Access violation vulnerability in Freemius SDK (620 components affected)

Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could have allowed malicious actors to access confidential information or perform Cross-Site Request Forgery (CSRF). To prevent this, WordPress plugin and theme developers should upgrade to a version of Freemius greater than 2.4.2.

Detected in:

3D Viewer – 3D Model Viewer Plugin fixed vulnerable versions:
3D viewer – Embed 3D Models on WordPress fixed vulnerable versions: >= * < 1.2.7
Abeta Link PunchOut fixed vulnerable versions:
Abeta OCI PunchOut fixed vulnerable versions: >= * <= *
Accept Stripe Donation – AidWP fixed vulnerable versions: >= * < 2.9
Add Expires Headers & Optimized Minify fixed vulnerable versions: >= * < 2.6
Add Linkedin insight tags for Linkedin ads fixed vulnerable versions: >= * < 1.2.4
Add Tiktok Pixel for Tiktok ads (+Woocommerce) fixed vulnerable versions: >= * < 1.2.2
Add Twitter Pixel for Twitter ads fixed vulnerable versions: >= * < 1.0.4
Ads.txt & App-ads.txt Manager for WordPress fixed vulnerable versions: >= * < 1.1.7.0
Advanced Classifieds & Directory Pro fixed vulnerable versions: >= * < 1.8.8
Advanced Custom Fields options import/export fixed vulnerable versions: >= * <= *
AFI – The Easiest Integration Plugin fixed vulnerable versions:
Age Verification Screen for WooCommerce fixed vulnerable versions: >= * < 1.0.1
All in One Invite Codes fixed vulnerable versions: >= * < 1.0.13
All-in-One Video Gallery fixed vulnerable versions: >= * < 2.5.4
Alley Business Toolkit fixed vulnerable versions: >= * < 1.1.8
Amela fixed vulnerable versions: >= * < 1.0.5
annasta Woocommerce Product Filters fixed vulnerable versions: >= * < 1.5.0
Anti Spam by Fullworks fixed vulnerable versions: >= * < 1.3.2
Anti Spam by Fullworks : Spam Protection fixed vulnerable versions:
AnyWhere Elementor fixed vulnerable versions: >= * < 1.2.5
Aquarella Lite fixed vulnerable versions: >= * <= *
Arendelle fixed vulnerable versions: >= * < 1.1.3
Authorize.Net Payment Gateway For WooCommerce fixed vulnerable versions: >= * < 5.1.27
Automatic YouTube Gallery fixed vulnerable versions: >= * < 1.6.5
Awesome SSL fixed vulnerable versions: >= * <= *
Banner Management For WooCommerce fixed vulnerable versions: >= * < 2.2.3
Battle Suit for Divi fixed vulnerable versions: >= * <= *
bbResolutions fixed vulnerable versions: >= * <= *
Best WordPress Gallery Plugin – FooGallery fixed vulnerable versions: >= * < 2.1.34
Better Messages – Integration for WC Vendors Marketplace fixed vulnerable versions: >= * < 1.0.7
Better Messages – WCFM Integration fixed vulnerable versions: >= * <= *
Better Sharing fixed vulnerable versions: >= * <= 1.7.1
Block Styler For Gravity Forms fixed vulnerable versions: >= * <= 6.1.0
Block, Suspend, Report for BuddyPress fixed vulnerable versions: >= * < 3.3.3
BlockMeister – Block Pattern Builder fixed vulnerable versions: >= * < 3.0.5
Blocksy Companion fixed vulnerable versions: >= * < 1.8.20
BlockyPage – Gutenberg Based Page Builder fixed vulnerable versions: >= * <= *
Blog Sidebar Widget fixed vulnerable versions: >= * <= *
Booking Calendar | Appointment Booking | BookIt fixed vulnerable versions: >= * < 2.2.9
BookPress – For Book Authors fixed vulnerable versions: >= * < 1.2.3
Broadcast Lite fixed vulnerable versions: >= * < 2.0.3
Bulk Edit and Create User Profiles – WP Sheet Editor fixed vulnerable versions: >= * < 1.5.13
Bulk Edit Posts and Products in Spreadsheet fixed vulnerable versions: >= * < 2.24.13
CAPTCHA 4WP fixed vulnerable versions: >= * < 7.0.5
Cartoon Url fixed vulnerable versions: >= * <= *
Change Price Title for WooCommerce fixed vulnerable versions: >= * <= 2.5
Change Prices with Time for WooCommerce fixed vulnerable versions: >= * <= *
Checkout with Zelle on Woocommerce fixed vulnerable versions: >= * < 2.0
ClimateClick: Climate Action for all fixed vulnerable versions:
Code Manager fixed vulnerable versions: >= * < 1.0.14
CodeKit – Custom Codes Editor fixed vulnerable versions: >= * < 2.3
Coinbase Commerce – Crypto Gateway for WooCommerce fixed vulnerable versions: >= * < 1.4.1
Comments Not Replied To fixed vulnerable versions: >= * < 1.5.3
ConeBlog – Elementor Blog Widgets fixed vulnerable versions:
Contact Form 7 Module For Divi Builder fixed vulnerable versions: >= * < 1.3.0
Contact Form 7 Multi-Step Forms fixed vulnerable versions: >= * < 4.1.91
Contact List — Directory Plugin fixed vulnerable versions:
Conversion de moneda Woocommerce fixed vulnerable versions: >= * <= *
Country Based Payments for WooCommerce fixed vulnerable versions: >= * < 1.4.1
Court Reservation – Manage Your Court Bookings Online fixed vulnerable versions: >= * < 1.7.0
Cryptocurrency Product for WooCommerce fixed vulnerable versions: >= * < 3.14.6
Cuisine Palace fixed vulnerable versions: >= * <= *
Custom Login Page Customizer fixed vulnerable versions: >= * < 2.1.8
Da Reactions fixed vulnerable versions: >= * < 3.20.2
DancePress (TRWA) fixed vulnerable versions: >= * <= 3.1.2
Delete All Comments of wordpress fixed vulnerable versions: >= * < 4.3
Delete Duplicate Posts fixed vulnerable versions: >= * < 4.7.5
Delete old Posts automatically fixed vulnerable versions: >= * < 2.1.2
Delete Posts automatically fixed vulnerable versions:
Delicious Recipes – Best WordPress Recipe Plugin fixed vulnerable versions: >= * < 1.3.5
Digital Goods for WooCommerce Checkout fixed vulnerable versions: >= * < 3.6.4
Display Eventbrite Events fixed vulnerable versions: >= * < 4.4.8
Divi Content Restrictor fixed vulnerable versions: >= * <= 1.3.0
Divi Torque Lite fixed vulnerable versions:
Document Viewer for Office fixed vulnerable versions: >= * < 2.2.5
Dreamfox Media Shipping gateway per Product for Woocommerce fixed vulnerable versions: >= * < 2.0.4
Drip Feed Content Extended for Learndash fixed vulnerable versions: >= * <= *
Duplicate Variations for Woocommerce fixed vulnerable versions: >= * <= *
Dynamic Pricing and Discount Rules for WooCommerce fixed vulnerable versions: >= * < 2.2.3
Easy Age Verify fixed vulnerable versions: >= * < 1.6.1
Easy Math Captcha for CF7 fixed vulnerable versions: >= * <= *
Easy Post Views Count fixed vulnerable versions: >= * < 1.0.5
Easy Tiktok Feed fixed vulnerable versions: >= * < 1.1.1
Easy Zillow Reviews fixed vulnerable versions: >= * < 1.4.1
Elasta fixed vulnerable versions: >= * < 1.0.8
Elation fixed vulnerable versions: >= * <= *
Elementor Addon Elements fixed vulnerable versions: >= * < 1.11.14
Elementor Addons by Livemesh fixed vulnerable versions:
Elements for LifterLMS fixed vulnerable versions: >= * <= *
Emails Blacklist for Everest Forms fixed vulnerable versions: >= * < 1.0.4
Enhanced Ecommerce Google Analytics for WooCommerce fixed vulnerable versions: >= * < 3.6.3
Error Log Monitor fixed vulnerable versions: >= * < 1.7.1
Ether and ERC20 tokens WooCommerce Payment Gateway fixed vulnerable versions: >= * < 4.12.9
Ethereum Wallet fixed vulnerable versions: >= * < 4.0.9
EthereumICO fixed vulnerable versions: >= * < 2.3.11
EthPress – Web3 Login fixed vulnerable versions: >= * < 1.5.1
Event Tickets and Registration fixed vulnerable versions: >= * < 5.3.0.1
Events Calendar Registration fixed vulnerable versions: >= * <= *
Everse fixed vulnerable versions: >= * < 1.8.6
Extend Filter Products By Price Widget fixed vulnerable versions: >= * <= *
Extra Fees Plugin for WooCommerce fixed vulnerable versions: >= * < 3.8.2
FAQ Manager For Divi, Gutenberg Block & Shortcode fixed vulnerable versions: >= * < 5.4.1
Featured Images in RSS for Mailchimp & More fixed vulnerable versions: >= * < 1.5.9
FiboSearch – Ajax Search for WooCommerce fixed vulnerable versions: >= * < 1.17.0
Filr – Secure document library fixed vulnerable versions: >= * < 1.2.1
Five-Star Ratings Shortcode fixed vulnerable versions: >= * < 1.2.39
Flat Rate Shipping Plugin For WooCommerce fixed vulnerable versions: >= * < 4.0.3
Focus on Reviews for WooCommerce fixed vulnerable versions: >= * <= *
Food Store – Online Food Delivery & Pickup fixed vulnerable versions: >= * < 1.4
Form Vibes – Database Manager for Forms fixed vulnerable versions: >= * < 1.4.3
Fraud Prevention For Woocommerce fixed vulnerable versions: >= * < 2.1.0
Fraud Prevention For WooCommerce and EDD fixed vulnerable versions:
Front End PM fixed vulnerable versions: >= * < 11.3.4
Full Page Blog Designer fixed vulnerable versions: >= * <= *
Fullscreen Menu fixed vulnerable versions:
FullScreen Menu – Mobile Friendly and Responsive fixed vulnerable versions: >= * <= 2.2.7
Fuse Social Floating Sidebar fixed vulnerable versions: >= * < 5.4.3
Gallery PhotoBlocks fixed vulnerable versions: >= * < 1.2.6
Gateway for PayLate on WooCommerce fixed vulnerable versions: >= * <= 1.4
Genealogical Tree – WordPress Family Tree fixed vulnerable versions: >= * <= 2.1.5
Geo Mashup fixed vulnerable versions: >= * < 1.13.6
Get Directions Map fixed vulnerable versions: >= * < 2.15.8
Gift Message for WooCommerce fixed vulnerable versions: >= * < 1.6.0
Glossary fixed vulnerable versions: >= * < 2.1.8
Go Fetch Jobs (for WP Job Manager) fixed vulnerable versions: >= * <= 1.7.3.2
Google Analytics WordPress Plugin by GA4WP fixed vulnerable versions: >= * < 1.3
Greenshift – animation and page builder blocks fixed vulnerable versions: >= * < 1.1.6
Grid & Styler For Contact Form 7 And Divi fixed vulnerable versions: >= * < 1.4.1
Gutenberg Blocks – ACF Blocks Suite fixed vulnerable versions: >= * < 2.6.8
Hasium fixed vulnerable versions: >= * < 1.6.5
Hide Shipping Method For WooCommerce fixed vulnerable versions: >= * < 1.3.1
HM Multiple Roles fixed vulnerable versions: >= * < 1.6
HuCommerce | Magyar WooCommerce kiegészítések fixed vulnerable versions: >= * < 30.3.0
Iks Menu – WordPress Category Accordion Menu & FAQs fixed vulnerable versions: >= * < 1.9.2
Image Carousel For Divi fixed vulnerable versions: >= * < 1.5.0
Image Photo Gallery Final Tiles Grid fixed vulnerable versions: >= * < 3.5.5
Impexium Single Sign On fixed vulnerable versions: >= * <= *
Insert or Embed Articulate Content into WordPress fixed vulnerable versions: >= * < 4.3000000016
Interactive Geo Maps fixed vulnerable versions: >= * < 1.5.4
Internal Link Juicer: SEO Auto Linker for WordPress fixed vulnerable versions: >= * < 1.3.0
Ivory Search – WordPress Search Plugin fixed vulnerable versions: >= * < 5.4.4
jav's – WooCommerce and Trello integration WooTrello fixed vulnerable versions: >= * < 2.3.1
JDs Portfolio fixed vulnerable versions: >= * <= *
Joli FAQ SEO – WordPress FAQ Plugin fixed vulnerable versions: >= * < 1.0.4
Joli Table Of Contents fixed vulnerable versions: >= * < 1.3.9
Justified Gallery fixed vulnerable versions: >= * < 1.5.1
kk Star Ratings fixed vulnerable versions: >= * < 5.2.9
Lightbox & Modal Popup WordPress Plugin – FooBox fixed vulnerable versions: >= * < 2.7.17
Lightweight Widget Area Plugin – Content Aware Sidebars fixed vulnerable versions: >= * < 3.17.2
ListPlus – Unlimited Listing Directory fixed vulnerable versions: >= * <= *
LittleBot ACH for Stripe + Plaid fixed vulnerable versions: >= * <= *
Live Drag and Drop Builder for Contact Form 7 fixed vulnerable versions: >= * < 1.2.4
Livemesh Addons for Beaver Builder fixed vulnerable versions: >= * < 2.8.4
Livemesh Addons for WPBakery Page Builder fixed vulnerable versions: >= * < 2.9.2
Livemesh SiteOrigin Widgets fixed vulnerable versions: >= * < 2.8.3
Local Delivery Drivers for WooCommerce fixed vulnerable versions: >= * < 1.8.5
LocalSEOMap fixed vulnerable versions: >= * <= *
Magic Post Thumbnail fixed vulnerable versions: >= * < 3.3.11
MapGeo – Interactive Geo Maps fixed vulnerable versions:
Marijuana Age Verify fixed vulnerable versions: >= * < 1.3.1
Market Exporter fixed vulnerable versions: >= * <= 2.0.13
Mass Pages/Posts Creator fixed vulnerable versions: >= * < 2.1.5
Master Accordion ( Former WP Awesome FAQ Plugin ) fixed vulnerable versions: >= * < 4.1.8
Master Addons for Elementor fixed vulnerable versions: >= * < 1.8.5
Menu Image, Icons made easy fixed vulnerable versions: >= * < 3.0.6
Menu Item Scheduler fixed vulnerable versions: >= * <= *
Meridia fixed vulnerable versions: >= * < 2.2.7
Migrate WordPress Website & Backups – Prime Mover fixed vulnerable versions: >= * < 1.5.0
Modern Designs for Gravity Forms fixed vulnerable versions: >= * <= *
Multi Page Auto Advance for Gravity Forms fixed vulnerable versions: >= * < 4.3
New User Approve fixed vulnerable versions: >= * < 2.1
NicheBase fixed vulnerable versions: >= * < 1.2.2
Ninja Libs Amazon SES fixed vulnerable versions: >= * <= *
Nokke fixed vulnerable versions: >= * < 1.0.11
Ocean Extra fixed vulnerable versions: >= * < 1.9.4
One Click Login fixed vulnerable versions: >= * <= *
Out of stock display for woocommerce fixed vulnerable versions: >= * <= *
Overlay Image Divi Module fixed vulnerable versions: >= * < 1.3.2
Page Builder for Gutenberg – StarterBlocks fixed vulnerable versions: >= * <= *
Panorama Viewer – 360 Degree Image + Video Viewer fixed vulnerable versions: >= * < 1.0.8
Pay For Post with WooCommerce fixed vulnerable versions: >= * < 3.0.9
Payment Gateway for PayFabric fixed vulnerable versions: >= * <= *
Payment gateway per Product for WooCommerce fixed vulnerable versions:
Performance Kit fixed vulnerable versions: >= * <= *
Pinblocks — Gutenberg blocks with Pinterest widgets fixed vulnerable versions: >= * <= *
Place Order Without Payment for WooCommerce fixed vulnerable versions: >= * < 2.2
Post Carousel Divi fixed vulnerable versions: >= * < 1.1.2
Post to Google My Business (Google Business Profile) fixed vulnerable versions: >= * < 3.0.10
Postcode Redirect fixed vulnerable versions: >= * <= 4.4.1
Power Ups for Elementor fixed vulnerable versions: >= * < 1.2.2
Premmerce Brands for WooCommerce fixed vulnerable versions: >= * < 1.2.12
Premmerce Multi-currency for Woocommerce fixed vulnerable versions: >= * < 2.3.2
Premmerce Permalink Manager for WooCommerce fixed vulnerable versions: >= * < 2.3.5
Premmerce Product Filter for WooCommerce fixed vulnerable versions: >= * < 3.6.2
Premmerce Product Search for WooCommerce fixed vulnerable versions: >= * < 2.2.3
Premmerce SEO for WooCommerce fixed vulnerable versions: >= * < 2.1.5
Premmerce User Roles fixed vulnerable versions: >= * < 1.0.11
Premmerce Variation Swatches for WooCommerce fixed vulnerable versions: >= * < 1.2.1
Premmerce Wholesale Pricing for WooCommerce fixed vulnerable versions: >= * < 1.1.8
Premmerce Wishlist for WooCommerce fixed vulnerable versions: >= * < 1.1.8
Premmerce WooCommerce Customers Manager fixed vulnerable versions: >= * < 1.1.13
Primary Addon for Elementor fixed vulnerable versions: >= * < 1.5.2
Pro Broken Links Maintainer fixed vulnerable versions: >= * <= *
Product Attachment for WooCommerce fixed vulnerable versions: >= * < 2.1.3
Product Author for WooCommerce fixed vulnerable versions: >= * < 1.0.3
Product Carousel For WooCommerce – WoorouSell fixed vulnerable versions: >= * < 1.0.9
Product Customer List for WooCommerce fixed vulnerable versions: >= * < 3.0.0
Product Image Watermark for Woo fixed vulnerable versions: >= * < 1.0.4
Product Size Charts Plugin for WooCommerce fixed vulnerable versions: >= * < 2.2.3
Purosa fixed vulnerable versions: >= * < 1.1.0
Quick Affiliate Store fixed vulnerable versions: >= * <= *
Quick Contact Form fixed vulnerable versions: >= * < 8.0.2
Quick Event Manager fixed vulnerable versions: >= * < 9.2.17
Quick Paypal Payments fixed vulnerable versions: >= * < 5.7.22
Quote for WooCommerce Lite fixed vulnerable versions: >= * < 1.4.9
Qyrr – simply and modern QR-Code creation fixed vulnerable versions: >= * < 0.8
RaCar Clear Cart for WooCommerce fixed vulnerable versions: >= * < 1.2.3
RankBear fixed vulnerable versions: >= * <= *
RecurWP – WordPress Recurly Payment Gateway fixed vulnerable versions: >= * <= *
Redirection for Contact Form 7 fixed vulnerable versions: >= * < 2.5.0
Responsive Social Slider Widget fixed vulnerable versions: >= * <= *
Restrict User Access – Membership & Content Protection fixed vulnerable versions: >= * < 2.2.2
Revolution for Elementor fixed vulnerable versions: >= * <= *
Royal Elementor Addons and Templates fixed vulnerable versions: >= * < 1.3.33
Run Contests, Raffles, and Giveaways with ContestsWP fixed vulnerable versions: >= * < 1.9.0
RW Divi Unite Gallery fixed vulnerable versions: >= * <= 1.0
Scheduled Notification Bar fixed vulnerable versions: >= * <= *
Schema Plugin For Divi, Gutenberg & Shortcodes fixed vulnerable versions: >= * <= 4.0.1
Secure IP Logins fixed vulnerable versions: >= * <= *
Send Prebuilt Emails fixed vulnerable versions: >= * <= *
SEO Booster fixed vulnerable versions: >= * < 3.8.5
Shipping Method Display Style for WooCommerce fixed vulnerable versions: >= * < 3.7.5
Simple Feature Requests Free – User Feedback Board fixed vulnerable versions: >= * < 2.2.4
Simple Sitemap – Create a Responsive HTML Sitemap fixed vulnerable versions: >= * < 3.5.5
SKT Templates – Elementor & Gutenberg templates fixed vulnerable versions: >= * < 4.3
Sky Login Redirect fixed vulnerable versions: >= * < 3.6.0
SlideDeck: Responsive WordPress Slider Plugin fixed vulnerable versions: >= * <= *
Smart Variations Images & Swatches for WooCommerce fixed vulnerable versions: >= * < 5.1.10
Social Kit fixed vulnerable versions: >= * <= *
Spanish Market Enhancements for WooCommerce fixed vulnerable versions: >= * < 2.1
Spotlight Social Feeds [Block, Shortcode, and Widget] fixed vulnerable versions: >= * < 0.10.2
Stackable – Page Builder Gutenberg Blocks fixed vulnerable versions: >= * < 3.1.5
Starfish Review Generation & Marketing for WordPress fixed vulnerable versions: >= * < 3.0.26
Station Pro Plugin fixed vulnerable versions: >= * <= *
STAX Header Builder fixed vulnerable versions: >= * < 1.3.6
Sticky add to cart for Woo fixed vulnerable versions: >= * <= *
Store Toolkit for WooCommerce fixed vulnerable versions: >= * < 2.3.4
Super Video Player fixed vulnerable versions: >= * < 1.6.11
Surbma | GDPR Proof Cookie Consent & Notice Bar fixed vulnerable versions: >= * < 17.5.3
SurveyFunnel – Survey Plugin for WordPress fixed vulnerable versions: >= * < 1.1.3
SV Proven Expert fixed vulnerable versions: >= * < 1.8.01
SV Tracking Manager fixed vulnerable versions: >= * < 1.8.02
Tabs with Recommended Posts (Widget) fixed vulnerable versions: >= * <= *
Tag Groups is the Advanced Way to Display Your Taxonomy Terms fixed vulnerable versions: >= * < 1.43.10.1
Tarot Card Oracle fixed vulnerable versions: >= * < 1.0.6
Thank You Page for WooCommerce fixed vulnerable versions:
The Events Calendar fixed vulnerable versions: >= * < 5.14.0.4
Tiered Pricing Table for WooCommerce fixed vulnerable versions: >= * < 2.6.1
TK Google Fonts GDPR Compliant fixed vulnerable versions: >= * < 2.2.1
TK SmugMug Slideshow Shortcode fixed vulnerable versions: >= * <= *
Top Bar – PopUps – by WPOptin fixed vulnerable versions: >= * <= 1.2.3
Torque Forms Styler For Divi fixed vulnerable versions:
Torque Modules for Divi and Extra Theme fixed vulnerable versions:
TreePress – Easy Family Trees & Ancestor Profiles fixed vulnerable versions: >= * < 2.0.21
TwentyFourth WP Scraper fixed vulnerable versions: >= * <= *
Ultimate Blocks – Gutenberg Blocks Plugin fixed vulnerable versions: >= * < 2.4.13
Ultimate Carousel For Divi fixed vulnerable versions: >= * < 4.3.1
Ultimeter fixed vulnerable versions: >= * < 2.7.6
Ultra Elementor Addons fixed vulnerable versions: >= * <= *
Unakit fixed vulnerable versions: >= * < 1.2.4.2
Under Construction fixed vulnerable versions:
User Menus – Nav Menu Visibility fixed vulnerable versions: >= * < 1.2.9
Video Player for YouTube fixed vulnerable versions: >= * < 1.5.1
Videopack fixed vulnerable versions: >= * < 4.7.4
Vit Website Reviews fixed vulnerable versions: >= * <= *
VO Store Locator – WP Store Locator Plugin fixed vulnerable versions: >= * <= *
W3SCloud Contact Form 7 to Zoho CRM fixed vulnerable versions: >= * < 2.1.0
Wadi Survey fixed vulnerable versions: >= * <= *
Walker Core fixed vulnerable versions: >= * < 1.1.8
WCC SEO Keyword Research fixed vulnerable versions: >= * <= *
Webba Booking: Appointment & Event Booking Calendar Plugin fixed vulnerable versions: >= * < 4.2.18
Wholesale For WooCommerce Lite – B2B & B2C Solution fixed vulnerable versions: >= * < 1.6.1
Widget Detector for Elementor fixed vulnerable versions: >= * < 1.2.0
Widgets on Pages fixed vulnerable versions: >= * < 1.6.0
Woo Ukrposhta fixed vulnerable versions: >= * < 1.6.18
WooCommerce Bulk Edit Coupons – WP Sheet Editor fixed vulnerable versions: >= * < 1.3.28
WooCommerce Bulk Edit Products – WP Sheet Editor fixed vulnerable versions: >= * < 1.7.13
WooCommerce Customers Table: View, Search, Bulk Editor fixed vulnerable versions: >= * < 1.0.8
WooCommerce Disable Payment Methods based on cart conditions fixed vulnerable versions: >= * < 1.13.1.1
WooCommerce EU VAT Assistant fixed vulnerable versions: >= * < 2.0.28.220224
WooCommerce PayPlug fixed vulnerable versions: >= * <= *
WooCommerce Variation Swatches for Products fixed vulnerable versions: >= * <= *
WordPress Auto SEO Plugin – Upfiv SEO Wizard fixed vulnerable versions: >= * <= *
WordPress Books Gallery fixed vulnerable versions: >= * < 3.6
WordPress Everse Starter Sites – Elementor Templates fixed vulnerable versions: >= * < 1.2.1
WordPress Google Translate fixed vulnerable versions: >= * < 1.2
WordPress News Plugin – TopNewsWp fixed vulnerable versions: >= * < 2.0
WordPress Persistent Login fixed vulnerable versions: >= * < 2.0.0
WordPress SEO Audit Plugin – WP Site Auditor fixed vulnerable versions: >= * < 1.2.5
WordPress Slider Block Gutenslider fixed vulnerable versions: >= * < 5.7.0
WordPress Slider Plugin – Block Slider fixed vulnerable versions: >= * < 2.0.0
WordPress WooCommerce Sync for Google Sheet fixed vulnerable versions: >= * <= *
WP Activity Log fixed vulnerable versions: >= * < 4.4.0
WP Affiliate Disclosure fixed vulnerable versions: >= * < 1.2.3
WP Contact Slider fixed vulnerable versions: >= * < 2.4.5
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent fixed vulnerable versions: >= * < 2.1.1
WP Coupons and Deals – WordPress Coupon Plugin fixed vulnerable versions: >= * < 3.1.12
WP Data Access fixed vulnerable versions: >= * < 5.1.4
WP Disable Sitemap fixed vulnerable versions: >= * < 1.0.4
WP Emaily fixed vulnerable versions: >= * <= *
WP fail2ban – Advanced Security fixed vulnerable versions:
WP Frontend Admin – Display WP Admin Pages in the Frontend fixed vulnerable versions: >= * < 1.17.0.4
WP Get Personal fixed vulnerable versions: >= * <= *
WP Gratify fixed vulnerable versions: >= * <= *
WP Meta and Date Remover fixed vulnerable versions: >= * < 1.9.6
WP Mobile Menu – The Mobile-Friendly Responsive Menu fixed vulnerable versions: >= * < 2.8.2.7
WP Munich Blocks – Gutenberg Blocks for WordPress fixed vulnerable versions: >= * < 0.11.0
WP Notification Bell fixed vulnerable versions: >= * < 1.3.13
WP Page Templates fixed vulnerable versions: >= * < 1.1.13
WP Photo Effects fixed vulnerable versions: >= * < 1.2.1
WP Post Block fixed vulnerable versions: >= * <= *
WP Required Taxonomies – Categories and Tags Mandatory fixed vulnerable versions: >= * < 1.1.8
WP School Calendar fixed vulnerable versions: >= * < 3.6
WP Search Filter fixed vulnerable versions: >= * <= *
WP Security Safe fixed vulnerable versions: >= * < 2.4.4
WP Sessions Time Monitoring Full Automatic fixed vulnerable versions: >= * < 1.0.6
WP SMS Plugin Notification for WordPress fixed vulnerable versions:
WP SMS: WP SMS Notification for WordPress fixed vulnerable versions:
WP SPID Italia fixed vulnerable versions: >= * < 2.3.5
WP Table Builder – WordPress Table Plugin fixed vulnerable versions: >= * < 1.3.16
WP Tools Divi Blog Carousel fixed vulnerable versions: >= * < 1.3.0
WP Tools Divi Product Carousel fixed vulnerable versions: >= * < 1.5.0
WP Tools Gravity Forms Divi Module fixed vulnerable versions: >= * < 6.6.3
WP Travel Engine – Best Travel Booking WordPress Plugin fixed vulnerable versions: >= * < 5.3.8
WP-Cron Status Checker fixed vulnerable versions: >= * < 1.2.4
WPBakery Page Builder Addons by Livemesh fixed vulnerable versions:
WPTools Masonry Gallery & Posts For Divi fixed vulnerable versions: >= * < 3.1.2
WS Bootstrap fixed vulnerable versions: >= * <= *
WUPO Group Attributes for WooCommerce fixed vulnerable versions: >= * <= 2.0.0
XT Ajax Add To Cart for WooCommerce fixed vulnerable versions: >= * < 1.0.4
XT Floating Cart for WooCommerce fixed vulnerable versions: >= * < 2.6.3
XT Points & Rewards for WooCommerce fixed vulnerable versions: >= * < 1.4.3
XT Quick View for WooCommerce fixed vulnerable versions: >= * < 1.9.6
XT Variation Swatches for WooCommerce fixed vulnerable versions: >= * < 1.8.1
Yasr – Yet Another Stars Rating fixed vulnerable versions: >= * < 2.0.2
Zip Code Redirect fixed vulnerable versions:
Zipcode Redirect fixed vulnerable versions: >= * <= 4.0.1
A no-code page builder for beautiful performance-based content open vulnerable versions: >= * < 2.1.17
ACF for WooCommerce Product open vulnerable versions: >= * < 1.8
Activity Log For MainWP open vulnerable versions: >= * < 1.7.1
AdFoxly – Ad Manager, AdSense Ads & Ads.txt open vulnerable versions: >= * <= 1.8.4
Advance Menu Manager open vulnerable versions: >= * <= *
Advanced Database Replacer open vulnerable versions: >= * <= *
Agy – Age verification for WooCommerce open vulnerable versions: >= * < 4.3.1
Airpress open vulnerable versions: >= * <= *
Alt Manager open vulnerable versions: >= * < 1.5.0
Announcement & Notification Banner – Bulletin open vulnerable versions: >= * < 3.1.0
Ant Admin Notices for Team open vulnerable versions: >= * <= *
Any Popup – Popup Forms, Optins & Ads open vulnerable versions: >= * <= *
APIExperts Square for WooCommerce open vulnerable versions: >= * < 4.2.1
Atlas – Knowledge Base open vulnerable versions: >= * <= *
Automizy Gravity Forms open vulnerable versions: >= * <= *
AutoSave Net open vulnerable versions: >= * <= *
azw woocommerce file uploads open vulnerable versions: >= * <= *
Bani open vulnerable versions: >= * <= *
BAVOKO SEO Tools – All-in-One WordPress SEO open vulnerable versions: >= * <= *
Before and After Product Images for WooCommerce open vulnerable versions: >= * <= *
Better Elementor Addons open vulnerable versions: >= * < 1.3.1
Book BuyBack Prices open vulnerable versions: >= * <= *
Booking Addon for WooCommerce open vulnerable versions: >= * < 4.2.0
Brand open vulnerable versions: >= * <= *
Bulk Attachment Download open vulnerable versions: >= * < 1.3.5
Bulk WooCommerce Category Creator open vulnerable versions: >= * <= *
Caxton – Create Pro page layouts in Gutenberg open vulnerable versions: >= * < 1.30.0
CF7 Constant Contact Fields Mapping open vulnerable versions: >= * <= *
Chat Button- Leads and Order over Chat open vulnerable versions: >= * < 1.6.1
Checkout with Cash App on EDD open vulnerable versions: >= * <= *
Checkout with Venmo on EDD open vulnerable versions: >= * <= *
Choice Payment Gateway for WooCommerce open vulnerable versions: >= * < 2.0.5
Clean Social Icons open vulnerable versions: >= * <= *
ConeBlog – WordPress Blog Widgets open vulnerable versions: >= * < 1.4.6
Connected Sermons open vulnerable versions: >= * <= *
ConsultPress Lite open vulnerable versions: >= * <= *
Contact Form 7 – Capsule CRM – Integration open vulnerable versions: >= * < 1.0.5
Coupon Affiliates – WooCommerce Affiliate Plugin open vulnerable versions: >= * < 4.16.4
CP Simple Newsletter open vulnerable versions: >= * <= *
Cryptocurrency Portfolio Tracker open vulnerable versions: >= * <= *
Custom WooCommerce Checkout Fields Editor open vulnerable versions: >= * <= 1.2.6
Dashy – Google Analytics advanced dashboard open vulnerable versions: >= * <= *
Deals of the Day WooCommerce open vulnerable versions: >= * <= *
Delivery for WooCommerce open vulnerable versions: >= * <= *
DeMomentSomTres Address open vulnerable versions: >= * <= *
DeMomentSomTres Grid Archive open vulnerable versions: >= * <= *
DeMomentSomTres Media Tools Auto open vulnerable versions: >= * <= *
Divi Collage open vulnerable versions: >= * <= *
Drop Shadow Boxes open vulnerable versions: >= * < 1.7.4
Easy Code Snippets open vulnerable versions: >= * < 1.0.1
Easy Newsletter Signups open vulnerable versions: >= * < 1.0.4
Easy Prayer open vulnerable versions: >= * <= *
Easy Settings for LearnDash open vulnerable versions: >= * <= *
Easy Smooth Scroll Links – Smooth Scrolling Anchor open vulnerable versions: >= * < 2.23.1
Education Addon for Elementor open vulnerable versions: >= * < 1.2
Email Header Footer open vulnerable versions: >= * <= *
Events Addon for Elementor open vulnerable versions: >= * < 1.9.8
Expire tags open vulnerable versions: >= * <= *
Fast Checkout for WooCommerce open vulnerable versions: >= * < 1.1.17
Fast WordPress open vulnerable versions: >= * <= *
Feedpress Generator open vulnerable versions: >= * < 1.2.0
FIT: Featured Image Toolkit open vulnerable versions: >= * <= *
Footer Plugin for Divi open vulnerable versions: >= * <= *
ForceField open vulnerable versions: >= * <= *
Frontend Admin by DynamiApps open vulnerable versions: >= * < 3.3.33
Frontend group restriction for LearnDash open vulnerable versions: >= * <= *
Funnelmentals open vulnerable versions: >= * <= *
Get Better Reviews for WooCommerce open vulnerable versions: >= * <= 3.0.6
GFireM Action After open vulnerable versions: >= * <= *
GFireM Advance Search open vulnerable versions: >= * <= *
GFireM Fields open vulnerable versions: >= * <= *
Giveaways for woocommerce open vulnerable versions: >= * <= *
Glorious Services & Support open vulnerable versions: >= * <= *
GloriousThemes Starter Sites open vulnerable versions: >= * <= *
Hooked Editable Content open vulnerable versions: >= * <= *
HQTheme Extra open vulnerable versions: >= * <= *
Inbound Brew open vulnerable versions: >= * <= *
KRSP Frontend File Uploader open vulnerable versions: >= * <= *
KVoucher open vulnerable versions: >= * <= *
LawPress – Law Firm Website Management open vulnerable versions: >= * <= *
LearnMore open vulnerable versions: >= * <= *
License Manager for WooCommerce open vulnerable versions: >= * < 2.2.6
Lightbox – EverlightBox Gallery open vulnerable versions: >= * < 1.1.18
Limb Gallery | Create Beautiful Image & Video Galleries open vulnerable versions: >= * < 1.5.2
LittleBot Invoices open vulnerable versions: >= * <= *
Live Scores for SportsPress open vulnerable versions: >= * <= *
Livemesh Addons for Elementor open vulnerable versions: >= * < 7.1.4
LMS Plugin – eLearning, Online Courses by Attest open vulnerable versions: >= * <= *
MailChimp Manager open vulnerable versions: >= * <= *
Master Blocks – Gutenberg Site Builder open vulnerable versions: >= * <= *
Media Library File Download open vulnerable versions: >= * < 1.1
Modern Addons for Elementor Page Builder open vulnerable versions: >= * < 1.2.0
Multipurpose Gutenberg Block open vulnerable versions: >= * <= 1.7.3
Multisite Robots.txt Manager open vulnerable versions: >= * <= *
NEXUS open vulnerable versions: >= * <= *
Nitek Carousel Slider Cool Transitions open vulnerable versions: >= * <= *
Number Chat open vulnerable versions: >= * <= *
Opensea open vulnerable versions: >= * < 1.0.3
Order and Inventory Manager for WooCommerce open vulnerable versions: >= * < 1.4.3
Page Builder Gutenberg Blocks – Kioken Blocks open vulnerable versions: >= * <= *
Past Events Extension open vulnerable versions: >= * <= *
Podcast Box – Best Podcasting Plugin for WordPress open vulnerable versions: >= * < 1.0.2
Pootle Pagebuilder – WordPress Page builder open vulnerable versions: >= * < 5.7.1
Preloader for Divi open vulnerable versions: >= * <= *
Premmerce open vulnerable versions: >= * < 1.3.16
Premmerce Redirect Manager open vulnerable versions: >= * < 1.0.7
Price Bands for WooCommerce open vulnerable versions: >= * <= *
Protect Uploads with Login – Protect Your Uploads open vulnerable versions: >= * <= *
Purus open vulnerable versions: >= * <= *
Rating-Widget: Star Review System open vulnerable versions: >= * < 3.1.4
Remove Add to Cart WooCommerce open vulnerable versions: >= * < 1.4.3
Replyable – Subscribe to Comments and Reply by Email open vulnerable versions: >= * < 2.2.9
Reset Course Progress For LearnDash open vulnerable versions: >= * <= *
Restaurant & Cafe Addon for Elementor open vulnerable versions: >= * < 1.4.6
RevivePress – Keep your Old Content Evergreen open vulnerable versions: >= * < 1.3.1
Rocket Maintenance Mode & Coming Soon Page open vulnerable versions: >= * < 4.3
RT Easy Builder – Advanced addons for Elementor open vulnerable versions: >= * <= 1.4
Run time Image resizing open vulnerable versions: >= * <= *
Salon booking system open vulnerable versions: >= * < 7.6.3
Server Info open vulnerable versions: >= * <= *
Share This Image open vulnerable versions: >= * < 1.67
Shuban open vulnerable versions: >= * <= *
Simple Social Page Widget & Shortcode open vulnerable versions: >= * <= *
Simple Sponsorships open vulnerable versions: >= * <= *
SnazzyAdmin WP Admin Theme open vulnerable versions: >= * <= *
Social Gallery Lite open vulnerable versions: >= * <= *
South Pole: Climate action now open vulnerable versions: >= * < 1.0.2.0
Sparrow: Product Reviews and Ratings for WooCommerce open vulnerable versions: >= * <= *
Speculor open vulnerable versions: >= * <= *
SQL Reporting Services – SSRS Plugin for WordPress open vulnerable versions: >= * <= *
STEWoo – Super Transactional Emails for WooCommerce open vulnerable versions: >= * < 1.2.4
StreamCast – Radio Player for WordPress open vulnerable versions: >= * < 2.1.4
StreamWeasels Twitch Integration open vulnerable versions: >= * < 1.3.4
Strumenti Partita IVA per Woocommerce open vulnerable versions: >= * <= 1.3.23
Sync eCommerce NEO open vulnerable versions: >= * <= *
Tickera – WordPress Event Ticketing open vulnerable versions: >= * < 3.4.9.2
TinyMCE Annotate open vulnerable versions: >= * <= *
Turbo Widgets open vulnerable versions: >= * <= *
Ultimate Divi Modules Suite – Divi Sumo Lite open vulnerable versions: >= * <= *
Ultimate Gutenberg – Custom Block Templates open vulnerable versions: >= * <= *
Ultimate Widgets Light open vulnerable versions: >= * <= *
Villar open vulnerable versions: >= * < 1.0.8
Viralike open vulnerable versions: >= * <= *
wGauge – Free Version open vulnerable versions: >= * <= *
Widget for Contact form 7 open vulnerable versions: >= * <= *
Widgets for WooCommerce Products on Elementor open vulnerable versions: >= * < 1.0.9
Widgets on Pages and Posts open vulnerable versions: >= * <= *
Woo Admin Product Notes open vulnerable versions: >= * <= *
Woocommerce Customers Order History open vulnerable versions: >= * < 5.2.1
WooCommerce Next Order Coupon open vulnerable versions: >= * <= *
WooCommerce upcoming Products open vulnerable versions: >= * <= *
WordPress Animation Plugin – Animated Everything open vulnerable versions: >= * <= *
WordPress Gallery Plugin – Edge Photo Gallery open vulnerable versions: >= * <= *
WordPress Reviews by ReviewPress open vulnerable versions: >= * <= *
WordPress SEO Checklist open vulnerable versions: >= * <= *
WP Author Bio open vulnerable versions: >= * <= *
WP AutoMedic open vulnerable versions: >= * <= *
WP BugBot open vulnerable versions: >= * <= *
WP Conference Schedule open vulnerable versions: >= * < 1.1.0
WP EasyPay – Square for WordPress open vulnerable versions: >= * < 4.0.2
WP Frontend Profile open vulnerable versions: >= * < 1.2.5
WP Group Promoter open vulnerable versions: >= * <= *
WP Lead Stream open vulnerable versions: >= * <= *
WP Link Bio open vulnerable versions: >= * < 1.4.5
WP Moose open vulnerable versions: >= * < 1.0.1
Wp My Admin Bar open vulnerable versions: >= * <= *
WP Relevant Ads open vulnerable versions: >= * <= *
WP Sierra open vulnerable versions: >= * <= *
WP Smart Export (Free) open vulnerable versions: >= * <= *
WP-HR Manager: The Human Resources Plugin for WordPress open vulnerable versions: >= * < 3.0.3
WPBITS Addons For Elementor Page Builder open vulnerable versions: >= * < 1.3.2
Yatri Tools open vulnerable versions: >= * < 1.1.3
Кнопка ЮMoney open vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.