No new WordPress core vulnerabilities were disclosed this week.
WordPress Plugin Vulnerabilities — Patched
In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!
These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.
WooCommerce Stripe Payment Gateway
PLUGIN SLUGwoocommerce-gateway-stripe
INSTALLATIONS900,000+
VULNERABILITYUnauthenticated Broken Access Control
PATCHED IN VERSION7.4.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 7.4.1.
WooCommerce Stripe Payment Gateway
PLUGIN SLUGwoocommerce-gateway-stripe
INSTALLATIONS900,000+
VULNERABILITYInsecure Direct Object References (IDOR)
PATCHED IN VERSION7.4.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 7.4.1.
Password Protected
PLUGIN SLUGpassword-protected
INSTALLATIONS300,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION2.6.3
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.6.3.
Photo Gallery by 10Web
PLUGIN SLUGphoto-gallery
INSTALLATIONS200,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION1.8.16
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.8.16.
Unlimited Elements For Elementor
PLUGIN SLUGunlimited-elements-for-elementor
INSTALLATIONS200,000+
VULNERABILITYUnrestricted Zip Extraction
PATCHED IN VERSION1.5.67
SEVERITY SCORECritical
The vulnerability has been patched, so you should update to version 1.5.67.
Download Monitor
PLUGIN SLUGdownload-monitor
INSTALLATIONS100,000+
VULNERABILITYArbitrary File Upload
PATCHED IN VERSION4.8.4
SEVERITY SCORECritical
The vulnerability has been patched, so you should update to version 4.8.4.
WooCommerce Square
PLUGIN SLUGwoocommerce-square
INSTALLATIONS100,000+
VULNERABILITYInsecure Direct Object References (IDOR)
PATCHED IN VERSION3.8.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.8.2.
PLUGIN SLUGconditional-menus
INSTALLATIONS70,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION1.2.1
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.2.1.
Dokan
PLUGIN SLUGdokan-lite
INSTALLATIONS60,000+
VULNERABILITYPHP Object Injection
PATCHED IN VERSION3.7.20
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.7.20.
Dynamic Visibility for Elementor
PLUGIN SLUGdynamic-visibility-for-elementor
INSTALLATIONS40,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION5.0.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 5.0.6.
Super Socializer
PLUGIN SLUGsuper-socializer
INSTALLATIONS40,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION7.13.53
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 7.13.53.
Super Socializer
PLUGIN SLUGsuper-socializer
INSTALLATIONS40,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSION7.13.52
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 7.13.52.
Gutenverse – Gutenberg Blocks – Page Builder for Site Editor
PLUGIN SLUGgutenverse
INSTALLATIONS30,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION1.8.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.8.6.
Stock Manager for WooCommerce
PLUGIN SLUGwoocommerce-stock-manager
INSTALLATIONS30,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION2.11.0
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.11.0.
myCred plugin
PLUGIN SLUGmycred
INSTALLATIONS20,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION2.5.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.5.1.
CMS Commander
PLUGIN SLUGcms-commander-client
INSTALLATIONS10,000+
VULNERABILITYAuthorization Bypass through Use of Insufficiently Unique Cryptographic Signature
PATCHED IN VERSION2.288
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.288.
Directorist
PLUGIN SLUGdirectorist
INSTALLATIONS10,000+
VULNERABILITYArbitrary Content Deletion
PATCHED IN VERSION7.5.5
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 7.5.5.
File Renaming on Upload
PLUGIN SLUGfile-renaming-on-upload
INSTALLATIONS10,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION2.5.2
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.5.2.
LWS Tools
PLUGIN SLUGlws-tools
INSTALLATIONS10,000+
VULNERABILITYMultiple Cross Site Request Forgery (CSRF)
PATCHED IN VERSION2.4.2
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.4.2.
SupportCandy
PLUGIN SLUGsupportcandy
INSTALLATIONS10,000+
VULNERABILITYSubscriber+ SQL Injection
PATCHED IN VERSION3.1.7
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.1.7.
SupportCandy
PLUGIN SLUGsupportcandy
INSTALLATIONS10,000+
VULNERABILITYAdmin+ SQL Injection
PATCHED IN VERSION3.1.7
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.1.7.
YaySMTP
PLUGIN SLUGyaysmtp
INSTALLATIONS6,000+
VULNERABILITYUnauthenticated Stored Cross Site Scripting (XSS)
PATCHED IN VERSION2.4.6
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.4.6.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYSQL Injection
PATCHED IN VERSION3.9.8
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.9.8.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Product Limit Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Message Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Title Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Title Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Order Status Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYCross Site Request Forgery (CSRF) to Firebase Server Key Update
PATCHED IN VERSION3.9.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.7.
MStore API
PLUGIN SLUGmstore-api
INSTALLATIONS5,000+
VULNERABILITYMissing Authorization
PATCHED IN VERSION3.9.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.6.
WP Custom Cursors
PLUGIN SLUGwp-custom-cursors
INSTALLATIONS5,000+
VULNERABILITYAdmin+ SQL Injection
PATCHED IN VERSION3.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.2.
AI ChatBot
PLUGIN SLUGchatbot
INSTALLATIONS4,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION4.5.5
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 4.5.5.
AI ChatBot
PLUGIN SLUGchatbot
INSTALLATIONS4,000+
VULNERABILITYAdmin+ Stored Cross Site Scripting (XSS)
PATCHED IN VERSION4.5.6
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 4.5.6.
Integration for Contact Form 7 and Zoho CRM, Bigin
PLUGIN SLUGcf7-zoho
INSTALLATIONS3,000+
VULNERABILITYAdmin+ SQL Injection
PATCHED IN VERSION1.2.4
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.2.4.
CHP Ads Block Detector
PLUGIN SLUGchp-ads-block-detector
INSTALLATIONS3,000+
VULNERABILITYAuthenticated (Subscriber+) Stored Cross Site Scripting (XSS)
PATCHED IN VERSION3.9.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.9.8.
Recipe Maker For Your Food Blog from Zip Recipes
PLUGIN SLUGzip-recipes
INSTALLATIONS3,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION8.0.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 8.0.8.
All Bootstrap Blocks
PLUGIN SLUGall-bootstrap-blocks
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.3.7
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.3.7.
ARMember
PLUGIN SLUGarmember-membership
INSTALLATIONS2,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION4.0.3
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 4.0.3.
Core Web Vitals & PageSpeed Booster
PLUGIN SLUGcore-web-vitals-pagespeed-booster
INSTALLATIONS2,000+
VULNERABILITYOpen Redirection
PATCHED IN VERSION1.0.13
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.0.13.
Extra User Details
PLUGIN SLUGextra-user-details
INSTALLATIONS2,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION0.5.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 0.5.1.
Extra User Details
PLUGIN SLUGextra-user-details
INSTALLATIONS2,000+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION0.5.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 0.5.1.
WP Directory Kit
PLUGIN SLUGwpdirectorykit
INSTALLATIONS2,000+
VULNERABILITYMissing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action
PATCHED IN VERSION1.2.4
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.2.4.
Church Admin
PLUGIN SLUGchurch-admin
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSION3.7.30
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.7.30.
Contact Forms by Cimatti
PLUGIN SLUGcontact-forms
INSTALLATIONS1,000+
VULNERABILITYBroken Access Control
PATCHED IN VERSION1.5.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.5.8.
WordPress Contact Forms by Cimatti
PLUGIN SLUGcontact-forms
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF) via _accua_forms_form_edit_action
PATCHED IN VERSION1.5.8
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.5.8.
EventPrime
PLUGIN SLUGeventprime-event-calendar-management
INSTALLATIONS1,000+
VULNERABILITYReflected Cross Site Scripting (XSS)
PATCHED IN VERSION3.0.6
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 3.0.6.
WP PDF Generator
PLUGIN SLUGwp-pdf-generator
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.2.3
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.2.3.
Zephyr Project Manager
PLUGIN SLUGzephyr-project-manager
INSTALLATIONS1,000+
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION3.3.94
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.3.94.
LWS Cleaner
PLUGIN SLUGlws-cleaner
INSTALLATIONS900+
VULNERABILITYMultiple Cross Site Request Forgery (CSRF)
PATCHED IN VERSION2.3.1
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 2.3.1.
WP Sticky Social
PLUGIN SLUGwp-sticky-social
INSTALLATIONS300+
VULNERABILITYCross-Site Request Forgery to Stored Cross-Site Scripting
PATCHED IN VERSION1.0.2
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 1.0.2.
Booking and Rental Manager
PLUGIN SLUGbooking-and-rental-manager-for-woocommerce
INSTALLATIONS200+
VULNERABILITYCross Site Scripting (XSS)
PATCHED IN VERSION1.2.2
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.2.2.
Front User Submit | Front Editor
PLUGIN SLUGfront-editor
INSTALLATIONS200+
VULNERABILITYAuthenticated (Subscriber+) Stored Cross Site Scripting (XSS)
PATCHED IN VERSION3.8.0
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 3.8.0.
PLUGINContact Form by WD
PLUGIN SLUGcontact-form-maker
VULNERABILITYMissing Authorization in check_score
PATCHED IN VERSION1.15.17
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.15.17.
PLUGINWooCommerce Brands
PLUGIN SLUGwoocommerce-brands
VULNERABILITYCross Site Request Forgery (CSRF)
PATCHED IN VERSION1.6.50
SEVERITY SCOREMedium
The vulnerability has been patched, so you should update to version 1.6.50.
WooCommerce Product Vendors
PLUGINWooCommerce Product Vendors
PLUGIN SLUGwoocommerce-product-vendors
VULNERABILITYShop Manager+ SQL Injection
PATCHED IN VERSION2.1.79
SEVERITY SCOREHigh
The vulnerability has been patched, so you should update to version 2.1.79.