WordPress Vulnerability Report

WordPress Vulnerability Report — March 5, 2025

Last week, 209 new vulnerabilities emerged in the WordPress ecosystem, including 197 plugins and 12 themes. 105 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 209 vulnerabilities have been publicly disclosed. Security patches for 104 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 105 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8 Beta 1 is available for download and testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, set up a test environment or a local site to explore the new features.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 93 Patched / 104 Unpatched

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ibtana – WordPress Website Builder

Plugin Slug:
ibtana-visual-editor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forex Calculators

Plugin Slug:
fx-calculators
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PiwigoPress

Plugin Slug:
piwigopress
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
list-related-attachments-widget
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL Media Uploader

Plugin Slug:
url-media-uploader
Installations
100+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WHMCS Client Area for WordPress by WHMpress

Plugin:
WHMCS Client Area for WordPress by WHMpress
Plugin Slug:
WHMpress_Client_Area_Api
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Add Linked Images To Gallery
Plugin Slug:
add-linked-images-to-gallery-v01
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ADFO

Plugin:
ADFO
Plugin Slug:
admin-form
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Manager

Plugin:
Admin Menu Manager
Plugin Slug:
admin-menu-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All-In-One Cufon

Plugin:
All-In-One Cufon
Plugin Slug:
all-in-one-cufon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Archive Page

Plugin:
Archive Page
Plugin Slug:
archive-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ark Theme Core

Plugin:
Ark Theme Core
Plugin Slug:
ark-core
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Auto Tag Links
Plugin Slug:
auto-tag-links
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blightly Explorer

Plugin:
Blightly Explorer
Plugin Slug:
blighty-explorer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Booknetic

Plugin:
Booknetic
Plugin Slug:
booknetic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bravo Search & Replace

Plugin:
Bravo Search & Replace
Plugin Slug:
bravo-search-and-replace
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Content Creator

Plugin:
Bulk Content Creator
Plugin Slug:
bulk-content-creator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Clicface Trombi

Plugin:
Clicface Trombi
Plugin Slug:
clicface-trombi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Star Rating

Plugin:
Contact Form 7 Star Rating
Plugin Slug:
contact-form-7-star-rating
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Star Rating with font Awesome

Plugin:
Contact Form 7 Star Rating with font Awesome
Plugin Slug:
contact-form-7-star-rating-with-font-awersome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Currency Switcher for WooCommerce

Plugin:
Currency Switcher for WooCommerce
Plugin Slug:
currency-switcher-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Download HTML TinyMCE Button

Plugin:
Download HTML TinyMCE Button
Plugin Slug:
download-html-tinymce-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
Plugin Slug:
easy-broken-link-checker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener | Conversion Tracking | AB Testing | WooCommerce

Plugin:
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
Plugin Slug:
easy-broken-link-checker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Erima Zarinpal Donate

Plugin:
Erima Zarinpal Donate
Plugin Slug:
erima-zarinpal-donate
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

F12-Profiler

Plugin:
F12-Profiler
Plugin Slug:
f12-profiler
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fresh Framework

Plugin:
Fresh Framework
Plugin Slug:
fresh-framework
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FS Poster

Plugin:
FS Poster
Plugin Slug:
fs-poster
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Maps for WordPress

Plugin:
Google Maps for WordPress
Plugin Slug:
google-maps-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hover Image Button

Plugin:
Hover Image Button
Plugin Slug:
hover-image-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EZ InLinkz linkup

Plugin:
EZ InLinkz linkup
Plugin Slug:
inlinkz-scripter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just Variables

Plugin:
Just Variables
Plugin Slug:
just-wp-variables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:
Limit Bio
Plugin Slug:
limit-bio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Limit Bio

Plugin:
Limit Bio
Plugin Slug:
limit-bio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link My Posts
Plugin Slug:
linkmyposts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Phee’s LinkPreview

Plugin:
Phee’s LinkPreview
Plugin Slug:
linkpreview
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Local Search SEO Contact Page

Plugin:
Local Search SEO Contact Page
Plugin Slug:
local-search-seo-contact-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce – Loi Hamon

Plugin:
Woocommerce – Loi Hamon
Plugin Slug:
loi-hamon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

mEintopf

Plugin:
mEintopf
Plugin Slug:
meintopf
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Minimum Password Strength

Plugin:
Minimum Password Strength
Plugin Slug:
minimum-password-strength
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Modal Portfolio

Plugin:
Modal Portfolio
Plugin Slug:
modal-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multilevel Referral Affiliate Plugin for WooCommerce

Plugin:
Multilevel Referral Affiliate Plugin for WooCommerce
Plugin Slug:
multilevel-referral-plugin-for-woocommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Quota

Plugin:
My Quota
Plugin Slug:
my-quota
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Namaste! LMS

Plugin:
Namaste! LMS
Plugin Slug:
namaste-lms
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NewsTicker

Plugin:
NewsTicker
Plugin Slug:
news-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NHR Options Table Manager

Plugin:
NHR Options Table Manager
Plugin Slug:
nhrrob-options-table-manager
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Pages

Plugin:
Ninja Pages
Plugin Slug:
ninja-page-categories-and-tags
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Get Posts

Plugin:
Get Posts
Plugin Slug:
nurelm-get-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ohio Extra

Plugin:
Ohio Extra
Plugin Slug:
ohio-extra
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Om Stripe

Plugin:
Om Stripe
Plugin Slug:
om-stripe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Önceki Yaz? Link
Plugin Slug:
onceki-yazi-linki
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OneStore Sites

Plugin:
OneStore Sites
Plugin Slug:
onestore-sites
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Order Attachments for WooCommerce

Plugin:
Order Attachments for WooCommerce
Plugin Slug:
order-attachments-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Passbeemedia Web Push Notification

Plugin:
Passbeemedia Web Push Notification
Plugin Slug:
passbeemedia-web-push-notifications
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pathomation

Plugin:
Pathomation
Plugin Slug:
pathomation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Photo Gallery ( Responsive )
Plugin Slug:
photo-gallery-pearlbells
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pricing Table by PickPlugins

Plugin:
Pricing Table by PickPlugins
Plugin Slug:
pricingtable
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:
PrivateContent
Plugin Slug:
private-content
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:
PrivateContent
Plugin Slug:
private-content
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:
PrivateContent
Plugin Slug:
private-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent

Plugin:
PrivateContent
Plugin Slug:
private-content
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Profile Widget Ninja

Plugin:
Profile Widget Ninja
Plugin Slug:
profile-widget-ninja
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quiz Organizer

Plugin:
Quiz Organizer
Plugin Slug:
quiz-organizer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RAYS Grid

Plugin:
RAYS Grid
Plugin Slug:
rays-grid
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reactive Mortgage Calculator

Plugin:
Reactive Mortgage Calculator
Plugin Slug:
reactive-mortgage-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management System – SakolaWP

Plugin:
School Management System – SakolaWP
Plugin Slug:
sakolawp-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Google Sitemap

Plugin:
Simple Google Sitemap
Plugin Slug:
simple-google-sitemap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple:Press

Plugin:
Simple:Press
Plugin Slug:
simplepress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Maintenance & Countdown

Plugin:
Smart Maintenance & Countdown
Plugin Slug:
smart-maintenance-countdown
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SpotBot

Plugin:
SpotBot
Plugin Slug:
spotbot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Live Streaming Video Player – by SRS Player

Plugin:
Live Streaming Video Player – by SRS Player
Plugin Slug:
srs-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Header On Scroll

Plugin:
Sticky Header On Scroll
Plugin Slug:
sticky-header-on-scroll
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Block

Plugin:
Table of Contents Block
Plugin Slug:
table-of-contents
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyHolis TableSearch

Plugin:
BuddyHolis TableSearch
Plugin Slug:
tablesearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Countdown Timer

Plugin:
Countdown Timer
Plugin Slug:
timer-countdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultra Addons Lite for Elementor

Plugin:
Ultra Addons Lite for Elementor
Plugin Slug:
ut-elementor-addons-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VG PostCarousel

Plugin:
VG PostCarousel
Plugin Slug:
vg-postcarousel
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video.js HLS Player

Plugin:
Video.js HLS Player
Plugin Slug:
videojs-hls-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ViperBar

Plugin:
ViperBar
Plugin Slug:
viperbar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tabs for WooCommerce

Plugin:
Tabs for WooCommerce
Plugin Slug:
wc-tabs
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin / AltCoin Payment Gateway for WooCommerce

Plugin:
Bitcoin / AltCoin Payment Gateway for WooCommerce
Plugin Slug:
woo-altcoin-payment-gateway
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Direct Checkout Button for WooCommerce

Plugin:
Direct Checkout Button for WooCommerce
Plugin Slug:
woo-direct-checkout-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Recargo de Equivalencia

Plugin:
WooCommerce Recargo de Equivalencia
Plugin Slug:
woo-recargo-de-equivalencia
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Display Products by Tags

Plugin:
WooCommerce Display Products by Tags
Plugin Slug:
woocommerce-display-products-by-tags
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates

Plugin:
WooCommerce Ultimate Gift Card – Create, Sell and Manage Gift Cards with Customized Email Templates
Plugin Slug:
woocommerce-ultimate-gift-card
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WOW Entrance Effects (WEE!)

Plugin:
WOW Entrance Effects (WEE!)
Plugin Slug:
wow-entrance-effects-wee
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WoWPth

Plugin:
WoWPth
Plugin Slug:
wowpth
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP About Author

Plugin:
WP About Author
Plugin Slug:
wp-about-author
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Asambleas

Plugin:
WP-Asambleas
Plugin Slug:
wp-asambleas
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Click Info

Plugin:
WP Click Info
Plugin Slug:
wp-click-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP e-Customers Beta

Plugin:
WP e-Customers Beta
Plugin Slug:
wp-e-customers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JPG, PNG Compression and Optimization

Plugin:
JPG, PNG Compression and Optimization
Plugin Slug:
wp-image-compression
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-PostRatings Cheater

Plugin:
WP-PostRatings Cheater
Plugin Slug:
wp-postratings-cheater
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-PManager

Plugin:
WP-PManager
Plugin Slug:
wp-programmmanager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Sitemap

Plugin:
WP Sitemap
Plugin Slug:
wp-sitemap
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Social SEO Booster – Knowledge Graph Social Signals SEO

Plugin:
WP Social SEO Booster – Knowledge Graph Social Signals SEO
Plugin Slug:
wp-social-seo-booster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Video Posts

Plugin:
WP Video Posts
Plugin Slug:
wp-video-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:
????????
Plugin Slug:
wumii-related-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yawave

Plugin:
Yawave
Plugin Slug:
yawave
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SVG Support

Plugin Slug:
svg-support
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.9.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.31.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.31.5.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
PHP Object Injection
Patched in Version:
10.1.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 10.1.1.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.3.4.

Jeg Elementor Kit

Plugin Slug:
jeg-elementor-kit
Installations
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.12.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha
Installations
200,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.28.

GenerateBlocks

Plugin Slug:
generateblocks
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

WP Activity Log

Plugin Slug:
wp-security-audit-log
Installations
200,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.3.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.20.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.20.0.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.6.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.4.2.

Simple Image Sizes

Plugin Slug:
simple-image-sizes
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Advanced AJAX Product Filters

Plugin Slug:
woocommerce-ajax-filters
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.2.
Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Post Grid and Gutenberg Blocks – ComboBlocks

Plugin Slug:
post-grid
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Accept Donations with PayPal & Stripe

Plugin Slug:
easy-paypal-donation
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.
Plugin Slug:
final-tiles-grid-gallery-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.8.

NextMove Lite – Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.0.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

IP2Location Redirection

Plugin Slug:
ip2location-redirection
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.33.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.33.4.

WPO365 | MICROSOFT 365 GRAPH MAILER

Plugin Slug:
wpo365-msgraphmailer
Installations
8,000+
Vulnerability:
Open Redirection
Patched in Version:
3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.

Animated Text Block

Plugin Slug:
animated-text-block
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.
Plugin Slug:
new-album-gallery
Installations
5,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.4.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
SQL Injection
Patched in Version:
3.7.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.7.9.

Authors List

Plugin Slug:
authors-list
Installations
4,000+
Vulnerability:
Content Injection
Patched in Version:
2.0.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.1.

Card Elements for Elementor

Plugin Slug:
card-elements-for-elementor
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.
Plugin Slug:
wp-posts-carousel
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
3.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.8.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
9.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.8.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
26.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 26.0.1.

Product Catalog Simple

Plugin Slug:
post-type-x
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Quotes llama

Plugin Slug:
quotes-llama
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.2.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Subscriptions & Memberships for PayPal

Plugin Slug:
subscriptions-memberships-for-paypal
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction
Installations
1,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
4.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.0.

PlayerJS

Plugin:
PlayerJS
Plugin Slug:
playerjs
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.24.

m1.DownloadList

Plugin Slug:
m1downloadlist
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.20.

RateMyAgent Official

Plugin Slug:
ratemyagent-official
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Multiple Shipping And Billing Address For Woocommerce

Plugin Slug:
different-shipping-and-billing-address-for-woocommerce
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.

DefendWP Firewall

Plugin Slug:
defend-wp-firewall
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

MK Google Directions

Plugin Slug:
google-distance-calculator
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.1.

Activity Log WinterLock

Plugin Slug:
winterlock
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Academist Membership

Plugin:
Academist Membership
Plugin Slug:
academist-membership
Vulnerability:
Broken Authentication
Patched in Version:
1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.

Alloggio Membership

Plugin:
Alloggio Membership
Plugin Slug:
alloggio-membership
Vulnerability:
Broken Authentication
Patched in Version:
1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.

Animation Addons for Elementor Pro

Plugin:
Animation Addons for Elementor Pro
Plugin Slug:
animation-addons-for-elementor-pro
Vulnerability:
Broken Access Control
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.00
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.00.

DHVC Form

Plugin:
DHVC Form
Plugin Slug:
dhvc-form
Vulnerability:
Privilege Escalation
Patched in Version:
2.4.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.8.

Edd Google Sheet Connector Pro

Plugin:
Edd Google Sheet Connector Pro
Plugin Slug:
edd-google-sheet-connector-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Exertio Framework

Plugin:
Exertio Framework
Plugin Slug:
exertio-framework
Vulnerability:
Privilege Escalation
Patched in Version:
1.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.2.

Easy Digital Downloads Google Sheet Connector

Plugin Slug:
gsheetconnector-easy-digital-downloads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Pie Register Premium

Plugin:
Pie Register Premium
Plugin Slug:
pie-register-premium
Vulnerability:
Path Traversal
Patched in Version:
3.8.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.3.3.

Pie Register Premium

Plugin:
Pie Register Premium
Plugin Slug:
pie-register-premium
Vulnerability:
Broken Access Control
Patched in Version:
3.8.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.3.3.

SetSail Membership

Plugin:
SetSail Membership
Plugin Slug:
setsail-membership
Vulnerability:
Broken Authentication
Patched in Version:
1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.

Social Share And Social Locker

Plugin:
Social Share And Social Locker
Plugin Slug:
social-share-and-social-locker-arsocial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

SureMembers

Plugin:
SureMembers
Plugin Slug:
suremembers
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.7.

Templines Elementor Helper Core

Plugin:
Templines Elementor Helper Core
Plugin Slug:
templines-helper-core
Vulnerability:
Privilege Escalation
Patched in Version:
2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.

ThemeMakers PayPal Express Checkout

Plugin:
ThemeMakers PayPal Express Checkout
Plugin Slug:
tmm_paypal_checkout
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

ThemeMakers Stripe Checkout

Plugin:
ThemeMakers Stripe Checkout
Plugin Slug:
tmm_stripe_checkout
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

WHMpress

Plugin:
WHMpress
Plugin Slug:
whmpress
Vulnerability:
Local File Inclusion
Patched in Version:
6.3-revision-1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.3-revision-1.

WooCommerce Cart Count Shortcode

Plugin:
WooCommerce Cart Count Shortcode
Plugin Slug:
woo-cart-count-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

WordPress File Upload

Plugin:
WordPress File Upload
Plugin Slug:
wp-file-upload
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.25.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.25.3.

WordPress Themes — 11 Patched / 1 Unpatched

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Newscrunch

Theme Slug:
newscrunch
Downloads
175,636
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.4.1.

Newscrunch

Theme Slug:
newscrunch
Downloads
175,636
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.8.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.4.1.

VW Storefront

Theme Slug:
vw-storefront
Downloads
60,130
Vulnerability:
Broken Access Control
Patched in Version:
1.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.0.

Bricks Builder

Theme:
Bricks Builder
Theme Slug:
bricks
Vulnerability:
Privilege Escalation
Patched in Version:
1.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.7.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Broken Access Control
Patched in Version:
1.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.5.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.4.

Enfold

Theme:
Enfold
Theme Slug:
enfold
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.

Enfold

Theme:
Enfold
Theme Slug:
enfold
Vulnerability:
Broken Access Control
Patched in Version:
7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.

Nokri

Theme:
Nokri
Theme Slug:
nokri
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security