugin -
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms
Plugin Slug -
fluentform
Installations -
300,000+
Vulnerability -
SQL Injection
Patched In Version -
5.0.0
Severity -
Medium
CVE Code -

6 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin -
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin Slug -
post-smtp
Installations -
300,000+
Vulnerability -
Unauthenticated Stored Cross-Site Scripting via Email
Patched In Version -
2.5.8
Severity -
High
CVE Code -

7 - HT Mega – Absolute Addons For Elementor
Plugin -
HT Mega – Absolute Addons For Elementor
Plugin Slug -
ht-mega-for-elementor
Installations -
100,000+
Vulnerability -
Unauthenticated Privilege Escalation
Patched In Version -
2.2.1
Severity -
Critical
CVE Code -

8 - YARPP – Yet Another Related Posts Plugin
Plugin -
YARPP – Yet Another Related Posts Plugin
Plugin Slug -
yet-another-related-posts-plugin
Installations -
100,000+
Vulnerability -
Authenticated (Contributor+) Stored Cross Site Scripting (XSS)
Patched In Version -
5.30.4
Severity -
Medium
CVE Code -

9 - kk Star Ratings
Plugin -
Plugin Slug -
kk-star-ratings
Installations -
90,000+
Vulnerability -
Rate Manipulation due to IP Spoofing
Patched In Version -
5.4.4
Severity -
Medium
CVE Code -

10 - Media Library Assistant
Plugin -
Plugin Slug -
media-library-assistant
Installations -
70,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.0.8
Severity -
Medium
CVE Code -

11 - Advanced AJAX Product Filters
Plugin -
Plugin Slug -
woocommerce-ajax-filters
Installations -
60,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.6.3.4
Severity -
Medium
CVE Code -

12 - HTTP Headers
Plugin -
Plugin Slug -
http-headers
Installations -
40,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
1.19.0
Severity -
Medium
CVE Code -

13 - HTTP Headers
Plugin -
Plugin Slug -
http-headers
Installations -
40,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.19.0
Severity -
Medium
CVE Code -

14 - Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
Plugin -
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress
Plugin Slug -
quiz-master-next
Installations -
40,000+
Vulnerability -
Broken Access Control
Patched In Version -
8.1.11
Severity -
Medium
CVE Code -

15 - Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin -
Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin Slug -
super-socializer
Installations -
40,000+
Vulnerability -
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched In Version -
7.13.54
Severity -
Medium

16 - JetFormBuilder — Dynamic Blocks Form Builder
Plugin -
JetFormBuilder — Dynamic Blocks Form Builder
Plugin Slug -
jetformbuilder
Installations -
30,000+
Vulnerability -
Authenticated Privilege Escalation
Patched In Version -
3.0.9
Severity -
High
CVE Code -

17 - IP2Location Country Blocker
Plugin -
Plugin Slug -
ip2location-country-blocker
Installations -
20,000+
Vulnerability -
IP Bypass Vulnerability
Patched In Version -
2.29.2
Severity -
Medium
CVE Code -

18 - Yasr – Yet Another Stars Rating
Plugin -
Yasr – Yet Another Stars Rating
Plugin Slug -
yet-another-stars-rating
Installations -
20,000+
Vulnerability -
Race Condition
Patched In Version -
3.3.9
Severity -
Low
CVE Code -

19 - Booking Package
Plugin -
Plugin Slug -
booking-package
Installations -
10,000+
Vulnerability -
Unathenticated Privilege Escalation
Patched In Version -
1.5.99
Severity -
High
CVE Code -

20 - User Activity Log
Plugin -
Plugin Slug -
user-activity-log
Installations -
10,000+
Vulnerability -
SQL Injection
Patched In Version -
1.6.3
Severity -
High
CVE Code -

21 - Variation Swatches for WooCommerce
Plugin -
Variation Swatches for WooCommerce
Plugin Slug -
woo-product-variation-swatches
Installations -
10,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.3.8
Severity -
High
CVE Code -

22 - Zippy
Plugin -
Plugin Slug -
zippy
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.6.3
Severity -
Medium
CVE Code -

23 - Restaurant Menu and Food Ordering by Five Star Plugins
Plugin -
Restaurant Menu and Food Ordering by Five Star Plugins
Plugin Slug -
food-and-drink-menu
Installations -
8,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.4.7
Severity -
Medium
CVE Code -

24 - Variation Images Gallery for WooCommerce
Plugin -
Variation Images Gallery for WooCommerce
Plugin Slug -
woo-product-variation-gallery
Installations -
8,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.3.4
Severity -
High
CVE Code -

25 - BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin
Plugin -
BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin
Plugin Slug -
bookingpress-appointment-booking
Installations -
7,000+
Vulnerability -
Unauth. Server Information Disclosure
Patched In Version -
1.0.65
Severity -
Medium
CVE Code -

26 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.8
Severity -
Medium
CVE Code -

27 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.8
Severity -
Medium
CVE Code -

28 - WooCommerce Product Stock Alert
Plugin -
WooCommerce Product Stock Alert
Plugin Slug -
woocommerce-product-stock-alert
Installations -
6,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
2.0.2
Severity -
Medium
CVE Code -

29 - WooCommerce Product Stock Alert
Plugin -
WooCommerce Product Stock Alert
Plugin Slug -
woocommerce-product-stock-alert
Installations -
6,000+
Vulnerability -
Settings Change
Patched In Version -
2.0.2
Severity -
Medium
CVE Code -

30 - AnsPress – Question and answer
Plugin -
AnsPress – Question and answer
Plugin Slug -
anspress-question-answer
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
4.3.2
Severity -
Medium
CVE Code -

31 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin -
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin Slug -
wpfunnels
Installations -
5,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.7.17
Severity -
High
CVE Code -

32 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin -
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin Slug -
wpfunnels
Installations -
5,000+
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
2.7.16
Severity -
Medium

33 - Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site
Plugin -
Plugin Slug -
integrate-google-drive
Installations -
3,000+
Vulnerability -
Unauthenticated Broken Access Control
Patched In Version -
1.2.0
Severity -
Critical
CVE Code -

34 - ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Plugin -
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Plugin Slug -
armember-membership
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
4.0.6
Severity -
Medium
CVE Code -

35 - Authors List
Plugin -
Plugin Slug -
authors-list
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.0.3
Severity -
High
CVE Code -

36 - Integration for Contact Form 7 and Salesforce
Plugin -
Integration for Contact Form 7 and Salesforce
Plugin Slug -
cf7-salesforce
Installations -
2,000+
Vulnerability -
Open Redirection
Patched In Version -
1.3.4
Severity -
Medium
CVE Code -

37 - Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Plugin -
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Plugin Slug -
gift-voucher
Installations -
2,000+
Vulnerability -
Cross-Site Request Forgery in new_voucher_template.php
Patched In Version -
4.3.6
Severity -
Medium

38 - KB Support – WordPress Help Desk
Plugin -
KB Support – WordPress Help Desk
Plugin Slug -
kb-support
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.5.89
Severity -
Medium
CVE Code -


40 - BuddyPress Builder for Elementor – BuddyBuilder
Plugin -
BuddyPress Builder for Elementor – BuddyBuilder
Plugin Slug -
stax-buddy-builder
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.7.4
Severity -
Medium

41 - Checkout with Zelle on Woocommerce
Plugin -
Checkout with Zelle on Woocommerce
Plugin Slug -
wc-zelle
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.1.1
Severity -
Medium
CVE Code -

42 - Custom Field For WP Job Manager
Plugin -
Custom Field For WP Job Manager
Plugin Slug -
custom-field-for-wp-job-manager
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2
Severity -
Medium
CVE Code -

43 - DirectoryPress – Business Directory And Classified Ad Listing
Plugin -
DirectoryPress – Business Directory And Classified Ad Listing
Plugin Slug -
directorypress
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.6.3
Severity -
Medium
CVE Code -

44 - Falang multilanguage for WordPress
Plugin -
Falang multilanguage for WordPress
Plugin Slug -
falang
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.3.40
Severity -
Medium
CVE Code -
45 - MF Gig Calendar
Plugin -
Plugin Slug -
mf-gig-calendar
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2.1
Severity -
Medium
CVE Code -
46 - WP Social AutoConnect
Plugin -
Plugin Slug -
wp-fb-autoconnect
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
4.6.2
Severity -
Medium
CVE Code -
47 - MailArchiver
Plugin -
Plugin Slug -
mailarchiver
Installations -
100+
Vulnerability -
Unauthenticated Stored Cross-Site Scripting via Email Subject
Patched In Version -
2.11.0
Severity -
High
CVE Code -
48 - CartFlows Pro
Plugin -
Plugin Slug -
cartflows-pro
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.11.12
Severity -
High
CVE Code -
49 - Grid Kit Premium
Plugin -
Plugin Slug -
grid-kit-premium
Vulnerability -
Multiple Reflected Cross Site Scripting (XSS)
Patched In Version -
2.2.0
Severity -
High
CVE Code -
50 - Premium Addons PRO
Plugin -
Plugin Slug -
premium-addons-pro
Vulnerability -
Broken Access Control
Patched In Version -
2.9.1
Severity -
Medium
CVE Code -
51 - Premium Addons PRO
Plugin -
Plugin Slug -
premium-addons-pro
Vulnerability -
Sensitive Data Exposure
Patched In Version -
2.9.1
Severity -
Medium
CVE Code -
52 - WooCommerce GoCardless Gateway
Plugin -
WooCommerce GoCardless Gateway
Plugin Slug -
woocommerce-gateway-gocardless
Vulnerability -
Unauth. Insecure Direct Object References (IDOR)
Patched In Version -
2.5.7
Severity -
High
CVE Code -
53 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.8.6
Severity -
High
CVE Code -
54 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Broken Access Control
Patched In Version -
3.8.6
Severity -
Medium
CVE Code -
55 - WooCommerce Warranty Requests
Plugin -
Plugin Slug -
woocommerce-warranty
Vulnerability -
Broken Access Control
Patched In Version -
2.2.0
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - Chat Button by GetButton.io
Plugin -
Plugin Slug -
whatshelp-chat-button
Installations -
50,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Coming Soon Chop Chop
Plugin -
Plugin Slug -
cc-coming-soon
Installations -
4,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

3 - Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider
Plugin -
Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider
Plugin Slug -
sliderspack-all-in-one-image-sliders
Installations -
4,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

4 - OptiMonk: Popups, Personalization & A/B Testing
Plugin -
OptiMonk: Popups, Personalization & A/B Testing
Plugin Slug -
exit-intent-popups-by-optimonk
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
5 - Social Media Icons Widget
Plugin -
Plugin Slug -
spoontalk-social-media-icons-widget
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

6 - Easyship WooCommerce Shipping Rates
Plugin -
Easyship WooCommerce Shipping Rates
Plugin Slug -
easyship-woocommerce-shipping-rates
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

7 - School Management System – WPSchoolPress
Plugin -
School Management System – WPSchoolPress
Plugin Slug -
wpschoolpress
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - WPAdmin AWS CDN
Plugin -
Plugin Slug -
aws-cdn-by-wpadmin
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

9 - Contact Form Generator : Creative form builder for WordPress
Plugin -
Contact Form Generator : Creative form builder for WordPress
Plugin Slug -
contact-form-generator
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

10 - Contact Form to Any API
Plugin -
Plugin Slug -
contact-form-to-any-api
Installations -
1,000+
Vulnerability -
SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -

11 - Shortcode IMDB
Plugin -
Plugin Slug -
shortcode-imdb
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

12 - Radio Forge Muses Player with Skins
Plugin -
Radio Forge Muses Player with Skins
Plugin Slug -
radio-forge
Installations -
900+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

13 - Replace Word
Plugin -
Plugin Slug -
replace-word
Installations -
900+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
14 - Art Direction
Plugin -
Plugin Slug -
art-direction
Installations -
800+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

15 - WPBulky – WordPress Bulk Edit Post Types
Plugin -
WPBulky – WordPress Bulk Edit Post Types
Plugin Slug -
wpbulky-wp-bulk-edit-post-types
Installations -
200+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

16 - ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store
Plugin -
ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store
Plugin Slug -
shopconstruct
Installations -
60+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
17 - Dovetail
Plugin -
Plugin Slug -
dovetail
Installations -
10+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
18 - YourMembership Single Sign On – YM SSO Login
Plugin -
YourMembership Single Sign On – YM SSO Login
Plugin Slug -
login-with-yourmembership
Installations -
10+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
19 - YourMembership Single Sign On – YM SSO Login
Plugin -
YourMembership Single Sign On – YM SSO Login
Plugin Slug -
login-with-yourmembership
Installations -
10+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

20 - Twittee Text Tweet
Plugin -
Plugin Slug -
twittee-text-tweet
Installations -
10+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
21 - Mail Control
Plugin -
Plugin Slug -
mail-control
Vulnerability -
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched In Version -
No Fix
Severity -
High
CVE Code -

22 - PDQ CSV
Plugin -
Plugin Slug -
pdq-csv
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

23 - WP Default Feature Image
Plugin -
Plugin Slug -
wp-default-feature-image
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
1 - RealHomes
Theme -
RealHomes
Theme Slug -
realhomes
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
2 - RealHomes
Theme -
RealHomes
Theme Slug -
realhomes
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.