WordPress Vulnerability Report

WordPress Vulnerability Report — February 12, 2025

This last week, 155 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 101 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 155 vulnerabilities have been publicly disclosed. Security patches for 54 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 101 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.2 is now available! This minor release includes 35 bug fixes, addressing issues affecting multiple components including the block editor, HTML API, and Customize.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 51 Patched / 100 Unpatched

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog, Posts and Category Filter for Elementor

Plugin Slug:
blog-posts-and-category-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Paytm Payment Donation

Plugin Slug:
paytm-donation
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Music Press Pro

Plugin Slug:
music-press-pro
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Rotator

Plugin Slug:
appten-image-rotator
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Print PDF Generator and Publisher

Plugin Slug:
nopeamedia
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AIO Performance Profiler, Monitor, Optimize, Compress & Debug

Plugin Slug:
all-in-one-performance-accelerator
Installations
20+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointment Buddy Widget By Accrete

Plugin Slug:
appointment-buddy-online-appointment-booking-by-accrete
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Auto SEO

Plugin:
Auto SEO
Plugin Slug:
auto-seo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Banner Garden

Plugin:
Banner Garden
Plugin Slug:
banner-garden
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BookPress – For Book Authors

Plugin:
BookPress – For Book Authors
Plugin Slug:
book-press
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Breaking News Ticker

Plugin:
Breaking News Ticker
Plugin Slug:
breaking-news-ticker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Builder Shortcode Extras

Plugin:
Builder Shortcode Extras
Plugin Slug:
builder-shortcode-extras
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Child Themes Helper

Plugin:
Child Themes Helper
Plugin Slug:
child-themes-helper
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment Notifications

Plugin:
Custom Comment Notifications
Plugin Slug:
custom-comment-notifications
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Custom Links On Admin Dashboard Toolbar
Plugin Slug:
customize-wpadmin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
CWD – Stealth Links
Plugin Slug:
cwd-stealth-links
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Easy Chart Builder for WordPress

Plugin:
Easy Chart Builder for WordPress
Plugin Slug:
easy-chart-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Related Posts
Plugin Slug:
easy-related-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Tiles

Plugin:
Easy WP Tiles
Plugin Slug:
easy-wp-tiles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Embed RSS

Plugin:
Embed RSS
Plugin Slug:
embed-rss
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

External Video For Everybody

Plugin:
External Video For Everybody
Plugin Slug:
external-video-for-everybody
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Facilita Form Tracker

Plugin:
Facilita Form Tracker
Plugin Slug:
facilita-form-tracker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Status Updater

Plugin:
Status Updater
Plugin Slug:
fb-status-updater
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FlexIDX Home Search
Plugin Slug:
flexidx-home-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fyrebox Quizzes

Plugin:
Fyrebox Quizzes
Plugin Slug:
fyrebox-shortcode
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Giga Messenger – Express

Plugin:
Giga Messenger – Express
Plugin Slug:
giga-messenger-bots
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GlobalQuran

Plugin:
GlobalQuran
Plugin Slug:
globalquran
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Glossy

Plugin:
Glossy
Plugin Slug:
glossy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

URL-Preview-Box

Plugin:
URL-Preview-Box
Plugin Slug:
good-url-preview-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Earth Embed

Plugin:
Google Earth Embed
Plugin Slug:
google-earth-tours
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Graceful Email Obfuscation

Plugin:
Graceful Email Obfuscation
Plugin Slug:
graceful-email-obfuscation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iBuildApp

Plugin:
iBuildApp
Plugin Slug:
ibuildapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Indeed API

Plugin:
Indeed API
Plugin Slug:
indeed-api
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infusionsoft Analytics

Plugin:
Infusionsoft Analytics
Plugin Slug:
infusionsoft-web-tracker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

InLocation

Plugin:
InLocation
Plugin Slug:
inlocation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JustRows free

Plugin:
JustRows free
Plugin Slug:
justrows-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Event Kikfyre

Plugin:
Event Kikfyre
Plugin Slug:
kikfyre-events-calendar-tickets
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Kona Gallery Block
Plugin Slug:
kona-instagram-feed-for-gutenberg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Legull

Plugin:
Legull
Plugin Slug:
legull
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LikeBot

Plugin:
LikeBot
Plugin Slug:
likebot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Link to URL / Post

Plugin:
Link to URL / Post
Plugin Slug:
link-to-url-post
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Links in Captions
Plugin Slug:
links-in-captions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login-box

Plugin:
Login-box
Plugin Slug:
login-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Munk Sites

Plugin:
Munk Sites
Plugin Slug:
munk-sites
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Musicbox

Plugin:
Musicbox
Plugin Slug:
musicbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
NextGen Cooliris Gallery
Plugin Slug:
nextgen-cooliris-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OneStore Sites

Plugin:
OneStore Sites
Plugin Slug:
onestore-sites
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

On Page SEO + Whatsapp Chat Button

Plugin:
On Page SEO + Whatsapp Chat Button
Plugin Slug:
ops-robots-txt
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Optimate Ads

Plugin:
Optimate Ads
Plugin Slug:
optimate-ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pop Up

Plugin:
Pop Up
Plugin Slug:
popup-seo-optimized
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quote Comments

Plugin:
Quote Comments
Plugin Slug:
quote-comments
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Read More Copy Link
Plugin Slug:
read-more-copy-link
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive iframe

Plugin:
Responsive iframe
Plugin Slug:
responsive-iframe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ReverbNation Widgets

Plugin:
ReverbNation Widgets
Plugin Slug:
reverbnation-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RSS in Page

Plugin:
RSS in Page
Plugin Slug:
rss-in-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Show notice or message on admin area

Plugin:
Show notice or message on admin area
Plugin Slug:
show-notice-or-message-on-admin-area
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Add Pages or Posts

Plugin:
Simple Add Pages or Posts
Plugin Slug:
simple-add-pages-or-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Auto Tag

Plugin:
Simple Auto Tag
Plugin Slug:
simple-auto-tag
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Select All Text Box

Plugin:
Simple Select All Text Box
Plugin Slug:
simple-select-all-text-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Profile

Plugin:
Simple User Profile
Plugin Slug:
simple-user-profile
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slide Banners

Plugin:
Slide Banners
Plugin Slug:
slide-banners
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Countdown FX

Plugin:
Smart Countdown FX
Plugin Slug:
smart-countdown-fx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart DoFollow

Plugin:
Smart DoFollow
Plugin Slug:
smart-dofollow
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Songkick Concerts and Festivals

Plugin:
Songkick Concerts and Festivals
Plugin Slug:
songkick-concerts-and-festivals
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Starter Templates by FancyWP

Plugin:
Starter Templates by FancyWP
Plugin Slug:
starter-templates
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Style Tweaker

Plugin:
Style Tweaker
Plugin Slug:
style-tweaker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theasys

Plugin:
Theasys
Plugin Slug:
theasys
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Options Z

Plugin:
Theme Options Z
Plugin Slug:
theme-options-z
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TransFinanz

Plugin:
TransFinanz
Plugin Slug:
transfinanz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Vignette Ads

Plugin:
Vignette Ads
Plugin Slug:
vignete-ads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:
VR-Frases
Plugin Slug:
vr-frases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WizShop

Plugin:
WizShop
Plugin Slug:
wizshop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Custom Page

Plugin:
WP Admin Custom Page
Plugin Slug:
wp-admin-custom-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post RSS Feed

Plugin:
WP Custom Post RSS Feed
Plugin Slug:
wp-custom-post-rss-feed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Directorybox Manager

Plugin:
WP Directorybox Manager
Plugin Slug:
wp-directorybox-manager
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Dream Carousel
Plugin Slug:
wp-dream-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Newsletter

Plugin:
WP Email Newsletter
Plugin Slug:
wp-email-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:
WP Finance
Plugin Slug:
wp-finance
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:
WP Finance
Plugin Slug:
wp-finance
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Keyword Monitor

Plugin:
WP Keyword Monitor
Plugin Slug:
wp-keyword-monitor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Projects Portfolio

Plugin:
WP Projects Portfolio
Plugin Slug:
wp-projects-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Projects Portfolio

Plugin:
WP Projects Portfolio
Plugin Slug:
wp-projects-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP SimpleWeather

Plugin:
WP SimpleWeather
Plugin Slug:
wp-simpleweather
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Stream

Plugin:
WP Social Stream
Plugin Slug:
wp-social-stream
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Spell Check

Plugin:
WP Spell Check
Plugin Slug:
wp-spell-check
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP doodlez

Plugin:
WP doodlez
Plugin Slug:
wpdoodlez
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZMSEO

Plugin:
ZMSEO
Plugin Slug:
zmseo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.8.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.45.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.2.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Dynamic Conditions

Plugin Slug:
dynamicconditions
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.5.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.

Sensei LMS – Online Courses, Quizzes, & Learning

Plugin Slug:
sensei-lms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.24.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.4.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.3.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.9.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.6.

B Slider- Gutenberg Slider Block for WP

Plugin Slug:
b-slider
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.24.

Product Blocks for WooCommerce

Plugin Slug:
product-blocks-for-woocommerce
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

Medical Addon for Elementor

Plugin Slug:
medical-addon-for-elementor
Installations
2,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

SendPulse Email Marketing Newsletter

Plugin Slug:
sendpulse-email-marketing-newsletter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Directory Listings WordPress plugin – uListing

Plugin Slug:
ulisting
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.1.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.7.

Directory Listings WordPress plugin – uListing

Plugin Slug:
ulisting
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
2.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.7.

SuperSaaS – online appointment scheduling

Plugin Slug:
supersaas-appointment-scheduling
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

RapidLoad AI – Optimize Web Vitals Automatically

Plugin Slug:
unusedcss
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Include Mastodon Feed

Plugin Slug:
include-mastodon-feed
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.10.

Product Table For WooCommerce

Plugin Slug:
product-table-for-woocommerce
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Uix Shortcodes

Plugin Slug:
uix-shortcodes
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Disable Elementor Editor Translation

Plugin Slug:
disable-elementor-editor-translation
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Listings for Appfolio

Plugin Slug:
listings-for-appfolio
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Contact Manager

Plugin Slug:
contact-manager
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.6.5.
Plugin Slug:
gallery-for-ultimate-member
Installations
100+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

ShopSite

Plugin:
ShopSite
Plugin Slug:
shopsite-plugin
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.11.

Awesome Event Booking

Plugin Slug:
awesome-event-booking
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

Awesome Event Booking

Plugin Slug:
awesome-event-booking
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

Admin and Site Enhancements (ASE) Pro

Plugin:
Admin and Site Enhancements (ASE) Pro
Plugin Slug:
admin-site-enhancements-pro
Vulnerability:
Privilege Escalation
Patched in Version:
7.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.3.

BoomBox Theme Extensions

Plugin:
BoomBox Theme Extensions
Plugin Slug:
boombox-theme-extensions
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Nextend Social Login Pro

Plugin:
Nextend Social Login Pro
Plugin Slug:
nextend-social-login-pro
Vulnerability:
Broken Authentication
Patched in Version:
3.1.17
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.17.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
SQL Injection
Patched in Version:
7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.1.

WooCommerce Support Ticket System

Plugin:
WooCommerce Support Ticket System
Plugin Slug:
woocommerce-support-ticket-system
Vulnerability:
Broken Access Control
Patched in Version:
17.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 17.9.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.2.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.2.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.8.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
PHP Object Injection
Patched in Version:
4.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.8.

WordPress Themes — 3 Patched / 1 Unpatched

OnePress

Theme:
OnePress
Theme Slug:
onepress
Downloads
2,355,283
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

DWT – Directory & Listing

Theme:
DWT – Directory & Listing
Theme Slug:
dwt-listing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.5.

SocialV

Theme:
SocialV
Theme Slug:
socialv
Vulnerability:
Broken Access Control
Patched in Version:
2.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.16.

Zox News

Theme:
Zox News
Theme Slug:
zox-news
Vulnerability:
Broken Access Control
Patched in Version:
3.17.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.17.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security