WordPress Vulnerability Report – August 23, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON AUGUST 23, 2023
Last Updated on August 23, 2023
Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!
Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- InfiniteWP Client
- Advanced File Manager
- Blog2Social
- wpDataTables
- WP-PostRatings
- Cost Calculator Builder
- Countdown Timer Ultimate
- Media from FTP
- User Submitted Posts
- Album and Image Gallery plus Lightbox
- Cookies and Content Security Policy
- Stripe Payment Plugin for WooCommerce
- Smart SEO Tool
- Orders Tracking for WooCommerce
- Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
- WP VR
- Blog Designer – Post and Widget
- WP Remote Users Sync
- WP Remote Users Sync
- Meta Slider and Carousel with Lightbox
- Plausible Analytics
- Post grid and filter ultimate
- Timeline and History slider
- JS Help Desk – Best Help Desk & Support Plugin
- Team Slider and Team Grid Showcase plus Team Carousel
- Trending/Popular Post Slider and Widget
- Video Gallery & Management
- Accordion and Accordion Slider
- DoLogin Security
- Video gallery and Player
- WooCommerce PDF Invoice Builder
- WooCommerce PDF Invoice Builder
- WooCommerce PDF Invoice Builder
- Accordion Slider
- Doofinder for WooCommerce
- Portfolio and Projects
- Post Ticker Ultimate
- CLUEVO LMS
- Serial Codes Generator and Validator with WooCommerce Support
- Event Tickets with Ticket Scanner
- Products Quick View for WooCommerce
- 123.chat
- Paid Memberships Pro CCBill Gateway
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- Simple URLs
- Simple URLs
- Simple URLs
- Enhanced Ecommerce Google Analytics for WooCommerce
- GD Security Headers
- LINE Notify
- fitness calculators plugin
- Kanban Boards for WordPress
- Save as PDF plugin by Pdfcrowd
- Schedule Posts Calendar
- Schedule Posts Calendar
- Tabs & Accordion
- Dynamic Pricing and Discount Rules for WooCommerce
- rsvpmaker
- rsvpmaker
- Save as Image plugin by Pdfcrowd
- Typing Effect
- Password Reset with Code for WordPress REST API
- BigBlueButton
- Carrot
- Cartpauj Register Captcha
- Contact form 7 Custom validation
- Cleverwise Daily Quotes
- Cookies by JM
- CT Commerce
- Custom Admin Login Page | WPZest
- DX-auto-save-images
- Mortgage Calculator Estatik
- Make Paths Relative
- Simple Org Chart
- Simple Org Chart
- Simple Staff List
- Donations Made Easy – Smart Donations
- Sticky Social Media Icons
- WebLibrarian
- Putler Connector for WooCommerce
- Putler Connector for WooCommerce
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
WordPress Plugin Vulnerabilities – Patched

1 - InfiniteWP Client
Plugin -
Plugin Slug -
iwp-client
Installations -
300,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
1.12.1
Severity -
High
CVE Code -

2 - Advanced File Manager
Plugin -
Plugin Slug -
file-manager-advanced
Installations -
100,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
5.1.1
Severity -
Medium
CVE Code -

3 - Blog2Social: Social Media Auto Post & Scheduler
Plugin -
Blog2Social: Social Media Auto Post & Scheduler
Plugin Slug -
blog2social
Installations -
70,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
7.2.1
Severity -
High
CVE Code -

4 - wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
Plugin -
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
Plugin Slug -
wpdatatables
Installations -
70,000+
Vulnerability -
PHP Object Injection
Patched In Version -
2.1.66
Severity -
Medium

5 - WP-PostRatings
Plugin -
Plugin Slug -
wp-postratings
Installations -
50,000+
Vulnerability -
Bypass Vulnerability
Patched In Version -
1.91.1
Severity -
Medium
CVE Code -

6 - Cost Calculator Builder
Plugin -
Plugin Slug -
cost-calculator-builder
Installations -
30,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.1.43
Severity -
Medium
CVE Code -

7 - Countdown Timer Ultimate
Plugin -
Plugin Slug -
countdown-timer-ultimate
Installations -
20,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.4.1
Severity -
Medium
CVE Code -

8 - Media from FTP
Plugin -
Plugin Slug -
media-from-ftp
Installations -
20,000+
Vulnerability -
Settings Change
Patched In Version -
11.17
Severity -
Low
CVE Code -

9 - User Submitted Posts – Enable Users to Submit Posts from the Front End
Plugin -
User Submitted Posts – Enable Users to Submit Posts from the Front End
Plugin Slug -
user-submitted-posts
Installations -
20,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
20230811
Severity -
High
CVE Code -

10 - Album and Image Gallery plus Lightbox
Plugin -
Album and Image Gallery plus Lightbox
Plugin Slug -
album-and-image-gallery-plus-lightbox
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.7.1
Severity -
Medium
CVE Code -

11 - Cookies and Content Security Policy
Plugin -
Cookies and Content Security Policy
Plugin Slug -
cookies-and-content-security-policy
Installations -
10,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
2.16
Severity -
Medium
CVE Code -

12 - Stripe Payment Plugin for WooCommerce
Plugin -
Stripe Payment Plugin for WooCommerce
Plugin Slug -
payment-gateway-stripe-and-woocommerce-integration
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.8.0
Severity -
Medium
CVE Code -

13 - Smart SEO Tool – SEO
Plugin -
Plugin Slug -
smart-seo-tool
Installations -
10,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
4.0.2
Severity -
Medium
14 - Orders Tracking for WooCommerce
Plugin -
Orders Tracking for WooCommerce
Plugin Slug -
woo-orders-tracking
Installations -
10,000+
Vulnerability -
Directory Traversal
Patched In Version -
1.2.6
Severity -
Low
CVE Code -

15 - Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
Plugin -
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
Plugin Slug -
wp-testimonial-with-widget
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.3.1
Severity -
Medium
CVE Code -

16 - WP VR – 360 Panorama and Virtual Tour Builder For WordPress
Plugin -
WP VR – 360 Panorama and Virtual Tour Builder For WordPress
Plugin Slug -
wpvr
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
8.3.5
Severity -
High
CVE Code -

17 - Blog Designer – Post and Widget
Plugin -
Blog Designer – Post and Widget
Plugin Slug -
blog-designer-for-post-and-widget
Installations -
8,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.5.2
Severity -
Medium
CVE Code -

18 - WP Remote Users Sync
Plugin -
Plugin Slug -
wp-remote-users-sync
Installations -
8,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.2.12
Severity -
Medium
CVE Code -

19 - WP Remote Users Sync
Plugin -
Plugin Slug -
wp-remote-users-sync
Installations -
8,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
1.2.13
Severity -
High
CVE Code -

20 - Meta Slider and Carousel with Lightbox
Plugin -
Meta Slider and Carousel with Lightbox
Plugin Slug -
meta-slider-and-carousel-with-lightbox
Installations -
7,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.8.3
Severity -
Medium
CVE Code -

21 - Plausible Analytics
Plugin -
Plugin Slug -
plausible-analytics
Installations -
7,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.3.4
Severity -
Medium
CVE Code -

22 - Post grid and filter ultimate
Plugin -
Plugin Slug -
post-grid-and-filter-ultimate
Installations -
7,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.5.3
Severity -
Medium
CVE Code -

23 - Timeline and History slider
Plugin -
Plugin Slug -
timeline-and-history-slider
Installations -
6,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.1.1
Severity -
Medium
CVE Code -

24 - JS Help Desk – Best Help Desk & Support Plugin
Plugin -
JS Help Desk – Best Help Desk & Support Plugin
Plugin Slug -
js-support-ticket
Installations -
5,000+
Vulnerability -
Arbitrary File Upload
Patched In Version -
2.7.8
Severity -
Critical
CVE Code -

25 - Team Slider and Team Grid Showcase plus Team Carousel
Plugin -
Team Slider and Team Grid Showcase plus Team Carousel
Plugin Slug -
wp-team-showcase-and-slider
Installations -
4,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.6.1
Severity -
Medium
CVE Code -

26 - Trending/Popular Post Slider and Widget
Plugin -
Trending/Popular Post Slider and Widget
Plugin Slug -
wp-trending-post-slider-and-widget
Installations -
4,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.6.1
Severity -
Medium
CVE Code -

27 - Video Gallery for YouTube Videos and WordPress
Plugin -
Video Gallery for YouTube Videos and WordPress
Plugin Slug -
youtube-showcase
Installations -
4,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.3.6
Severity -
Medium
CVE Code -

28 - Accordion and Accordion Slider
Plugin -
Accordion and Accordion Slider
Plugin Slug -
accordion-and-accordion-slider
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.2.5
Severity -
Medium
CVE Code -
29 - DoLogin Security
Plugin -
Plugin Slug -
dologin
Installations -
3,000+
Vulnerability -
Bypass Vulnerability
Patched In Version -
3.7
Severity -
Medium

30 - Video gallery and Player
Plugin -
Plugin Slug -
html5-videogallery-plus-player
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.6.6
Severity -
Medium
CVE Code -

31 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin -
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug -
woo-pdf-invoice-builder
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.2.92
Severity -
Medium
CVE Code -

32 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin -
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug -
woo-pdf-invoice-builder
Installations -
3,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2.91
Severity -
Medium
CVE Code -

33 - WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin -
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more
Plugin Slug -
woo-pdf-invoice-builder
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.2.91
Severity -
Medium
CVE Code -

34 - Accordion Slider
Plugin -
Plugin Slug -
accordion-slider
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.9.7
Severity -
Medium
CVE Code -
35 - Doofinder WP & WooCommerce Search
Plugin -
Doofinder WP & WooCommerce Search
Plugin Slug -
doofinder-for-woocommerce
Installations -
2,000+
Vulnerability -
Open Redirection
Patched In Version -
2.0.0
Severity -
Medium
CVE Code -

36 - Portfolio and Projects
Plugin -
Plugin Slug -
portfolio-and-projects
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.3.8
Severity -
Medium
CVE Code -

37 - Post Ticker Ultimate
Plugin -
Plugin Slug -
ticker-ultimate
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.5.6
Severity -
Medium
CVE Code -

38 - CLUEVO LMS, E-Learning Platform
Plugin -
CLUEVO LMS, E-Learning Platform
Plugin Slug -
cluevo-lms
Installations -
700+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.11.0
Severity -
Medium
CVE Code -

39 - Serial Codes Generator and Validator with WooCommerce Support
Plugin -
Serial Codes Generator and Validator with WooCommerce Support
Plugin Slug -
serial-codes-generator-and-validator
Installations -
600+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.4.15
Severity -
Medium

40 - Event Tickets with Ticket Scanner
Plugin -
Event Tickets with Ticket Scanner
Plugin Slug -
event-tickets-with-ticket-scanner
Installations -
500+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.5.5
Severity -
Medium

41 - Products Quick View for WooCommerce
Plugin -
Products Quick View for WooCommerce
Plugin Slug -
woocommerce-products-quick-view
Installations -
100+
Vulnerability -
Broken Access Control
Patched In Version -
2.3.0
Severity -
Medium

42 - 123.chat – 1:1 Live Video Chat Tool Plugin
Plugin -
123.chat – 1:1 Live Video Chat Tool Plugin
Plugin Slug -
123-chat-videochat
Installations -
40+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.3.1
Severity -
Medium
CVE Code -
43 - Paid Memberships Pro CCBill Gateway
Plugin -
Paid Memberships Pro CCBill Gateway
Plugin Slug -
pmpro-ccbill
Vulnerability -
Broken Access Control
Patched In Version -
0.4
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

3 - Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin -
Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management
Plugin Slug -
simple-urls
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
4 - Enhanced Ecommerce Google Analytics for WooCommerce
Plugin -
Enhanced Ecommerce Google Analytics for WooCommerce
Plugin Slug -
woo-ecommerce-tracking-for-google-and-facebook
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

5 - GD Security Headers
Plugin -
Plugin Slug -
gd-security-headers
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
6 - WP LINE Notify
Plugin -
Plugin Slug -
wp-line-notify
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

7 - fitness calculators plugin
Plugin -
Plugin Slug -
fitness-calculators
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - Kanban Boards for WordPress
Plugin -
Plugin Slug -
kanban
Installations -
1,000+
Vulnerability -
Arbitrary Code Execution
Patched In Version -
No Fix
Severity -
Critical
CVE Code -
9 - Save as PDF plugin by Pdfcrowd
Plugin -
Save as PDF plugin by Pdfcrowd
Plugin Slug -
save-as-pdf-by-pdfcrowd
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

10 - Schedule Posts Calendar
Plugin -
Plugin Slug -
schedule-posts-calendar
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

11 - Schedule Posts Calendar
Plugin -
Plugin Slug -
schedule-posts-calendar
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

12 - Tabs & Accordion
Plugin -
Plugin Slug -
tabs
Installations -
1,000+
Vulnerability -
Content Injection
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

13 - Dynamic Pricing and Discount Rules for WooCommerce
Plugin -
Dynamic Pricing and Discount Rules for WooCommerce
Plugin Slug -
woo-conditional-discount-rules-for-checkout
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

14 - RSVPMaker
Plugin -
Plugin Slug -
rsvpmaker
Installations -
400+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

15 - RSVPMaker
Plugin -
Plugin Slug -
rsvpmaker
Installations -
400+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
16 - Save as Image plugin by Pdfcrowd
Plugin -
Save as Image plugin by Pdfcrowd
Plugin Slug -
save-as-image-by-pdfcrowd
Installations -
50+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
17 - Typing Effect
Plugin -
Plugin Slug -
animated-typing-effect
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
18 - Password Reset with Code for WordPress REST API
Plugin -
Password Reset with Code for WordPress REST API
Plugin Slug -
bdvs-password-reset
Vulnerability -
Broken Authentication
Patched In Version -
No Fix
Severity -
Critical
CVE Code -
19 - BigBlueButton
Plugin -
Plugin Slug -
bigbluebutton
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
20 - Carrot
Plugin -
Plugin Slug -
carrrot
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
21 - Cartpauj Register Captcha
Plugin -
Plugin Slug -
cartpauj-register-captcha
Vulnerability -
Bypass Vulnerability
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
22 - Contact form 7 Custom validation
Plugin -
Contact form 7 Custom validation
Plugin Slug -
cf7-field-validation
Vulnerability -
SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
23 - Cleverwise Daily Quotes
Plugin -
Plugin Slug -
cleverwise-daily-quotes
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
24 - Cookies by JM
Plugin -
Plugin Slug -
cookies-by-jm
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
25 - CT Commerce
Plugin -
Plugin Slug -
ct-commerce
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
26 - Custom Admin Login Page | WPZest
Plugin -
Custom Admin Login Page | WPZest
Plugin Slug -
custom-admin-login-styler-wpzest
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
27 - DX-auto-save-images
Plugin -
Plugin Slug -
dx-auto-save-images
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
28 - Mortgage Calculator Estatik
Plugin -
Plugin Slug -
estatik-mortgage-calculator
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
29 - Make Paths Relative
Plugin -
Plugin Slug -
make-paths-relative
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
30 - Simple Org Chart
Plugin -
Plugin Slug -
simple-org-chart
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
31 - Simple Org Chart
Plugin -
Plugin Slug -
simple-org-chart
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
32 - Simple Staff List
Plugin -
Plugin Slug -
simple-staff-list
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
33 - Donations Made Easy – Smart Donations
Plugin -
Donations Made Easy – Smart Donations
Plugin Slug -
smart-donations
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
34 - Sticky Social Media Icons
Plugin -
Plugin Slug -
sticky-social-media-icons
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
35 - WebLibrarian
Plugin -
Plugin Slug -
weblibrarian
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
36 - Putler Connector for WooCommerce
Plugin -
Putler Connector for WooCommerce
Plugin Slug -
woocommerce-putler-connector
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
37 - Putler Connector for WooCommerce
Plugin -
Putler Connector for WooCommerce
Plugin Slug -
woocommerce-putler-connector
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities

1 - Bazaar Lite
Theme -
Bazaar Lite
Theme Slug -
bazaar-lite
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.8.6
Severity -
High
CVE Code -

2 - Aapna
Theme -
Aapna
Theme Slug -
aapna
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

3 - College
Theme -
College
Theme Slug -
college
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.5.1
Severity -
High
CVE Code -

4 - BunnyPressLite
Theme -
BunnyPressLite
Theme Slug -
bunnypresslite
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.1
Severity -
High
CVE Code -

5 - Anfaust
Theme -
Anfaust
Theme Slug -
anfaust
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

6 - Brain Power
Theme -
Brain Power
Theme Slug -
brain-power
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

7 - Cafe Bistro
Theme -
Cafe Bistro
Theme Slug -
cafe-bistro
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.1.4
Severity -
High
CVE Code -

8 - Anand
Theme -
Anand
Theme Slug -
anand
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -

9 - Arendelle
Theme -
Arendelle
Theme Slug -
arendelle
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.1.3
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.