Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

3 vulnerability records

MediumCVE-2024-32110

Appsero <= 2.0.0 - Missing Authorization via handle_optin_optout

Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedEasy Table Rate Shipping for WooCommmerce: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedHappy WooCommerce FAQs – Ultimate Product FAQ Plugin: Currently marked unpatchedLoad More Anything: Currently marked unpatchedClick To Dial – Wp Click To Call Support: Currently marked unpatchedGS Posts Widget: Currently marked unpatchedEvent Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar: Currently marked unpatchedEvents Slider, Events Carousel, Events Grid, Events Timeline and Events Filter Bar for The Events Calendar – Eventful: Currently marked unpatchedDuplicate Page, Hide Title, Custom CSS & JS, Exclude Search, Template Info – Pagely: Currently marked unpatchedClick To Email – Chat Bubble & Mail Button for WP: Currently marked unpatchedIDonate – Blood Donation, Request And Donor Management System: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedTOP Table Of Contents: Currently marked unpatchedChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatched

Affected versions: *-1.7.7; *-10.42; *-3.5.0; *-1.3.0; *-1.0.7; *-1.5.0; *-3.3.5; *-1.2.9

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout function in versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to opt-in or opt-out of tracking. This was patched in version 2.0.1 of Appsero with a nonce check.

Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode

Affected versions: *-1.7.7

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.42

Patched versions: 10.43

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-3.5.0

Patched versions: 3.5.1

Easy Table Rate Shipping for WooCommmerce

Affected versions: *-1.3.0

Patched versions: Not supplied

Dashboard Welcome for Elementor

Affected versions: *-1.0.7

Patched versions: 1.0.8

Happy WooCommerce FAQs – Ultimate Product FAQ Plugin

Affected versions: *-1.5.0

Patched versions: 1.5.1

Load More Anything

Affected versions: *-3.3.5

Patched versions: 3.3.6

Click To Dial – Wp Click To Call Support

Affected versions: *-1.2.9

Patched versions: Not supplied

GS Posts Widget

Affected versions: *-1.2.9

Patched versions: Not supplied

Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar

Affected versions: *-4.1.2

Patched versions: 4.1.3

Events Slider, Events Carousel, Events Grid, Events Timeline and Events Filter Bar for The Events Calendar – Eventful

Affected versions: *-2.1.7

Patched versions: Not supplied

Duplicate Page, Hide Title, Custom CSS & JS, Exclude Search, Template Info – Pagely

Affected versions: *-1.1.12

Patched versions: 1.1.13

Click To Email – Chat Bubble & Mail Button for WP

Affected versions: *-1.2.8

Patched versions: Not supplied

IDonate – Blood Donation, Request And Donor Management System

Affected versions: *-2.1.15

Patched versions: Not supplied

Exclusive Addons for Elementor

Affected versions: *-2.6.9

Patched versions: 2.6.9.1

TOP Table Of Contents

Affected versions: *-1.3.15

Patched versions: 1.3.16

ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

Affected versions: *-1.4.9

Patched versions: 1.6.0

Boostify Header Footer Builder for Elementor

Affected versions: *-1.3.1

Patched versions: 1.3.2

Gallery Box

Affected versions: *-1.7.33

Patched versions: 1.7.34

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.4

Patched versions: 1.0.5

Researcher credit: Dhabaleshwar Das

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 11, 2024
CVSS
4.3
Medium

Appsero <= 1.2.1 - Missing Authorization

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function intended for administrator use.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: 1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: *-2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 16, 2022
CVSS
4.3
MediumCVE-2022-47150

Appsero <= 1.2.0 - Cross-Site Request Forgery

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedZero BS Accounting: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function intended for administrator use via forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: *-1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Zero BS Accounting

Affected versions: *-1.0.6

Patched versions: 2.0.0

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: 2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Researcher credit: István Márton

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 14, 2022
CVSS
4.3

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.