WordPress Vulnerability Report — April 17, 2024

<div style&equals;"text-align&colon;center"><img src&equals;"data&colon;image&sol;gif&semi;base64&comma;R0lGODlhAQABAIAAAAAAAP&sol;&sol;&sol;ywAAAAAAQABAAACAUwAOw&equals;&equals;" fifu-lazy&equals;"1" fifu-data-sizes&equals;"auto" fifu-data-srcset&equals;"https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;75&resize&equals;75&ssl&equals;1 75w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;100&resize&equals;100&ssl&equals;1 100w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;150&resize&equals;150&ssl&equals;1 150w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;240&resize&equals;240&ssl&equals;1 240w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;320&resize&equals;320&ssl&equals;1 320w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;500&resize&equals;500&ssl&equals;1 500w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;640&resize&equals;640&ssl&equals;1 640w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;800&resize&equals;800&ssl&equals;1 800w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;1024&resize&equals;1024&ssl&equals;1 1024w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;1280&resize&equals;1280&ssl&equals;1 1280w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1&w&equals;1600&resize&equals;1600&ssl&equals;1 1600w" width&equals;"2500" height&equals;"1311" fifu-data-src&equals;"https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1" class&equals;"attachment-post-thumbnail size-post-thumbnail wp-post-image" alt&equals;"WordPress Vulnerability Report — April 17&comma; 2024" title&equals;"WordPress Vulnerability Report — April 17&comma; 2024" srcset&equals;"https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024&period;png&quest;ssl&equals;1 2500w&comma; https&colon;&sol;&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024-300x157&period;png 300w&comma; https&colon;&sol;&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024-1024x537&period;png 1024w&comma; https&colon;&sol;&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024-768x403&period;png 768w&comma; https&colon;&sol;&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024-1536x805&period;png 1536w&comma; https&colon;&sol;&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;11&sol;wordpress-vulnerability-report-april-17-2024-2048x1074&period;png 2048w" sizes&equals;"&lpar;max-width&colon; 2500px&rpar; 100vw&comma; 2500px" &sol;><&sol;div><div>&NewLine;<div>&NewLine;<p><img src&equals;"data&colon;image&sol;gif&semi;base64&comma;R0lGODlhAQABAIAAAAAAAP&sol;&sol;&sol;ywAAAAAAQABAAACAUwAOw&equals;&equals;" fifu-lazy&equals;"1" fifu-data-sizes&equals;"auto" fifu-data-srcset&equals;"https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;75&resize&equals;75&ssl&equals;1 75w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;100&resize&equals;100&ssl&equals;1 100w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;150&resize&equals;150&ssl&equals;1 150w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;240&resize&equals;240&ssl&equals;1 240w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;320&resize&equals;320&ssl&equals;1 320w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;500&resize&equals;500&ssl&equals;1 500w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;640&resize&equals;640&ssl&equals;1 640w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;800&resize&equals;800&ssl&equals;1 800w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;1024&resize&equals;1024&ssl&equals;1 1024w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;1280&resize&equals;1280&ssl&equals;1 1280w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1&w&equals;1600&resize&equals;1600&ssl&equals;1 1600w" decoding&equals;"async" width&equals;"800" height&equals;"419"src&equals;"https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1" class&equals;"attachment-post-thumbnail size-post-thumbnail wp-post-image" alt&equals;"WordPress Vulnerability Report — April 17&comma; 2024" srcset&equals;"https&colon;&sol;&sol;rssfeeds&period;cloudsite&period;builders&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024&period;png 800w&comma; https&colon;&sol;&sol;i1&period;wp&period;com&sol;www&period;awordpresscommenter&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-E28094-April-17-2024-1160x608-1&period;png&quest;ssl&equals;1 1160w&comma; https&colon;&sol;&sol;wparchives&period;com&sol;wp-content&sol;uploads&sol;2024&sol;04&sol;WordPress-Vulnerability-Report-—-April-17-2024-485x254&period;png 485w" sizes&equals;"&lpar;max-width&colon; 800px&rpar; 100vw&comma; 800px" title&equals;"WordPress Vulnerability Report — April 17&comma; 2024 4"><&sol;p>&NewLine;<p class&equals;"has-drop-cap has-medium-font-size">In this report&comma; 342 vulnerabilities have been publicly disclosed&period; Security patches for 254 of these plugins&comma; themes&comma; and Core are available now&comma; so run those updates as soon as possible&period; If you’re a Solid Security Pro user&comma; the version management tool may have already warned you and updated these plugins&comma; depending on your settings&period;<&sol;p>&NewLine;<p>Additionally&comma; there are 88 plugin and theme vulnerabilities with no patch available yet&period; If you’re a Solid Security Pro user&comma; those vulnerabilities are already protected by the Solid Security firewall&period; Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk&period; If no patch is forthcoming from the vendor or the vulnerable software has been marked &OpenCurlyDoubleQuote;closed” and dropped from the official WordPress repositories&comma; you should deactivate it soon and look for alternative solutions&period;<&sol;p>&NewLine;<p>Along with poor user account security&comma; <strong>vulnerable plugins and themes are among the top reasons why WordPress websites get hacked&period;<&sol;strong> Unfortunately&comma; cyberattacks are increasing in volume and sophistication&period; They’re also increasingly aimed at small to mid-sized businesses&period;<&sol;p>&NewLine;<h2 class&equals;"solidwp-post-toc&lowbar;&lowbar;heading">Table of Contents<&sol;h2>&NewLine;<ol class&equals;"solidwp-post-toc&lowbar;&lowbar;list">&lbrack;…&rsqb;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;wparchives&period;com&sol;wordpress-vulnerability-report-2024&sol;" target&equals;"&lowbar;blank" rel&equals;"noopener"><span class&equals;"screen-reader-text">WordPress Vulnerability Report — April 17&comma; 2024<&sol;span> Keep Reading »<&sol;a><br &sol;>&num;Blogging &num;WordPress &num;BloggingTips &num;BlogChat<&sol;p>&NewLine;<&sol;ol>&NewLine;<&sol;div>&NewLine;<&sol;div>&NewLine;

Sponsored
Sponsored
A WordPress Commenter

Recent Posts

Blocktober Wraps Up as Telex Inspires a Wave of WordPress Experimentation

As October winds down, so too does Blocktober, Tammie Lister’s month-long challenge to create a…

10 hours ago

WordPress Foundation and WooCommerce Join Countersuit Against WP Engine, Alleging Trademark Infringement and False Advertising

The WordPress Foundation and WooCommerce have joined Automattic and Matt Mullenweg in countersuing WP Engine,…

4 days ago

FAIR and Patchstack Joining Forces at CloudFest USA Hackathon to Build New Security Integration

The first-ever CloudFest USA Hackathon, taking place November 4 in Miami, will bring together contributors…

5 days ago

WordCamp Canada 2025 Fosters Connections Between Generations of WordPress Users

Canada’s largest gathering of WordPress enthusiasts drew a strong turnout at Carleton University last weekend,…

5 days ago

WooCommerce 10.3 Brings Cost of Goods Sold to Core, MCP Beta for AI Integrations

WooCommerce 10.3 was released this week, introducing one of the most requested features for store…

6 days ago

Devin Walker Joins Automattic as Artistic Director for Jetpack

Automattic has hired GiveWP co-founder Devin Walker as Artistic Director for Jetpack, where he will…

6 days ago