WordPress Plugins with Reported Vulnerabilities Last Week

Updating WordPress themes and plugins is crucial for maintaining the security of your website. Outdated software components are one of the primary vulnerabilities that hackers exploit to gain unauthorized access to WordPress sites.

Security is the foremost reason to keep your themes and plugins updated. Developers regularly release patches to fix known bugs and weaknesses in their software. By not updating, you leave your site exposed to potential security breaches. In fact, over 80% of hacked WordPress sites had outdated plugins or themes, according to WPBeginner.

Outdated themes and plugins can lead to various security risks, including:

  1. Cross-site scripting (XSS) vulnerabilities
  2. SQL injection attacks
  3. Malware infections
  4. Unauthorized access to sensitive data

Updates often include critical security fixes that address these vulnerabilities. By staying current, you essentially “lock all your doors and windows,” making it much harder for malicious actors to breach your site.

Moreover, outdated components can cause compatibility issues with the latest version of WordPress core, leading to errors, crashes, and unexpected behavior. This not only affects your site’s functionality but can also create security loopholes.

According to a survey by WP WhiteSecurity, over 50% of hacked WordPress sites were out of date. This statistic underscores the importance of regular updates in maintaining a secure website.

To mitigate these risks, it’s essential to establish a routine for checking and updating your themes and plugins. Prioritize security-related updates and consider enabling automatic updates for critical components. By keeping your WordPress site up-to-date, you significantly reduce the risk of security breaches and ensure a smoother, more secure experience for your users.

Vulnerability Details

Software NameSoftware Slug
140+ Widgets | Xpro Addons For Elementor – FREExpro-elementor-addons
ABCBiz Addons for Elementorabcbiz-addons
Accessibility by AllAccessibleallaccessible
Accordion Slideraccordion-slider
Accounting for WooCommerceaccounting-for-woocommerce
Additional Custom Order Status for WooCommerceorder-status-for-woocommerce
Advanced Element Bucket Addons for Elementorcs-element-bucket
Advanced File Managerfile-manager-advanced
AI Quiz | Quiz Makerai-quiz
All Bootstrap Blocksall-bootstrap-blocks
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy)wp-analytify
AnyWhere Elementoranywhere-elementor
ARformsarforms
Arkhe Blocksarkhe-blocks
ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signuparmember-membership
Authors Listauthors-list
AWeber Forms by Optin Cataweber-wp
Awesome Shortcodesawesome-shortcodes
B Testimonial – Testimonial plugin for WPb-testimonial
Beautiful taxonomy filtersbeautiful-taxonomy-filters
Beaver Builder – WordPress Page Builderbeaver-builder-lite-version
Block Controllerblock-controller
BMLT Tabbed Mapbmlt-tabbed-map
Bold Page Builderbold-page-builder
Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenbergborderless
BP Profile Shortcodes Extrabp-profile-shortcodes-extra
Broadcastthreewp-broadcast
Campaign Monitor Forms by Optin Catcampaign-monitor-wp
Captivate Synccaptivatesync-trade
CardGate Payments for WooCommercecardgate
Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Gridwp-carousel-free
Charity Addon for Elementorcharity-addon-for-elementor
Church Adminchurch-admin
Classic Addons – WPBakery Page Builderclassic-addons-wpbakery-page-builder-addons
Clickbank WordPress Plugin (Storefront)clickbank-storefront
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPresssprout-invoices
CLUEVO LMS, E-Learning Platformcluevo-lms
CMSMasters Elementor Addoncmsmasters-elementor-addon
Colibri Page Buildercolibri-page-builder
Comfino Payment Gatewaycomfino-payment-gateway
Connexion Logslogs-de-connexion
Contact Form Builder by vcitacontact-form-with-a-meeting-scheduler-by-vcita
Contact Form, Survey & Form Builder – MightyFormsmightyforms
Contact Form, Survey, Quiz & Popup Form Builder – ARFormsarforms-form-builder
Cookielaycookielay
Country Blockercountry-blocker
Designer – Addons for Elementordesigner
DN Shipping by Weight for WooCommercedn-shipping-by-weight
Dollie Hub – Build Your Own WordPress Cloud Platformdollie
Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more!pie-forms-for-wp
Easy Code Snippetseasy-code-snippets
Easy Social Feed Premiumeasy-facebook-likebox-premium
Eleblog – Elementor Blog And Magazine Addonsele-blog
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows)bdthemes-element-pack-lite
ElementsReady Addons for Elementorelement-ready-lite
Email Address Obfuscationemail-address-obfuscation
Event Tickets with Ticket Scannerevent-tickets-with-ticket-scanner
FancyBox for WordPressfancybox-for-wordpress
Feedpress Generator – External RSS Frontend Customizerfeedpress-generator
FileBird – WordPress Media Library Folders & File Managerfilebird
FileOrganizer – Manage WordPress and Website Filesfileorganizer
Firelight Lightboxeasy-fancybox
float blockfloat-block
FloristPress – Customize your Woo store for your Floristbakkbone-florist-companion
Flower Delivery by Florist Oneflower-delivery-by-florist-one
Folder Galleryfolder-gallery
Form Data Collectorform-data-collector
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builderform-maker
ForumWP – Forum & Discussion Boardforumwp
Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonialsstars-testimonials-with-slider-and-masonry-grid
Friendsfriends
Futurio Extrafuturio-extra
FV Flowplayer Video Playerfv-wordpress-flowplayer
Gallerymulti-gallery
Gallery Plugin for WordPress – Envira Photo Galleryenvira-gallery-lite
Getwid – Gutenberg Blocksgetwid
Gold Addons for Elementorgold-addons-for-elementor
Goodlayers Coregoodlayers-core
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editorgutentor
IdeaPushideapush
If Menu – Visibility control for Menusif-menu
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Freefunnelforms-free
Intro Tour Tutorial DeepPresentationdp-intro-tours
jAlbum Bridgejalbum-bridge
KiviCare – Clinic & Patient Management System (EHR)kivicare-clinic-management-system
Knowledge Base documentation & wiki plugin – BasePress Docsbasepress
LA-Studio Element Kit for Elementorlastudio-element-kit
Library Management System – Manage e-Digital Books Librarylibrary-management-system
Listdom – Business Directory and Classified Ads Listings WordPress Pluginlistdom
Login Widget With Shortcodelogin-sidebar-widget
Login With OTPotp-login
Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )magical-addons-for-elementor
Maspik – Advanced Spam Protectioncontact-forms-anti-spam
Message Filter for Contact Form 7cf7-message-filter
Mini Program APIwp-mini-program
Minimum and Maximum Quantity for WooCommercemin-and-max-quantity-for-woocommerce
Mollie for Contact Form 7cf7-mollie
My auctions allegromy-auctions-allegro-free-edition
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.mycred
Namaste! LMSnamaste-lms
News Kit Elementor Addonsnews-kit-elementor-addons
NEX-Forms – Ultimate Form Builder – Contact forms and much morenex-forms-express-wp-form-builder
Next-Cart Store to WooCommerce Migrationnextcart-woocommerce-migration
Ni WooCommerce Order Exportni-woocommerce-order-export
NPS computynps-computy
Online Booking & Scheduling Calendar for WordPress by vcitameeting-scheduler-by-vcita
ONLYOFFICE Docsonlyoffice
Paloma Widgetpostman-widget
PDF Builder for WooCommerce. Create invoices,packing slips and morewoo-pdf-invoice-builder
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallerynextgen-gallery
Pie Register – Social Sites Login (Add on)pie-register-social-site
Pie Register Premiumpie-register-premium
Pinpoint Booking System – #1 WordPress Booking Pluginbooking-system
Pojo Formspojo-forms
Poll Maker – Versus Polls, Anonymous Polls, Image Pollspoll-maker
Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostXultimate-post
Posti Shippingposti-shipping
PowerPack Elementor Addons (Free Widgets, Extensions and Templates)powerpack-lite-for-elementor
Prodigy Commerceprodigy-commerce
Product Labels For Woocommerce (Sale Badges)aco-product-labels-for-woocommerce
Pulsating Chat Buttonamin-chat-button
Quick License Manager – WooCommerce Pluginquick-license-manager
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPluginsrelated-post
Responsive Lightbox & Galleryresponsive-lightbox
Responsive Videosresponsive-youtube-videos
Revyrevy
RRAddons for Elementorrrdevs-for-elementor
Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and morescratch-win-giveaways-for-website-facebook
SearchIQ – The Search Solutionsearchiq
SG Helpersg-helper
Shortcodes Blocks Creator Ultimateultimate-shortcodes-creator
Simple Ecommerce Shopping Cart Plugin- Sell products through Paypalsimple-e-commerce-shopping-cart
Simple Redirectioneelv-redirection
Simple User Registrationwp-registration
Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carouseldepicter
Smart PopUp Blastersmart-popup-blaster
Smoove connector for Elementor formssmoove-elementor
SMS for Lead Capture Formsclicksend-lead-capture-form
Spectra – WordPress Gutenberg Blocksultimate-addons-for-gutenberg
Splash Syncsplash-connector
SV100 Companionsv100-companion
Swift Performance Liteswift-performance-lite
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommercethe-plus-addons-for-elementor-page-builder
Themesflat Addons For Elementorthemesflat-addons-for-elementor
TI WooCommerce Wishlistti-woocommerce-wishlist
Tutor LMS Elementor Addonstutor-lms-elementor-addons
TWChat – Send or receive messages from userstwchat
TwentyTwentytwentytwenty
Ultimate Coming Soon & Maintenanceultimate-coming-soon
Unlock Addons for Elementorunlock-addons-for-elementor
Verowa Connectverowa-connect
Video Gallery – YouTube Gallery and Vimeo Gallerygallery-videos
Visual Portfolio, Photo Gallery & Post Gridvisual-portfolio
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builderwdesignkit
WIP WooCarousel Litewip-woocarousel-lite
WordPress Auction Pluginwp-auctions
WordPress Page Builder – Zion Builderzionbuilder
WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layoutgs-pinterest-portfolio
Wot Elementor Widgetswot-elementor-widgets
WP eCardswp-ecards-invites
WP GeoNameswp-geonames
WP Hide & Security Enhancerwp-hide-security-enhancer
WP Job Manager – Company Profileswp-job-manager-companies
WP Mailsterwp-mailster
WP Media Optimizer (.webp)wp-media-optimizer-webp
WP Private Content Pluswp-private-content-plus
WP Systemwp-system
WP Travel – Ultimate Travel Booking System, Tour Management Enginewp-travel
WP Umbrella: Update Backup Restore & Monitoringwp-health
WP-SVGwp-svg
WPBITS Addons For Elementor Page Builderwpbits-addons-for-elementor
WPC Smart Quick View for WooCommercewoo-smart-quick-view
WPCasawpcasa
XLTab – Accordions and Tabs for Elementor Page Builderxl-tab
Z-Downloadsz-downloads
Zooomzooom
افزونه پیامک ووکامرس Persian WooCommerce SMSpersian-woocommerce-sms
워드프레스 결제 심플페이 – 우커머스 결제 플러그인pgall-for-woocommerce
코드엠샵 소셜톡mshop-naver-talktalk

WordPress Themes with Reported Vulnerabilities Last Week

Software NameSoftware Slug
Blocksyblocksy
Flixitaflixita
NewsMashnewsmash
NewsMunchnewsmunch
Pubnewspubnews
Soledadsoledad

Updating WordPress themes and plugins is crucial for maintaining the security of your website. Outdated software components are one of the primary vulnerabilities that hackers exploit to gain unauthorized access to WordPress sites.

Security is the foremost reason to keep your themes and plugins updated. Developers regularly release patches to fix known bugs and weaknesses in their software. By not updating, you leave your site exposed to potential security breaches. In fact, over 80% of hacked WordPress sites had outdated plugins or themes, according to WPBeginner.

Outdated themes and plugins can lead to various security risks, including:

  1. Cross-site scripting (XSS) vulnerabilities
  2. SQL injection attacks
  3. Malware infections
  4. Unauthorized access to sensitive data

Updates often include critical security fixes that address these vulnerabilities. By staying current, you essentially “lock all your doors and windows,” making it much harder for malicious actors to breach your site.

Moreover, outdated components can cause compatibility issues with the latest version of WordPress core, leading to errors, crashes, and unexpected behavior. This not only affects your site’s functionality but can also create security loopholes.

According to a survey by WP WhiteSecurity, over 50% of hacked WordPress sites were out of date. This statistic underscores the importance of regular updates in maintaining a secure website.

To mitigate these risks, it’s essential to establish a routine for checking and updating your themes and plugins. Prioritize security-related updates and consider enabling automatic updates for critical components. By keeping your WordPress site up-to-date, you significantly reduce the risk of security breaches and ensure a smoother, more secure experience for your users.

Please note that if you run the Wordfence plugin on your WordPress site, with the scanner enabled, you should’ve already been notified if your site was affected by any of these vulnerabilities

Back To Top

News, tutorials and deals