Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

10 vulnerability records

MediumCVE-2026-12734

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute

Affected versions: *-2.3.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'connectorWidth' Block Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.3.0

Patched versions: 2.3.1

Researcher credit: Wordfence PRISM

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 2, 2026
CVSS
6.4
MediumCVE-2026-12729

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action

Affected versions: *-2.3.0

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the wedocs_migrate_betterdocs_to_wedocs AJAX action, which performs no nonce verification via check_ajax_referer() and no capability check via current_user_can() before executing sensitive operations. This makes it possible for authenticated attackers, with Subscriber-level access and above, to trigger a full BetterDocs-to-weDocs data migration, creating and modifying 'docs' custom post type entries with attacker-controlled titles, updating site options, and deactivating the BetterDocs and BetterDocs Pro plugins via deactivate_plugins().

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.3.0

Patched versions: 2.3.1

Researcher credit: Wordfence PRISM

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 2, 2026
CVSS
4.3
MediumCVE-2026-12731

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes

Affected versions: *-2.3.0

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.3.0

Patched versions: 2.3.1

Researcher credit: Wordfence PRISM

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
July 2, 2026
CVSS
6.4
MediumCVE-2026-39520

weDocs <= 2.1.18 - Missing Authorization

Affected versions: *-2.1.18

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The weDocs plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.1.18. This makes it possible for unauthenticated attackers to perform an unauthorized action.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.1.18

Patched versions: 2.2.1

Researcher credit: hhhai

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
February 25, 2026
CVSS
5.3
MediumCVE-2025-13921

weDocs <= 2.1.16 - Missing Authorization to Authenticated (Subscriber+) Documentation Post Update

Affected versions: *-2.1.16

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unauthorized modification or loss of data due to a missing capability check on the 'wedocs_user_documentation_handling_capabilities' function in all versions up to, and including, 2.1.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit any documentation post. The vulnerability was partially patched in version 2.1.16.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.1.16

Patched versions: 2.1.17

Researcher credit: blue0x1

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 22, 2026
CVSS
4.3
MediumCVE-2025-14574

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.1.15 - Unauthenticated Sensitive Information Exposure

Affected versions: *-2.1.15

Vulnerability type: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Affected software, patched versions and attribution

The weDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.15 via the `/wp-json/wp/v2/docs/settings` REST API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including third party services API keys.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.1.15

Patched versions: 2.1.16

Researcher credit: DityaRA

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
January 8, 2026
CVSS
5.3
MediumCVE-2025-12505

weDocs <= 2.1.14 - Missing Authorization to Settings Update

Affected versions: *-2.1.14

Vulnerability type: CWE-285 Improper Authorization

Affected software, patched versions and attribution

The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not properly verifying that a user is authorized to perform an action in the create_item_permissions_check function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global plugin settings.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.1.14

Patched versions: 2.1.15

Researcher credit: Md. Moniruzzaman Prodhan (NomanProdhan)

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 5, 2025
CVSS
5.4
MediumCVE-2024-34442

weDocs <= 2.1.4 - Missing Authorization

Affected versions: *-2.1.4

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The weDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_helpfullness REST API endpoint in versions up to, and including, 2.1.4. This makes it possible for unauthenticated attackers to update settings.

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: *-2.1.4

Patched versions: 2.1.5

Researcher credit: Peng Zhou

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
May 7, 2024
CVSS
5.3
Medium

Appsero <= 1.2.1 - Missing Authorization

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to authorization bypass due to a missing capability check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function intended for administrator use.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: 1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: *-2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 16, 2022
CVSS
4.3
MediumCVE-2022-47150

Appsero <= 1.2.0 - Cross-Site Request Forgery

PT Addons for Elementor Lite: Currently marked unpatchedSubscribe2 – Form, Email Subscribers & Newsletters: Currently marked unpatchedwePOS – Point Of Sale (POS) for WooCommerce & Dokan: Currently marked unpatchedEasy Video Reviews – Testimonial Grid & Social Proof: Currently marked unpatchedWorth The Read: Currently marked unpatchedWoostify Sites Library: Currently marked unpatchedFlexTable – Data Table Sync with Google Sheets: Currently marked unpatchedPost Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget: Currently marked unpatchedWPEPP – Essential Security, Password Protect & Login Page Customizer: Currently marked unpatchedProduct Carousel Slider & Grid Ultimate for WooCommerce: Currently marked unpatchedProduct Gallery Slider, Additional Variation Images for WooCommerce: Currently marked unpatchedMarkdown Editor (Formerly Dark Mode): Currently marked unpatchedProject Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker: Currently marked unpatchedDashboard Welcome for Elementor: Currently marked unpatchedWP Dark Mode – Improve Accessibility with AI Powered Dark Theme: Currently marked unpatchedFuse Social Floating Sidebar: Currently marked unpatchedStylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator: Currently marked unpatchedSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider: Currently marked unpatchedProduct Category Slider for WooCommerce: Currently marked unpatchedFlexMeeting – Webinar & Meeting Plugin for Jitsi Meet: Currently marked unpatchedW4 Post List: Currently marked unpatchedweMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce: Currently marked unpatchedBuddyPress Builder for Elementor – BuddyBuilder: Currently marked unpatchedLegal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator: Currently marked unpatchedHappy Addons for Elementor: Currently marked unpatchedWP VR – 360 Panorama and Virtual Tour Builder: Currently marked unpatchedConversion Tracking for WooCommerce: Currently marked unpatchedSolid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews: Currently marked unpatchedEasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time: Currently marked unpatchedweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot: Currently marked unpatchedBangladeshi Payment Gateways – Make Payment Using QR Code: Currently marked unpatchedTexty – SMS Notification for WordPress, WooCommerce, Dokan and more: Currently marked unpatchedVisibility Logic for Elementor: Currently marked unpatchedPDF Invoices & Packing Slips for WooCommerce – Challan: Currently marked unpatchedDarklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin: Currently marked unpatchedExclusive Team for Elementor: Currently marked unpatchedClick to top: Currently marked unpatchedUpdate Image Tag Alt Attribute: Currently marked unpatchedMagical Posts Display – Elementor Advanced Posts widgets: Currently marked unpatchedGS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets: Currently marked unpatchedWP Mail Logging: Currently marked unpatchedDirectorist: AI-Powered Business Directory, Listings & Classified Ads: Currently marked unpatchedUser Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration: Currently marked unpatchedZero BS Accounting: Currently marked unpatchedExclusive Addons for Elementor: Currently marked unpatchedBoostify Header Footer Builder for Elementor: Currently marked unpatchedStax Addons for Elementor: Currently marked unpatchedWP CTA – Call Now Button, Sticky Button & Call to Action Builder: Currently marked unpatchedGallery Box: Currently marked unpatchedPrime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: Currently marked unpatchedWiremo – Product Reviews for WooCommerce: Currently marked unpatchedCart Lift – Abandoned Cart Recovery for WooCommerce and EDD: Currently marked unpatchedWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: Currently marked unpatchedProduct Category Showcase for WooCommerce: Currently marked unpatched

Affected versions: *-2.2; *-10.37; *-1.2.5; *-1.4.2; *-1.14; *-1.4.3; *-2.12.14; *-1.6.3

Vulnerability type: CWE-352 Cross-Site Request Forgery (CSRF)

Affected software, patched versions and attribution

The Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function intended for administrator use via forged request, granted they can trick a site administrator into performing an action such as clicking on a link.

PT Addons for Elementor Lite

Affected versions: *-2.2

Patched versions: Not supplied

Subscribe2 – Form, Email Subscribers & Newsletters

Affected versions: *-10.37

Patched versions: 10.38

wePOS – Point Of Sale (POS) for WooCommerce & Dokan

Affected versions: *-1.2.5

Patched versions: 1.2.6

Easy Video Reviews – Testimonial Grid & Social Proof

Affected versions: *-1.4.2

Patched versions: 1.5.0

Worth The Read

Affected versions: *-1.14

Patched versions: 1.14.1

Woostify Sites Library

Affected versions: *-1.4.3

Patched versions: 1.4.4

FlexTable – Data Table Sync with Google Sheets

Affected versions: *-2.12.14

Patched versions: 2.12.15

Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget

Affected versions: *-1.6.3

Patched versions: 1.6.4

WPEPP – Essential Security, Password Protect & Login Page Customizer

Affected versions: *-1.2.3

Patched versions: 1.2.4

Product Carousel Slider & Grid Ultimate for WooCommerce

Affected versions: *-1.9.3

Patched versions: 1.9.4

Product Gallery Slider, Additional Variation Images for WooCommerce

Affected versions: *-2.2.6

Patched versions: 2.2.7

Markdown Editor (Formerly Dark Mode)

Affected versions: *-4.1.2

Patched versions: 4.1.3

Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker

Affected versions: *-2.6.12

Patched versions: 2.6.13

Dashboard Welcome for Elementor

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Dark Mode – Improve Accessibility with AI Powered Dark Theme

Affected versions: *-3.0.4

Patched versions: 3.0.5

Fuse Social Floating Sidebar

Affected versions: *-5.4.6

Patched versions: 5.4.7

Stylish Cost Calculator – Quote Generator, Lead Gen & Price Estimator

Affected versions: *-7.3.6

Patched versions: 7.3.7

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider

Affected versions: *-3.28.0

Patched versions: 3.28.1

Product Category Slider for WooCommerce

Affected versions: *-4.1.5

Patched versions: 4.1.6

FlexMeeting – Webinar & Meeting Plugin for Jitsi Meet

Affected versions: *-1.2.5

Patched versions: 2.0.0

W4 Post List

Affected versions: *-2.4.2

Patched versions: 2.4.3

weMail – Email Marketing, Newsletters Builder & Email Automations for WooCommerce

Affected versions: *-1.14.1

Patched versions: 1.14.2

BuddyPress Builder for Elementor – BuddyBuilder

Affected versions: *-1.7.1

Patched versions: 1.7.2

Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

Affected versions: *-1.4.1

Patched versions: 1.4.2

Happy Addons for Elementor

Affected versions: *-3.8.2

Patched versions: 3.8.3

WP VR – 360 Panorama and Virtual Tour Builder

Affected versions: *-8.2.5

Patched versions: 8.2.6

Conversion Tracking for WooCommerce

Affected versions: *-2.0.10

Patched versions: 2.0.11

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

Affected versions: *-1.9.7

Patched versions: 1.9.8

EasyMedia – Increase Media Upload File Size | Role-Based Upload Limit | Increase Execution Time

Affected versions: *-1.0.9

Patched versions: 1.1.0

weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot

Affected versions: 1.6-1.7.5

Patched versions: 1.7.6

Bangladeshi Payment Gateways – Make Payment Using QR Code

Affected versions: *-2.0.6

Patched versions: 2.0.7

Texty – SMS Notification for WordPress, WooCommerce, Dokan and more

Affected versions: *-1.1.1

Patched versions: 1.1.2

Visibility Logic for Elementor

Affected versions: *-2.3.3

Patched versions: 2.3.4

PDF Invoices & Packing Slips for WooCommerce – Challan

Affected versions: *-3.4.8

Patched versions: 3.4.9

Darklup – Enhanced WordPress Dark Mode, Dark Theme, Night Mode & Accessibility Plugin

Affected versions: *-2.1.1

Patched versions: 2.1.2

Exclusive Team for Elementor

Affected versions: *-1.2.4

Patched versions: Not supplied

Click to top

Affected versions: *-1.2.19

Patched versions: 1.2.20

Update Image Tag Alt Attribute

Affected versions: *-2.4.3

Patched versions: Not supplied

Magical Posts Display – Elementor Advanced Posts widgets

Affected versions: *-1.2.15

Patched versions: 1.2.16

GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets

Affected versions: *-1.6.2

Patched versions: 1.6.3

WP Mail Logging

Affected versions: *-1.10.5

Patched versions: 1.11.0

Directorist: AI-Powered Business Directory, Listings & Classified Ads

Affected versions: *-7.7.1

Patched versions: 7.7.2

User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration

Affected versions: *-3.6.0

Patched versions: 3.6.1

Zero BS Accounting

Affected versions: *-1.0.6

Patched versions: 2.0.0

Exclusive Addons for Elementor

Affected versions: *-2.6.1

Patched versions: 2.6.2

Boostify Header Footer Builder for Elementor

Affected versions: *-1.2.8

Patched versions: 1.2.9

Stax Addons for Elementor

Affected versions: *-1.4.3

Patched versions: 1.4.4

WP CTA – Call Now Button, Sticky Button & Call to Action Builder

Affected versions: *-1.5.8

Patched versions: 1.5.9

Gallery Box

Affected versions: *-1.7.30

Patched versions: 1.7.31

Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages

Affected versions: *-1.0.1

Patched versions: 1.0.2

Wiremo – Product Reviews for WooCommerce

Affected versions: *-1.4.96

Patched versions: 1.4.97

Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD

Affected versions: *-3.1.3

Patched versions: 3.1.4

WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell

Affected versions: 2.6.4

Patched versions: 2.6.5

Product Category Showcase for WooCommerce

Affected versions: *-1.1.9

Patched versions: 2.0.0

Researcher credit: István Márton

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
December 14, 2022
CVSS
4.3

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.