Vulnerabilities

WP Plugin Vulnerabilities Image - SiteSEO – SEO Simplified Vulnerability – Missing Authorization to Authenticated (Author+) Plugin Settings Update – CVE-2025-12367 | WordPress Plugin Vulnerability Report - Vulnerabilities

SiteSEO – SEO Simplified Vulnerability – Missing Authorization to Authenticated (Author+) Plugin Settings Update – CVE-2025-12367 | WordPress Plugin Vulnerability Report

By Your WP Guy / Oct 31, 2025

Plugin Name: SiteSEO – SEO Simplified Key Information: Software Type: PluginSoftware Slug: siteseoSoftware Status: ActiveSoftware Author: softaculousSoftware Downloads: 976,564Active Installs: 400,000Last Updated: November 1, 2025Patched Versions: 1.3.2Affected Versions: ≤ 1.3.1 Vulnerability Details: Name: SiteSEO – SEO Simplified ≤ 1.3.1 – Missing Authorization to Authenticated (Author+) Plugin Settings UpdateType: Missing AuthorizationCVE: CVE-2025-12367CVSS Score: 4.3 (Medium)Publicly Published:…

Read More
WP Plugin Vulnerabilities Image - Qi Blocks Vulnerability - Missing Authorization to Authenticated (Contributor+) Plugin Settings Update - CVE-2025-12180 | WordPress Plugin Vulnerability Report - Vulnerabilities

Qi Blocks Vulnerability – Missing Authorization to Authenticated (Contributor+) Plugin Settings Update – CVE-2025-12180 | WordPress Plugin Vulnerability Report

By Your WP Guy / Oct 31, 2025

Plugin Name: Qi Blocks Key Information: Software Type: PluginSoftware Slug: qi-blocksSoftware Status: ActiveSoftware Author: qodeinteractiveSoftware Downloads: 648,392Active Installs: 60,000Last Updated: October 2025Patched Versions: 1.4.4Affected Versions: ≤ 1.4.3 Vulnerability Details Name: Qi Blocks ≤ 1.4.3Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NCVE: CVE-2025-12180CVSS Score: 4.3Publicly Published: October 31, 2025Researcher: Adrian LukitaDescription:The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in…

Read More
WP Plugin Vulnerabilities Image - LiteSpeed Cache Vulnerability - Unauthenticated Sensitive Information Exposure via Log Files - CVE-2024-44000 | WordPress Plugin Vulnerability Report - Vulnerabilities

LiteSpeed Cache Vulnerability – Unauthenticated Sensitive Information Exposure via Log Files – CVE-2024-44000 | WordPress Plugin Vulnerability Report

By Your WP Guy / Sep 5, 2024

Plugin Name: LiteSpeed Cache Key Information: Software Type: Plugin Software Slug: litespeed-cache Software Status: Active Software Author: litespeedtech Software Downloads: 79,208,611 Active Installs: 6,000,000 Last Updated: September 6, 2024 Patched Versions: 6.5.0.1 Affected Versions: <= 6.4.1 Vulnerability Details: Name: LiteSpeed Cache <= 6.4.1 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE: CVE-2024-44000 CVSS Score: 7.5 Publicly Published: September 5, 2024…

Read More
WP Plugin Vulnerabilities Image - Elementor Addon Elements Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Parameters - CVE-2024-4401, CVE-2024-7122 | WordPress Plugin Vulnerability Report - Vulnerabilities

Elementor Addon Elements Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Parameters – CVE-2024-4401, CVE-2024-7122 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 29, 2024

Plugin Name: Elementor Addon Elements Key Information: Software Type: Plugin Software Slug: addon-elements-for-elementor-page-builder Software Status: Active Software Author: webtechstreet Software Downloads: 2,783,086 Active Installs: 100,000 Last Updated: September 14, 2024 Patched Versions: 1.13.6, 1.13.7 Affected Versions: <= 1.13.5, <= 1.13.6 Vulnerability 1 Details: Name: Elementor Addon Elements <= 1.13.5 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-4401 CVSS Score:…

Read More
WP Plugin Vulnerabilities Image - The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Vulnerability - Authenticated (Contributor+) Information Disclosure - CVE-2024-7418 | WordPress Plugin Vulnerability Report - Vulnerabilities

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Vulnerability – Authenticated (Contributor+) Information Disclosure – CVE-2024-7418 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 28, 2024

Plugin Name: The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Key Information: Software Type: Plugin Software Slug: the-post-grid Software Status: Active Software Author: techlabpro1 Software Downloads: 2,131,603 Active Installs: 100,000 Last Updated: September 14, 2024 Patched Versions: 7.7.12 Affected Versions: <= 7.7.11 Vulnerability Details: Name: The Post Grid <= 7.7.11…

Read More
WP Plugin Vulnerabilities Image - GiveWP – Donation Plugin and Fundraising Platform Vulnerability - Unauthenticated Full Path Disclosure - CVE-2024-6551 | WordPress Plugin Vulnerability Report - Vulnerabilities

GiveWP – Donation Plugin and Fundraising Platform Vulnerability – Unauthenticated Full Path Disclosure – CVE-2024-6551 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 28, 2024

Plugin Name: GiveWP – Donation Plugin and Fundraising Platform Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 7,990,636 Active Installs: 100,000 Last Updated: September 14, 2024 Patched Versions: 3.16.0 Affected Versions: <= 3.15.1 Vulnerability Details: Name: GiveWP <= 3.15.1 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-6551 CVSS Score: 5.3 Publicly…

Read More
WP Plugin Vulnerabilities Image - Beaver Builder – WordPress Page Builder Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter - CVE-2024-7895 | WordPress Plugin Vulnerability Report - Vulnerabilities

Beaver Builder – WordPress Page Builder Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter – CVE-2024-7895 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 28, 2024

Plugin Name: Beaver Builder – WordPress Page Builder Key Information: Software Type: Plugin Software Slug: beaver-builder-lite-version Software Status: Active Software Author: justinbusa Software Downloads: 10,741,953 Active Installs: 100,000 Last Updated: September 3, 2024 Patched Versions: 2.8.3.6 Affected Versions: <= 2.8.3.5 Vulnerability Details: Name: Beaver Builder (Lite Version) <= 2.8.3.5 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-7895 CVSS Score:…

Read More
WP Plugin Vulnerabilities Image - Mollie Payments for WooCommerce Vulnerability - Unauthenticated Full Path Disclosure - CVE-2024-6448 | WordPress Plugin Vulnerability Report - Vulnerabilities

Mollie Payments for WooCommerce Vulnerability – Unauthenticated Full Path Disclosure – CVE-2024-6448 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 27, 2024

Plugin Name: Mollie Payments for WooCommerce Key Information: Software Type: Plugin Software Slug: mollie-payments-for-woocommerce Software Status: Active Software Author: mollieintegration Software Downloads: 3,421,407 Active Installs: 100,000 Last Updated: August 27, 2024 Patched Versions: 7.8.0 Affected Versions: <= 7.7.0 Vulnerability Details: Name: Mollie Payments for WooCommerce <= 7.7.0 Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-6448 CVSS Score: 5.3 Publicly…

Read More
WP Plugin Vulnerabilities Image - Jeg Elementor Kit Vulnerability - Authenticated (Author+) Stored Cross-Site Scripting via SVG File - CVE-2024-6804 | WordPress Plugin Vulnerability Report - Vulnerabilities

Jeg Elementor Kit Vulnerability – Authenticated (Author+) Stored Cross-Site Scripting via SVG File – CVE-2024-6804 | WordPress Plugin Vulnerability Report

By Your WP Guy / Aug 26, 2024

Plugin Name: Jeg Elementor Kit Key Information: Software Type: Plugin Software Slug: jeg-elementor-kit Software Status: Active Software Author: jegtheme Software Downloads: 1,587,316 Active Installs: 200,000 Last Updated: September 14, 2024 Patched Versions: 2.6.8 Affected Versions: <= 2.6.7 Vulnerability Details: Name: Jeg Elementor Kit <= 2.6.7 Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-6804 CVSS Score: 6.4 Publicly Published: August…

Read More