Plugin Updates

Appointment Booking Calendar Vulnerability— Simply Schedule Appointments Booking Plugin – Authenticated (Subscriber+) SQL Injection – CVE-2024-2341 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 20, 2024

Plugin Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin Key Information: Software Type: Plugin Software Slug: simply-schedule-appointments Software Status: Active Software Author: croixhaug Software Downloads: 963,505 Active Installs: 30,000 Last Updated: March 20, 2024 Patched Versions: 1.6.7.9 Affected Versions: <= 1.6.7.7 Vulnerability Details: Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin…

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-2255 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 19, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,747,397 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 4.5.4 Affected Versions: <= 4.5.2 Vulnerability Details: Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns…

GiveWP Vulnerability– Donation Plugin and Fundraising Platform – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1424 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 19, 2024

Plugin Name: GiveWP – Donation Plugin and Fundraising Platform Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 6,822,276 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 3.6.0 Affected Versions: <= 3.5.1 Vulnerability Details: Name: GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 Title: Authenticated…

Translate WordPress and go Multilingual Vulnerability– Weglot – Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes – CVE-2024-2124 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 18, 2024

Plugin Name: Translate WordPress and go Multilingual – Weglot Key Information: Software Type: Plugin Software Slug: weglot Software Status: Active Software Author: remyb92 Software Downloads: 2,296,771 Active Installs: 60,000 Last Updated: March 19, 2024 Patched Versions: 4.2.6 Affected Versions: <= 4.2.5 Vulnerability Details: Name: Translate WordPress and go Multilingual – Weglot <= 4.2.5 Title: Authenticated…

Permalink Manager Pro Vulnerability – Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification – CVE-2024-2538 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 18, 2024

Plugin Name: Permalink Manager Pro Key Information: Software Type: Plugin Software Slug: permalink-manager Software Status: Active Software Author: mbis Software Downloads: 1,661,826 Active Installs: 80,000 Last Updated: March 19, 2024 Patched Versions: 2.4.3.2 Affected Versions: <= 2.4.3.1 Vulnerability Details: Name: Permalink Manager <= 2.4.3.1 Title: Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification Type:…

Qi Addons For Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0826 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Qi Addons For Elementor Key Information: Software Type: Plugin Software Slug: qi-addons-for-elementor Software Status: Active Software Author: qodeinteractive Software Downloads: 1,685,695 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 1.6.8 Affected Versions: <= 1.6.7 Vulnerability Details: Name: Qi Addons For Elementor <= 1.6.7 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Backuply Vulnerability– Backup, Restore, Migrate and Clone – Authenticated (Admin+) Directory Traversal – CVE-2024-2294 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Backuply – Backup, Restore, Migrate and Clone Key Information: Software Type: Plugin Software Slug: backuply Software Status: Active Software Author: softaculous Software Downloads: 2,266,088 Active Installs: 200,000 Last Updated: March 19, 2024 Patched Versions: 1.2.8 Affected Versions: <= 1.2.7 Vulnerability Details: Name: Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 Title: Authenticated…

ElementsKit Elementor addons Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1239 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: ElementsKit Elementor addons Key Information: Software Type: Plugin Software Slug: elementskit-lite Software Status: Active Software Author: xspeedstudio Software Downloads: 16,983,084 Active Installs: 1,000,000 Last Updated: March 19, 2024 Patched Versions: 3.0.5 Affected Versions: <= 3.0.4 Vulnerability Details: Name: ElementsKit Elementor addons <= 3.0.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1239…

Everest Forms Vulnerability- Unauthenticated Server-Side Request Forgery via font_url – CVE-2024-1812 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 15, 2024

Plugin Name: Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! Key Information: Software Type: Plugin Software Slug: everest-forms Software Status: Active Software Author: wpeverest Software Downloads: 5,605,349 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 2.0.8 Affected Versions: <= 2.0.7 Vulnerability Details: Name:…

Metform Elementor Contact Form Builder Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-1585 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: Metform Elementor Contact Form Builder Key Information: Software Type: Plugin Software Slug: metform Software Status: Active Software Author: xpeedstudio Software Downloads: 3,185,155 Active Installs: 300,000 Last Updated: March 12, 2024 Patched Versions: 3.8.4 Affected Versions: <= 3.8.3 Vulnerability Details: Name: Metform Elementor Contact Form Builder <= 3.8.3 Title: Authenticated (Contributor+) Stored Cross-Site Scripting…