WordPress Vulnerability Report – July 12, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON JUly 12, 2023
Last Updated on July 12, 2023
Since last week, 82 total vulnerabilities emerged in public disclosure. They may affect over 4 million WordPress sites. There are 46 plugin vulnerabilities and one theme vulnerability with security patches available, so run those updates!
Additionally, there are 34 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- WP-Optimize
- Ninja Forms
- Forminator
- POST SMTP Mailer
- POST SMTP Mailer
- ShopLentor
- WP Content Copy Protection & No Right Click
- LearnPress
- LearnPress
- HTTP Headers
- HTTP Headers
- All-in-one Floating Contact Form
- JetFormBuilder
- Visibility Logic for Elementor
- IP2Location Country Blocker
- ND Shortcodes
- wpForo Forum
- Yasr – Yet Another Stars Rating
- Booking Package SAASPROJECT
- Cryptocurrency Widgets – Price Ticker & Coins List
- Image Regenerate & Select Crop
- WP Mail Log
- Companion Sitemap Generator
- Buy Me a Coffee – Button and Widget Plugin
- Buy Me a Coffee – Button and Widget Plugin
- Buy Me a Coffee
- WP Dummy Content Generator
- WP Dummy Content Generator
- WebwinkelKeu
- ARMember
- Gift Cards
- Masteriyo – LMS
- BuddyBuilder BuddyPress Builder for Elementor
- Terms descriptions
- Sublanguage
- WP Reroute Email
- WPFactory Helper
- RSVPMaker
- Getnet Argentina para Woocommerce
- My Content Management
- Auto Location for WP Job Manager via Google
- tagDiv Cloud Library
- WooCommerce GoCardless Gateway
- WooCommerce Ship to Multiple Addresses
- WooCommerce Ship to Multiple Addresses
- WooCommerce Warranty Requests
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- oAuth Twitter Feed for Developers
- Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
- Media Library Helper by Codexin
- Secondary Title
- Classified Listing
- Mobile Call Now & Map Buttons
- Social Share Boost
- Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)
- WPFunnels
- Animated Number Counters
- Social Media Icons Widget
- Kingkong Board
- Menubar
- Product Category Tree
- WP RSS Images
- Image Social Feed Plugin
- Simple Giveaways
- Coming Soon Page
- Simple Site Verify
- WP-Cirrus
- WP Full Stripe Free
- Baidu Tongji generator
- Querlo Chatbot
- BadgeOS
- BadgeOS
- BadgeOS
- Livestream Notice
- Mail Control
- Premium Addons PRO
- Premium Addons PRO
- Reservation.Studio Widget
- SMTP Mail
- WordPress Mobile Pack
- WP Default Feature Image
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
WordPress Plugin Vulnerabilities – Patched

1 - WP-Optimize – Cache, Clean, Compress.
Plugin -
WP-Optimize – Cache, Clean, Compress.
Plugin Slug -
wp-optimize
Installations -
1,000,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.2.13
Severity -
High
CVE Code -

2 - Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin -
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug -
ninja-forms
Installations -
900,000+
Vulnerability -
Denial of Service Attack
Patched In Version -
3.6.26
Severity -
Medium
CVE Code -

3 - Forminator – Contact Form, Payment Form & Custom Form Builder
Plugin -
Forminator – Contact Form, Payment Form & Custom Form Builder
Plugin Slug -
forminator
Installations -
400,000+
Vulnerability -
Unauth. Race Condition
Patched In Version -
1.24.1
Severity -
Low
CVE Code -

4 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin -
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin Slug -
post-smtp
Installations -
300,000+
Vulnerability -
Account Takeover via Cross Site Request Forgery (CSRF)
Patched In Version -
2.5.7
Severity -
High
CVE Code -

5 - POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin -
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress
Plugin Slug -
post-smtp
Installations -
300,000+
Vulnerability -
Arbitrary Log Deletion via Cross Site Request Forgery (CSRF)
Patched In Version -
2.5.7
Severity -
Medium
CVE Code -

6 - ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor)
Plugin -
Plugin Slug -
woolentor-addons
Installations -
100,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.6.3
Severity -
Medium
CVE Code -

7 - WP Content Copy Protection & No Right Click
Plugin -
WP Content Copy Protection & No Right Click
Plugin Slug -
wp-content-copy-protector
Installations -
100,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
3.5.6
Severity -
Medium
CVE Code -

8 - LearnPress – WordPress LMS Plugin
Plugin -
LearnPress – WordPress LMS Plugin
Plugin Slug -
learnpress
Installations -
90,000+
Vulnerability -
Authenticated Broken Access Control
Patched In Version -
4.2.3.1
Severity -
High
CVE Code -

9 - LearnPress – WordPress LMS Plugin
Plugin -
LearnPress – WordPress LMS Plugin
Plugin Slug -
learnpress
Installations -
90,000+
Vulnerability -
Unauthenticated Broken Access Control
Patched In Version -
4.2.3.1
Severity -
High
CVE Code -

10 - HTTP Headers
Plugin -
Plugin Slug -
http-headers
Installations -
40,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.19.0
Severity -
Medium
CVE Code -

11 - HTTP Headers
Plugin -
Plugin Slug -
http-headers
Installations -
40,000+
Vulnerability -
Admin+ Remote Code Execution (RCE)
Patched In Version -
1.18.11
Severity -
High
CVE Code -

12 - All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements
Plugin -
All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements
Plugin Slug -
mystickyelements
Installations -
40,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
2.1.2
Severity -
Medium
CVE Code -

13 - JetFormBuilder — Dynamic Blocks Form Builder
Plugin -
JetFormBuilder — Dynamic Blocks Form Builder
Plugin Slug -
jetformbuilder
Installations -
30,000+
Vulnerability -
Authenticated Privilege Escalation
Patched In Version -
3.0.9
Severity -
High
CVE Code -

14 - Visibility Logic for Elementor
Plugin -
Visibility Logic for Elementor
Plugin Slug -
visibility-logic-elementor
Installations -
30,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.3.5
Severity -
Medium
CVE Code -

15 - IP2Location Country Blocker
Plugin -
Plugin Slug -
ip2location-country-blocker
Installations -
20,000+
Vulnerability -
IP Bypass Vulnerability
Patched In Version -
2.29.2
Severity -
Medium
CVE Code -

16 - ND Shortcodes
Plugin -
Plugin Slug -
nd-shortcodes
Installations -
20,000+
Vulnerability -
Auth. Cross Site Scripting (XSS)
Patched In Version -
7.0
Severity -
Medium
CVE Code -

17 - wpForo Forum
Plugin -
Plugin Slug -
wpforo
Installations -
20,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.1.9
Severity -
High
CVE Code -

18 - Yasr – Yet Another Stars Rating
Plugin -
Yasr – Yet Another Stars Rating
Plugin Slug -
yet-another-stars-rating
Installations -
20,000+
Vulnerability -
Race Condition
Patched In Version -
3.3.9
Severity -
Low
CVE Code -

19 - Booking Package
Plugin -
Plugin Slug -
booking-package
Installations -
10,000+
Vulnerability -
Unauthenticated Privilege Escalation
Patched In Version -
1.5.99
Severity -
High
CVE Code -

20 - Cryptocurrency Widgets – Price Ticker & Coins List
Plugin -
Cryptocurrency Widgets – Price Ticker & Coins List
Plugin Slug -
cryptocurrency-price-ticker-widget
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.6.3
Severity -
Medium
CVE Code -

21 - Image Regenerate & Select Crop
Plugin -
Image Regenerate & Select Crop
Plugin Slug -
image-regenerate-select-crop
Installations -
10,000+
Vulnerability -
Broken Access Control
Patched In Version -
7.2.0
Severity -
Medium
CVE Code -

22 - WP Mail Log
Plugin -
Plugin Slug -
wp-mail-log
Installations -
10,000+
Vulnerability -
Unauthenticated Stored Cross Site Scripting (XSS) via Email
Patched In Version -
1.1.2
Severity -
High
CVE Code -

23 - Companion Sitemap Generator – HTML & XML
Plugin -
Companion Sitemap Generator – HTML & XML
Plugin Slug -
companion-sitemap-generator
Installations -
9,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
4.5.3
Severity -
High
CVE Code -

24 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.8
Severity -
Medium
CVE Code -

25 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Missing Authorization
Patched In Version -
3.8
Severity -
Medium
CVE Code -

26 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.8
Severity -
Medium
CVE Code -

27 - WP Dummy Content Generator
Plugin -
Plugin Slug -
wp-dummy-content-generator
Installations -
4,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.0.0
Severity -
Medium
CVE Code -

28 - WP Dummy Content Generator
Plugin -
Plugin Slug -
wp-dummy-content-generator
Installations -
4,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.0.0
Severity -
Medium
CVE Code -
29 - WebwinkelKeur: Webshop keurmerk & reviews for WordPress
Plugin -
WebwinkelKeur: Webshop keurmerk & reviews for WordPress
Plugin Slug -
webwinkelkeur
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.25
Severity -
Medium
CVE Code -

30 - ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Plugin -
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
Plugin Slug -
armember-membership
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
4.0.6
Severity -
Medium
CVE Code -

31 - Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Plugin -
Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)
Plugin Slug -
gift-voucher
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF) in new_voucher_template.php
Patched In Version -
4.3.6
Severity -
Medium

32 - LMS by Masteriyo – WordPress Learning Management System, eLearning Platform, Online Education System & Online Course Builder
Plugin -
Plugin Slug -
learning-management-system
Installations -
2,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
1.6.8
Severity -
Medium

33 - BuddyPress Builder for Elementor – BuddyBuilder
Plugin -
BuddyPress Builder for Elementor – BuddyBuilder
Plugin Slug -
stax-buddy-builder
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.7.4
Severity -
Medium

34 - Terms descriptions
Plugin -
Plugin Slug -
terms-descriptions
Installations -
2,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.4.5
Severity -
High
CVE Code -

35 - Sublanguage
Plugin -
Plugin Slug -
sublanguage
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
2.10
Severity -
Medium
CVE Code -

36 - WP Reroute Email
Plugin -
Plugin Slug -
wp-reroute-email
Installations -
1,000+
Vulnerability -
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched In Version -
1.5.0
Severity -
High
CVE Code -

37 - WPFactory Helper
Plugin -
Plugin Slug -
wpcodefactory-helper
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.5.3
Severity -
High
CVE Code -

38 - RSVPMaker
Plugin -
Plugin Slug -
rsvpmaker
Installations -
400+
Vulnerability -
SQL Injection
Patched In Version -
10.5.5
Severity -
High
CVE Code -

39 - Getnet Argentina para Woocommerce
Plugin -
Getnet Argentina para Woocommerce
Plugin Slug -
integrar-getnet-con-woo
Installations -
200+
Vulnerability -
Authorization Bypass via webhook
Patched In Version -
0.0.5
Severity -
High
CVE Code -

40 - My Content Management
Plugin -
Plugin Slug -
my-content-management
Installations -
200+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.7.7
Severity -
Medium
CVE Code -
41 - Auto Location for WP Job Manager via Google
Plugin -
Auto Location for WP Job Manager via Google
Plugin Slug -
auto-location-for-wp-job-manager
Installations -
100+
Vulnerability -
Admin+ Cross Site Scripting (XSS)
Patched In Version -
1.1
Severity -
Medium
CVE Code -
42 - tagDiv Cloud Library
Plugin -
Plugin Slug -
td-cloud-library
Vulnerability -
Unauthenticated Arbitrary User Metadata Update to Privilege Escalation
Patched In Version -
2.7
Severity -
Critical
CVE Code -
43 - WooCommerce GoCardless Gateway
Plugin -
WooCommerce GoCardless Gateway
Plugin Slug -
woocommerce-gateway-gocardless
Vulnerability -
Unauth. Insecure Direct Object References (IDOR)
Patched In Version -
2.5.7
Severity -
High
CVE Code -
44 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.8.6
Severity -
High
CVE Code -
45 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Broken Access Control
Patched In Version -
3.8.6
Severity -
Medium
CVE Code -
46 - WooCommerce Warranty Requests
Plugin -
Plugin Slug -
woocommerce-warranty
Vulnerability -
Broken Access Control
Patched In Version -
2.2.0
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched
1 - oAuth Twitter Feed for Developers
Plugin -
oAuth Twitter Feed for Developers
Plugin Slug -
oauth-twitter-feed-for-developers
Installations -
60,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
Plugin -
Video Gallery – YouTube Playlist, Channel Gallery by YotuWP
Plugin Slug -
yotuwp-easy-youtube-embed
Installations -
30,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

3 - Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin
Plugin -
Bulk edit image alt tag, caption & description – WordPress Media Library Helper by Codexin
Plugin Slug -
media-library-helper
Installations -
10,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

4 - Secondary Title
Plugin -
Plugin Slug -
secondary-title
Installations -
10,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

5 - Classified Listing – Classified ads & Business Directory Plugin
Plugin -
Classified Listing – Classified ads & Business Directory Plugin
Plugin Slug -
classified-listing
Installations -
9,000+
Vulnerability -
Cross Site Request Forgery (CSRF) Leading To Thumbnail Removal
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

6 - Mobile Call Now & Map Buttons
Plugin -
Plugin Slug -
mobile-call-now-map-buttons
Installations -
9,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
7 - Social Share Boost
Plugin -
Plugin Slug -
social-share-boost
Installations -
6,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)
Plugin -
Simple Light Weight Social Share (Tweet, Like, Share and Linkedin)
Plugin Slug -
only-tweet-like-share-and-google-1
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

9 - Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin -
Drag & Drop Sales Funnel Builder for WordPress – WPFunnels
Plugin Slug -
wpfunnels
Installations -
5,000+
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
No Fix
Severity -
Medium

10 - Animated Number Counters
Plugin -
Plugin Slug -
animated-number-counters
Installations -
3,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
11 - Social Media Icons Widget
Plugin -
Plugin Slug -
spoontalk-social-media-icons-widget
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

12 - Kingkong Board
Plugin -
Plugin Slug -
kingkong-board
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
13 - Menubar
Plugin -
Plugin Slug -
menubar
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

14 - Product Category Tree
Plugin -
Plugin Slug -
product-category-tree
Installations -
2,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
15 - WP RSS Images
Plugin -
Plugin Slug -
wp-rss-images
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

16 - Image Social Feed Plugin
Plugin -
Plugin Slug -
add-instagram
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

17 - Simple Giveaways – Grow your business, email lists and traffic with contests
Plugin -
Simple Giveaways – Grow your business, email lists and traffic with contests
Plugin Slug -
giveasap
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

18 - Coming Soon Page – Responsive Coming Soon & Maintenance Mode
Plugin -
Coming Soon Page – Responsive Coming Soon & Maintenance Mode
Plugin Slug -
responsive-coming-soon-page
Installations -
1,000+
Vulnerability -
SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -

19 - Simple Site Verify
Plugin -
Plugin Slug -
simple-site-verify
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
20 - WP-Cirrus
Plugin -
Plugin Slug -
wp-cirrus
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

21 - WP Full Stripe Free
Plugin -
Plugin Slug -
wp-full-stripe-free
Installations -
1,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
22 - Baidu Tongji generator
Plugin -
Plugin Slug -
baidu-tongji-generator
Installations -
100+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
23 - Querlo Chatbot
Plugin -
Plugin Slug -
querlo-chatbots
Installations -
10+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

27 - Livestream Notice
Plugin -
Plugin Slug -
livestream-notice
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
28 - Mail Control
Plugin -
Plugin Slug -
mail-control
Vulnerability -
Unauthenticated Stored Cross Site Scripting (XSS) via Email Subject
Patched In Version -
No Fix
Severity -
High
CVE Code -
29 - Premium Addons PRO
Plugin -
Plugin Slug -
premium-addons-pro
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
30 - Premium Addons PRO
Plugin -
Plugin Slug -
premium-addons-pro
Vulnerability -
Sensitive Data Exposure
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

31 - Reservation.Studio widget
Plugin -
Plugin Slug -
reservation-studio-widget
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
33 - WordPress Mobile Pack
Plugin -
Plugin Slug -
wordpress-mobile-pack
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

34 - WP Default Feature Image
Plugin -
Plugin Slug -
wp-default-feature-image
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities

1 - Consulting
Theme -
Consulting
Theme Slug -
consulting
Vulnerability -
Local File Inclusion
Patched In Version -
No Fix
Severity -
High
CVE Code -
2 - WPLMS
Theme -
WPLMS
Theme Slug -
wplms
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
4.900
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.