WordPress Vulnerability Report – June 28, 2023

by | Jun 28, 2023 | Security

DETAILS FROM DAN KNAUSS OF ITHEMES ON JUNE 28, 2023

original available here

Last Updated on June 29, 2023

 

This week, 140 total vulnerabilities emerged in public disclosure. They may affect over 13 million WordPress sites. There are 116 plugin vulnerabilities and one theme vulnerability that has security patches available, so run those updates!

Additionally, there are 23 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

Is Your WordPress Website Secure?

DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?

Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!

WordPress Core Vulnerabilities

No new WordPress core vulnerabilities were disclosed this week. 

WordPress Plugin Vulnerabilities – Patched

These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.

Jump to section

WordPress Theme Vulnerabilities

Jump to section

These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.

WordPress Plugin Vulnerabilities – Patched

Contact Form by WPForms – Drag & Drop Form Builder for WordPress

1 - Contact Form by WPForms – Drag & Drop Form Builder for WordPress

Plugin -

Contact Form by WPForms – Drag & Drop Form Builder for WordPress


Plugin Slug -

wpforms-lite


Installations -

5,000,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.8.1.3


Severity -

Medium


CVE Code -

2023-30500


Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

2 - Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress

Plugin -

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress


Plugin Slug -

ninja-forms


Installations -

900,000+


Vulnerability -

Arbitrary File Deletion


Patched In Version -

3.6.25


Severity -

Medium


CVE Code -

2023-36505


Complianz – GDPR/CCPA Cookie Consent

3 - Complianz – GDPR/CCPA Cookie Consent

Plugin -

Complianz – GDPR/CCPA Cookie Consent


Plugin Slug -

complianz-gdpr


Installations -

700,000+


Vulnerability -

Cross Site Request Forgery (CSRF) lead to Site Wide Cross Site Scripting (XSS)


Patched In Version -

6.4.5


Severity -

High


CVE Code -

2023-33333


Complianz – GDPR/CCPA Cookie Consent

4 - Complianz – GDPR/CCPA Cookie Consent

Plugin -

Complianz – GDPR/CCPA Cookie Consent


Plugin Slug -

complianz-gdpr


Installations -

700,000+


Vulnerability -

Multiple Cross Site Request Forgery (CSRF)


Patched In Version -

6.4.6


Severity -

Medium


CVE Code -

2023-34030


MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard

5 - MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard

Plugin -

MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard


Plugin Slug -

mainwp-child


Installations -

600,000+


Vulnerability -

Information Disclosure via Back-Up Files


Patched In Version -

4.4.1.2


Severity -

High


CVE Code -

2023-3132


WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo

6 - WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo

Plugin -

WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo


Plugin Slug -

woocommerce-payments


Installations -

600,000+


Vulnerability -

SQL Injection


Patched In Version -

5.9.1


Severity -

High


CVE Code -

2023-35915


WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo

7 - WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo

Plugin -

WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo


Plugin Slug -

woocommerce-payments


Installations -

600,000+


Vulnerability -

Insecure Direct Object References (IDOR)


Patched In Version -

5.9.1


Severity -

High


CVE Code -

2023-35916


WooCommerce PayPal Payments

8 - WooCommerce PayPal Payments

Plugin -

WooCommerce PayPal Payments


Plugin Slug -

woocommerce-paypal-payments


Installations -

600,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.0.5


Severity -

Medium


CVE Code -

2023-35917


Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

9 - Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

Plugin -

Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress


Plugin Slug -

wp-user-avatar


Installations -

300,000+


Vulnerability -

Reflected Cross Site Scripting (XSS) via error message


Patched In Version -

4.11.0


Severity -

High


Spam protection, AntiSpam, FireWall by CleanTalk

10 - Spam protection, AntiSpam, FireWall by CleanTalk

Plugin -

Spam protection, AntiSpam, FireWall by CleanTalk


Plugin Slug -

cleantalk-spam-protect


Installations -

200,000+


Vulnerability -

Broken Access Control


Patched In Version -

6.11


Severity -

High


CVE Code -

2023-33996


Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress

11 - Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress

Plugin -

Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress


Plugin Slug -

metform


Installations -

200,000+


Vulnerability -

Cross Site Request Forgery (CSRF) via permalink_setup


Patched In Version -

3.3.3


Severity -

Medium


CVE Code -

2023-2517


Photo Gallery by 10Web – Mobile-Friendly Image Gallery

12 - Photo Gallery by 10Web – Mobile-Friendly Image Gallery

Plugin -

Photo Gallery by 10Web – Mobile-Friendly Image Gallery


Plugin Slug -

photo-gallery


Installations -

200,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.8.16


Severity -

Medium


CVE Code -

2023-33995


Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

13 - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

Plugin -

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin


Plugin Slug -

ultimate-member


Installations -

200,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.6.1


Severity -

Medium


CVE Code -

2023-31216


Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

14 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin -

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)


Plugin Slug -

unlimited-elements-for-elementor


Installations -

200,000+


Vulnerability -

Multiple Broken Access Control


Patched In Version -

1.5.66


Severity -

High


CVE Code -

2023-31080


Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

15 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Plugin -

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)


Plugin Slug -

unlimited-elements-for-elementor


Installations -

200,000+


Vulnerability -

Arbitrary File Upload


Patched In Version -

1.5.66


Severity -

Critical


CVE Code -

2023-31231


WP Mail Logging

16 - WP Mail Logging

Plugin -

WP Mail Logging


Plugin Slug -

wp-mail-logging


Installations -

200,000+


Vulnerability -

Missing Authorization to Notice Dismissal


Patched In Version -

1.12.0


Severity -

Medium


WP Activity Log

17 - WP Activity Log

Plugin -

WP Activity Log


Plugin Slug -

wp-security-audit-log


Installations -

200,000+


Vulnerability -

Subscriber+ Information Leak


Patched In Version -

4.5.2


Severity -

Medium


CVE Code -

2023-2261


Colibri Page Builder

18 - Colibri Page Builder

Plugin -

Colibri Page Builder


Plugin Slug -

colibri-page-builder


Installations -

100,000+


Vulnerability -

Auth. SQL Injection


Patched In Version -

1.0.229


Severity -

High


CVE Code -

2023-2188


WordPress Button Plugin MaxButtons

19 - WordPress Button Plugin MaxButtons

Plugin -

WordPress Button Plugin MaxButtons


Plugin Slug -

maxbuttons


Installations -

100,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

9.6


Severity -

Medium


CVE Code -

2023-36503


WooCommerce Square

20 - WooCommerce Square

Plugin -

WooCommerce Square


Plugin Slug -

woocommerce-square


Installations -

100,000+


Vulnerability -

Insecure Direct Object References (IDOR)


Patched In Version -

3.8.2


Severity -

High


CVE Code -

2023-35876


EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor

21 - EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor

Plugin -

EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor


Plugin Slug -

embedpress


Installations -

80,000+


Vulnerability -

Sensitive Data Exposure


Patched In Version -

3.8.0


Severity -

Medium


CVE Code -

2023-3371


WordPress Online Booking and Scheduling Plugin – Bookly

22 - WordPress Online Booking and Scheduling Plugin – Bookly

Plugin -

WordPress Online Booking and Scheduling Plugin – Bookly


Plugin Slug -

bookly-responsive-appointment-booking-tool


Installations -

70,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS) via service titles


Patched In Version -

21.8


Severity -

Medium


CVE Code -

2023-1159


23 - Conditional Menus

Plugin -

Conditional Menus


Plugin Slug -

conditional-menus


Installations -

70,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2.1


Severity -

High


CVE Code -

2023-2654


Tutor LMS – eLearning and online course solution

24 - Tutor LMS – eLearning and online course solution

Plugin -

Tutor LMS – eLearning and online course solution


Plugin Slug -

tutor


Installations -

70,000+


Vulnerability -

Unauthenticated Access to Tutor LMS Lesson Resources via REST API


Patched In Version -

2.2.1


Severity -

Medium


CVE Code -

2023-3133


Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

25 - Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

Plugin -

Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy


Plugin Slug -

dokan-lite


Installations -

60,000+


Vulnerability -

PHP Object Injection


Patched In Version -

3.7.20


Severity -

Medium


CVE Code -

2023-34382


CF7 Google Sheets Connector

26 - CF7 Google Sheets Connector

Plugin -

CF7 Google Sheets Connector


Plugin Slug -

cf7-google-sheets-connector


Installations -

40,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

5.0.2


Severity -

High


CVE Code -

2023-2320


ConvertKit – Email Marketing, Email Newsletter, Subscribers and Landing Pages

27 - ConvertKit – Email Marketing, Email Newsletter, Subscribers and Landing Pages

Plugin -

ConvertKit – Email Marketing, Email Newsletter, Subscribers and Landing Pages


Plugin Slug -

convertkit


Installations -

40,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.2.1


Severity -

High


CVE Code -

2023-2337


Social Share, Social Login and Social Comments Plugin – Super Socializer

28 - Social Share, Social Login and Social Comments Plugin – Super Socializer

Plugin -

Social Share, Social Login and Social Comments Plugin – Super Socializer


Plugin Slug -

super-socializer


Installations -

40,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

7.13.53


Severity -

Medium


CVE Code -

2023-35882


Social Share, Social Login and Social Comments Plugin – Super Socializer

29 - Social Share, Social Login and Social Comments Plugin – Super Socializer

Plugin -

Social Share, Social Login and Social Comments Plugin – Super Socializer


Plugin Slug -

super-socializer


Installations -

40,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

7.13.52


Severity -

High


CVE Code -

2023-2779


Login/Signup Popup ( Inline Form + Woocommerce )

30 - Login/Signup Popup ( Inline Form + Woocommerce )

Plugin -

Login/Signup Popup ( Inline Form + Woocommerce )


Plugin Slug -

easy-login-woocommerce


Installations -

30,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

2.4


Severity -

Medium


Float menu – awesome floating side menu

31 - Float menu – awesome floating side menu

Plugin -

Float menu – awesome floating side menu


Plugin Slug -

float-menu


Installations -

30,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

5.0.3


Severity -

Medium


CVE Code -

2023-3225


Gutenverse – Gutenberg Blocks – Page Builder for Site Editor

32 - Gutenverse – Gutenberg Blocks – Page Builder for Site Editor

Plugin -

Gutenverse – Gutenberg Blocks – Page Builder for Site Editor


Plugin Slug -

gutenverse


Installations -

30,000+


Vulnerability -

Broken Access Control


Patched In Version -

1.8.6


Severity -

Medium


CVE Code -

2023-35875


Icegram Engage – The Best WordPress Popup, Optin, CTA and Lead Generation Plugin

33 - Icegram Engage – The Best WordPress Popup, Optin, CTA and Lead Generation Plugin

Plugin -

Icegram Engage – The Best WordPress Popup, Optin, CTA and Lead Generation Plugin


Plugin Slug -

icegram


Installations -

30,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.1.12


Severity -

High


CVE Code -

2023-2398


Subscribe2 – Form, Email Subscribers & Newsletters

34 - Subscribe2 – Form, Email Subscribers & Newsletters

Plugin -

Subscribe2 – Form, Email Subscribers & Newsletters


Plugin Slug -

subscribe2


Installations -

30,000+


Vulnerability -

Broken Access Control


Patched In Version -

10.41


Severity -

Medium


CVE Code -

2023-1844


Subscribe2 – Form, Email Subscribers & Newsletters

35 - Subscribe2 – Form, Email Subscribers & Newsletters

Plugin -

Subscribe2 – Form, Email Subscribers & Newsletters


Plugin Slug -

subscribe2


Installations -

30,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

10.41


Severity -

Medium


CVE Code -

2023-3407


PostX – Gutenberg Post Grid Blocks

36 - PostX – Gutenberg Post Grid Blocks

Plugin -

PostX – Gutenberg Post Grid Blocks


Plugin Slug -

ultimate-post


Installations -

30,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.9.10


Severity -

High


CVE Code -

2023-36385


Abandoned Cart Lite for WooCommerce

37 - Abandoned Cart Lite for WooCommerce

Plugin -

Abandoned Cart Lite for WooCommerce


Plugin Slug -

woocommerce-abandoned-cart


Installations -

30,000+


Vulnerability -

Stored Cross Site Scripting (XSS)


Patched In Version -

5.2.0


Severity -

High


CVE Code -

2019-25152


ND Shortcodes

38 - ND Shortcodes

Plugin -

ND Shortcodes


Plugin Slug -

nd-shortcodes


Installations -

20,000+


Vulnerability -

Subscriber+ Local File Inclusion


Patched In Version -

7.0


Severity -

High


CVE Code -

2023-1273


Popup by Supsystic

39 - Popup by Supsystic

Plugin -

Popup by Supsystic


Plugin Slug -

popup-by-supsystic


Installations -

20,000+


Vulnerability -

Prototype Pollution


Patched In Version -

1.10.19


Severity -

High


CVE Code -

2023-3186


Protect WP Admin

40 - Protect WP Admin

Plugin -

Protect WP Admin


Plugin Slug -

protect-wp-admin


Installations -

20,000+


Vulnerability -

Unauthenticated Protection Bypass Vulnerability


Patched In Version -

4.0


Severity -

Medium


CVE Code -

2023-3139


Quiz Maker

41 - Quiz Maker

Plugin -

Quiz Maker


Plugin Slug -

quiz-maker


Installations -

20,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

6.4.2.7


Severity -

High


CVE Code -

2023-2571


wpForo Forum

42 - wpForo Forum

Plugin -

wpForo Forum


Plugin Slug -

wpforo


Installations -

20,000+


Vulnerability -

Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents


Patched In Version -

2.1.8


Severity -

High


CVE Code -

2023-2249


Afterpay Gateway for WooCommerce

43 - Afterpay Gateway for WooCommerce

Plugin -

Afterpay Gateway for WooCommerce


Plugin Slug -

afterpay-gateway-for-woocommerce


Installations -

10,000+


Vulnerability -

Admin+ SQL Injection


Patched In Version -

1.12.4


Severity -

High


CVE Code -

2023-2744


Booking Calendar | Appointment Booking | BookIt

44 - Booking Calendar | Appointment Booking | BookIt

Plugin -

Booking Calendar | Appointment Booking | BookIt


Plugin Slug -

bookit


Installations -

10,000+


Vulnerability -

Authentication Bypass


Patched In Version -

2.3.8


Severity -

Critical


CVE Code -

2023-2834


CMS Commander – Manage Multiple Sites

45 - CMS Commander – Manage Multiple Sites

Plugin -

CMS Commander – Manage Multiple Sites


Plugin Slug -

cms-commander-client


Installations -

10,000+


Vulnerability -

Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature


Patched In Version -

2.288


Severity -

High


CVE Code -

2023-3325


Contact Form Email

46 - Contact Form Email

Plugin -

Contact Form Email


Plugin Slug -

contact-form-to-email


Installations -

10,000+


Vulnerability -

Unauthenticated Stored Cross Site Scripting (XSS)


Patched In Version -

1.3.38


Severity -

High


CVE Code -

2023-2718


Custom 404 Pro

47 - Custom 404 Pro

Plugin -

Custom 404 Pro


Plugin Slug -

custom-404-pro


Installations -

10,000+


Vulnerability -

Multiple SQL Injection


Patched In Version -

3.8.1


Severity -

High


CVE Code -

2023-2032


File Renaming on Upload

48 - File Renaming on Upload

Plugin -

File Renaming on Upload


Plugin Slug -

file-renaming-on-upload


Installations -

10,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

2.5.2


Severity -

Medium


CVE Code -

2023-2684


Accordion & FAQ – Helpie WordPress Frequently Asked Questions plugin

49 - Accordion & FAQ – Helpie WordPress Frequently Asked Questions plugin

Plugin -

Accordion & FAQ – Helpie WordPress Frequently Asked Questions plugin


Plugin Slug -

helpie-faq


Installations -

10,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.9.9


Severity -

High


CVE Code -

2023-1891


Five Star Restaurant Reservations – WordPress Booking Plugin

50 - Five Star Restaurant Reservations – WordPress Booking Plugin

Plugin -

Five Star Restaurant Reservations – WordPress Booking Plugin


Plugin Slug -

restaurant-reservations


Installations -

10,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.6.8


Severity -

High


CVE Code -

2023-34017


Membership Plugin – Restrict Content

51 - Membership Plugin – Restrict Content

Plugin -

Membership Plugin – Restrict Content


Plugin Slug -

restrict-content


Installations -

10,000+


Vulnerability -

Missing Authorization to Notice Dismissal


Patched In Version -

3.2.3


Severity -

Medium


Membership Plugin – Restrict Content

52 - Membership Plugin – Restrict Content

Plugin -

Membership Plugin – Restrict Content


Plugin Slug -

restrict-content


Installations -

10,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.2.3


Severity -

High


SupportCandy – Helpdesk & Support Ticket System

53 - SupportCandy – Helpdesk & Support Ticket System

Plugin -

SupportCandy – Helpdesk & Support Ticket System


Plugin Slug -

supportcandy


Installations -

10,000+


Vulnerability -

Subscriber+ SQL Injection


Patched In Version -

3.1.7


Severity -

High


CVE Code -

2023-2719


SupportCandy – Helpdesk & Support Ticket System

54 - SupportCandy – Helpdesk & Support Ticket System

Plugin -

SupportCandy – Helpdesk & Support Ticket System


Plugin Slug -

supportcandy


Installations -

10,000+


Vulnerability -

Admin+ SQL Injection


Patched In Version -

3.1.7


Severity -

High


CVE Code -

2023-2805


Event Manager and Tickets Selling Plugin for WooCommerce

55 - Event Manager and Tickets Selling Plugin for WooCommerce

Plugin -

Event Manager and Tickets Selling Plugin for WooCommerce


Plugin Slug -

mage-eventpress


Installations -

9,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

3.9.6


Severity -

Medium


CVE Code -

2023-36383


Buy Me a Coffee – Button and Widget Plugin

56 - Buy Me a Coffee – Button and Widget Plugin

Plugin -

Buy Me a Coffee – Button and Widget Plugin


Plugin Slug -

buymeacoffee


Installations -

6,000+


Vulnerability -

Auth. Stored Cross Site Scripting (XSS)


Patched In Version -

3.7


Severity -

Medium


CVE Code -

2023-2578


FormCraft – Contact Form Builder for WordPress

57 - FormCraft – Contact Form Builder for WordPress

Plugin -

FormCraft – Contact Form Builder for WordPress


Plugin Slug -

formcraft-form-builder


Installations -

5,000+


Vulnerability -

Auth. SQL Injection


Patched In Version -

3.9.7


Severity -

High


CVE Code -

2023-2592


WPForms Google Sheet Connector

58 - WPForms Google Sheet Connector

Plugin -

WPForms Google Sheet Connector


Plugin Slug -

gsheetconnector-wpforms


Installations -

5,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.4.6


Severity -

High


CVE Code -

2023-2321


MStore API

59 - MStore API

Plugin -

MStore API


Plugin Slug -

mstore-api


Installations -

5,000+


Vulnerability -

Unauth. SQL Injection


Patched In Version -

4.0.2


Severity -

Critical


CVE Code -

2023-3197


MStore API

60 - MStore API

Plugin -

MStore API


Plugin Slug -

mstore-api


Installations -

5,000+


Vulnerability -

SQL Injection


Patched In Version -

3.9.8


Severity -

High


CVE Code -

2022-47614


Poll Maker – Best WordPress Poll Plugin

61 - Poll Maker – Best WordPress Poll Plugin

Plugin -

Poll Maker – Best WordPress Poll Plugin


Plugin Slug -

poll-maker


Installations -

5,000+


Vulnerability -

Server Side Request Forgery (SSRF)


Patched In Version -

4.6.3


Severity -

Medium


CVE Code -

2023-34013


62 - Simple Iframe

Plugin -

Simple Iframe


Plugin Slug -

simple-iframe


Installations -

5,000+


Vulnerability -

Contributor+ Stored Cross Site Scripting (XSS)


Patched In Version -

1.2.0


Severity -

Medium


CVE Code -

2023-2964


WP Custom Cursors | WordPress Cursor Plugin

63 - WP Custom Cursors | WordPress Cursor Plugin

Plugin -

WP Custom Cursors | WordPress Cursor Plugin


Plugin Slug -

wp-custom-cursors


Installations -

5,000+


Vulnerability -

Admin+ SQL Injection


Patched In Version -

3.2


Severity -

High


CVE Code -

2023-2221


AI ChatBot

64 - AI ChatBot

Plugin -

AI ChatBot


Plugin Slug -

chatbot


Installations -

4,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

4.5.5


Severity -

Medium


CVE Code -

2023-2742


AI ChatBot

65 - AI ChatBot

Plugin -

AI ChatBot


Plugin Slug -

chatbot


Installations -

4,000+


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

4.5.6


Severity -

Medium


CVE Code -

2023-2811


Survey Maker – Best WordPress Survey Plugin

66 - Survey Maker – Best WordPress Survey Plugin

Plugin -

Survey Maker – Best WordPress Survey Plugin


Plugin Slug -

survey-maker


Installations -

4,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.4.7


Severity -

High


CVE Code -

2023-2572


Integration for Contact Form 7 and Zoho CRM, Bigin

67 - Integration for Contact Form 7 and Zoho CRM, Bigin

Plugin -

Integration for Contact Form 7 and Zoho CRM, Bigin


Plugin Slug -

cf7-zoho


Installations -

3,000+


Vulnerability -

Admin+ SQL Injection


Patched In Version -

1.2.4


Severity -

High


CVE Code -

2023-2527


CHP Ads Block Detector

68 - CHP Ads Block Detector

Plugin -

CHP Ads Block Detector


Plugin Slug -

chp-ads-block-detector


Installations -

3,000+


Vulnerability -

Broken Access Control


Patched In Version -

3.9.8


Severity -

Medium


CVE Code -

2023-36509


Potent Donations for WooCommerce

69 - Potent Donations for WooCommerce

Plugin -

Potent Donations for WooCommerce


Plugin Slug -

donations-for-woocommerce


Installations -

3,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.1.10


Severity -

Medium


CVE Code -

2023-35912


EventON

70 - EventON

Plugin -

EventON


Plugin Slug -

eventon-lite


Installations -

3,000+


Vulnerability -

Unauthenticated Event Access


Patched In Version -

2.1.2


Severity -

Medium


CVE Code -

2023-2796


EventON

71 - EventON

Plugin -

EventON


Plugin Slug -

eventon-lite


Installations -

3,000+


Vulnerability -

Unauthenticated Post Access via Insecure Direct Object References (IDOR)


Patched In Version -

2.1.2


Severity -

Medium


CVE Code -

2023-3219


Core Web Vitals & PageSpeed Booster

72 - Core Web Vitals & PageSpeed Booster

Plugin -

Core Web Vitals & PageSpeed Booster


Plugin Slug -

core-web-vitals-pagespeed-booster


Installations -

2,000+


Vulnerability -

Open Redirection


Patched In Version -

1.0.13


Severity -

Medium


CVE Code -

2023-35883


Extra User Details

73 - Extra User Details

Plugin -

Extra User Details


Plugin Slug -

extra-user-details


Installations -

2,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

0.5.1


Severity -

Medium


CVE Code -

2023-35877


Extra User Details

74 - Extra User Details

Plugin -

Extra User Details


Plugin Slug -

extra-user-details


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

0.5.1


Severity -

Medium


CVE Code -

2023-35878


KiviCare – Clinic & Patient Management System (EHR)

75 - KiviCare – Clinic & Patient Management System (EHR)

Plugin -

KiviCare – Clinic & Patient Management System (EHR)


Plugin Slug -

kivicare-clinic-management-system


Installations -

2,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.2.1


Severity -

High


CVE Code -

2023-2624


KiviCare – Clinic & Patient Management System (EHR)

76 - KiviCare – Clinic & Patient Management System (EHR)

Plugin -

KiviCare – Clinic & Patient Management System (EHR)


Plugin Slug -

kivicare-clinic-management-system


Installations -

2,000+


Vulnerability -

Subscriber+ Sensitive Data Exposure


Patched In Version -

3.2.1


Severity -

Medium


CVE Code -

2023-2623


KiviCare – Clinic & Patient Management System (EHR)

77 - KiviCare – Clinic & Patient Management System (EHR)

Plugin -

KiviCare – Clinic & Patient Management System (EHR)


Plugin Slug -

kivicare-clinic-management-system


Installations -

2,000+


Vulnerability -

Subscriber+ Unauthorised AJAX Calls


Patched In Version -

3.2.1


Severity -

Medium


CVE Code -

2023-2627


KiviCare – Clinic & Patient Management System (EHR)

78 - KiviCare – Clinic & Patient Management System (EHR)

Plugin -

KiviCare – Clinic & Patient Management System (EHR)


Plugin Slug -

kivicare-clinic-management-system


Installations -

2,000+


Vulnerability -

Multiple Cross Site Request Forgery (CSRF)


Patched In Version -

3.2.1


Severity -

Medium


CVE Code -

2023-2628


79 - teachPress

Plugin -

teachPress


Plugin Slug -

teachpress


Installations -

2,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

9.0.3


Severity -

High


CVE Code -

2023-36501


WP Directory Kit

80 - WP Directory Kit

Plugin -

WP Directory Kit


Plugin Slug -

wpdirectorykit


Installations -

2,000+


Vulnerability -

Unauthenticated Local File Inclusion


Patched In Version -

1.2.4


Severity -

High


CVE Code -

2023-2278


Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

81 - Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress

Plugin -

Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress


Plugin Slug -

contact-form-to-db


Installations -

1,000+


Vulnerability -

SQL Injection


Patched In Version -

1.7.2


Severity -

High


CVE Code -

2023-36508


EventPrime – Modern Events Calendar, Bookings and Tickets

82 - EventPrime – Modern Events Calendar, Bookings and Tickets

Plugin -

EventPrime – Modern Events Calendar, Bookings and Tickets


Plugin Slug -

eventprime-event-calendar-management


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

3.0.6


Severity -

High


CVE Code -

2023-35884


Photo Gallery by Ays – Responsive Image Gallery

83 - Photo Gallery by Ays – Responsive Image Gallery

Plugin -

Photo Gallery by Ays – Responsive Image Gallery


Plugin Slug -

gallery-photo-gallery


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

5.1.7


Severity -

High


CVE Code -

2023-2568


Elementor Forms Google Sheet Connector

84 - Elementor Forms Google Sheet Connector

Plugin -

Elementor Forms Google Sheet Connector


Plugin Slug -

gsheetconnector-for-elementor-forms


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.0.7


Severity -

High


CVE Code -

2023-2324


Ninja Forms Google Sheet Connector

85 - Ninja Forms Google Sheet Connector

Plugin -

Ninja Forms Google Sheet Connector


Plugin Slug -

gsheetconnector-ninja-forms


Installations -

1,000+


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.2.7


Severity -

High


CVE Code -

2023-2333


MyCurator Content Curation

86 - MyCurator Content Curation

Plugin -

MyCurator Content Curation


Plugin Slug -

mycurator


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.75


Severity -

Medium


CVE Code -

2023-32104


OOPSpam Anti-Spam

87 - OOPSpam Anti-Spam

Plugin -

OOPSpam Anti-Spam


Plugin Slug -

oopspam-anti-spam


Installations -

1,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.1.45


Severity -

Medium


CVE Code -

2023-35913


ReDi Restaurant Reservation

88 - ReDi Restaurant Reservation

Plugin -

ReDi Restaurant Reservation


Plugin Slug -

redi-restaurant-reservation


Installations -

1,000+


Vulnerability -

Broken Access Control


Patched In Version -

23.0212


Severity -

High


CVE Code -

2023-36510


Booking Calendar Contact Form

89 - Booking Calendar Contact Form

Plugin -

Booking Calendar Contact Form


Plugin Slug -

booking-calendar-contact-form


Installations -

900+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

1.2.41


Severity -

High


CVE Code -

2023-36384


Customer Service Software & Support Ticket System

90 - Customer Service Software & Support Ticket System

Plugin -

Customer Service Software & Support Ticket System


Plugin Slug -

wp-ticket


Installations -

600+


Vulnerability -

Authenticated (Administrator+) Stored Cross Site Scripting (XSS)


Patched In Version -

5.13


Severity -

Medium


WP Sticky Social

91 - WP Sticky Social

Plugin -

WP Sticky Social


Plugin Slug -

wp-sticky-social


Installations -

300+


Vulnerability -

Cross-Site Request Forgery to Stored Cross-Site Scripting


Patched In Version -

1.0.2


Severity -

High


CVE Code -

2023-3320


Mail Queue

92 - Mail Queue

Plugin -

Mail Queue


Plugin Slug -

mail-queue


Installations -

80+


Vulnerability -

Unauthenticated Stored Cross-Site Scripting via Email Subject


Patched In Version -

1.2


Severity -

High


CVE Code -

2023-3167


Lana Shortcodes

93 - Lana Shortcodes

Plugin -

Lana Shortcodes


Plugin Slug -

lana-shortcodes


Installations -

70+


Vulnerability -

Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode


Patched In Version -

1.2.0


Severity -

Medium


Mailtree Log Mail

94 - Mailtree Log Mail

Plugin -

Mailtree Log Mail


Plugin Slug -

mailtree-log-mail


Installations -

10+


Vulnerability -

Unauth. Stored Cross Site Scripting (XSS)


Patched In Version -

1.0.1


Severity -

High


CVE Code -

2023-3135


95 - AutomateWoo

Plugin -

AutomateWoo


Plugin Slug -

automatewoo


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

5.7.6


Severity -

Medium


CVE Code -

2023-36513


96 - AutomateWoo

Plugin -

AutomateWoo


Plugin Slug -

automatewoo


Vulnerability -

Broken Access Control


Patched In Version -

5.7.6


Severity -

Medium


CVE Code -

2023-36512


97 - Complianz Premium

Plugin -

Complianz Premium


Plugin Slug -

complianz-gdpr-premium


Vulnerability -

Cross Site Request Forgery (CSRF) to Site Wide Cross Site Scripting (XSS


Patched In Version -

6.4.7


Severity -

High


CVE Code -

2023-33333


98 - Complianz Premium

Plugin -

Complianz Premium


Plugin Slug -

complianz-gdpr-premium


Vulnerability -

Multiple Cross Site Request Forgery (CSRF)


Patched In Version -

6.4.8


Severity -

Medium


CVE Code -

2023-34030


99 - Elementor Pro

Plugin -

Elementor Pro


Plugin Slug -

elementor-pro


Vulnerability -

Auth. Broken Access Control


Patched In Version -

3.13.1


Severity -

Medium


CVE Code -

2023-35050


100 - Go Pricing

Plugin -

Go Pricing


Plugin Slug -

go-pricing-wordpress-responsive-pricing-tables


Vulnerability -

Broken Access Control


Patched In Version -

3.4


Severity -

Medium


CVE Code -

2023-2494


101 - Go Pricing

Plugin -

Go Pricing


Plugin Slug -

go-pricing-wordpress-responsive-pricing-tables


Vulnerability -

Contributor+ Cross Site Scripting (XSS)


Patched In Version -

3.4


Severity -

Medium


CVE Code -

2023-2498


102 - MonsterInsights Pro

Plugin -

MonsterInsights Pro


Plugin Slug -

google-analytics-premium


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

8.15


Severity -

Medium


CVE Code -

2023-32291


103 - Gravity Forms

Plugin -

Gravity Forms


Plugin Slug -

gravityforms


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

2.7.5


Severity -

High


CVE Code -

2023-2701


104 - WPBakery Page Builder

Plugin -

WPBakery Page Builder


Plugin Slug -

js_composer


Vulnerability -

Contributor+ Cross Site Scripting (XSS)


Patched In Version -

6.13.0


Severity -

Medium


CVE Code -

2023-31213


Lana Text to Image

105 - Lana Text to Image

Plugin -

Lana Text to Image


Plugin Slug -

lana-text-to-image


Vulnerability -

Auth. Stored Cross Site Scripting (XSS)


Patched In Version -

1.1.0


Severity -

Medium


CVE Code -

2023-3387


106 - PixelYourSite PRO

Plugin -

PixelYourSite PRO


Plugin Slug -

pixelyoursite-pro


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

9.6.2


Severity -

Medium


CVE Code -

2023-2584


107 - USM Premium

Plugin -

USM Premium


Plugin Slug -

ultimate-premium-plugin


Vulnerability -

Admin+ Stored Cross Site Scripting (XSS)


Patched In Version -

16.3


Severity -

Medium


CVE Code -

2023-1166


108 - Abandoned Cart Pro

Plugin -

Abandoned Cart Pro


Plugin Slug -

woocommerce-abandoned-cart-pro


Vulnerability -

Stored Cross Site Scripting (XSS)


Patched In Version -

7.13.0


Severity -

High


CVE Code -

2019-25152


109 - WooCommerce Brands

Plugin -

WooCommerce Brands


Plugin Slug -

woocommerce-brands


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.6.50


Severity -

Medium


CVE Code -

2023-35880


110 - WooCommerce Bulk Stock Management

Plugin -

WooCommerce Bulk Stock Management


Plugin Slug -

woocommerce-bulk-stock-management


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

2.2.34


Severity -

High


CVE Code -

2023-35918


111 - WooCommerce Order Barcodes

Plugin -

WooCommerce Order Barcodes


Plugin Slug -

woocommerce-order-barcodes


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

1.6.5


Severity -

Medium


CVE Code -

2023-36511


112 - WooCommerce Product Vendors

Plugin -

WooCommerce Product Vendors


Plugin Slug -

woocommerce-product-vendors


Vulnerability -

Shop Manager+ SQL Injection


Patched In Version -

2.1.79


Severity -

High


CVE Code -

2023-35879


113 - WooCommerce Ship to Multiple Addresses

Plugin -

WooCommerce Ship to Multiple Addresses


Plugin Slug -

woocommerce-shipping-multiple-addresses


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

3.8.6


Severity -

Medium


CVE Code -

2023-36514


114 - WooCommerce Subscriptions

Plugin -

WooCommerce Subscriptions


Plugin Slug -

woocommerce-subscriptions


Vulnerability -

Insecure Direct Object References (IDOR)


Patched In Version -

5.1.3


Severity -

High


CVE Code -

2023-35914


115 - File Uploader

Plugin -

File Uploader


Plugin Slug -

wp-file-uploader


Vulnerability -

Admin+ Path Traversal


Patched In Version -

4.19.2


Severity -

Medium


CVE Code -

2023-2688


116 - WPForms Pro

Plugin -

WPForms Pro


Plugin Slug -

wpforms


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.8.1.3


Severity -

Medium


CVE Code -

2023-30500


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Plugin Vulnerabilities – Unpatched

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

1 - WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

Plugin -

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent


Plugin Slug -

gdpr-cookie-consent


Installations -

9,000+


Vulnerability -

CSV Injection


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-23678


Form Builder | Create Responsive Contact Forms

2 - Form Builder | Create Responsive Contact Forms

Plugin -

Form Builder | Create Responsive Contact Forms


Plugin Slug -

contact-form-add


Installations -

6,000+


Vulnerability -

Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-23795


ApplyOnline – Application Form Builder and Manager

3 - ApplyOnline – Application Form Builder and Manager

Plugin -

ApplyOnline – Application Form Builder and Manager


Plugin Slug -

apply-online


Installations -

5,000+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-24391


JS Help Desk – Best Help Desk & Support Plugin

4 - JS Help Desk – Best Help Desk & Support Plugin

Plugin -

JS Help Desk – Best Help Desk & Support Plugin


Plugin Slug -

js-support-ticket


Installations -

5,000+


Vulnerability -

Insecure Direct Object References (IDOR) Leading To Ticket Deletion


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-23679


MojoPlug Slide Panel

5 - MojoPlug Slide Panel

Plugin -

MojoPlug Slide Panel


Plugin Slug -

mojoplug-slide-panel


Installations -

800+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-23807


Smoothscroller

6 - Smoothscroller

Plugin -

Smoothscroller


Plugin Slug -

smoothscroller


Installations -

800+


Vulnerability -

Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-23811


Enable SVG Uploads

7 - Enable SVG Uploads

Plugin -

Enable SVG Uploads


Plugin Slug -

enable-svg-uploads


Installations -

300+


Vulnerability -

Auth. Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2529


Caldera Forms Google Sheets Connector

8 - Caldera Forms Google Sheets Connector

Plugin -

Caldera Forms Google Sheets Connector


Plugin Slug -

gsheetconnector-caldera-forms


Installations -

200+


Vulnerability -

Access Code Update via Cross Site Request Forgery (CSRF)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2330


9 - About Me 3000 widget

Plugin -

About Me 3000 widget


Plugin Slug -

about-me-3000


Vulnerability -

Authenticated (Administrator+) Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-3369


10 - AN_GradeBook

Plugin -

AN_GradeBook


Plugin Slug -

an-gradebook


Vulnerability -

Auth. Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2709


11 - BBS e-Popup

Plugin -

BBS e-Popup


Plugin Slug -

bbs-e-popup


Vulnerability -

Broken Access Control


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-36504


12 - CF7 Google Sheets Connector Pro

Plugin -

CF7 Google Sheets Connector Pro


Plugin Slug -

cf7-google-sheets-connector-pro


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2320


13 - Contact Form by WD

Plugin -

Contact Form by WD


Plugin Slug -

contact-form-maker


Vulnerability -

Admin+ SQL Injection


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2655


14 - Defa Online Image Protector

Plugin -

Defa Online Image Protector


Plugin Slug -

defa-online-image-protector


Vulnerability -

Auth. Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2026


15 - Gallery Metabox

Plugin -

Gallery Metabox


Plugin Slug -

gallery-metabox


Vulnerability -

Missing Authorization via gallery_remove


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2561


16 - Gallery Metabox

Plugin -

Gallery Metabox


Plugin Slug -

gallery-metabox


Vulnerability -

Missing Authorization


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2562


17 - Greeklish-permalink

Plugin -

Greeklish-permalink


Plugin Slug -

greeklish-permalink


Vulnerability -

Unauth. Post Slug Update


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2495


18 - Image Map Pro

Plugin -

Image Map Pro


Plugin Slug -

image-map-pro-lite


Vulnerability -

Missing Authorization to Stored Cross-Site Scripting


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-3412


19 - InventoryPress

Plugin -

InventoryPress


Plugin Slug -

inventorypress


Vulnerability -

Author+ Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2579


20 - PrePost SEO

Plugin -

PrePost SEO


Plugin Slug -

prepost-seo


Vulnerability -

Auth. Stored Cross Site Scripting (XSS)


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2029


21 - Quick Post Duplicator

Plugin -

Quick Post Duplicator


Plugin Slug -

rduplicator


Vulnerability -

Authenticated (Contributor+) SQL Injection


Patched In Version -

No Fix


Severity -

High


CVE Code -

2023-2229


22 - Upload Resume

Plugin -

Upload Resume


Plugin Slug -

resume-upload-form


Vulnerability -

Captcha Bypass Vulnerability


Patched In Version -

No Fix


Severity -

Medium


CVE Code -

2023-2751


23 - User Email Verification for WooCommerce

Plugin -

User Email Verification for WooCommerce


Plugin Slug -

woo-confirmation-email


Vulnerability -

Authentication bypass via weak token generation


Patched In Version -

No Fix


Severity -

Critical


CVE Code -

2023-2781


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

WordPress Theme Vulnerabilities

1 - Balkon

Theme -

Balkon


Theme Slug -

balkon


Vulnerability -

Reflected Cross Site Scripting (XSS)


Patched In Version -

1.3.3


Severity -

High


CVE Code -

2023-36502


Protect Your WordPress Website Today With Website Guardian

Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.

Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!

We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.

Click to access the login or register cheese