CVE-2022-4974
Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
CWE
- CWE-862 — CWE-862 Missing Authorization
Affected
- dashlabsltd / YASR – Yet Another Star Rating Plugin for WordPress — v=0 <2.0.2 [affected]
- nicheaddons / Events Addon for Elementor — v=0 <1.9.8 [affected]
- dots / Fraud Prevention For WooCommerce and EDD — v=0 <2.1.0 [affected]
- wpengine / Gutenberg Blocks – ACF Blocks Suite — v=0 <2.6.8 [affected]
- bouncingsprout / Ultimeter — v=0 <2.7.6 [affected]
- toddhalfpenny / Past Events Extension — v=0 [affected]
- pootlepress / Pootle Pagebuilder – WordPress Page builder — v=0 <5.7.1 [affected]
- powerfulwp / Local Delivery Drivers for WooCommerce — v=0 <1.8.5 [affected]
- kkikuchi1220 / Ultimate Gutenberg – Custom Block Templates — v=0 [affected]
- josevega / WP Required Taxonomies – Categories and Tags Mandatory — v=0 <1.1.8 [affected]
- pmbaldha / Featured Products First for WooCommerce – A Extension of WooCommerce (WooCommerce Addon Plugin) — v=0 [affected]
- sslzen / SSL Zen — SSL Certificate Installer & HTTPS Redirects — v=0 ≤4.0.4 [affected]
- wisersteps / Streak CRM For Gmail For Contact Form 7 – WordPress Plugin — v=0 <1.0.9 [affected]
- wpdevpowers / WordPress Dev Powers – ACF Color Coded Field Types Plugin — v=0 [affected]
- benmoreassynt / DancePress (TRWA) — v=0 ≤3.1.2 [affected]
- dots / Product Size Charts Plugin for WooCommerce — v=0 <2.2.3 [affected]
- tribalnerd / Wp My Admin Bar — v=0 [affected]
- setka / A no-code page builder for beautiful performance-based content — v=0 <2.1.17 [affected]
- mikebels / LocalSEOMap — v=0 [affected]
- cromer12 / Easy Prayer — v=0 [affected]
- rafalosinski / AdFoxly – Ad Manager, AdSense Ads & Ads.txt — v=0 ≤1.8.4 [affected]
- stevehenty / WP Get Personal — v=0 [affected]
- theafricanboss/ / Checkout with Cash App on EDD — v=0 [affected]
- usmanaliqureshi / Server Info — v=0 [affected]
- themelocation / Custom WooCommerce Checkout Fields Editor — v=0 ≤1.2.6 [affected]
- krsp / KRSP Frontend File Uploader — v=0 [affected]
- bplugins / Panorama – 360 Virtual Tour, Panoramic image viewer and More — v=0 <1.0.8 [affected]
- janwyl / Bulk Attachment Download — v=0 <1.3.5 [affected]
- majick / AutoSave Net — v=0 [affected]
- premmerce / Premmerce Wholesale Pricing for WooCommerce — v=0 <1.1.8 [affected]
- jcodex / Any Popup – Popup Forms, Optins & Ads — v=0 [affected]
- theafricanboss/ / Checkout with Venmo on EDD — v=0 [affected]
- dreamfox / Payment Gateway Per Product for WooCommerce — v=0 <3.1.6 [affected]
- hqtheme / HQTheme Extra — v=0 [affected]
- vincoit / Vit Website Reviews — v=0 [affected]
- daigo75 / EU VAT Assistant for WooCommerce — v=0 <2.0.28.220224 [affected]
- eedee / WordPress Slider Block Gutenslider — v=0 <5.7.0 [affected]
- surbma / HuCommerce | Magyar kiegészítések WooCommerce webáruházakhoz — v=0 <30.3.0 [affected]
- lostboy7 / KVoucher — v=0 [affected]
- bplugins / YT Player – Embed and Customize Video Players — v=0 <1.5.1 [affected]
- whiteshadow / Error Log Monitor — v=0 <1.7.1 [affected]
- slidedeck / SlideDeck: Responsive WordPress Slider Plugin — v=0 [affected]
- premmerce / Premmerce Multi-currency for Woocommerce — v=0 <2.3.2 [affected]
- mvvapps/ / Booking Addon for WooCommerce — v=0 <4.2.0 [affected]
- wpeventpartners/ / WP Event Partners – WordPress Plugin for Event and Conference Management — v=0 ≤1.2.4 [affected]
- saadiqbal / WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce — v=0 <4.2.1 [affected]
- passionatebrains / AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization — v=0 <2.6 [affected]
- majick / ForceField — v=0 [affected]
- richard-b / FIT: Featured Image Toolkit — v=0 [affected]
- themekraft / All in One Invite Codes — v=0 <1.0.13 [affected]
- dots / Dynamic Pricing and Discount Rules for WooCommerce — v=0 <2.2.3 [affected]
- wordplus / Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages — v=0 <1.9.9.170 [affected]
- wpt00ls / Grid & Styler For Contact Form 7 And Divi — v=0 <1.4.1 [affected]
- protectyouruploads / Protect Uploads with Login – Protect Your Uploads — v=0 [affected]
- sakurapixel / Atlas – Knowledge Base — v=0 [affected]
- dgwyer / Simple Sitemap – Create a Responsive HTML Sitemap — v=0 <3.5.5 [affected]
- bplugins / Super Video player – Fully Customizable Video Player with Playlist — v=0 <1.6.11 [affected]
- mhmrajib / WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes — v=0 <3.6 [affected]
- damian-gora / FiboSearch – Ajax Search for WooCommerce — v=0 <1.17.0 [affected]
- stevejburge / Tag Groups is the Advanced Way to Display Your Taxonomy Terms — v=0 <1.43.10.1 [affected]
- prasadkirpekar / WP Free SSL — v=0 <1.2.7 [affected]
- clickervolt / ClickerVolt – Affiliate Links & Click Tracking for Performance Marketers — v=0 [affected]
- proteusthemes / ConsultPress Lite — v=0 [affected]
- badhonrocks / Styler Mate for Contact Form 7 — v=0 <1.3.0 [affected]
- streamweasels / StreamWeasels Twitch Integration — v=0 <1.3.4 [affected]
- pagup / MOBILOOK — Mobile View & Mobile‑Friendly Test — v=0 <1.2.4 [affected]
- paulio21 / Zip Code Redirect — v=0 ≤4.0.1 [affected]
- vohotv/ / Guestofy – Restaurant Reservations Plugin, Room Planer, Reservation Form — v=0 [affected]
- ahmed17 / CF7 Constant Contact Fields Mapping — v=0 [affected]
- stellarwp / Bookit — Booking & Appointment Calendar — v=0 <2.2.9 [affected]
- ethereumicoio / EthereumICO — v=0 <2.3.11 [affected]
- risetheme / RT Easy Builder – Advanced addons for Elementor — v=0 ≤1.4 [affected]
- saadiqbal / WP Contact Slider – Contact Form Slider Widget — v=0 <2.4.5 [affected]
- ivan_paulin / Country Based Payments for WooCommerce — v=0 <1.4.1 [affected]
- wpchill / Filr – Secure document library — v=0 <1.2.1 [affected]
- nicheaddons / Elasta — v=0 <1.0.8 [affected]
- interactivegeomaps / MapGeo – Interactive Geo Maps — v=0 <1.5.4 [affected]
- galoover / WordPress Animation Plugin – Animated Everything — v=0 [affected]
- wpdever / WP Notification Bell — v=0 <1.3.13 [affected]
- melapress / Activity Log For MainWP — v=0 <1.7.1 [affected]
- oceas / Connected Sermons — v=0 [affected]
- josevega / Bulk Edit and Create User Profiles – WP Sheet Editor — v=0 <1.5.13 [affected]
- milukove/ / Кнопка ЮMoney — v=0 [affected]
- kartikparmar/ / Bulk WooCommerce Category Creator — v=0 [affected]
- alphabposervice / Easy Math Captcha for CF7 — v=0 [affected]
- litonice13 / Master Accordion ( Former WP Awesome FAQ Plugin ) — v=0 <4.1.8 [affected]
- wpdive / Better Addons for Elementor — v=0 <1.3.1 [affected]
- livemesh / Livemesh Addons by Elementor — v=0 <7.1.4 [affected]
- nitin247 / Place Order Without Payment for WooCommerce — v=0 <2.2 [affected]
- boriscolombier/ / STEWoo – Super Transactional Emails for WooCommerce — v=0 <1.2.4 [affected]
- marcqueralt / DeMomentSomTres Address — v=0 [affected]
- johnc1979 / Out of stock display for woocommerce — v=0 [affected]
- ultimateblocks / Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor — v=0 <2.4.13 [affected]
- pagup / Bulk Auto Image Title Attribute (Image Title tag) optimizer (Image SEO) — v=0 <1.2.3 [affected]
- princeahmed / WP Radio – Worldwide Online Radio Stations Directory for WordPress — v=0 <3.1.4 [affected]
- blackandwhitedigital / BookPress – For Book Authors — v=0 <1.2.3 [affected]
- wpchill / Qyrr – simply and modern QR-Code creation — v=0 <0.8 [affected]
- wpeka-club / WordPress Directory Plugin For Business Listings – WP Local Plus — v=0 <1.4.5 [affected]
- equalizedigital / Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance — v=0 <1.2.8 [affected]
- therealwebdisrupt / Funnelmentals — v=0 [affected]
- blockspare / BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor — v=0 <2.0.1 [affected]
- nasirahmed / Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook — v=0 <1.1.9 [affected]
- mojofywp / Product Carousel For WooCommerce – WoorouSell — v=0 <1.0.9 [affected]
- pagup / Better Robots.txt – AI-Ready Crawl Control & Bot Governance — v=0 <1.4.4 [affected]
- gfirem / GFireM Fields — v=0 [affected]
- elliotvs / Coupon Affiliates – Affiliate Plugin for WooCommerce — v=0 <4.16.4 [affected]
- dipcode / WP Post Block — v=0 [affected]
- attest / LMS Plugin – eLearning, Online Courses by Attest — v=0 [affected]
- shabti / Frontend Admin by DynamiApps — v=0 <3.3.33 [affected]
- ibenic / Simple Giveaways – Grow your business, email lists and traffic with contests — v=0 <2.42.1 [affected]
- wpt00ls / Masonry Gallery & Posts For Divi (WP Tools) — v=0 <3.1.2 [affected]
- gfirem / GFireM Action After — v=0 [affected]
- bandido / Ukrposhta — v=0 <1.6.18 [affected]
- annastaa / annasta Filters for WooCommerce — v=0 <1.5.0 [affected]
- tprintyedisonave / WP Lead Stream — v=0 [affected]
- stellarwp / The Events Calendar — v=0 <5.14.0.4 [affected]
- johnc1979 / Focus on Reviews for WooCommerce — v=0 [affected]
- pmbaldha / Email Tracker — v=0 ≤5.3.8 [affected]
- wpt00ls / Block Styler For Gravity Forms — v=0 ≤6.1.0 [affected]
- josevega / WP Page Templates — v=0 <1.1.13 [affected]
- ggwicz / Product Customer List for WooCommerce — v=0 <3.0.0 [affected]
- wpmoose / WP Moose — v=0 <1.0.1 [affected]
- samdani / Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More — v=0 <1.1.0 [affected]
- jwebsol / Floating Social Share Icons and Social Share buttons – Next Previous Post Links – FL — v=0 <3.6.0 [affected]
- co2ok / South Pole: Climate action now — v=0 <1.0.2.0 [affected]
- jwind / LittleBot Invoices — v=0 [affected]
- akdevs / Genealogical Tree – Family Tree & Ancestry for WordPress — v=0 ≤2.1.5 [affected]
- plugins360 / Automatic YouTube Gallery — v=0 <1.6.5 [affected]
- nitin247 / Thank You Page for WooCommerce — v=0 <3.1 [affected]
- 5starplugins / Marijuana Age Verify — v=0 <1.3.1 [affected]
- skshaikat / WooCommerce upcoming Products — v=0 [affected]
- shabti / Frontend Admin – Add and edit posts, pages, users and more all from the frontend — v=0 <3.3.33 [affected]
- matthias-reuter / SV Tracking Manager — v=0 <1.8.02 [affected]
- saadiqbal / WP Easy Pay – Payment and Donation form Builder for Square — v=0 <4.0.2 [affected]
- flexithemes / WordPress SEO Checklist — v=0 [affected]
- wgauge / wGauge – Free Version — v=0 [affected]
- bdthemes / Prime Slider – Addons for Elementor — v=0 <2.7.0 [affected]
- themekraft / Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) — v=0 <2.6.3 [affected]
- wpt00ls / WP Tools Divi Product Carousel — v=0 <1.5.0 [affected]
- aharonyan / Guest posting / Frontend Posting / Front Editor – WP Front User Submit — v=0 <3.4.1 [affected]
- woodyhayday / Social Gallery Lite — v=0 [affected]
- bfintal / Stackable – Page Builder Gutenberg Blocks — v=0 <3.1.5 [affected]
- seezee / Five-Star Ratings Shortcode — v=0 <1.2.39 [affected]
- wpkube / CAPTCHA 4WP – Antispam CAPTCHA solution for WordPress — v=0 <7.0.5 [affected]
- premmerce / Premmerce Wishlist for WooCommerce — v=0 <1.1.8 [affected]
- wordpresschef / Salon Booking System – Free Version — v=0 <7.6.3 [affected]
- surbma / Surbma | GDPR Proof Cookie Consent & Notice Bar — v=0 <17.5.3 [affected]
- dots / Advanced Menu Manager Pro – Built for Content-heavy WordPress Sites to Add, Filter, Lock, and Edit Menus Easily — v=0 [affected]
- princeahmed / Live TV Player – Worldwide Live TV Channels Player for WordPress — v=0 <1.2.3 [affected]
- vanyukov / Market Exporter — v=0 ≤2.0.13 [affected]
- litonice13 / WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer — v=0 <2.0.5 [affected]
- themekraft / TK Google Fonts GDPR Compliant — v=0 <2.2.1 [affected]
- starfishwp / Starfish Review Generation & Marketing for WordPress — v=0 <3.0.26 [affected]
- halmat / WP Emaily — v=0 [affected]
- nicheaddons / Education Addon for Elementor — v=0 <1.2 [affected]
- matthias-reuter / SV Proven Expert — v=0 <1.8.01 [affected]
- wpeka-club / SurveyFunnel – Survey Plugin for WordPress — v=0 <1.1.3 [affected]
- pluginsware / Advanced Classifieds & Directory Pro — v=0 <1.8.8 [affected]
- smartwpress / Music Player for Elementor – Audio Player & Podcast Player — v=0 <1.5.5 [affected]
- ethereumicoio / Cryptocurrency Product for WooCommerce — v=0 <3.14.6 [affected]
- kenanfallon / WooCommerce Next Order Coupon — v=0 [affected]
- themeythemes / Overlay Image Divi Module — v=0 <1.3.2 [affected]
- pmbaldha / Email Header Footer — v=0 [affected]
- bplugins / Document Viewer – Embed Word, Excel, PowerPoint & PDFs Instantly — v=0 <2.2.5 [affected]
- nplugins / Price Bands for WooCommerce — v=0 [affected]
- wpvibes / Addon Elements for Elementor (formerly Elementor Addon Elements) — v=0 <1.11.14 [affected]
- drosendo / Smart Variations Images & Swatches for WooCommerce — v=0 <5.1.10 [affected]
- 5starplugins / Featured Images in RSS for Mailchimp & More — v=0 <1.5.9 [affected]
- ibenic / Simple Sponsorships — v=0 [affected]
- unitecms / Unlimited Elements For Elementor — v=0 <1.5.3 [affected]
- wpjoli / Joli Table Of Contents — v=0 <1.3.9 [affected]
- getsparrow / Sparrow: Product Reviews and Ratings for WooCommerce — v=0 [affected]
- zerozendesign / Multi Page Auto Advance for Gravity Forms — v=0 <4.3 [affected]
- mcurly / Generate Images (AI) – Magic Post Thumbnail — v=0 <3.3.11 [affected]
- ibenic / Live Scores for SportsPress — v=0 [affected]
- dots / Hide Shipping Method For WooCommerce — v=0 <1.3.1 [affected]
- wpt00ls / Ultimate Carousel For Divi — v=0 <4.3.1 [affected]
- prasadkirpekar / WP Meta and Date Remover — v=0 <1.9.6 [affected]
- wpt00ls / Image Carousel For Divi — v=0 <1.5.0 [affected]
- dudo / Comments Not Replied To — v=0 <1.5.3 [affected]
- wisersteps / Contact Form 7 – Capsule CRM – Integration — v=0 <1.0.5 [affected]
- alexmoss / Opensea — v=0 <1.0.3 [affected]
- tranzly / WordPress Translation plugin for Post, Pages & WooCommerce products. Tranzly IO AI DeepL automatic WordPress Translator. — v=0 <1.1.1 [affected]
- alekv / Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing — v=0 <1.14.3 [affected]
- gowebsmarty / Modern Addons for Elementor Page Builder — v=0 <1.2.0 [affected]
- themesei / Viralike — v=0 [affected]
- wpdevpowers / WordPress Dev Powers – Element Selector jQuery Powers Plugin — v=0 [affected]
- wpmunich / WP Munich Blocks – Gutenberg Blocks for WordPress — v=0 <0.11.0 [affected]
- inputwp / Availability Datepicker – Booking Calendar for Contact Form 7 – Input WP — v=0 ≤2.1 [affected]
- diviframework / Footer Plugin for Divi — v=0 [affected]
- mhmrajib / AidWP – Donation & Payment Forms (Stripe Powered) — v=0 <2.9 [affected]
- saadiqbal / New User Approve — v=0 <2.1 [affected]
- gfirem / GFireM Advance Search — v=0 [affected]
- giladtakoni / WPMailer – The best mail builder, No More Core for your emails support Elementor, CF7 forms etc… — v=0 [affected]
- anssilaitila / Shared Files – Frontend File Upload Form & Secure File Sharing — v=0 <1.6.72 [affected]
- wpbits / WPBITS Addons For Elementor Page Builder — v=0 <1.3.2 [affected]
- prelc / Speculor — v=0 [affected]
- pagup / WP Google Street View (with 360° virtual tour) & Google maps + Local SEO — v=0 <1.0.9 [affected]
- deothemes / WordPress Everse Starter Sites – Elementor Templates — v=0 <1.2.1 [affected]
- litonice13 / Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits — v=0 <1.8.5 [affected]
- versacomp / Choice Payment Gateway for WooCommerce — v=0 <2.0.5 [affected]
- maartenbelmans / Domain Mapping System | Create Microsites with Multiple Alias Domains (multisite optional) — v=0 <1.7 [affected]
- stylingwebben / Order and Inventory Manager for WooCommerce — v=0 <1.4.3 [affected]
- ninjalibs / Ninja Libs Amazon SES — v=0 [affected]
- royalnavneet / WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments — v=0 <4.3 [affected]
- webheadllc / WP-Cron Status Checker — v=0 <1.2.4 [affected]
- bilaltas / CodeKit – Custom Codes Editor — v=0 <2.3 [affected]
- fooplugins / Gallery by FooGallery — v=0 <2.1.34 [affected]
- kartikparmar / Change Price Title for WooCommerce — v=0 ≤2.5 [affected]
- edgegalleryplugin / WordPress Gallery Plugin – Edge Photo Gallery — v=0 [affected]
- gloriousthemes / Glorious Services & Support — v=0 [affected]
- alphabposervice / Easy Newsletter Signups — v=0 <1.0.4 [affected]
- mikewire_rocksolid / Announcement & Notification Banner – Bulletin — v=0 <3.1.0 [affected]
- dam6pl / Advanced Database Replacer — v=0 [affected]
- tribalnerd / Multisite Robots.txt Manager — v=0 [affected]
- irkanu / Simple Social Page Widget & Shortcode — v=0 [affected]
- josevega / Product Country Restrictions for WooCommerce – Country Catalogs — v=0 <1.13.0 [affected]
- shamim51 / Front End PM — v=0 <11.3.4 [affected]
- divisumo / Ultimate Divi Modules Suite – Divi Sumo Lite — v=0 [affected]
- xplodedthemes / XT Points & Rewards for WooCommerce — v=0 <1.4.3 [affected]
- themelocation / Widgets for WooCommerce Products on Elementor — v=0 <1.0.9 [affected]
- popeating / Delivery for WooCommerce — v=0 [affected]
- mohsinoffline / NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce — v=0 <1.3.7 [affected]
- cleverplugins / Security Ninja – WordPress Security & Firewall — v=0 <5.135 [affected]
- xyulex / TinyMCE Annotate — v=0 [affected]
- damian-gora / Justified Gallery — v=0 <1.5.1 [affected]
- mberding / Book BuyBack Prices — v=0 [affected]
- daniyalahmedk / Fuse Social Floating Sidebar — v=0 <5.4.3 [affected]
- wphrmanager / WP-HR Manager: The Human Resources Plugin for WordPress — v=0 <3.0.3 [affected]
- coderpress / Emails Blacklist for Everest Forms — v=0 <1.0.4 [affected]
- plugins360 / All-in-One Video Gallery — v=0 <2.5.4 [affected]
- oloyede-jamiu / Woo Admin Product Notes — v=0 [affected]
- themelocation / Remove Add to Cart WooCommerce — v=0 <1.4.3 [affected]
- theafricanboss / Checkout with Zelle on Woocommerce — v=0 <2.0 [affected]
- wpt00ls / Divi Gravity Forms (WP Tools) — v=0 <6.6.3 [affected]
- deothemes / Everse — v=0 <1.8.6 [affected]
- commercepundit / Run time Image resizing — v=0 [affected]
- wp-making / Rest Routes – Custom Endpoints for WordPress REST API — v=0 <4.24.0 [affected]
- olezhyk5 / Widget for Contact form 7 — v=0 [affected]
- pagup / Add Pinterest conversion tags for Pinterest Ads + Site verification — v=0 <1.2.3 [affected]
- javmah / WPGSI: Spreadsheet Integration — v=0 <3.6.1 [affected]
- majick / WP BugBot — v=0 [affected]
- princeahmed / File Manager for Google Drive – Integrate Google Drive — v=0 <1.1.0 [affected]
- deothemes / Nokke — v=0 <1.0.11 [affected]
- josevega / Customers Table for WooCommerce: View, Search, Bulk Editor — v=0 <1.0.8 [affected]
- closemarketing/ / Sync eCommerce NEO — v=0 [affected]
- wpcohort / Preloader for Divi — v=0 [affected]
- tobias_conrad/ / Get Better Reviews for WooCommerce — v=0 ≤3.0.6 [affected]
- codesavory / Knowledge Base documentation & wiki plugin – BasePress Docs — v=0 <2.15.14 [affected]
- webba-agency / Easy Appointment Booking & Scheduling System – Webba Booking Calendar — v=0 <4.2.18 [affected]
- salttechno / Shuban — v=0 [affected]
- pmbaldha/ / ACF for WooCommerce Product — v=0 <1.8 [affected]
- johnc1979 / Scheduled Notification Bar — v=0 [affected]
- bplugins / 3D Viewer – Display Interactive 3D Models — v=0 <1.2.7 [affected]
- samuelsilvapt / Fullscreen Menu — v=0 ≤2.2.7 [affected]
- wpchill / Gallery PhotoBlocks — v=0 <1.2.6 [affected]
- themeisle / Redirection for Contact Form 7 — v=0 <2.5.0 [affected]
- marcqueralt / DeMomentSomTres Grid Archive — v=0 [affected]
- seancarrico / Inbound Brew — v=0 [affected]
- muhammad-rehman / WP Photo Effects — v=0 <1.2.1 [affected]
- danish-ali / WPOptin – AI-Powered Top Bars, PopUps & Lead Generation — v=0 ≤1.2.3 [affected]
- dots / Extra Fees for WooCommerce — v=0 <3.8.2 [affected]
- ldninjas/ / Reset Course Progress For LearnDash — v=0 [affected]
- princeahmed / Podcast Box – Best Podcasting Plugin for WordPress — v=0 <1.0.2 [affected]
- giladtakoni / The best plugin for restrict content, support all Custom Post Types and Elementor – Password Protected — v=0 [affected]
- toddhalfpenny / Turbo Widgets — v=0 [affected]
- wpchill / Passster – Password Protect Pages and Content — v=0 <3.5.5.2 [affected]
- powerfulwp / Gift Message for WooCommerce — v=0 <1.6.0 [affected]
- actuaryzask / azw woocommerce file uploads — v=0 [affected]
- infornweb / Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News — v=0 <2.3.1 [affected]
- jburleigh1 / Broadcast Lite — v=0 <2.0.3 [affected]
- fooplugins / Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar — v=0 <2.1.15 [affected]
- penguininitiatives / WP Author Bio — v=0 [affected]
- ahmed17 / RW Divi Unite Gallery — v=0 ≤1.0 [affected]
- essekia / Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent — v=0 <0.6.7 [affected]
- wpwebinfotech / Product Image Watermark for Woo — v=0 <1.0.4 [affected]
- nasirahmed / AFI – The Easiest Integration Plugin — v=0 <1.49.0 [affected]
- janthielemann / Revolution for Elementor — v=0 [affected]
- wpconedev / ConeBlog – Elementor Blog Widgets — v=0 <1.4.6 [affected]
- linekal / Under Construction — v=0 <4.0 [affected]
- ekanath / WP Gratify — v=0 [affected]
- cmbibby/ / Automizy Gravity Forms — v=0 [affected]
- toddhalfpenny / Widgets on Pages — v=0 <1.6.0 [affected]
- ggriesser / Get feedback from visitors – WP Feedback Suite Plugin — v=0 [affected]
- dejanmarkovic / WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule — v=0 <2020.1.0 [affected]
- intoxstudio / Content Aware Sidebars – Fastest Widget Area Plugin — v=0 <3.17.2 [affected]
- salttechno / Bani — v=0 [affected]
- ggriesser / Fast WordPress — v=0 [affected]
- sonalsinha21 / SKT Templates – 100% Free Templates for Elementor & Gutenberg — v=0 <4.3 [affected]
- frenify / Categorify – WordPress Media Library Category & File Manager — v=0 <1.0.5 [affected]
- vinod-dalvi / Ivory Search – WordPress Search Plugin — v=0 <5.4.4 [affected]
- pagup / Add Twitter Pixel for Twitter ads — v=0 <1.0.4 [affected]
- xplodedthemes / XT Variation Swatches for WooCommerce — v=0 <1.8.1 [affected]
- kaizencoders / URL Shortify – Simple and Easy URL Shortener — v=0 <1.5.11 [affected]
- mohsinoffline / Pledged Plugins Secure Gateway for Authorize.net and WooCommerce — v=0 <5.1.27 [affected]
- themekraft / BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages — v=0 <3.4.2 [affected]
- cloudliving / Affiliate Link Builder Plugin for Amazon Associates – Review Engine — v=0 [affected]
- mte90 / Glossary — v=0 <2.1.8 [affected]
- bavokoservices / BAVOKO SEO Tools – All-in-One WordPress SEO — v=0 [affected]
- foxmoon / Cartoon Url — v=0 [affected]
- josevega / WP Frontend Admin – Display WP Admin Pages in the Frontend — v=0 <1.17.0.4 [affected]
- bouncingsprout / Block, Suspend, Report for BuddyPress — v=0 <3.3.3 [affected]
- takanakui / Menu Image, Icons made easy — v=0 <3.0.6 [affected]
- xplodedthemes / XT Ajax Add To Cart for WooCommerce — v=0 <1.0.4 [affected]
- bestpluginswordpress / One Click Login — v=0 [affected]
- ethereumicoio / Ether and ERC20 tokens WooCommerce Payment Gateway — v=0 <4.12.9 [affected]
- mvvapps/ / Chat Button- Leads and Order over Chat — v=0 <1.6.1 [affected]
- dreamfox / Shipping Gateway Per Product for WooCommerce — v=0 <2.0.4 [affected]
- deothemes / Purosa — v=0 <1.1.0 [affected]
- tauhidpro / NicheTable – Responsive Comparison Table Block — v=0 <2.2.3 [affected]
- ankitmaru / Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress — v=0 <6.0.0 [affected]
- themesty / WP Sierra — v=0 [affected]
- dots / Digital Goods (Checkout Field Editor) for WooCommerce Checkout — v=0 <3.6.4 [affected]
- cleverplugins / SEO Booster — v=0 <3.8.5 [affected]
- fullworks / Stop Contact Form 7 Spam & WPForms Spam – Free Protection — v=0 <1.3.2 [affected]
- khothemes / Ultimate Widgets Light — v=0 [affected]
- beeneeb / Insert or Embed Articulate Content into WordPress — v=0 <4.3000000016 [affected]
- saadiqbal / APPExperts – Mobile App Builder for WordPress | WooCommerce to iOS and Android Apps — v=0 <1.2.2 [affected]
- bdthemes / Ultimate Post Kit Addons for Elementor — v=0 <2.9.1 [affected]
- pootlepress / Caxton – Create Pro page layouts in Gutenberg — v=0 <1.30.0 [affected]
- djenh / Nitek Carousel Slider Cool Transitions — v=0 [affected]
- kartechify / Extend Filter Products By Price Widget — v=0 [affected]
- blockmeister / BlockMeister – Block Pattern Builder — v=0 <3.0.5 [affected]
- mantrabrain / Yatri Tools — v=0 <1.1.3 [affected]
- tickera / Restrict – membership, site, content and user access restrictions for WordPress — v=0 <2.1.9 [affected]
- ibenic / Change Prices with Time for WooCommerce — v=0 [affected]
- dots / Flat Rate Shipping Method for WooCommerce — v=0 <4.0.3 [affected]
- frostbourn / Responsive Social Slider Widget — v=0 [affected]
- ahmed17 / Menu Item Scheduler — v=0 [affected]
- avidthemes/ / Blog Sidebar Widget — v=0 [affected]
- dots / Multipurpose Gutenberg Block — v=0 ≤1.7.3 [affected]
- codeies / Full Page Blog Designer — v=0 [affected]
- jcodex / WooCommerce Variation Swatches for Products — v=0 [affected]
- melapress / WP Activity Log — v=0 <4.4.0 [affected]
- patrickgarman / Simple Feature Requests Free – User Feedback Board — v=0 <2.2.4 [affected]
- josevega / Bulk Edit Categories and Tags – Create Thousands Quickly on the Editor — v=0 <1.5.23 [affected]
- saadiqbal / License Manager for WooCommerce — v=0 <2.2.6 [affected]
- skyminds / Sky Login Redirect — v=0 <3.6.0 [affected]
- passionatebrains / GA4WP – Analytics Dashboard for the Website — v=0 <1.3 [affected]
- munirkamal / Divi Collage — v=0 [affected]
- lukeseager / Persistent Login — v=0 <2.0.0 [affected]
- themelocation / Deals of the Day WooCommerce — v=0 [affected]
- pagup / Add Linkedin insight tags for Linkedin ads — v=0 <1.2.4 [affected]
- maurolopes/ / Easy Settings for LearnDash — v=0 [affected]
- mihail-barinov / Share This Image — v=0 <1.67 [affected]
- sjaved / Easy Social Feed – Social Photos Gallery and Post Feed for WordPress — v=0 <6.3.4 [affected]
- jamesparkninja / NEXUS — v=0 [affected]
- deothemes / Meridia — v=0 <2.2.7 [affected]
- tobias_conrad / WebinarIgnition – Live, Automated & Evergreen Webinars for WooCommerce — v=0 <2.8.12 [affected]
- wpmagics / Delete Posts automatically — v=0 <2.1.2 [affected]
- maxsdesign / Brand — v=0 [affected]
- livemesh / WPBakery Page Builder Addons by Livemesh — v=0 <2.9.2 [affected]
- wptb / WP Table Builder – Drag & Drop Table Builder — v=0 <1.3.16 [affected]
- princeahmed / Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player — v=0 <1.0.8 [affected]
- wpt00ls / Divi Content Restrictor — v=0 ≤1.3.0 [affected]
- infornweb / Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid — v=0 <2.0.3 [affected]
- premmerce / Premmerce Variation Swatches for WooCommerce — v=0 <1.2.1 [affected]
- dotrex / PowerFolio – Portfolio & Image Gallery for Elementor — v=0 <2.1.7 [affected]
- sslatlas / SSL Atlas – Free SSL Certificate & HTTPS Redirect for WordPress — v=0 <1.1.1 [affected]
- gallerycreator / Mixed Media Gallery Blocks — v=0 <2.3.6 [affected]
- maltathemes / Easy TikTok Feed – TikTok Video, Feed & Gallery Plugin — v=0 <1.1.1 [affected]
- webmuehle / PopOverXYZ – Show Light Weight Beautiful Tool Tips On Any Text — v=0 [affected]
- pagup / Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO) — v=0 <1.4.5.0 [affected]
- wpcohort/ / Number Chat — v=0 [affected]
- svovaf / Rating-Widget: Star Review System — v=0 <3.1.4 [affected]
- rebelcode / Spotlight Social Feeds – Block, Shortcode, and Widget — v=0 <0.10.2 [affected]
- xyulex / Expire tags — v=0 [affected]
- gowebsmarty / Go Viral – social share, social sharebar, social locker, social chat, open graph, reactions, share & view counters — v=0 <1.8.0 [affected]
- tobias_conrad / WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms — v=0 <1.4.2 [affected]
- tropicalista / Dashy – Google Analytics advanced dashboard — v=0 [affected]
- premmerce / Premmerce User Roles — v=0 <1.0.11 [affected]
- tonyzeoli / Radio Station by netmix® – Manage and play your Show Schedule in WordPress! — v=0 <2.4.0.6 [affected]
- saadiqbal / Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred — v=0 <2.4.3.1 [affected]
- greenjaymedia / SEO Audit – WP Site Auditor — v=0 <1.2.5 [affected]
- hiddenpearls / WordPress Reviews by ReviewPress — v=0 [affected]
- wptravelengine / WP Travel Engine – Tour Booking Plugin – Tour Operator Software — v=0 <5.3.8 [affected]
- takanakui / WP Mobile Menu – The Mobile-Friendly Responsive Menu — v=0 <2.8.2.7 [affected]
- sebet/ / WP Smart Export (Free) — v=0 [affected]
- syntactics / eaSYNC Booking – Hotels, Restaurants & Car Rentals — v=0 <1.1.10 [affected]
- theeventscalendar / WP Conference Schedule — v=0 <1.1.0 [affected]
- mte90 / Strumenti Partita IVA per Woocommerce — v=0 <1.3.23 [affected]
- anfrageformular / Anfrageformular – Multi Step Drag & Drop Formular Builder – Leadgenerierung — v=0 [affected]
- premmerce / Premmerce Brands for WooCommerce — v=0 <1.2.12 [affected]
- ethereumicoio / Ethereum Wallet — v=0 <4.0.9 [affected]
- limbcode / Limb Gallery | Create Beautiful Image & Video Galleries — v=0 <1.5.2 [affected]
- peterschulznl / Code Manager — v=0 <1.0.14 [affected]
- cypressnorth / Payment Gateway for PayFabric — v=0 [affected]
- commercepundit / CP Simple Newsletter — v=0 [affected]
- jwind / LittleBot ACH for Stripe + Plaid — v=0 [affected]
- dotrex / Aquarella Lite — v=0 [affected]
- coderpress / Coinbase Commerce – Crypto Gateway for WooCommerce — v=0 <1.4.1 [affected]
- wpmoose / Villar — v=0 <1.0.8 [affected]
- uriahs-victor / Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce — v=0 <1.4.5 [affected]
- meowcrew / Age Verification Screen for WooCommerce — v=0 <1.0.1 [affected]
- dots / Enhanced Ecommerce Google Analytics for WooCommerce — v=0 <3.6.3 [affected]
- wpjoli / Joli FAQ SEO – WordPress FAQ Plugin — v=0 <1.0.4 [affected]
- dots / Mass Pages/Posts Creator — v=0 <2.1.5 [affected]
- sebet / WP Relevant Ads — v=0 [affected]
- gloriousthemes / GloriousThemes Starter Sites — v=0 [affected]
- oloyede-jamiu / WP Group Promoter — v=0 [affected]
- chetmac / Airpress — v=0 [affected]
- wpt00ls / Schema Plugin For Divi, Gutenberg & Shortcodes — v=0 ≤4.0.1 [affected]
- sindyakinsergei / Giveaways for woocommerce — v=0 [affected]
- hiddenpearls / Custom Login Page Customizer — v=0 <2.1.8 [affected]
- humblethemes / LearnMore — v=0 [affected]
- marcqueralt / DeMomentSomTres Media Tools Auto — v=0 [affected]
- oceanwp / Ocean Extra — v=0 <1.9.4 [affected]
- properfraction / kk Star Ratings – Rate Post & Collect User Feedbacks — v=0 <5.2.9 [affected]
- stevehenty / Drop Shadow Boxes — v=0 <1.7.4 [affected]
- wpt00ls / FAQ Manager For Divi, Gutenberg Block & Shortcode — v=0 <5.4.1 [affected]
- pagup / Ads.txt & App-ads.txt Manager for WordPress — v=0 <1.1.7.0 [affected]
- saadiqbal / Quick Contact Form — v=0 <8.0.2 [affected]
- glowlogix / WP Frontend Profile — v=0 <1.2.5 [affected]
- dgwyer / SVG Flags – Beautiful Scalable Flags For All Countries! — v=0 <0.9.6 [affected]
- ldninjas/ / Drip Feed Content Extended for Learndash — v=0 [affected]
- infornweb / Post List Designer – Category Post, Recent Post, Post List — v=0 <2.1.7 [affected]
- aguilerasoft / Conversion de moneda Woocommerce — v=0 [affected]
- pagup / VidSEO – Video transcript embedding for WordPress & LLM — v=0 <1.2.4 [affected]
- nplugins / Before and After Product Images for WooCommerce — v=0 [affected]
- renaudbod / Woocommerce Customer Reviews with Artificial Intelligence analyzis, with IBM Watson Tone Analyzer — v=0 [affected]
- ivanchernyakov / LawPress – Law Firm Website Management — v=0 [affected]
- dots / Shipping Method Display Style for WooCommerce — v=0 <3.7.5 [affected]
- wproyal / Royal Addons for Elementor – Addons and Templates Kit for Elementor — v=0 <1.3.33 [affected]
- modulemasters / SQL Reporting Services – SSRS Plugin for WordPress — v=0 [affected]
- josevega / Bulk Edit Posts and Products in Spreadsheet — v=0 <2.24.13 [affected]
- lkoudal / Delete Duplicate Posts — v=0 <4.7.5 [affected]
- xjohnyk / WS Bootstrap — v=0 [affected]
- meeplugins / Clean Social Icons — v=0 [affected]
- andyabelow / Media Library File Download — v=0 <1.1 [affected]
- cadudecastroalves / WP Link Bio — v=0 <1.4.5 [affected]
- pagup / Automatic Internal Links for SEO by Pagup — v=0 <1.0.4 [affected]
- cyberhobo / Geo Mashup — v=0 <1.13.6 [affected]
- tobias_conrad / Builder for WooCommerce product reviews shortcodes – ReviewShort — v=0 <1.0.17 [affected]
- anssilaitila / Contact List – Online Staff Directory & Address Book — v=0 <2.9.50 [affected]
- saadiqbal / Post Snippets – Custom WordPress Code Snippets Customizer — v=0 <3.1.7 [affected]
- shawoninfo / SocialMark – Easy Watermark/Logo on Social Media Post Link Share Preview — v=0 <2.0.5 [affected]
- mnelson4 / Print My Blog – Print, PDF, & eBook Converter WordPress Plugin — v=0 <3.11.4 [affected]
- wpdelicious / WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) — v=0 <1.3.5 [affected]
- blackandwhitedigital / TreePress – Easy Family Trees & Ancestor Profiles — v=0 <2.0.21 [affected]
- paulio21 / Postcode Redirect — v=0 ≤4.4.1 [affected]
- nitin247 / Product Author for WooCommerce — v=0 <1.0.3 [affected]
- imtiazrayhan / WP Coupons and Deals – Coupon Plugin For Affiliate Marketers — v=0 <3.1.12 [affected]
- spartac / Feedpress Generator – External RSS Frontend Customizer — v=0 <1.2.0 [affected]
- wpvibes / Form Vibes – Database Manager for Forms — v=0 <1.4.3 [affected]
- majick/ / WP AutoMedic — v=0 [affected]
- dots / Banner Management, Product Slider, Product Carousel for WooCommerce — v=0 <2.2.3 [affected]
- smgteam / Duplicate Variations for Woocommerce — v=0 [affected]
- thinleek / Send Prebuilt Emails — v=0 [affected]
- essekia / Helpie FAQ — Accordion, Docs & Knowledge Base — v=0 <1.7.7 [affected]
- livemesh / Livemesh SiteOrigin Widgets — v=0 <2.8.3 [affected]
- livemesh / Livemesh Addons for Beaver Builder — v=0 <2.8.4 [affected]
- 9brada6 / Tabs with Recommended Posts (Widget) — v=0 [affected]
- closetechnology / Connect WooCommerce Shop to ERP/CRM, Verifactu and EU/VAT Compliance — v=0 <2.1 [affected]
- infosatech / RevivePress – Keep your Old Content Evergreen — v=0 <1.3.1 [affected]
- invisnet / WP fail2ban – Advanced Security — v=0 <4.4.0.2 [affected]
- ultradevs / Ultra Elementor Addons — v=0 [affected]
- wpcohort/ / RecurWP – WordPress Recurly Payment Gateway — v=0 [affected]
- buttonizer / Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder — v=0 <2.6.3 [affected]
- brightvesseldev / Quick Event Manager — v=0 <9.2.17 [affected]
- wpchill / Image Photo Gallery Final Tiles Grid — v=0 <3.5.5 [affected]
- fooplugins / Lightbox & Modal Popup WordPress Plugin – FooBox — v=0 <2.7.17 [affected]
- wpdevpowers / WP Dev Powers – Display Screen Dimensions to Admin Plugin — v=0 [affected]
- johnc1979 / Ultimate Bulk SEO Noindex Nofollow – Speed up Penalty Recovery Ultimate SEO Booster — v=0 [affected]
- peterschulznl / WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards — v=0 <5.1.4 [affected]
- kaira / StoreCustomizer – A plugin to Customize all WooCommerce Pages — v=0 <2.3.8 [affected]
- mhmrajib / TopNewsWp – Display Tikcer News, RSS Feed Widget and Many More — v=0 <2.0 [affected]
- danieliser / User Menus – Nav Menu Visibility — v=0 <1.2.9 [affected]
- webheadllc / Contact Form 7 Multi-Step Forms — v=0 <4.1.91 [affected]
- 5starplugins / Easy Age Verify — v=0 <1.6.1 [affected]
- brandonfire / Blocked in China | Check if your site is available in the Chinese mainland — v=0 <1.0.3 [affected]
- josevega / Disable Payment Methods based on cart conditions for WooCommerce — v=0 <1.13.1.1 [affected]
- ejslondon/ / Awesome SSL — v=0 [affected]
- iksstudio / Iks Menu – WordPress Category Accordion Menu & FAQs — v=0 <1.9.2 [affected]
- prelc / Purus — v=0 [affected]
- janwyl / Hooked Editable Content — v=0 [affected]
- mdedev / Run Contests, Raffles, and Giveaways with ContestsWP — v=0 <1.9.0 [affected]
- themeythemes / Post Carousel Divi — v=0 <1.1.2 [affected]
- anasbinmukim / MailChimp Manager — v=0 [affected]
- premmerce / Premmerce Permalink Manager for WooCommerce — v=0 <2.3.5 [affected]
- ivacy / Secure IP Logins — v=0 [affected]
- kylegilman / Videopack — v=0 <4.7.4 [affected]
- premmerce / Premmerce WooCommerce Customers Manager — v=0 <1.1.13 [affected]
- wpvibes / Dynific Addons for Elementor (formerly AnyWhere Elementor) — v=0 <1.2.5 [affected]
- badhonrocks / Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme — v=0 <3.5.0 [affected]
- elbisnero / Events Calendar Registration — v=0 [affected]
- saadiqbal / Rocket Maintenance Mode & Coming Soon Page — v=0 <4.3 [affected]
- h3technologies / WordPress WooCommerce Sync for Google Sheet — v=0 [affected]
- pootlepress/ / Easy Smooth Scroll Links – Smooth Scrolling Anchor — v=0 <2.23.1 [affected]
- sj_o / Page Builder Gutenberg Blocks – Kioken Blocks — v=0 [affected]
- matstars / Cryptocurrency Portfolio Tracker — v=0 [affected]
- sebet / Go Fetch Jobs (for WP Job Manager) — v=0 ≤1.7.3.2 [affected]
- sangaran / Quick Affiliate Store — v=0 [affected]
- wpt00ls / WP Tools Divi Blog Carousel — v=0 <1.3.0 [affected]
- koen12344 / Post to Google My Business (Google Business Profile) — v=0 <3.0.10 [affected]
- nicheaddons / NicheBase — v=0 <1.2.2 [affected]
- webmuehle / WPVisitorInfo – Show Visitor Information & Conditional Data Based On That Information — v=0 [affected]
- premmerce / Premmerce — v=0 <1.3.16 [affected]
- woopops / CartPops – High Converting Add To Cart Popup For WooCommerce — v=0 <1.4.17 [affected]
- scrollsequence / Scrollsequence – Cinematic Scroll Image Animation Plugin — v=0 <1.2.4 [affected]
- kaira / Elation — v=0 [affected]
- thecodechime / Cuisine Palace — v=0 [affected]
- dots / Product Attachment for WooCommerce — v=0 <2.1.3 [affected]
- masterblocks / Master Blocks – Gutenberg Site Builder — v=0 [affected]
- moomooagency / Product Options and Price Calculation Formulas for WooCommerce – Uni CPO — v=0 <4.9.14 [affected]
- kitthemes / WordPress Coupon Plugin for Bloggers and Marketers – WP Offers — v=0 <1.1.4 [affected]
- tripetto / WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto — v=0 <5.3.1 [affected]
- mumarym1985 / Widgets on Pages and Posts — v=0 [affected]
- wordplus / Better Messages – WCFM Integration — v=0 [affected]
- wpgeniuz / SheetPress – Manage WordPress Meta data with Google Sheets — v=0 [affected]
- olezhyk5 / Advanced Custom Fields options import/export — v=0 [affected]
- fullworks / Quick Paypal Payments — v=0 <5.7.22 [affected]
- chillichalli / Tarot Card Oracle — v=0 <1.0.6 [affected]
- cloudsponge / Better Sharing — v=0 ≤1.7.1 [affected]
- intoxstudio / Restrict User Access – Ultimate Membership & Content Protection — v=0 <2.2.2 [affected]
- wupo / WUPO Group Attributes for WooCommerce — v=0 ≤2.0.0 [affected]
- shelob9 / Nugget by Ingot: Easy, automated and native A/B testing for everyone — v=0 [affected]
- fsruslan / FeedbackScout: The easiest way to collect, prioritise, manage and track customer feedback. — v=0 [affected]
- deothemes / Arendelle — v=0 <1.1.3 [affected]
- boltonstudios / Easy Zillow Reviews — v=0 <1.4.1 [affected]
- janthielemann / Battle Suit for Divi — v=0 [affected]
- jkohlbach / Store Toolkit – WooCommerce Extensions, Quick Enhancements & Handy Tools — v=0 <2.3.4 [affected]
- weconnectcode / WCC SEO Keyword Research — v=0 [affected]
- zeetheme / Elements for LifterLMS — v=0 [affected]
- commercepundit / Custom Registration and Custom Login Forms with New Recaptcha — v=0 [affected]
- saadiqbal / B2B Request a Quote — v=0 <1.4.9 [affected]
- mohammedrezq / Wadi Survey — v=0 [affected]
- atakanoz / Performance Kit — v=0 [affected]
- dovyp / Page Builder for Gutenberg – StarterBlocks — v=0 [affected]
- gkher/ / Impexium Single Sign On — v=0 [affected]
- xplodedthemes / XT Quick View for WooCommerce — v=0 <1.9.6 [affected]
- josevega / Live Drag and Drop Builder for Contact Form 7 — v=0 <1.2.4 [affected]
- nicheaddons / Primary Addon for Elementor — v=0 <1.5.2 [affected]
- jaydeep-nimavat / JDs Portfolio — v=0 [affected]
- mbrown24 / TwentyFourth WP Scraper — v=0 [affected]
- creativethemeshq / Blocksy Companion — v=0 <1.8.20 [affected]
- kartikparmar/ / WordPress Google Translate — v=0 <1.2 [affected]
- darell / Hasium — v=0 <1.6.5 [affected]
- marviorocha / Station Pro – Advanced Audio Streaming & Player for WordPress — v=0 [affected]
- stellarwp / Event Tickets and Registration — v=0 <5.3.0.1 [affected]
- kaggdesign / Gateway for PayLate on WooCommerce — v=0 ≤1.4 [affected]
- pagup / Auto SEO META keywords (META tags keywords) optimization + WooCommerce — v=0 <1.0.4 [affected]
- co2ok / ClimateClick: Climate Action for all — v=0 ≤1.0.9.21 [affected]
- premmerce / Premmerce SEO for WooCommerce — v=0 <2.1.5 [affected]
- saadiqbal / Wholesale for WooCommerce — v=0 <1.6.1 [affected]
- ldninjas/ / Frontend group restriction for LearnDash — v=0 [affected]
- jetixwp / Really Simple Featured Video – Featured Video Support for Posts, Pages & WooCommerce Products — v=0 ≤0.5.1 [affected]
- fullworks / Display Eventbrite Events — v=0 <4.4.8 [affected]
- xplodedthemes / XT Floating Cart for WooCommerce — v=0 <2.6.3 [affected]
- wplegalpages / Cookie Banner for GDPR / CCPA – WPLP Cookie Consent — v=0 <2.1.1 [affected]
- milmor / WP SPID Italia — v=0 <2.3.5 [affected]
- bycrik / Tiered Pricing Table for WooCommerce — v=0 <2.6.1 [affected]
- codexonics / Prime Mover – Migrate WordPress Website & Backups — v=0 <1.5.0 [affected]
- vernal / Replyable – Subscribe to Comments and Reply by Email — v=0 <2.2.9 [affected]
- webmuehle / Court Reservation – Manage Your Court Bookings Online — v=0 <1.7.0 [affected]
- jurski / VO Store Locator – WP Store Locator Plugin — v=0 [affected]
- fullworks / Get Directions Map — v=0 <2.15.8 [affected]
- premmerce / Premmerce Redirect Manager — v=0 <1.0.7 [affected]
- snazzythemes / SnazzyAdmin WP Admin Theme — v=0 [affected]
- deothemes / Amela — v=0 <1.0.5 [affected]
- javmah / Woocommerce Customers Order History — v=0 <5.2.1 [affected]
- lynn999 / EthPress – Web3 Login — v=0 <1.5.1 [affected]
- dangub86 / Ant Admin Notices for Team — v=0 [affected]
- josevega / Bulk Edit Coupons for WooCommerce – WP Sheet Editor — v=0 <1.3.28 [affected]
- mattpramschufer / Pay For Post with WooCommerce — v=0 <3.0.9 [affected]
- alex-ye / bbResolutions — v=0 [affected]
- passionatebrains / AWCA – The Great Analytics Insights for Your eStore — v=0 <3.0.1 [affected]
- cliffpaulick / TK SmugMug Slideshow Shortcode — v=0 [affected]
- wpchill / Lightbox – EverlightBox Gallery — v=0 <1.1.18 [affected]
- cebbi / Unakit — v=0 <1.2.4.2 [affected]
- mojofywp / WP Affiliate Disclosure — v=0 <1.2.3 [affected]
- interfacelab / Media Cloud for Bunny CDN, Amazon S3, Cloudflare R2, Google Cloud Storage, DigitalOcean and more — v=0 <4.3.1 [affected]
- rafacarvalhido / RaCar Clear Cart for WooCommerce — v=0 <1.2.3 [affected]
- litonice13 / WP Disable Sitemap — v=0 <1.0.4 [affected]
- davidanderson / Internal Link Juicer: SEO Auto Linker for WordPress — v=0 <1.3.0 [affected]
- munirkamal / Block Slider – Responsive Image Slider, Video Slider & Post Slider — v=0 <2.0.0 [affected]
- milukove / Pinblocks — Gutenberg blocks with Pinterest widgets — v=0 [affected]
- ronena100 / Contact Widgets For Elementor all the contact links you need in one place — v=0 [affected]
- tickera / Tickera – Sell Tickets & Manage Events — v=0 <3.4.9.2 [affected]
- bplugins / StreamCast – Live Radio Streaming Player — v=0 <2.1.4 [affected]
- johnc1979 / Sticky add to cart for Woo — v=0 [affected]
- blockypage / BlockyPage – Gutenberg Based Page Builder — v=0 [affected]
- maciejbak85 / Pro Broken Links Maintainer — v=0 [affected]
- sorsawo / WP School Calendar — v=0 <3.6 [affected]
- listplus / ListPlus – Unlimited Listing Directory — v=0 [affected]
- walkerwp / Walker Core — v=0 <1.1.8 [affected]
- patrickposner / Agy – Age verification for WooCommerce — v=0 <4.3.1 [affected]
- ggedde / Modern Designs for Gravity Forms — v=0 [affected]
- rankbear / RankBear — v=0 [affected]
- staxwp / STAX Header Builder — v=0 <1.3.6 [affected]
- fastaf/ / Fast Checkout for WooCommerce — v=0 <1.1.17 [affected]
- boriscolombier/ / WooCommerce PayPlug — v=0 [affected]
- alphabposervice / Easy Code Snippets — v=0 <1.0.1 [affected]
- w3scloud / W3SCloud Contact Form 7 to Zoho CRM — v=0 <2.1.0 [affected]
- elementinvader / Widget Detector for Elementor — v=0 <1.2.0 [affected]
- pagup / Add Tiktok Pixel for Tiktok ads (+Woocommerce) — v=0 <1.2.2 [affected]
- gowebsmarty / WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan — v=0 <5.7.10 [affected]
- wordplus / Better Messages – Integration for WC Vendors Marketplace — v=0 <1.0.7 [affected]
- alleythemes / Alley Business Toolkit — v=0 <1.1.8 [affected]
- premmerce / Premmerce Product Filter for WooCommerce — v=0 <3.6.2 [affected]
- pippozanardo / WP Search Filter — v=0 [affected]
- alphabposervice / Easy Post Views Count — v=0 <1.0.5 [affected]
- dotrex / Power Ups for Elementor — v=0 <1.2.2 [affected]
- dvizhenia / Social Kit — v=0 [affected]
- pluginandplay / Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider — v=0 <2.1.2 [affected]
- mhmrajib / HM Multiple Roles — v=0 <1.6 [affected]
- multicollab / Team Collaboration & Content Workflow Plugin for WordPress Editorial Teams – Multicollab — v=0 <2.0.4 [affected]
- wpsaad / Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI — v=0 <1.5.0 [affected]
- premmerce / Premmerce Product Search for WooCommerce — v=0 <2.2.3 [affected]
- sovstack / Security Safe — v=0 <2.4.4 [affected]
- josevega / Bulk Edit Products for WooCommerce – WP Sheet Editor — v=0 <1.7.13 [affected]
- danielealessandra / Da Reactions — v=0 <3.20.2 [affected]
- wpscripts / Food Store – Online Food Delivery & Pickup — v=0 <1.4 [affected]
- thijzie / Abeta Link PunchOut — v=0 ≤0.4 [affected]
- javmah / jav's – WooCommerce and Trello integration WooTrello — v=0 <2.3.1 [affected]
- pagebuildersandwich / Page Builder Sandwich – Front End WordPress Page Builder Plugin — v=0 <4.5.5 [affected]
- switcorp / WP Sessions Time Monitoring Full Automatic — v=0 <1.0.6 [affected]
- pasyuk / WoowGallery — v=0 <1.1.9 [affected]
- upfiv / WordPress Auto SEO Plugin – Upfiv SEO Wizard — v=0 [affected]
- wpsoul / Greenshift – animation and page builder blocks — v=0 <1.1.6 [affected]
- nicheaddons / Restaurant & Cafe Addon for Elementor — v=0 <1.4.6 [affected]
CVSS
- 3.1 score=6.3 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=cve
- https://wpscan.com/vulnerability/6dae6dca-7474-4008-9fe5-4c62b9f12d0a
- https://freemius.com/blog/managing-security-issues-open-source-freemius-sdk-security-disclosure/
- https://wpdirectory.net/search/01FWPVWA7BC5DYGZHNSZQ9QMN5
- https://wpdirectory.net/search/01G02RSGMFS1TPT63FS16RWEYR
- https://web.archive.org/web/20220225174410/https%3A//www.pluginvulnerabilities.com/2022/02/25/our-security-review-of-wordpress-plugin-found-freemius-library-still-contained-vulnerabilities-3-years-after-major-security-incident/
Source
cvelistV5-main/cves/2022/4xxx/CVE-2022-4974.json