WordPress Vulnerability Report

WordPress Vulnerability Report — February 19, 2025

This last week, 230 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 95 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 230 vulnerabilities have been publicly disclosed. Security patches for 135 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 95 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.2 is now available! This minor release includes 35 bug fixes, addressing issues affecting multiple components including the block editor, HTML API, and Customize.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 123 Patched / 91 Unpatched

Easy MLS Listings Import

Plugin Slug:
easy-mls-listings-import
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gumlet Video

Plugin Slug:
gumlet-video
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync
Installations
50+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Filled In

Plugin:
Filled In
Plugin Slug:
filled-in
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:
1 Click WordPress Migration
Plugin Slug:
1-click-migration
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

1 Click WordPress Migration

Plugin:
1 Click WordPress Migration
Plugin Slug:
1-click-migration
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aparat Responsive

Plugin:
Aparat Responsive
Plugin Slug:
aparat-responsive
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Apus Framework

Plugin:
Apus Framework
Plugin Slug:
apus-framework
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Naver Syndication V2

Plugin:
Naver Syndication V2
Plugin Slug:
badr-naver-syndication
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BigBuy Dropshipping Connector for WooCommerce

Plugin:
BigBuy Dropshipping Connector for WooCommerce
Plugin Slug:
bigbuy-wc-dropshipping-connector
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Book a Room

Plugin:
Book a Room
Plugin Slug:
book-a-room
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap collapse

Plugin:
Bootstrap collapse
Plugin Slug:
bootstrap-collapse
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooODT Lite

Plugin:
WooODT Lite
Plugin Slug:
byconsole-woo-order-delivery-time
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CalendApp

Plugin:
CalendApp
Plugin Slug:
calendapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CATS Job Listings

Plugin:
CATS Job Listings
Plugin Slug:
cats-job-listings
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chalet-Montagne.com Tools

Plugin:
Chalet-Montagne.com Tools
Plugin Slug:
chalet-montagne-com-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Documentation

Plugin:
Simple Documentation
Plugin Slug:
client-documentation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DL Leadback

Plugin:
DL Leadback
Plugin Slug:
dl-leadback
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DX-auto-publish

Plugin:
DX-auto-publish
Plugin Slug:
dx-auto-publish
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Amazon Product Information

Plugin:
Easy Amazon Product Information
Plugin Slug:
easy-amazon-product-information
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:
Ebook Downloader
Plugin Slug:
ebook-downloader
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Embed Google Map

Plugin:
Embed Google Map
Plugin Slug:
embed-google-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Events Planner

Plugin:
Events Planner
Plugin Slug:
events-planner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Font Awesome WP

Plugin:
Font Awesome WP
Plugin Slug:
font-awesome-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-FormAssembly

Plugin:
WP-FormAssembly
Plugin Slug:
formassembly-web-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GetBookingsWP

Plugin:
GetBookingsWP
Plugin Slug:
get-bookings-wp
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Glance That

Plugin:
Glance That
Plugin Slug:
glance-that
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Global Meta Keyword & Description

Plugin:
Global Meta Keyword & Description
Plugin Slug:
global-meta-keyword-and-description
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Drive WP Media

Plugin:
Google Drive WP Media
Plugin Slug:
google-drive-wp-media
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IE CSS3 Support

Plugin:
IE CSS3 Support
Plugin Slug:
ie-css3-support
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Keap Official Opt-in Forms

Plugin:
Keap Official Opt-in Forms
Plugin Slug:
infusionsoft-official-opt-in-forms
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Library Bookshelves

Plugin:
Library Bookshelves
Plugin Slug:
library-bookshelves
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

magayo Lottery Results

Plugin:
magayo Lottery Results
Plugin Slug:
magayo-lottery-results
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mortgage Calculator / Loan Calculator

Plugin:
Mortgage Calculator / Loan Calculator
Plugin Slug:
mortgage-loan-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Login Logout Plugin

Plugin:
My Login Logout Plugin
Plugin Slug:
my-loginlogout
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Quiz Maker

Plugin:
Easy Quiz Maker
Plugin Slug:
n-media-wp-simple-quiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Open Hours

Plugin:
Open Hours
Plugin Slug:
open-hours
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Option Editor

Plugin:
Option Editor
Plugin Slug:
option-editor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Page/Post Specific Social Share Buttons

Plugin:
Page/Post Specific Social Share Buttons
Plugin Slug:
pagepost-specific-social-share-buttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pallet Packaging for WooCommerce

Plugin:
Pallet Packaging for WooCommerce
Plugin Slug:
pallet-packaging-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP PHPList

Plugin:
WP PHPList
Plugin Slug:
phplist-form-integration
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Sync

Plugin:
Post Sync
Plugin Slug:
post-sync
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Thumbs

Plugin:
Post Thumbs
Plugin Slug:
post-thumbs
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Prezi Embedder

Plugin:
Prezi Embedder
Plugin Slug:
prezi-embedder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

pushBIZ

Plugin:
pushBIZ
Plugin Slug:
pushbiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

R3W InstaFeed

Plugin:
R3W InstaFeed
Plugin Slug:
r3w-instafeed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rapid Cache

Plugin:
Rapid Cache
Plugin Slug:
rapid-cache
Vulnerability:
Content Spoofing
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Reaction Buttons

Plugin:
Reaction Buttons
Plugin Slug:
reaction-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts Line-up-Exactly by Milliard
Plugin Slug:
related-posts-line-up-exactry-by-milliard
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Reset

Plugin:
Reset
Plugin Slug:
reset
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rise Blocks

Plugin:
Rise Blocks
Plugin Slug:
rise-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mobile

Plugin:
Mobile
Plugin Slug:
rocket-wp-mobile
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RSS Filter

Plugin:
RSS Filter
Plugin Slug:
rss-filter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sensly Online Presence

Plugin:
Sensly Online Presence
Plugin Slug:
sensly-online-presence
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShipEngine Shipping Quotes

Plugin:
ShipEngine Shipping Quotes
Plugin Slug:
shipengine-shipping-quotes
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

sidebarTabs

Plugin:
sidebarTabs
Plugin Slug:
sidebartabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple catalogue

Plugin:
Simple catalogue
Plugin Slug:
simple-catalogue
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Charts

Plugin:
Simple Charts
Plugin Slug:
simple-charts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Pricing Tables For WPBakery Page Builder

Plugin:
Simple Pricing Tables For WPBakery Page Builder
Plugin Slug:
simple-pricing-tables-vc-extension
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Menu

Plugin:
Simple Responsive Menu
Plugin Slug:
simple-responsive-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Signup Form

Plugin:
Simple Signup Form
Plugin Slug:
simple-signup-form
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Video Management System

Plugin:
Simple Video Management System
Plugin Slug:
simple-video-management-system
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Small Package Quotes – Purolator Edition

Plugin:
Small Package Quotes – Purolator Edition
Plugin Slug:
small-package-quotes-purolator-edition
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Spiritual Gifts Survey

Plugin:
Spiritual Gifts Survey
Plugin Slug:
spiritual-gifts-survey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Stray Random Quotes

Plugin:
Stray Random Quotes
Plugin Slug:
stray-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Themes Coder

Plugin:
Themes Coder
Plugin Slug:
tc-ecommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:
Team Builder
Plugin Slug:
team-display
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TinyMCE Advanced qTranslate fix editor problems

Plugin:
TinyMCE Advanced qTranslate fix editor problems
Plugin Slug:
tinymce-advanced-qtranslate-fix-editor-problems
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Track Logins

Plugin:
Track Logins
Plugin Slug:
track-logins
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TTT Crop

Plugin:
TTT Crop
Plugin Slug:
ttt-crop
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tube Video Ads Lite

Plugin:
Tube Video Ads Lite
Plugin Slug:
tube-video-ads-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:
VR-Frases
Plugin Slug:
vr-frases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wibiya Toolbar

Plugin:
Wibiya Toolbar
Plugin Slug:
wibiya
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wise Forms

Plugin:
Wise Forms
Plugin Slug:
wise-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Uploads Addon for WooCommerce

Plugin:
File Uploads Addon for WooCommerce
Plugin Slug:
woo-addon-uploads
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Activity-o-meter

Plugin:
WordPress Activity-o-meter
Plugin Slug:
wordpress-activity-o-meter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Asambleas

Plugin:
WP-Asambleas
Plugin Slug:
wp-asambleas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-BibTeX

Plugin:
WP-BibTeX
Plugin Slug:
wp-bibtex
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Extra Fields

Plugin:
WP Extra Fields
Plugin Slug:
wp-extra-fields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Html Page Sitemap

Plugin:
WP Html Page Sitemap
Plugin Slug:
wp-html-page-sitemap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Job Board Pro

Plugin:
WP Job Board Pro
Plugin Slug:
wp-job-board-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Pricing Table

Plugin:
WP Pricing Table
Plugin Slug:
wp-pricing-table
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
OWL Carousel Slider
Plugin Slug:
wp-touch-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPMovieLibrary

Plugin:
WPMovieLibrary
Plugin Slug:
wpmovielibrary
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mortgage Lead Capture System

Plugin:
Mortgage Lead Capture System
Plugin Slug:
wprequal
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elfsight Yottie Lite

Plugin:
Elfsight Yottie Lite
Plugin Slug:
yottie-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zarinpal Paid Download

Plugin:
Zarinpal Paid Download
Plugin Slug:
zarinpal-paid-downloads
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
3,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.236
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.236.

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings

Plugin Slug:
seo-by-rank-math
Installations
3,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.236
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.236.

ElementsKit Elementor addons

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

Post SMTP – WordPress SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.0.

WP Ghost (Hide My WP Ghost) – Security & Firewall

Plugin Slug:
hide-my-wp
Installations
200,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.4.01
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.01.

WP Activity Log

Plugin Slug:
wp-security-audit-log
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.0.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.2.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.6.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.5.

Stream

Plugin:
Stream
Plugin Slug:
stream
Installations
70,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

Spotlight Social Feeds – Block, Shortcode, and Widget

Plugin Slug:
spotlight-social-photo-feeds
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

WP Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.10.1.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

FULL – Cliente

Plugin Slug:
full-customer
Installations
40,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.27
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.27.

Security & Malware scan by CleanTalk

Plugin Slug:
security-malware-firewall
Installations
30,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.150
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.150.

Ecwid by Lightspeed Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.12.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.12.28.

Read More & Accordion

Plugin Slug:
expand-maker
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

Custom Block Builder – Lazy Blocks

Plugin Slug:
lazy-blocks
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.3.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.10.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.1.

Qubely – Advanced Gutenberg Blocks

Plugin Slug:
qubely
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.13.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.10.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.5.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce
Installations
7,000+
Vulnerability:
Broken Authentication
Patched in Version:
2.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.6.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.9.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.9.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.4.3.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.9.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.4.3.

Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features

Plugin Slug:
woo-refund-and-exchange-lite
Installations
5,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.

Super Testimonials

Plugin Slug:
super-testimonial
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.2.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.31.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.31.9.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Timeline Block – Timeline block plugin for WordPress

Plugin Slug:
timeline-block-block
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Vitepos – Point of sale (POS) plugin for WooCommerce

Plugin Slug:
vitepos-lite
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

WP Airbnb Review Slider

Plugin Slug:
wp-airbnb-review-slider
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.

Calculator Builder – Create an Online Calculator

Plugin Slug:
calculator-builder
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.3.

DirectoryPress Frontend

Plugin Slug:
directorypress-frontend
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

iNET Webkit

Plugin Slug:
inet-webkit
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Oliver POS – A WooCommerce Point of Sale (POS)

Plugin Slug:
oliver-pos
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.4.2.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.2.4.

Simple Google Calendar Outlook Events Widget

Plugin Slug:
simple-google-icalendar-widget
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

SuperSaaS – online appointment scheduling

Plugin Slug:
supersaas-appointment-scheduling
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.14.

aBlocks – WordPress Gutenberg Blocks

Plugin Slug:
ablocks
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Marketing Automation

Plugin Slug:
marketing-automation
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.6.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.9.

Waymark

Plugin:
Waymark
Plugin Slug:
waymark
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.

Give – Divi Donation Modules

Plugin Slug:
give-donation-modules-for-divi
Installations
600+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Houzez Property Feed

Plugin Slug:
houzez-property-feed
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.22.
Plugin Slug:
ngg-smart-image-search
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

aDirectory – WordPress Directory Listing Plugin

Plugin Slug:
adirectory
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.

AForms Eats

Plugin Slug:
aforms-eats
Installations
400+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Keep Backup Daily

Plugin Slug:
keep-backup-daily
Installations
400+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

SpeedSize Image & Video AI-Optimizer

Plugin Slug:
speedsize-ai-image-optimizer
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Web Stories Enhancer – Level Up Your Web Stories

Plugin Slug:
web-stories-enhancer
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

WooCommerce Pricing – Product Pricing

Plugin Slug:
woo-pricing-table
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.0.

WP Abstracts

Plugin Slug:
wp-abstracts-manuscripts-manager
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.

what3words Address Field

Plugin Slug:
3-word-address-validation-field
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.0.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.16.

Content Snippet Manager

Plugin Slug:
content-snippet-manager
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.6.

Threepress

Plugin:
Threepress
Plugin Slug:
threepress
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Admire Extra

Plugin Slug:
admire-extra
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator
Installations
100+
Vulnerability:
Settings Change
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

Distance Based Shipping Calculator

Plugin Slug:
distance-based-shipping-calculator
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.23.

LTL Freight Quotes – Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.21.

LTL Freight Quotes – Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.22.

Magic the Gathering Card Tooltips

Plugin Slug:
magic-the-gathering-card-tooltips
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.0.

StaffList

Plugin:
StaffList
Plugin Slug:
stafflist
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.4.

Liveticker (by stklcode)

Plugin Slug:
stklcode-liveticker
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Shopwarden – Automated WooCommerce monitoring & testing

Plugin Slug:
shopwarden
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.12.

FuseDesk

Plugin:
FuseDesk
Plugin Slug:
fusedesk
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.

LTL Freight Quotes – FreightQuote Edition

Plugin Slug:
ltl-freight-quotes-freightquote-edition
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.12.

LTL Freight Quotes – FreightQuote Edition

Plugin Slug:
ltl-freight-quotes-freightquote-edition
Installations
60+
Vulnerability:
SQL Injection
Patched in Version:
2.3.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.12.

MemorialDay

Plugin Slug:
memorialday
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.0.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

LTL Freight Quotes – Estes Edition

Plugin Slug:
ltl-freight-quotes-estes-edition
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
3.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.8.

LTL Freight Quotes – XPO Edition

Plugin Slug:
ltl-freight-quotes-xpo-edition
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
4.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3.8.

Small Package Quotes – UPS Edition

Plugin Slug:
small-package-quotes-ups-edition
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
4.5.17
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.5.17.

LTL Freight Quotes – For Customers of FedEx Freight

Plugin Slug:
ltl-freight-quotes-fedex-freight-edition
Installations
20+
Vulnerability:
SQL Injection
Patched in Version:
3.4.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.2.

Simple Certain Time to Show Content

Plugin Slug:
simple-certain-time-to-show-content
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Chaty Pro

Plugin:
Chaty Pro
Plugin Slug:
chaty-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.4.

ConvertPlus

Plugin:
ConvertPlus
Plugin Slug:
convertplug
Vulnerability:
Broken Access Control
Patched in Version:
3.5.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.31.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.11.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.14.
Plugin:
Gallery
Plugin Slug:
gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin:
Global Gallery – WordPress Responsive Gallery
Plugin Slug:
global-gallery
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
9.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.6.

K Elements

Plugin:
K Elements
Plugin Slug:
k-elements
Vulnerability:
Privilege Escalation
Patched in Version:
5.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.0.

LTL Freight Quotes – Unishippers Edition

Plugin:
LTL Freight Quotes – Unishippers Edition
Plugin Slug:
ltl-freight-quotes-unishippers-edition
Vulnerability:
SQL Injection
Patched in Version:
2.5.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.9.

LTL Freight Quotes – Unishippers Edition

Plugin:
LTL Freight Quotes – Unishippers Edition
Plugin Slug:
ltl-freight-quotes-unishippers-edition
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.9.

LTL Freight Quotes – Unishippers Edition

Plugin:
LTL Freight Quotes – Unishippers Edition
Plugin Slug:
ltl-freight-quotes-unishippers-edition
Vulnerability:
Broken Access Control
Patched in Version:
2.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.9.

Notif Bell

Plugin:
Notif Bell
Plugin Slug:
notif-bell
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.9.

Tourmaster

Plugin:
Tourmaster
Plugin Slug:
tourmaster
Vulnerability:
SQL Injection
Patched in Version:
5.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.7.

Uncode Core

Plugin:
Uncode Core
Plugin Slug:
uncode-core
Vulnerability:
Content Injection
Patched in Version:
2.9.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.7.

WP Table Manager

Plugin:
WP Table Manager
Plugin Slug:
wp-table-manager
Vulnerability:
Directory Traversal
Patched in Version:
4.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.4.

WordPress Themes — 12 Patched / 4 Unpatched

Campress

Theme:
Campress
Theme Slug:
campress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:
Puzzles
Theme Slug:
puzzles
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:
Puzzles
Theme Slug:
puzzles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Puzzles

Theme:
Puzzles
Theme Slug:
puzzles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Uncode

Theme:
Uncode
Theme Slug:
uncode
Downloads
2,247
Vulnerability:
Arbitrary File Download
Patched in Version:
2.9.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.7.

Uncode

Theme:
Uncode
Theme Slug:
uncode
Downloads
2,247
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.1.7.

Uncode

Theme:
Uncode
Theme Slug:
uncode
Downloads
2,247
Vulnerability:
Arbitrary File Download
Patched in Version:
2.9.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.1.7.

Avada

Theme:
Avada
Theme Slug:
avada
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
7.11.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.11.14.

CarSpot

Theme:
CarSpot
Theme Slug:
carspot
Vulnerability:
Broken Authentication
Patched in Version:
2.4.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.4.

Click Mag

Theme:
Click Mag
Theme Slug:
click-mag
Vulnerability:
Broken Access Control
Patched in Version:
3.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.0.

Listivo – Classified Ads

Theme:
Listivo – Classified Ads
Theme Slug:
listivo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.68
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.68.

PressMart

Theme:
PressMart
Theme Slug:
pressmart
Vulnerability:
Content Injection
Patched in Version:
1.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.17.

Real Estate 7

Theme:
Real Estate 7
Theme Slug:
realestate-7
Vulnerability:
Privilege Escalation
Patched in Version:
3.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.1.

Zox News

Theme:
Zox News
Theme Slug:
zox-news
Vulnerability:
Broken Access Control
Patched in Version:
3.17.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.17.1.

ZoxPress

Theme:
ZoxPress
Theme Slug:
zoxpress
Vulnerability:
Broken Access Control
Patched in Version:
2.12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.12.1.

ZoxPress

Theme:
ZoxPress
Theme Slug:
zoxpress
Vulnerability:
Broken Access Control
Patched in Version:
2.12.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.12.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security