WordPress Vulnerability Report – June 28, 2023
DETAILS FROM DAN KNAUSS OF ITHEMES ON JUNE 28, 2023
Last Updated on June 29, 2023
This week, 140 total vulnerabilities emerged in public disclosure. They may affect over 13 million WordPress sites. There are 116 plugin vulnerabilities and one theme vulnerability that has security patches available, so run those updates!
Additionally, there are 23 plugin vulnerabilities with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.
Is Your WordPress Website Secure?
DID YOU KNOW – A staggering 83% of WordPress websites are not upgraded or updated, is your website one of these?
Hacks happen due to lack of website upkeep and protection, like updating WordPress or plugins, plus using weak passwords. Contrary to popular belief, web designers and website hosting companies are not responsible for the security of your WordPress website; you are. It’s like using your computer without Anti-virus!
WordPress Core Vulnerabilities
No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities – Patched
These are plugin vulnerabilities that have been fixed with the most recent updates, it’s recomended to update all plugins to the newest version to improve site safety.
Jump to section
- WPForms Lite
- Ninja Forms Contact Form
- Complianz
- Complianz
- MainWP Child
- WooCommerce Payments
- WooCommerce Payments
- WooCommerce PayPal Payments
- ProfilePress
- Spam protection, AntiSpam, FireWall by CleanTalk
- Metform Elementor Contact Form Builder
- Photo Gallery by 10Web
- Ultimate Member
- Unlimited Elements For Elementor
- Unlimited Elements For Elementor
- WP Mail Logging
- WP Activity Log
- Colibri Page Builder
- WordPress Button Plugin MaxButtons
- WooCommerce Square
- EmbedPress
- Bookly
- Conditional Menus
- Tutor LMS
- Dokan
- CF7 Google Sheets Connector
- ConvertKit
- Super Socializer
- Super Socializer
- Login/Signup Popup
- Float menu
- Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
- Icegram
- Subscribe2
- Subscribe2
- PostX – Gutenberg Post Grid Blocks
- Abandoned Cart Lite for WooCommerce
- ND Shortcodes
- Supsystic Popup
- Protect WP Admin
- Quiz Maker
- wpForo Forum
- WP ERP
- BookIt
- CMS Commander
- Contact Form Email
- Custom 404 Pro
- File Renaming on Upload
- Accordion & FAQ
- Five Star Restaurant Reservations
- Restrict Content
- Restrict Content
- SupportCandy
- SupportCandy
- Event Manager and Tickets Selling Plugin for WooCommerce
- Buy Me a Coffee
- FormCraft Premium
- WPForms Google Sheet Connector
- MStore API
- MStore API
- Poll Maker
- Simple Iframe
- WP Custom Cursors
- AI ChatBot
- AI ChatBot
- Survey Maker
- Integration for Contact Form 7 and Zoho CRM, Bigin
- CHP Ads Block Detector
- Potent Donations for WooCommerce
- EventON
- EventON
- Core Web Vitals & PageSpeed Booster
- Extra User Details
- Extra User Details
- KiviCare Management System
- KiviCare Management System
- KiviCare Management System
- KiviCare Management System
- teachPress
- WP Directory Kit
- Contact Form to DB by BestWebSoft
- EventPrime
- Photo Gallery by Ays
- Elementor Forms Google Sheet Connector
- Ninja Forms Google Sheet Connector
- MyCurator Content Curation
- OOPSpam Anti-Spam
- ReDi Restaurant Reservation
- Booking Calendar Contact Form
- Customer Service Software & Support Ticket System
- WP Sticky Social
- Mail Queue
- Lana Shortcodes
- Mailtree Log Mail
- AutomateWoo
- AutomateWoo
- Complianz Premium
- Complianz Premiumy
- Elementor Pro
- Go Pricing – WordPress Responsive Pricing Tables
- Go Pricing – WordPress Responsive Pricing Tables
- MonsterInsights Pro
- Gravity Forms
- WPBakery Page Builder
- Lana Text to Image
- PixelYourSite PRO
- USM Premium
- Abandoned Cart Pro for WooCommerce
- WooCommerce Brands
- WooCommerce Bulk Stock Management
- WooCommerce Order Barcodes
- WooCommerce Product Vendors
- WooCommerce Ship to Multiple Addresses
- WooCommerce Subscriptions
- WordPress File Upload
- WPForms Pro
WordPress Plugin Vulnerabilities – Unpatched
These are plugin vulnerabilities that have NOT been fixed with the most recent updates, it’s recomended you deactivate or remove these plugins from your site until they are fixed.
Jump to section
- WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
- Form Builder
- ApplyOnline – Application Form Builder and Manager
- JS Help Desk – Best Help Desk & Support Plugin
- MojoPlug Slide Panel
- Smoothscroller
- Enable SVG Uploads
- Caldera Forms Google Sheets Connector
- About Me 3000 widget
- AN_GradeBook
- BBS e-Popup
- CF7 Google Sheets Connector Pro
- Contact Form by WD
- Image Protector
- Gallery Metabox
- Gallery Metabox
- Greeklish-permalink
- Image Map Pro
- InventoryPress
- PrePost SEO
- Quick Post Duplicator
- Upload Resume
- User Email Verification for WooCommerce
WordPress Theme Vulnerabilities
Jump to section
These are vulnerabilities that have occoured in themes for wordpress. If there is a patch for the issue you should update the theme immediately, if there is no fix you should change your site to a different theme.
WordPress Plugin Vulnerabilities – Patched

1 - Contact Form by WPForms – Drag & Drop Form Builder for WordPress
Plugin -
Contact Form by WPForms – Drag & Drop Form Builder for WordPress
Plugin Slug -
wpforms-lite
Installations -
5,000,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.8.1.3
Severity -
Medium
CVE Code -

2 - Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin -
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress
Plugin Slug -
ninja-forms
Installations -
900,000+
Vulnerability -
Arbitrary File Deletion
Patched In Version -
3.6.25
Severity -
Medium
CVE Code -

3 - Complianz – GDPR/CCPA Cookie Consent
Plugin -
Complianz – GDPR/CCPA Cookie Consent
Plugin Slug -
complianz-gdpr
Installations -
700,000+
Vulnerability -
Cross Site Request Forgery (CSRF) lead to Site Wide Cross Site Scripting (XSS)
Patched In Version -
6.4.5
Severity -
High
CVE Code -

4 - Complianz – GDPR/CCPA Cookie Consent
Plugin -
Complianz – GDPR/CCPA Cookie Consent
Plugin Slug -
complianz-gdpr
Installations -
700,000+
Vulnerability -
Multiple Cross Site Request Forgery (CSRF)
Patched In Version -
6.4.6
Severity -
Medium
CVE Code -

5 - MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard
Plugin -
MainWP Child – Securely Connects Sites to the MainWP WordPress Manager Dashboard
Plugin Slug -
mainwp-child
Installations -
600,000+
Vulnerability -
Information Disclosure via Back-Up Files
Patched In Version -
4.4.1.2
Severity -
High
CVE Code -

6 - WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo
Plugin -
WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo
Plugin Slug -
woocommerce-payments
Installations -
600,000+
Vulnerability -
SQL Injection
Patched In Version -
5.9.1
Severity -
High
CVE Code -

7 - WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo
Plugin -
WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo
Plugin Slug -
woocommerce-payments
Installations -
600,000+
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
5.9.1
Severity -
High
CVE Code -

8 - WooCommerce PayPal Payments
Plugin -
Plugin Slug -
woocommerce-paypal-payments
Installations -
600,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.0.5
Severity -
Medium
CVE Code -
9 - Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Plugin -
Plugin Slug -
wp-user-avatar
Installations -
300,000+
Vulnerability -
Reflected Cross Site Scripting (XSS) via error message
Patched In Version -
4.11.0
Severity -
High

10 - Spam protection, AntiSpam, FireWall by CleanTalk
Plugin -
Spam protection, AntiSpam, FireWall by CleanTalk
Plugin Slug -
cleantalk-spam-protect
Installations -
200,000+
Vulnerability -
Broken Access Control
Patched In Version -
6.11
Severity -
High
CVE Code -

11 - Metform Elementor Contact Form Builder – Flexible and Design-Friendly Contact Form builder plugin for WordPress
Plugin -
Plugin Slug -
metform
Installations -
200,000+
Vulnerability -
Cross Site Request Forgery (CSRF) via permalink_setup
Patched In Version -
3.3.3
Severity -
Medium
CVE Code -

12 - Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Plugin -
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Plugin Slug -
photo-gallery
Installations -
200,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.8.16
Severity -
Medium
CVE Code -

13 - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Plugin -
Plugin Slug -
ultimate-member
Installations -
200,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.6.1
Severity -
Medium
CVE Code -

14 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Plugin -
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Plugin Slug -
unlimited-elements-for-elementor
Installations -
200,000+
Vulnerability -
Multiple Broken Access Control
Patched In Version -
1.5.66
Severity -
High
CVE Code -

15 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Plugin -
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Plugin Slug -
unlimited-elements-for-elementor
Installations -
200,000+
Vulnerability -
Arbitrary File Upload
Patched In Version -
1.5.66
Severity -
Critical
CVE Code -

16 - WP Mail Logging
Plugin -
Plugin Slug -
wp-mail-logging
Installations -
200,000+
Vulnerability -
Missing Authorization to Notice Dismissal
Patched In Version -
1.12.0
Severity -
Medium

17 - WP Activity Log
Plugin -
Plugin Slug -
wp-security-audit-log
Installations -
200,000+
Vulnerability -
Subscriber+ Information Leak
Patched In Version -
4.5.2
Severity -
Medium
CVE Code -

18 - Colibri Page Builder
Plugin -
Plugin Slug -
colibri-page-builder
Installations -
100,000+
Vulnerability -
Auth. SQL Injection
Patched In Version -
1.0.229
Severity -
High
CVE Code -

19 - WordPress Button Plugin MaxButtons
Plugin -
WordPress Button Plugin MaxButtons
Plugin Slug -
maxbuttons
Installations -
100,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
9.6
Severity -
Medium
CVE Code -

20 - WooCommerce Square
Plugin -
Plugin Slug -
woocommerce-square
Installations -
100,000+
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
3.8.2
Severity -
High
CVE Code -

21 - EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor
Plugin -
Plugin Slug -
embedpress
Installations -
80,000+
Vulnerability -
Sensitive Data Exposure
Patched In Version -
3.8.0
Severity -
Medium
CVE Code -

22 - WordPress Online Booking and Scheduling Plugin – Bookly
Plugin -
WordPress Online Booking and Scheduling Plugin – Bookly
Plugin Slug -
bookly-responsive-appointment-booking-tool
Installations -
70,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS) via service titles
Patched In Version -
21.8
Severity -
Medium
CVE Code -
23 - Conditional Menus
Plugin -
Plugin Slug -
conditional-menus
Installations -
70,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2.1
Severity -
High
CVE Code -

24 - Tutor LMS – eLearning and online course solution
Plugin -
Tutor LMS – eLearning and online course solution
Plugin Slug -
tutor
Installations -
70,000+
Vulnerability -
Unauthenticated Access to Tutor LMS Lesson Resources via REST API
Patched In Version -
2.2.1
Severity -
Medium
CVE Code -

25 - Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
Plugin -
Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
Plugin Slug -
dokan-lite
Installations -
60,000+
Vulnerability -
PHP Object Injection
Patched In Version -
3.7.20
Severity -
Medium
CVE Code -

26 - CF7 Google Sheets Connector
Plugin -
Plugin Slug -
cf7-google-sheets-connector
Installations -
40,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
5.0.2
Severity -
High
CVE Code -

27 - ConvertKit – Email Marketing, Email Newsletter, Subscribers and Landing Pages
Plugin -
ConvertKit – Email Marketing, Email Newsletter, Subscribers and Landing Pages
Plugin Slug -
convertkit
Installations -
40,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.2.1
Severity -
High
CVE Code -

28 - Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin -
Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin Slug -
super-socializer
Installations -
40,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
7.13.53
Severity -
Medium
CVE Code -

29 - Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin -
Social Share, Social Login and Social Comments Plugin – Super Socializer
Plugin Slug -
super-socializer
Installations -
40,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
7.13.52
Severity -
High
CVE Code -

30 - Login/Signup Popup ( Inline Form + Woocommerce )
Plugin -
Login/Signup Popup ( Inline Form + Woocommerce )
Plugin Slug -
easy-login-woocommerce
Installations -
30,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
2.4
Severity -
Medium

31 - Float menu – awesome floating side menu
Plugin -
Float menu – awesome floating side menu
Plugin Slug -
float-menu
Installations -
30,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
5.0.3
Severity -
Medium
CVE Code -

32 - Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
Plugin -
Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
Plugin Slug -
gutenverse
Installations -
30,000+
Vulnerability -
Broken Access Control
Patched In Version -
1.8.6
Severity -
Medium
CVE Code -

33 - Icegram Engage – The Best WordPress Popup, Optin, CTA and Lead Generation Plugin
Plugin -
Icegram Engage – The Best WordPress Popup, Optin, CTA and Lead Generation Plugin
Plugin Slug -
icegram
Installations -
30,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.1.12
Severity -
High
CVE Code -

34 - Subscribe2 – Form, Email Subscribers & Newsletters
Plugin -
Subscribe2 – Form, Email Subscribers & Newsletters
Plugin Slug -
subscribe2
Installations -
30,000+
Vulnerability -
Broken Access Control
Patched In Version -
10.41
Severity -
Medium
CVE Code -

35 - Subscribe2 – Form, Email Subscribers & Newsletters
Plugin -
Subscribe2 – Form, Email Subscribers & Newsletters
Plugin Slug -
subscribe2
Installations -
30,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
10.41
Severity -
Medium
CVE Code -

36 - PostX – Gutenberg Post Grid Blocks
Plugin -
PostX – Gutenberg Post Grid Blocks
Plugin Slug -
ultimate-post
Installations -
30,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.9.10
Severity -
High
CVE Code -

37 - Abandoned Cart Lite for WooCommerce
Plugin -
Abandoned Cart Lite for WooCommerce
Plugin Slug -
woocommerce-abandoned-cart
Installations -
30,000+
Vulnerability -
Stored Cross Site Scripting (XSS)
Patched In Version -
5.2.0
Severity -
High
CVE Code -

38 - ND Shortcodes
Plugin -
Plugin Slug -
nd-shortcodes
Installations -
20,000+
Vulnerability -
Subscriber+ Local File Inclusion
Patched In Version -
7.0
Severity -
High
CVE Code -

39 - Popup by Supsystic
Plugin -
Plugin Slug -
popup-by-supsystic
Installations -
20,000+
Vulnerability -
Prototype Pollution
Patched In Version -
1.10.19
Severity -
High
CVE Code -

40 - Protect WP Admin
Plugin -
Plugin Slug -
protect-wp-admin
Installations -
20,000+
Vulnerability -
Unauthenticated Protection Bypass Vulnerability
Patched In Version -
4.0
Severity -
Medium
CVE Code -

41 - Quiz Maker
Plugin -
Plugin Slug -
quiz-maker
Installations -
20,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
6.4.2.7
Severity -
High
CVE Code -

42 - wpForo Forum
Plugin -
Plugin Slug -
wpforo
Installations -
20,000+
Vulnerability -
Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents
Patched In Version -
2.1.8
Severity -
High
CVE Code -

43 - Afterpay Gateway for WooCommerce
Plugin -
Afterpay Gateway for WooCommerce
Plugin Slug -
afterpay-gateway-for-woocommerce
Installations -
10,000+
Vulnerability -
Admin+ SQL Injection
Patched In Version -
1.12.4
Severity -
High
CVE Code -

44 - Booking Calendar | Appointment Booking | BookIt
Plugin -
Booking Calendar | Appointment Booking | BookIt
Plugin Slug -
bookit
Installations -
10,000+
Vulnerability -
Authentication Bypass
Patched In Version -
2.3.8
Severity -
Critical
CVE Code -

45 - CMS Commander – Manage Multiple Sites
Plugin -
CMS Commander – Manage Multiple Sites
Plugin Slug -
cms-commander-client
Installations -
10,000+
Vulnerability -
Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature
Patched In Version -
2.288
Severity -
High
CVE Code -

46 - Contact Form Email
Plugin -
Plugin Slug -
contact-form-to-email
Installations -
10,000+
Vulnerability -
Unauthenticated Stored Cross Site Scripting (XSS)
Patched In Version -
1.3.38
Severity -
High
CVE Code -

47 - Custom 404 Pro
Plugin -
Plugin Slug -
custom-404-pro
Installations -
10,000+
Vulnerability -
Multiple SQL Injection
Patched In Version -
3.8.1
Severity -
High
CVE Code -

48 - File Renaming on Upload
Plugin -
Plugin Slug -
file-renaming-on-upload
Installations -
10,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
2.5.2
Severity -
Medium
CVE Code -

49 - Accordion & FAQ – Helpie WordPress Frequently Asked Questions plugin
Plugin -
Accordion & FAQ – Helpie WordPress Frequently Asked Questions plugin
Plugin Slug -
helpie-faq
Installations -
10,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.9.9
Severity -
High
CVE Code -

50 - Five Star Restaurant Reservations – WordPress Booking Plugin
Plugin -
Five Star Restaurant Reservations – WordPress Booking Plugin
Plugin Slug -
restaurant-reservations
Installations -
10,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.6.8
Severity -
High
CVE Code -

51 - Membership Plugin – Restrict Content
Plugin -
Membership Plugin – Restrict Content
Plugin Slug -
restrict-content
Installations -
10,000+
Vulnerability -
Missing Authorization to Notice Dismissal
Patched In Version -
3.2.3
Severity -
Medium

52 - Membership Plugin – Restrict Content
Plugin -
Membership Plugin – Restrict Content
Plugin Slug -
restrict-content
Installations -
10,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.2.3
Severity -
High

53 - SupportCandy – Helpdesk & Support Ticket System
Plugin -
SupportCandy – Helpdesk & Support Ticket System
Plugin Slug -
supportcandy
Installations -
10,000+
Vulnerability -
Subscriber+ SQL Injection
Patched In Version -
3.1.7
Severity -
High
CVE Code -

54 - SupportCandy – Helpdesk & Support Ticket System
Plugin -
SupportCandy – Helpdesk & Support Ticket System
Plugin Slug -
supportcandy
Installations -
10,000+
Vulnerability -
Admin+ SQL Injection
Patched In Version -
3.1.7
Severity -
High
CVE Code -

55 - Event Manager and Tickets Selling Plugin for WooCommerce
Plugin -
Event Manager and Tickets Selling Plugin for WooCommerce
Plugin Slug -
mage-eventpress
Installations -
9,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
3.9.6
Severity -
Medium
CVE Code -

56 - Buy Me a Coffee – Button and Widget Plugin
Plugin -
Buy Me a Coffee – Button and Widget Plugin
Plugin Slug -
buymeacoffee
Installations -
6,000+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
3.7
Severity -
Medium
CVE Code -

57 - FormCraft – Contact Form Builder for WordPress
Plugin -
FormCraft – Contact Form Builder for WordPress
Plugin Slug -
formcraft-form-builder
Installations -
5,000+
Vulnerability -
Auth. SQL Injection
Patched In Version -
3.9.7
Severity -
High
CVE Code -

58 - WPForms Google Sheet Connector
Plugin -
WPForms Google Sheet Connector
Plugin Slug -
gsheetconnector-wpforms
Installations -
5,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.4.6
Severity -
High
CVE Code -

59 - MStore API
Plugin -
Plugin Slug -
mstore-api
Installations -
5,000+
Vulnerability -
Unauth. SQL Injection
Patched In Version -
4.0.2
Severity -
Critical
CVE Code -

60 - MStore API
Plugin -
Plugin Slug -
mstore-api
Installations -
5,000+
Vulnerability -
SQL Injection
Patched In Version -
3.9.8
Severity -
High
CVE Code -

61 - Poll Maker – Best WordPress Poll Plugin
Plugin -
Poll Maker – Best WordPress Poll Plugin
Plugin Slug -
poll-maker
Installations -
5,000+
Vulnerability -
Server Side Request Forgery (SSRF)
Patched In Version -
4.6.3
Severity -
Medium
CVE Code -
62 - Simple Iframe
Plugin -
Plugin Slug -
simple-iframe
Installations -
5,000+
Vulnerability -
Contributor+ Stored Cross Site Scripting (XSS)
Patched In Version -
1.2.0
Severity -
Medium
CVE Code -

63 - WP Custom Cursors | WordPress Cursor Plugin
Plugin -
WP Custom Cursors | WordPress Cursor Plugin
Plugin Slug -
wp-custom-cursors
Installations -
5,000+
Vulnerability -
Admin+ SQL Injection
Patched In Version -
3.2
Severity -
High
CVE Code -

64 - AI ChatBot
Plugin -
Plugin Slug -
chatbot
Installations -
4,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
4.5.5
Severity -
Medium
CVE Code -

65 - AI ChatBot
Plugin -
Plugin Slug -
chatbot
Installations -
4,000+
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
4.5.6
Severity -
Medium
CVE Code -

66 - Survey Maker – Best WordPress Survey Plugin
Plugin -
Survey Maker – Best WordPress Survey Plugin
Plugin Slug -
survey-maker
Installations -
4,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.4.7
Severity -
High
CVE Code -

67 - Integration for Contact Form 7 and Zoho CRM, Bigin
Plugin -
Integration for Contact Form 7 and Zoho CRM, Bigin
Plugin Slug -
cf7-zoho
Installations -
3,000+
Vulnerability -
Admin+ SQL Injection
Patched In Version -
1.2.4
Severity -
High
CVE Code -

68 - CHP Ads Block Detector
Plugin -
Plugin Slug -
chp-ads-block-detector
Installations -
3,000+
Vulnerability -
Broken Access Control
Patched In Version -
3.9.8
Severity -
Medium
CVE Code -

69 - Potent Donations for WooCommerce
Plugin -
Potent Donations for WooCommerce
Plugin Slug -
donations-for-woocommerce
Installations -
3,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.1.10
Severity -
Medium
CVE Code -



72 - Core Web Vitals & PageSpeed Booster
Plugin -
Core Web Vitals & PageSpeed Booster
Plugin Slug -
core-web-vitals-pagespeed-booster
Installations -
2,000+
Vulnerability -
Open Redirection
Patched In Version -
1.0.13
Severity -
Medium
CVE Code -

73 - Extra User Details
Plugin -
Plugin Slug -
extra-user-details
Installations -
2,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
0.5.1
Severity -
Medium
CVE Code -

74 - Extra User Details
Plugin -
Plugin Slug -
extra-user-details
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
0.5.1
Severity -
Medium
CVE Code -

75 - KiviCare – Clinic & Patient Management System (EHR)
Plugin -
KiviCare – Clinic & Patient Management System (EHR)
Plugin Slug -
kivicare-clinic-management-system
Installations -
2,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.2.1
Severity -
High
CVE Code -

76 - KiviCare – Clinic & Patient Management System (EHR)
Plugin -
KiviCare – Clinic & Patient Management System (EHR)
Plugin Slug -
kivicare-clinic-management-system
Installations -
2,000+
Vulnerability -
Subscriber+ Sensitive Data Exposure
Patched In Version -
3.2.1
Severity -
Medium
CVE Code -

77 - KiviCare – Clinic & Patient Management System (EHR)
Plugin -
KiviCare – Clinic & Patient Management System (EHR)
Plugin Slug -
kivicare-clinic-management-system
Installations -
2,000+
Vulnerability -
Subscriber+ Unauthorised AJAX Calls
Patched In Version -
3.2.1
Severity -
Medium
CVE Code -

78 - KiviCare – Clinic & Patient Management System (EHR)
Plugin -
KiviCare – Clinic & Patient Management System (EHR)
Plugin Slug -
kivicare-clinic-management-system
Installations -
2,000+
Vulnerability -
Multiple Cross Site Request Forgery (CSRF)
Patched In Version -
3.2.1
Severity -
Medium
CVE Code -
79 - teachPress
Plugin -
Plugin Slug -
teachpress
Installations -
2,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
9.0.3
Severity -
High
CVE Code -

80 - WP Directory Kit
Plugin -
Plugin Slug -
wpdirectorykit
Installations -
2,000+
Vulnerability -
Unauthenticated Local File Inclusion
Patched In Version -
1.2.4
Severity -
High
CVE Code -

81 - Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
Plugin -
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
Plugin Slug -
contact-form-to-db
Installations -
1,000+
Vulnerability -
SQL Injection
Patched In Version -
1.7.2
Severity -
High
CVE Code -

82 - EventPrime – Modern Events Calendar, Bookings and Tickets
Plugin -
EventPrime – Modern Events Calendar, Bookings and Tickets
Plugin Slug -
eventprime-event-calendar-management
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
3.0.6
Severity -
High
CVE Code -

83 - Photo Gallery by Ays – Responsive Image Gallery
Plugin -
Photo Gallery by Ays – Responsive Image Gallery
Plugin Slug -
gallery-photo-gallery
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
5.1.7
Severity -
High
CVE Code -

84 - Elementor Forms Google Sheet Connector
Plugin -
Elementor Forms Google Sheet Connector
Plugin Slug -
gsheetconnector-for-elementor-forms
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.0.7
Severity -
High
CVE Code -

85 - Ninja Forms Google Sheet Connector
Plugin -
Ninja Forms Google Sheet Connector
Plugin Slug -
gsheetconnector-ninja-forms
Installations -
1,000+
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.2.7
Severity -
High
CVE Code -

86 - MyCurator Content Curation
Plugin -
Plugin Slug -
mycurator
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.75
Severity -
Medium
CVE Code -

87 - OOPSpam Anti-Spam
Plugin -
Plugin Slug -
oopspam-anti-spam
Installations -
1,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.1.45
Severity -
Medium
CVE Code -

88 - ReDi Restaurant Reservation
Plugin -
Plugin Slug -
redi-restaurant-reservation
Installations -
1,000+
Vulnerability -
Broken Access Control
Patched In Version -
23.0212
Severity -
High
CVE Code -

89 - Booking Calendar Contact Form
Plugin -
Plugin Slug -
booking-calendar-contact-form
Installations -
900+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
1.2.41
Severity -
High
CVE Code -

90 - Customer Service Software & Support Ticket System
Plugin -
Customer Service Software & Support Ticket System
Plugin Slug -
wp-ticket
Installations -
600+
Vulnerability -
Authenticated (Administrator+) Stored Cross Site Scripting (XSS)
Patched In Version -
5.13
Severity -
Medium

91 - WP Sticky Social
Plugin -
Plugin Slug -
wp-sticky-social
Installations -
300+
Vulnerability -
Cross-Site Request Forgery to Stored Cross-Site Scripting
Patched In Version -
1.0.2
Severity -
High
CVE Code -

92 - Mail Queue
Plugin -
Plugin Slug -
mail-queue
Installations -
80+
Vulnerability -
Unauthenticated Stored Cross-Site Scripting via Email Subject
Patched In Version -
1.2
Severity -
High
CVE Code -

93 - Lana Shortcodes
Plugin -
Plugin Slug -
lana-shortcodes
Installations -
70+
Vulnerability -
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Patched In Version -
1.2.0
Severity -
Medium

94 - Mailtree Log Mail
Plugin -
Plugin Slug -
mailtree-log-mail
Installations -
10+
Vulnerability -
Unauth. Stored Cross Site Scripting (XSS)
Patched In Version -
1.0.1
Severity -
High
CVE Code -
95 - AutomateWoo
Plugin -
Plugin Slug -
automatewoo
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
5.7.6
Severity -
Medium
CVE Code -
96 - AutomateWoo
Plugin -
Plugin Slug -
automatewoo
Vulnerability -
Broken Access Control
Patched In Version -
5.7.6
Severity -
Medium
CVE Code -
97 - Complianz Premium
Plugin -
Plugin Slug -
complianz-gdpr-premium
Vulnerability -
Cross Site Request Forgery (CSRF) to Site Wide Cross Site Scripting (XSS
Patched In Version -
6.4.7
Severity -
High
CVE Code -
98 - Complianz Premium
Plugin -
Plugin Slug -
complianz-gdpr-premium
Vulnerability -
Multiple Cross Site Request Forgery (CSRF)
Patched In Version -
6.4.8
Severity -
Medium
CVE Code -
99 - Elementor Pro
Plugin -
Plugin Slug -
elementor-pro
Vulnerability -
Auth. Broken Access Control
Patched In Version -
3.13.1
Severity -
Medium
CVE Code -
100 - Go Pricing
Plugin -
Plugin Slug -
go-pricing-wordpress-responsive-pricing-tables
Vulnerability -
Broken Access Control
Patched In Version -
3.4
Severity -
Medium
CVE Code -
101 - Go Pricing
Plugin -
Plugin Slug -
go-pricing-wordpress-responsive-pricing-tables
Vulnerability -
Contributor+ Cross Site Scripting (XSS)
Patched In Version -
3.4
Severity -
Medium
CVE Code -
102 - MonsterInsights Pro
Plugin -
Plugin Slug -
google-analytics-premium
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
8.15
Severity -
Medium
CVE Code -
103 - Gravity Forms
Plugin -
Plugin Slug -
gravityforms
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
2.7.5
Severity -
High
CVE Code -
104 - WPBakery Page Builder
Plugin -
Plugin Slug -
js_composer
Vulnerability -
Contributor+ Cross Site Scripting (XSS)
Patched In Version -
6.13.0
Severity -
Medium
CVE Code -

105 - Lana Text to Image
Plugin -
Plugin Slug -
lana-text-to-image
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
1.1.0
Severity -
Medium
CVE Code -
106 - PixelYourSite PRO
Plugin -
Plugin Slug -
pixelyoursite-pro
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
9.6.2
Severity -
Medium
CVE Code -
107 - USM Premium
Plugin -
Plugin Slug -
ultimate-premium-plugin
Vulnerability -
Admin+ Stored Cross Site Scripting (XSS)
Patched In Version -
16.3
Severity -
Medium
CVE Code -
108 - Abandoned Cart Pro
Plugin -
Plugin Slug -
woocommerce-abandoned-cart-pro
Vulnerability -
Stored Cross Site Scripting (XSS)
Patched In Version -
7.13.0
Severity -
High
CVE Code -
109 - WooCommerce Brands
Plugin -
Plugin Slug -
woocommerce-brands
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.6.50
Severity -
Medium
CVE Code -
110 - WooCommerce Bulk Stock Management
Plugin -
WooCommerce Bulk Stock Management
Plugin Slug -
woocommerce-bulk-stock-management
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
2.2.34
Severity -
High
CVE Code -
111 - WooCommerce Order Barcodes
Plugin -
Plugin Slug -
woocommerce-order-barcodes
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
1.6.5
Severity -
Medium
CVE Code -
112 - WooCommerce Product Vendors
Plugin -
Plugin Slug -
woocommerce-product-vendors
Vulnerability -
Shop Manager+ SQL Injection
Patched In Version -
2.1.79
Severity -
High
CVE Code -
113 - WooCommerce Ship to Multiple Addresses
Plugin -
WooCommerce Ship to Multiple Addresses
Plugin Slug -
woocommerce-shipping-multiple-addresses
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
3.8.6
Severity -
Medium
CVE Code -
114 - WooCommerce Subscriptions
Plugin -
Plugin Slug -
woocommerce-subscriptions
Vulnerability -
Insecure Direct Object References (IDOR)
Patched In Version -
5.1.3
Severity -
High
CVE Code -
115 - File Uploader
Plugin -
Plugin Slug -
wp-file-uploader
Vulnerability -
Admin+ Path Traversal
Patched In Version -
4.19.2
Severity -
Medium
CVE Code -
116 - WPForms Pro
Plugin -
Plugin Slug -
wpforms
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.8.1.3
Severity -
Medium
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Plugin Vulnerabilities – Unpatched

1 - WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Plugin -
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Plugin Slug -
gdpr-cookie-consent
Installations -
9,000+
Vulnerability -
CSV Injection
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

2 - Form Builder | Create Responsive Contact Forms
Plugin -
Form Builder | Create Responsive Contact Forms
Plugin Slug -
contact-form-add
Installations -
6,000+
Vulnerability -
Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
High
CVE Code -

3 - ApplyOnline – Application Form Builder and Manager
Plugin -
ApplyOnline – Application Form Builder and Manager
Plugin Slug -
apply-online
Installations -
5,000+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

4 - JS Help Desk – Best Help Desk & Support Plugin
Plugin -
JS Help Desk – Best Help Desk & Support Plugin
Plugin Slug -
js-support-ticket
Installations -
5,000+
Vulnerability -
Insecure Direct Object References (IDOR) Leading To Ticket Deletion
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

5 - MojoPlug Slide Panel
Plugin -
Plugin Slug -
mojoplug-slide-panel
Installations -
800+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

6 - Smoothscroller
Plugin -
Plugin Slug -
smoothscroller
Installations -
800+
Vulnerability -
Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

7 - Enable SVG Uploads
Plugin -
Plugin Slug -
enable-svg-uploads
Installations -
300+
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -

8 - Caldera Forms Google Sheets Connector
Plugin -
Caldera Forms Google Sheets Connector
Plugin Slug -
gsheetconnector-caldera-forms
Installations -
200+
Vulnerability -
Access Code Update via Cross Site Request Forgery (CSRF)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
9 - About Me 3000 widget
Plugin -
Plugin Slug -
about-me-3000
Vulnerability -
Authenticated (Administrator+) Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
10 - AN_GradeBook
Plugin -
Plugin Slug -
an-gradebook
Vulnerability -
Auth. Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
11 - BBS e-Popup
Plugin -
Plugin Slug -
bbs-e-popup
Vulnerability -
Broken Access Control
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
12 - CF7 Google Sheets Connector Pro
Plugin -
CF7 Google Sheets Connector Pro
Plugin Slug -
cf7-google-sheets-connector-pro
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
High
CVE Code -
13 - Contact Form by WD
Plugin -
Plugin Slug -
contact-form-maker
Vulnerability -
Admin+ SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
14 - Defa Online Image Protector
Plugin -
Plugin Slug -
defa-online-image-protector
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
15 - Gallery Metabox
Plugin -
Plugin Slug -
gallery-metabox
Vulnerability -
Missing Authorization via gallery_remove
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
16 - Gallery Metabox
Plugin -
Plugin Slug -
gallery-metabox
Vulnerability -
Missing Authorization
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
17 - Greeklish-permalink
Plugin -
Plugin Slug -
greeklish-permalink
Vulnerability -
Unauth. Post Slug Update
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
18 - Image Map Pro
Plugin -
Plugin Slug -
image-map-pro-lite
Vulnerability -
Missing Authorization to Stored Cross-Site Scripting
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
19 - InventoryPress
Plugin -
Plugin Slug -
inventorypress
Vulnerability -
Author+ Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
20 - PrePost SEO
Plugin -
Plugin Slug -
prepost-seo
Vulnerability -
Auth. Stored Cross Site Scripting (XSS)
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
21 - Quick Post Duplicator
Plugin -
Plugin Slug -
rduplicator
Vulnerability -
Authenticated (Contributor+) SQL Injection
Patched In Version -
No Fix
Severity -
High
CVE Code -
22 - Upload Resume
Plugin -
Plugin Slug -
resume-upload-form
Vulnerability -
Captcha Bypass Vulnerability
Patched In Version -
No Fix
Severity -
Medium
CVE Code -
23 - User Email Verification for WooCommerce
Plugin -
User Email Verification for WooCommerce
Plugin Slug -
woo-confirmation-email
Vulnerability -
Authentication bypass via weak token generation
Patched In Version -
No Fix
Severity -
Critical
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.
WordPress Theme Vulnerabilities
1 - Balkon
Theme -
Balkon
Theme Slug -
balkon
Vulnerability -
Reflected Cross Site Scripting (XSS)
Patched In Version -
1.3.3
Severity -
High
CVE Code -
Protect Your WordPress Website Today With Website Guardian
Join hundreds of businesses like yours who trust InterwebDEFENCE to protect their websites and livelihood. Using our proven website security analysis and best-in-class AI ‘Website Guardian” software, we are able to protect, monitor and backup your WordPress website.
Go ahead, keep the good guys In and the bad guys out – Click HERE to see our Website Guardian security plans NOW
PLUS
Find out about our unconditional ‘Double Protection’ Guarantee. This guarantee is better than risk free!
We’ll have you scanned, protected and secure in no time, giving you total peace of mind that your website is safe, leaving you to focus on your business success.