Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

8 vulnerability records

MediumCVE-2024-13362

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

YASR – Yet Another Star Rating Plugin for WordPress: Currently marked unpatchedEvents Addon for Elementor: Currently marked unpatchedUltimeter: Currently marked unpatchedCustom PHP Settings: Currently marked unpatchedFull Screen Background: Currently marked unpatchedCustom WooCommerce Checkout Fields Editor: Currently marked unpatchedDracula Dark Mode – Accessibility, Reading Mode & Dark Mode for WordPress: Currently marked unpatchedProduct Layouts for WooCommerce: Currently marked unpatchedAEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization: Currently marked unpatchedBetter Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots: Currently marked unpatchedBooks Gallery – Book Showcase, Library & Affiliate Plugin: Currently marked unpatchedStreamWeasels Twitch Integration: Currently marked unpatchedMapGeo – Interactive Geo Maps: Currently marked unpatchedWP Notification Bell: Currently marked unpatchedCarousel, Recent Post Slider and Banner Slider: Currently marked unpatchedPlace Order Without Payment for WooCommerce: Currently marked unpatchedHTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player: Currently marked unpatchedBlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites: Currently marked unpatchedCoupon Affiliates – Affiliate Plugin for WooCommerce: Currently marked unpatchedWP Page Templates: Currently marked unpatchedTeam Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More: Currently marked unpatchedAdvanced Scrollbar – Give Your Site a Sleek Branded Scrolling Feel: Currently marked unpatchedAutomatic YouTube Gallery – Embed Auto-Updating YouTube Video Galleries, Feeds, Playlists & Channels: Currently marked unpatchedThank You Page for WooCommerce: Currently marked unpatchedTablePress – Tables in WordPress made easy: Currently marked unpatchedMarijuana Age Verify: Currently marked unpatchedFive-Star Ratings Shortcode: Currently marked unpatchedAdvanced Classifieds & Directory Pro: Currently marked unpatchedMusic Player for Elementor – Audio Player & Podcast Player: Currently marked unpatchedOpen User Map – Interactive Leaflet Maps: Currently marked unpatchedFeatured Images in RSS for Mailchimp & More: Currently marked unpatchedUnlimited Elements For Elementor: Currently marked unpatchedJoli Table Of Contents: Currently marked unpatchedWP Meta and Date Remover: Currently marked unpatchedEazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder: Currently marked unpatchedAidWP – Donation & Payment Forms (Stripe Powered): Currently marked unpatchedWPBITS Addons For Elementor Page Builder: Currently marked unpatchedSmart phone field for Gravity Forms: Currently marked unpatchedSend Users Email – Email Subscribers, Email Marketing Newsletter: Currently marked unpatchedMaster Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits: Currently marked unpatchedPhoto Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel: Currently marked unpatchedAnnouncement & Notification Banner – Bulletin: Currently marked unpatchedCheckout with Cash App on WooCommerce: Currently marked unpatchedSecurity Ninja – WordPress Security & Firewall: Currently marked unpatchedGoal Tracker – Custom Event Tracking for GA4: Currently marked unpatchedJustified Gallery: Currently marked unpatchedRemove Add to Cart WooCommerce: Currently marked unpatchedFile Manager for Google Drive – Integrate Google Drive: Currently marked unpatchedWPIDE – File Manager & Code Editor: Currently marked unpatchedKnowledge Base documentation & wiki plugin – BasePress Docs: Currently marked unpatchedAI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o: Currently marked unpatchedEasy Appointment Booking & Scheduling System – Webba Booking Calendar: Currently marked unpatchedAI Puffer – Chat. Create. Automate. (formerly AI Power): Currently marked unpatchedPost SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App: Currently marked unpatchedBlog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News: Currently marked unpatchedNotification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar: Currently marked unpatchedTablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent: Currently marked unpatchedWidgets on Pages: Currently marked unpatchedIvory Search – WordPress Search Plugin: Currently marked unpatchedXT Variation Swatches for WooCommerce: Currently marked unpatchedURL Shortify – Simple and Easy URL Shortener: Currently marked unpatchedSecure Gateway for Authorize.net and WooCommerce by Pledged Plugins: Currently marked unpatchedIndependent Analytics – WordPress Analytics Plugin: Currently marked unpatchedGlossary: Currently marked unpatchedMenu Image, Icons made easy: Currently marked unpatchedPDF Poster – let visitors read PDFs without leaving the page: Currently marked unpatchedAnti-Spam Protection – No API Key, GDPR Friendly: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedRestrict – membership, site, content and user access restrictions for WordPress: Currently marked unpatchedTrueAna – True Analytics Dashboard: Currently marked unpatchedShare This Image: Currently marked unpatchedEasy Social Feed – Social Photos Gallery and Post Feed for WordPress: Currently marked unpatchedAuto Post Cleaner: Currently marked unpatchedRadio Player – Live Shoutcast, Icecast and Any Audio Stream Player: Currently marked unpatchedEleSpare – News, Magazine and Blog Addons for Elementor: Currently marked unpatchedLogo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid: Currently marked unpatchedSimpLy Gallery: Currently marked unpatchedBulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO): Currently marked unpatchedSpotlight Social Feeds – Block, Shortcode, and Widget: Currently marked unpatchedWOW Styler for CF7 – Visual Styler for Contact Form 7 Forms: Currently marked unpatchedRadio Station by netmix® – Manage and play your Show Schedule in WordPress!: Currently marked unpatchedWP Mobile Menu – The Mobile-Friendly Responsive Menu: Currently marked unpatchedMessage Filter for Contact Form 7: Currently marked unpatchedShortcodes Ultimate – Content Elements: Currently marked unpatchedCode Manager: Currently marked unpatchedKikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce: Currently marked unpatchedOcean Extra: Currently marked unpatchedTeam Members Showcase: Currently marked unpatchedPost List Designer – Category Post, Recent Post, Post List: Currently marked unpatchedBulk Edit Posts and Products in Spreadsheet: Currently marked unpatchedAutomatic Internal Links for SEO by Pagup: Currently marked unpatchedGeo Mashup: Currently marked unpatchedRole Based Pricing for Woo by Meow Crew: Currently marked unpatchedTreePress – Easy Family Trees & Ancestor Profiles: Currently marked unpatchedWP Coupons and Deals – WordPress Coupon Plugin: Currently marked unpatchedRevivePress – Keep your Old Content Evergreen: Currently marked unpatchedWP fail2ban – Advanced Security: Currently marked unpatchedWP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars: Currently marked unpatchedForumax – AI Powered Advanced Community Forum Plugin: Currently marked unpatchedLightbox & Modal Popup WordPress Plugin – FooBox: Currently marked unpatchedWP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards: Currently marked unpatchedStoreCustomizer – A plugin to Customize all WooCommerce Pages: Currently marked unpatchedTopNewsWp – Display Tikcer News, RSS Feed Widget and Many More: Currently marked unpatchedContact Form 7 Multi-Step Forms: Currently marked unpatchedEasy Age Verify: Currently marked unpatchedDisable Payment Methods based on cart conditions for WooCommerce: Currently marked unpatchedMeta Field Block – Display custom fields in the Block Editor without coding: Currently marked unpatchedPremmerce Permalink Manager for WooCommerce: Currently marked unpatchedGo Fetch Jobs (for WP Job Manager): Currently marked unpatchedPost to Google My Business (Google Business Profile): Currently marked unpatchedWordPress form builder plugin for contact forms, surveys and quizzes – Tripetto: Currently marked unpatchedXT Quick View for WooCommerce: Currently marked unpatchedPrimary Addon for Elementor: Currently marked unpatchedbBlocks – Essential Gutenberg Blocks & Patterns Collection: Currently marked unpatchedPayment Gateway for ACBA BANK: Currently marked unpatchedAuto-Install Free SSL – Generate & Install Free SSL Certificates: Currently marked unpatchedDynamic Copyright Year: Currently marked unpatchedText To Speech TTS Accessibility: Currently marked unpatchedDisplay Eventbrite Events: Currently marked unpatchedXT Floating Cart for WooCommerce: Currently marked unpatchedPay For Post with WooCommerce: Currently marked unpatchedAWCA – The Great Analytics Insights for Your eStore: Currently marked unpatchedInternal Link Juicer: SEO Auto Linker for WordPress: Currently marked unpatchedWP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security: Currently marked unpatchedInavii Social Feed – Live Social Proof Gallery: Currently marked unpatchedPremmerce Product Filter for WooCommerce: Currently marked unpatchedPost Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider: Currently marked unpatchedImage Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI: Currently marked unpatchedMapster WP Maps: Currently marked unpatchedEmbedder for Google Reviews: Currently marked unpatchedRestaurant & Cafe Addon for Elementor: Currently marked unpatched

Affected versions: *-3.4.12; *-2.2.2; *-3.0.5; *-2.3.1; *-2.0.2; *-1.3.4; *-1.2.7; *-1.3.1

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

YASR – Yet Another Star Rating Plugin for WordPress

Affected versions: *-3.4.12

Patched versions: 3.4.15

Events Addon for Elementor

Affected versions: *-2.2.2

Patched versions: 2.2.5

Ultimeter

Affected versions: *-3.0.5

Patched versions: 3.0.7

Custom PHP Settings

Affected versions: *-2.3.1

Patched versions: 2.3.2

Full Screen Background

Affected versions: *-2.0.2

Patched versions: 2.0.3

Custom WooCommerce Checkout Fields Editor

Affected versions: *-1.3.4

Patched versions: Not supplied

Dracula Dark Mode – Accessibility, Reading Mode & Dark Mode for WordPress

Affected versions: *-1.2.7

Patched versions: 1.2.8

Product Layouts for WooCommerce

Affected versions: *-1.3.1

Patched versions: 1.3.5

AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization

Affected versions: *-2.9.2

Patched versions: 2.10.0

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots

Affected versions: *-2.6.7

Patched versions: 2.7.0

Books Gallery – Book Showcase, Library & Affiliate Plugin

Affected versions: *-4.6.8

Patched versions: 4.7.6

StreamWeasels Twitch Integration

Affected versions: *-1.9.2

Patched versions: 1.9.3

MapGeo – Interactive Geo Maps

Affected versions: *-1.6.22

Patched versions: 1.6.23

WP Notification Bell

Affected versions: *-1.4.2

Patched versions: 1.4.3

Carousel, Recent Post Slider and Banner Slider

Affected versions: *-2.1

Patched versions: 2.2

Place Order Without Payment for WooCommerce

Affected versions: *-2.6.5

Patched versions: 2.6.7

HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player

Affected versions: *-2.2.27

Patched versions: 2.5.1

BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites

Affected versions: *-3.2.6

Patched versions: 3.2.8

Coupon Affiliates – Affiliate Plugin for WooCommerce

Affected versions: *-5.17.2

Patched versions: 5.19.0

WP Page Templates

Affected versions: *-1.1.16

Patched versions: 1.1.17

Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More

Affected versions: *-2.5.8

Patched versions: 2.6.1

Advanced Scrollbar – Give Your Site a Sleek Branded Scrolling Feel

Affected versions: *-1.1.3

Patched versions: 1.1.10

Automatic YouTube Gallery – Embed Auto-Updating YouTube Video Galleries, Feeds, Playlists & Channels

Affected versions: *-2.5.5

Patched versions: 2.5.6

Thank You Page for WooCommerce

Affected versions: *-4.2.0

Patched versions: 4.2.1

TablePress – Tables in WordPress made easy

Affected versions: *-3.0.2

Patched versions: 3.0.3

Marijuana Age Verify

Affected versions: *-1.5.5

Patched versions: 1.6

Five-Star Ratings Shortcode

Affected versions: *-1.2.56

Patched versions: 1.2.57

Advanced Classifieds & Directory Pro

Affected versions: *-3.2.4

Patched versions: 3.2.5

Music Player for Elementor – Audio Player & Podcast Player

Affected versions: *-2.4.1

Patched versions: 2.4.4

Open User Map – Interactive Leaflet Maps

Affected versions: *-1.4.0

Patched versions: 1.4.1

Featured Images in RSS for Mailchimp & More

Affected versions: *-1.6.3

Patched versions: 1.6.4

Unlimited Elements For Elementor

Affected versions: *-1.5.140

Patched versions: 1.5.141

Joli Table Of Contents

Affected versions: *-2.6.0

Patched versions: 2.6.1

WP Meta and Date Remover

Affected versions: *-2.3.4

Patched versions: 2.3.5

EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder

Affected versions: *-2.5.7

Patched versions: 2.5.9

AidWP – Donation & Payment Forms (Stripe Powered)

Affected versions: *-3.2.6

Patched versions: 3.2.9

WPBITS Addons For Elementor Page Builder

Affected versions: *-1.7

Patched versions: Not supplied

Smart phone field for Gravity Forms

Affected versions: *-2.1.6

Patched versions: 2.2.0

Send Users Email – Email Subscribers, Email Marketing Newsletter

Affected versions: *-1.5.10

Patched versions: 1.6.2

Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits

Affected versions: *-2.0.7.2

Patched versions: 2.0.7.3

Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel

Affected versions: *-2.4.27

Patched versions: 2.4.29

Announcement & Notification Banner – Bulletin

Affected versions: *-3.12.1

Patched versions: 3.13.1

Checkout with Cash App on WooCommerce

Affected versions: *-6.0.2

Patched versions: Not supplied

Security Ninja – WordPress Security & Firewall

Affected versions: *-5.222

Patched versions: 5.225

Goal Tracker – Custom Event Tracking for GA4

Affected versions: *-1.1.5

Patched versions: 1.1.6

Justified Gallery

Affected versions: *-1.9.0

Patched versions: 1.10.0

Remove Add to Cart WooCommerce

Affected versions: *-1.4.7

Patched versions: Not supplied

File Manager for Google Drive – Integrate Google Drive

Affected versions: *-1.4.9

Patched versions: 1.5.0

WPIDE – File Manager & Code Editor

Affected versions: *-3.5.1

Patched versions: 3.5.2

Knowledge Base documentation & wiki plugin – BasePress Docs

Affected versions: *-2.16.3.3

Patched versions: 2.16.3.6

AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o

Affected versions: *-1.7.2

Patched versions: 1.8.5

Easy Appointment Booking & Scheduling System – Webba Booking Calendar

Affected versions: *-5.0.57

Patched versions: 5.1.8

AI Puffer – Chat. Create. Automate. (formerly AI Power)

Affected versions: *-1.8.99

Patched versions: 2.3.17

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

Affected versions: *-3.0.0

Patched versions: 3.1.0

Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News

Affected versions: *-3.4.9

Patched versions: 3.4.11

Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar

Affected versions: *-2.1.34

Patched versions: 2.1.35

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

Affected versions: *-1.1.13

Patched versions: 1.1.17

Widgets on Pages

Affected versions: *-1.7

Patched versions: Not supplied

Ivory Search – WordPress Search Plugin

Affected versions: *-5.5.8

Patched versions: 5.5.9

XT Variation Swatches for WooCommerce

Affected versions: *-1.9.4

Patched versions: 1.9.7

URL Shortify – Simple and Easy URL Shortener

Affected versions: *-1.10.4

Patched versions: 1.10.5.1

Secure Gateway for Authorize.net and WooCommerce by Pledged Plugins

Affected versions: *-6.1.13

Patched versions: 6.1.14

Independent Analytics – WordPress Analytics Plugin

Affected versions: *-2.9.7

Patched versions: 2.10.0

Glossary

Affected versions: *-2.2.38

Patched versions: 2.2.39

Menu Image, Icons made easy

Affected versions: *-3.12

Patched versions: 3.13

PDF Poster – let visitors read PDFs without leaving the page

Affected versions: *-2.2.0

Patched versions: 2.3.1

Anti-Spam Protection – No API Key, GDPR Friendly

Affected versions: *-2.3.7

Patched versions: 2.3.12

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-3.2.8

Patched versions: 3.2.9

Restrict – membership, site, content and user access restrictions for WordPress

Affected versions: *-2.3.0

Patched versions: 2.3.1

TrueAna – True Analytics Dashboard

Affected versions: *-2.6.0

Patched versions: 2.10.0

Share This Image

Affected versions: *-2.07

Patched versions: 2.08

Easy Social Feed – Social Photos Gallery and Post Feed for WordPress

Affected versions: *-6.6.5

Patched versions: 6.6.6

Auto Post Cleaner

Affected versions: *-3.9.6

Patched versions: 3.9.7

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player

Affected versions: *-2.0.82

Patched versions: 2.0.83

EleSpare – News, Magazine and Blog Addons for Elementor

Affected versions: *-3.3.2

Patched versions: 3.3.4

Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

Affected versions: *-3.2.7

Patched versions: 3.2.9

SimpLy Gallery

Affected versions: *-3.2.4.4

Patched versions: 3.2.4.5

Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)

Affected versions: *-2.1.0

Patched versions: 2.2.0

Spotlight Social Feeds – Block, Shortcode, and Widget

Affected versions: *-1.7.0

Patched versions: 1.7.1

WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms

Affected versions: *-1.7.0

Patched versions: 1.7.1

Radio Station by netmix® – Manage and play your Show Schedule in WordPress!

Affected versions: *-2.5.9

Patched versions: 2.5.17

WP Mobile Menu – The Mobile-Friendly Responsive Menu

Affected versions: *-2.8.6

Patched versions: 2.8.7

Message Filter for Contact Form 7

Affected versions: *-1.6.3.2

Patched versions: 1.6.3.3

Shortcodes Ultimate – Content Elements

Affected versions: *-7.3.3

Patched versions: 7.3.4

Code Manager

Affected versions: *-1.0.40

Patched versions: 1.0.41

Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce

Affected versions: *-1.10.6

Patched versions: 1.10.8

Ocean Extra

Affected versions: *-2.4.2

Patched versions: 2.4.4

Team Members Showcase

Affected versions: *-3.3.0

Patched versions: 3.3.2

Post List Designer – Category Post, Recent Post, Post List

Affected versions: *-3.3.7

Patched versions: 3.3.8

Bulk Edit Posts and Products in Spreadsheet

Affected versions: *-2.25.16

Patched versions: 2.25.19

Automatic Internal Links for SEO by Pagup

Affected versions: *-2.0.0

Patched versions: 2.0.1

Geo Mashup

Affected versions: *-1.13.15

Patched versions: 1.13.16

Role Based Pricing for Woo by Meow Crew

Affected versions: *-1.6.0

Patched versions: 1.6.1

TreePress – Easy Family Trees & Ancestor Profiles

Affected versions: *-3.0.6

Patched versions: 3.0.7

WP Coupons and Deals – WordPress Coupon Plugin

Affected versions: *-3.2.2

Patched versions: 3.2.3

RevivePress – Keep your Old Content Evergreen

Affected versions: *-1.5.8

Patched versions: Not supplied

WP fail2ban – Advanced Security

Affected versions: *-5.3.4

Patched versions: 5.4.0

WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars

Affected versions: *-3.8.3

Patched versions: 3.8.4

Forumax – AI Powered Advanced Community Forum Plugin

Affected versions: *-1.2.7

Patched versions: 1.2.9

Lightbox & Modal Popup WordPress Plugin – FooBox

Affected versions: *-2.7.33

Patched versions: 2.7.34

WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards

Affected versions: *-5.5.31

Patched versions: 5.5.32

StoreCustomizer – A plugin to Customize all WooCommerce Pages

Affected versions: *-2.5.9

Patched versions: 2.6.0

TopNewsWp – Display Tikcer News, RSS Feed Widget and Many More

Affected versions: *-2.4.1

Patched versions: 2.4.3

Contact Form 7 Multi-Step Forms

Affected versions: *-4.4.1

Patched versions: 4.4.2

Easy Age Verify

Affected versions: *-1.8.5

Patched versions: 1.9

Disable Payment Methods based on cart conditions for WooCommerce

Affected versions: *-1.16.3

Patched versions: 1.16.4

Meta Field Block – Display custom fields in the Block Editor without coding

Affected versions: *-1.3.3

Patched versions: 1.3.4

Premmerce Permalink Manager for WooCommerce

Affected versions: *-2.3.11

Patched versions: Not supplied

Go Fetch Jobs (for WP Job Manager)

Affected versions: *-1.8.4.8.1

Patched versions: 1.8.4.9.1

Post to Google My Business (Google Business Profile)

Affected versions: *-3.1.28

Patched versions: 3.2.2

WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

Affected versions: *-8.0.7

Patched versions: 8.0.8

XT Quick View for WooCommerce

Affected versions: *-2.1.5

Patched versions: Not supplied

Primary Addon for Elementor

Affected versions: *-1.6.0

Patched versions: 1.6.5

bBlocks – Essential Gutenberg Blocks & Patterns Collection

Affected versions: *-1.9.8

Patched versions: 2.0.19

Payment Gateway for ACBA BANK

Affected versions: *-1.2.6

Patched versions: Not supplied

Auto-Install Free SSL – Generate & Install Free SSL Certificates

Affected versions: *-4.5.0

Patched versions: 4.5.1

Dynamic Copyright Year

Affected versions: *-1.0.4

Patched versions: 1.1

Text To Speech TTS Accessibility

Affected versions: *-1.7.34

Patched versions: 1.8.12

Display Eventbrite Events

Affected versions: *-6.1.10

Patched versions: 6.1.11

XT Floating Cart for WooCommerce

Affected versions: *-2.8.4

Patched versions: Not supplied

Pay For Post with WooCommerce

Affected versions: *-3.1.26

Patched versions: 3.1.28

AWCA – The Great Analytics Insights for Your eStore

Affected versions: *-3.12.0

Patched versions: 3.16.0

Internal Link Juicer: SEO Auto Linker for WordPress

Affected versions: *-2.24.6

Patched versions: 2.25.2

WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security

Affected versions: *-7.7.0

Patched versions: 7.7.3

Inavii Social Feed – Live Social Proof Gallery

Affected versions: *-2.7.0

Patched versions: 2.7.7

Premmerce Product Filter for WooCommerce

Affected versions: *-3.7.3

Patched versions: Not supplied

Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider

Affected versions: *-3.2.7

Patched versions: 3.2.9

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI

Affected versions: *-1.6.3

Patched versions: 1.6.6

Mapster WP Maps

Affected versions: *-1.9.0

Patched versions: 1.21.0

Embedder for Google Reviews

Affected versions: *-1.6.6

Patched versions: 1.7.5

Restaurant & Cafe Addon for Elementor

Affected versions: *-1.5.8

Patched versions: 1.6.1

Researcher credit: Asaf Mozes

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 30, 2026
CVSS
6.1
MediumCVE-2025-47467

GS Testimonial Slider <= 3.3.0 - Missing Authorization

Affected versions: *-3.3.0

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The GS Testimonial Slider plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_shortcode_pref() function in versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update shortcode preferences.

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-3.3.0

Patched versions: 3.3.1

Researcher credit: domiee13

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 7, 2025
CVSS
4.3
MediumCVE-2025-47481

GS Testimonial Slider <= 3.2.9 - Unauthenticated Arbitrary Shortcode Execution

Affected versions: *-3.2.9

Vulnerability type: CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected software, patched versions and attribution

The The A WordPress Testimonial Plugin to Showcase Testimonial Slider, Testimonial Grid and More: Solid Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-3.2.9

Patched versions: 3.3.0

Researcher credit: theviper17y

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 7, 2025
CVSS
6.5
MediumCVE-2024-30443

GS Testimonial Slider <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Affected versions: *-3.1.4

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-3.1.4

Patched versions: 3.1.5

Researcher credit: LVT-tholv2k

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
March 28, 2024
CVSS
6.4
Medium

Appsero <= 1.2.1 - Missing Authorization

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function intended for administrator use.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: 1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: *-2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 16, 2022
CVSS
4.3
MediumCVE-2022-47150

Appsero <= 1.2.0 - Cross-Site Request Forgery

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedZero BS Accounting: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function intended for administrator use via forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: *-1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Zero BS Accounting

Affected versions: *-1.0.6

Patched versions: 2.0.0

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: 2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Researcher credit: István Márton

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 14, 2022
CVSS
4.3
MediumCVE-2022-40213

GS Testimonial Slider <= 1.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Affected versions: *-1.9.6

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.6

Patched versions: 1.9.7

Researcher credit: Ngo Van Thien

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
September 15, 2022
CVSS
6.4
MediumCVE-2022-35882

GS Testimonial Slider <= 1.9.6 - Authenticated (Author+) Stored Cross-Site Scripting

Affected versions: *-1.9.6

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The GS Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as 'gs_t_client_company' and 'gs_t_client_design' in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.6

Patched versions: 1.9.7

Researcher credit: Tien Nguyen Ahn

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 27, 2022
CVSS
6.4

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.