In this report, 143 vulnerabilities have been publicly disclosed. Security patches for 86 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 57 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8 Beta 2 is ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, you should evaluate Beta 2 on a test server and site.
WordPress Plugins — 78 Patched / 51 Unpatched
SEO Plugin by Squirrly SEO
- Plugin:
- SEO Plugin by Squirrly SEO
- Plugin Slug:
- squirrly-seo
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24654
Master Slider – Responsive Touch Slider
- Plugin Slug:
- master-slider
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-11731
Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More
- Plugin Slug:
- content-control
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-11153
All-in-One Addons for Elementor – WidgetKit
- Plugin Slug:
- widgetkit-for-elementor
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-10321
Wishlist for WooCommerce: Multi Wishlists Per Customer
- Plugin Slug:
- wish-list-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13774
SearchIQ – The Search Solution
- Plugin:
- SearchIQ – The Search Solution
- Plugin Slug:
- searchiq
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13350
Point Maker
- Plugin:
- Point Maker
- Plugin Slug:
- point-maker
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12815
Recently Purchased Products For Woo
- Plugin Slug:
- recently-purchased-products-for-woo
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1008
Allow PHP Execute
- Plugin:
- Allow PHP Execute
- Plugin Slug:
- allow-php-execute
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13890
Code Snippets CPT
- Plugin:
- Code Snippets CPT
- Plugin Slug:
- code-snippets-cpt
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13895
Contact Us By Lord Linus
- Plugin:
- Contact Us By Lord Linus
- Plugin Slug:
- contact-us-by-lord-linus
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-1382
CS Framework
- Plugin:
- CS Framework
- Plugin Slug:
- cs-framework
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-12036
DesignThemes Core Features
- Plugin:
- DesignThemes Core Features
- Plugin Slug:
- designthemes-core-features
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13471
Download HTML TinyMCE Button
- Plugin:
- Download HTML TinyMCE Button
- Plugin Slug:
- download-html-tinymce-button
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-1286
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
- Plugin:
- URL Shortener | Conversion Tracking | AB Testing | WooCommerce
- Plugin Slug:
- easy-broken-link-checker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1363
URL Shortener | Conversion Tracking | AB Testing | WooCommerce
- Plugin:
- URL Shortener | Conversion Tracking | AB Testing | WooCommerce
- Plugin Slug:
- easy-broken-link-checker
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1362
WooMail
- Plugin:
- WooMail
- Plugin Slug:
- email-customizer-for-woocommerce-with-drag-drop-builder
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13747
Email Keep
- Plugin:
- Email Keep
- Plugin Slug:
- email-keep
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13826
Email Keep
- Plugin:
- Email Keep
- Plugin Slug:
- email-keep
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13825
Ultimate Video Player
- Plugin:
- Ultimate Video Player
- Plugin Slug:
- fwduvp
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-10804
I Am Gloria
- Plugin:
- I Am Gloria
- Plugin Slug:
- gloria-assistant-by-webtronic-labs
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-0990
Hero Maps Premium
- Plugin:
- Hero Maps Premium
- Plugin Slug:
- hmapsprem
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13781
Hero Mega Menu – Responsive WordPress Menu Plugin
- Plugin:
- Hero Mega Menu – Responsive WordPress Menu Plugin
- Plugin Slug:
- hmenu
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13780
Hero Slider
- Plugin:
- Hero Slider
- Plugin Slug:
- hslide
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13809
InWave Jobs
- Plugin:
- InWave Jobs
- Plugin Slug:
- iwjob
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-1315
Limit Bio
- Plugin:
- Limit Bio
- Plugin Slug:
- limit-bio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-1436
Limit Bio
- Plugin:
- Limit Bio
- Plugin Slug:
- limit-bio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13884
Link My Posts
- Plugin:
- Link My Posts
- Plugin Slug:
- linkmyposts
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13881
mEintopf
- Plugin:
- mEintopf
- Plugin Slug:
- meintopf
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13876
miniOrange Social Login and Register Pro Addon
- Plugin:
- miniOrange Social Login and Register Pro Addon
- Plugin Slug:
- miniorange-login-openid-pro
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-11087
My Quota
- Plugin:
- My Quota
- Plugin Slug:
- my-quota
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13880
Ninja Pages
- Plugin:
- Ninja Pages
- Plugin Slug:
- ninja-page-categories-and-tags
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1454
WP Online Contract
- Plugin:
- WP Online Contract
- Plugin Slug:
- onlinecontract
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-0954
Passbeemedia Web Push Notification
- Plugin:
- Passbeemedia Web Push Notification
- Plugin Slug:
- passbeemedia-web-push-notifications
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13877
Post Lockdown
- Plugin:
- Post Lockdown
- Plugin Slug:
- post-lockdown
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1504
Post Meta Data Manager
- Plugin:
- Post Meta Data Manager
- Plugin Slug:
- post-meta-data-manager
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13835
WooCommerce Recover Abandoned Cart
- Plugin:
- WooCommerce Recover Abandoned Cart
- Plugin Slug:
- rac
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-0956
Razorpay Subscription Button Elementor Plugin
- Plugin:
- Razorpay Subscription Button Elementor Plugin
- Plugin Slug:
- razorpay-subscription-button-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13827
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12610
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-12611
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-9658
Shortcode Cleaner Lite
- Plugin:
- Shortcode Cleaner Lite
- Plugin Slug:
- shortcode-cleaner-lite
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1481
Simple Notification
- Plugin:
- Simple Notification
- Plugin Slug:
- simple-notification
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13866
SpotBot
- Plugin:
- SpotBot
- Plugin Slug:
- spotbot
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13878
WoWPth
- Plugin:
- WoWPth
- Plugin Slug:
- wowpth
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-1486
WordPress Awesome Import & Export Plugin – Import & Export WordPress Data
- Plugin:
- WordPress Awesome Import & Export Plugin – Import & Export WordPress Data
- Plugin Slug:
- wp-awesome-import-export
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13232
WP Click Info
- Plugin:
- WP Click Info
- Plugin Slug:
- wp-click-info
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-1401
WP e-Customers Beta
- Plugin:
- WP e-Customers Beta
- Plugin Slug:
- wp-e-customers
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13885
WP-PManager
- Plugin:
- WP-PManager
- Plugin Slug:
- wp-programmmanager
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13875
WP Real Estate Manager
- Plugin:
- WP Real Estate Manager
- Plugin Slug:
- wp-realestate-manager
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-1515
Years Since
- Plugin:
- Years Since
- Plugin Slug:
- years-since
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12460
PixelYourSite – Your smart PIXEL (TAG) & API Manager
- Plugin Slug:
- pixelyoursite
- Installations
- 500,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 10.1.1.2
- Severity Score:
- Critical
- CVE:
- 2025-0769
WP Shortcodes Plugin — Shortcodes Ultimate
- Plugin Slug:
- shortcodes-ultimate
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.3.4
- Severity Score:
- Medium
- CVE:
- 2025-0370
Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more
- Plugin Slug:
- post-smtp
- Installations
- 400,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.1.3
- Severity Score:
- High
- CVE:
- 2024-13844
Page Builder: Pagelayer – Drag and Drop website builder
- Plugin Slug:
- pagelayer
- Installations
- 200,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.9.9
- Severity Score:
- Medium
- CVE:
- 2025-1926
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.10.1
- Severity Score:
- Critical
- CVE:
- 2025-1702
WP Activity Log
- Plugin:
- WP Activity Log
- Plugin Slug:
- wp-security-audit-log
- Installations
- 200,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 5.3.3
- Severity Score:
- High
- CVE:
- 2025-0767
Admin and Site Enhancements (ASE)
- Plugin Slug:
- admin-site-enhancements
- Installations
- 100,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 7.6.10
- Severity Score:
- Medium
- CVE:
- 2024-13685
bbPress
Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics
- Plugin Slug:
- cookiebot
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.4.2
- Severity Score:
- Medium
- CVE:
- 2025-1666
Download Manager
- Plugin:
- Download Manager
- Plugin Slug:
- download-manager
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.3.07
- Severity Score:
- Medium
- CVE:
- 2024-13126
Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates
- Plugin Slug:
- essential-blocks
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.2
- Severity Score:
- Medium
- CVE:
- 2025-1664
Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin
- Plugin Slug:
- file-manager-advanced
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.0
- Severity Score:
- Medium
- CVE:
- 2024-13805
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel
- Plugin Slug:
- foogallery
- Installations
- 100,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.4.30
- Severity Score:
- Medium
- CVE:
- 2024-12114
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel
- Plugin Slug:
- foogallery
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.30
- Severity Score:
- Medium
- CVE:
- 2024-12119
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel
- Plugin Slug:
- foogallery
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.30
- Severity Score:
- High
- CVE:
- 2025-22624
GiveWP – Donation Plugin and Fundraising Platform
- Plugin Slug:
- give
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.20.0
- Severity Score:
- Critical
- CVE:
- 2025-0912
SEO Plugin by Squirrly SEO
- Plugin:
- SEO Plugin by Squirrly SEO
- Plugin Slug:
- squirrly-seo
- Installations
- 100,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 12.4.06
- Severity Score:
- High
- CVE:
- 2025-1768
The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin:
- The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.2.3
- Severity Score:
- Medium
- CVE:
- 2025-1287
VK Blocks
- Plugin:
- VK Blocks
- Plugin Slug:
- vk-blocks
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.95.0.3
- Severity Score:
- Medium
- CVE:
- 2024-13635
HUSKY – Products Filter Professional for WooCommerce
- Plugin Slug:
- woocommerce-products-filter
- Installations
- 100,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.6.6
- Severity Score:
- High
- CVE:
- 2025-1661
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.3
- Severity Score:
- Medium
- CVE:
- 2025-1261
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
- Plugin Slug:
- simply-schedule-appointments
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.8.5
- Severity Score:
- High
- CVE:
- 2024-13431
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations
- Plugin Slug:
- master-addons
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.7.3
- Severity Score:
- Medium
- CVE:
- 2024-9618
Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations
- Plugin Slug:
- master-addons
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.7.2
- Severity Score:
- Medium
- CVE:
- 2025-0433
Print Invoice & Delivery Notes for WooCommerce
- Plugin Slug:
- woocommerce-delivery-notes
- Installations
- 30,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-13640
Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors
- Plugin Slug:
- publishpress-authors
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.7.4
- Severity Score:
- High
- CVE:
- 2025-26886
RomethemeKit For Elementor
- Plugin:
- RomethemeKit For Elementor
- Plugin Slug:
- rometheme-for-elementor
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.4
- Severity Score:
- Medium
- CVE:
- 2024-10326
140+ Widgets | Xpro Addons For Elementor – FREE
- Plugin Slug:
- xpro-elementor-addons
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.6.8
- Severity Score:
- Medium
- CVE:
- 2024-13649
Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress
- Plugin Slug:
- gallery-plugin
- Installations
- 10,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 4.7.4
- Severity Score:
- High
- CVE:
- 2024-13906
Qubely – Advanced Gutenberg Blocks
- Plugin Slug:
- qubely
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.8.14
- Severity Score:
- Medium
- CVE:
- 2024-13228
SupportCandy – Helpdesk & Customer Support Ticket System
- Plugin Slug:
- supportcandy
- Installations
- 10,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.3.1
- Severity Score:
- Medium
- CVE:
- 2024-13552
UiPress lite | Effortless custom dashboards, admin themes and pages
- Plugin Slug:
- uipress-lite
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.05
- Severity Score:
- High
- CVE:
- 2025-1309
WPGet API – Connect to any external REST API
- Plugin Slug:
- wpgetapi
- Installations
- 10,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.25.1
- Severity Score:
- Medium
- CVE:
- 2024-13857
Notibar – Notification Bar for WordPress
- Plugin Slug:
- notibar
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.6
- Severity Score:
- Medium
- CVE:
- 2025-1672
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.7.4
- Severity Score:
- Medium
- CVE:
- 2024-13526
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.2.3
- Severity Score:
- Medium
- CVE:
- 2025-1383
Product Input Fields for WooCommerce
- Plugin Slug:
- product-input-fields-for-woocommerce
- Installations
- 5,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.12.2
- Severity Score:
- High
- CVE:
- 2024-13359
Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins
- Plugin:
- Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins
- Plugin Slug:
- related-post
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.60
- Severity Score:
- High
- CVE:
- 2024-12634
VikRentCar Car Rental Management System
- Plugin Slug:
- vikrentcar
- Installations
- 4,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.4.3
- Severity Score:
- High
- CVE:
- 2024-11640
WP Posts Carousel
- Plugin:
- WP Posts Carousel
- Plugin Slug:
- wp-posts-carousel
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.8
- Severity Score:
- Medium
- CVE:
- 2025-1491
Moving Media Library
- Plugin:
- Moving Media Library
- Plugin Slug:
- moving-media-library
- Installations
- 3,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 1.23
- Severity Score:
- Medium
- CVE:
- 2024-13897
Wallet System for WooCommerce
- Plugin:
- Wallet System for WooCommerce
- Plugin Slug:
- wallet-system-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.6.3
- Severity Score:
- Medium
- CVE:
- 2024-13682
Wallet System for WooCommerce
- Plugin:
- Wallet System for WooCommerce
- Plugin Slug:
- wallet-system-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.3
- Severity Score:
- Medium
- CVE:
- 2024-13724
SMTP by BestWebSoft
- Plugin:
- SMTP by BestWebSoft
- Plugin Slug:
- bws-smtp
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.2.0
- Severity Score:
- High
- CVE:
- 2024-13908
Eventer
teachPress
- Plugin:
- teachPress
- Plugin Slug:
- teachpress
- Installations
- 2,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 9.0.8
- Severity Score:
- High
- CVE:
- 2025-1321
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 16.26.12
- Severity Score:
- Medium
- CVE:
- 2025-1322
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 2,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 16.26.12
- Severity Score:
- Critical
- CVE:
- 2025-1323
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 16.26.12
- Severity Score:
- Medium
- CVE:
- 2025-1325
WP-Recall – Registration, Profile, Commerce & More
- Plugin Slug:
- wp-recall
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 16.26.12
- Severity Score:
- Medium
- CVE:
- 2025-1324
WPCOM Member
- Plugin:
- WPCOM Member
- Plugin Slug:
- wpcom-member
- Installations
- 2,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.7.6
- Severity Score:
- Critical
- CVE:
- 2025-1475
Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table.
- Plugin Slug:
- wpgsi
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.8.3
- Severity Score:
- Medium
- CVE:
- 2025-1463
WPCS – WordPress Currency Switcher Professional
- Plugin Slug:
- currency-switcher
- Installations
- 1,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 1.2.0.5
- Severity Score:
- High
- CVE:
- 2025-2169
Flexmls® IDX Plugin
- Plugin:
- Flexmls® IDX Plugin
- Plugin Slug:
- flexmls-idx
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.14.29
- Severity Score:
- Medium
- CVE:
- 2025-0863
Greek Multi Tool – Fix peralinks, accents, auto create menus and more
- Plugin Slug:
- greek-multi-tool
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.2
- Severity Score:
- High
Simple Download Counter
- Plugin:
- Simple Download Counter
- Plugin Slug:
- simple-download-counter
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 2.1
- Severity Score:
- Medium
- CVE:
- 2025-1730
Solace Extra
- Plugin:
- Solace Extra
- Plugin Slug:
- solace-extra
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.3.1
- Severity Score:
- High
Ultimate WordPress Auction Plugin
- Plugin Slug:
- ultimate-auction
- Installations
- 1,000+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 4.3.0
- Severity Score:
- High
- CVE:
- 2025-0958
m1.DownloadList
- Plugin:
- m1.DownloadList
- Plugin Slug:
- m1downloadlist
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.20
- Severity Score:
- Medium
- CVE:
- 2025-26895
WordPress abandoned cart recovery and email marketing for WooCommerce by Recapture
- Plugin Slug:
- recapture-for-woocommerce
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.44
- Severity Score:
- Medium
- CVE:
- 2025-26899
Gallery Styles
- Plugin:
- Gallery Styles
- Plugin Slug:
- gallery-styles
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2025-1783
Reservit Hotel
- Plugin:
- Reservit Hotel
- Plugin Slug:
- reservit-hotel
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0
- Severity Score:
- Medium
- CVE:
- 2024-9458
Multiple Shipping And Billing Address For Woocommerce
- Plugin Slug:
- different-shipping-and-billing-address-for-woocommerce
- Installations
- 200+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5
- Severity Score:
- Critical
- CVE:
- 2025-26875
WPBookit
- Plugin:
- WPBookit
- Plugin Slug:
- wpbookit
- Installations
- 70+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.2
- Severity Score:
- High
- CVE:
- 2025-26910
Appsero Helper
- Plugin:
- Appsero Helper
- Plugin Slug:
- appsero-helper
- Installations
- 50+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.3
- Severity Score:
- High
- CVE:
- 2024-13436
Platform.ly for WooCommerce
- Plugin:
- Platform.ly for WooCommerce
- Plugin Slug:
- platformly-for-woocommerce
- Installations
- 10+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.1.7
- Severity Score:
- Medium
- CVE:
- 2024-13904
Aiomatic
- Plugin:
- Aiomatic
- Plugin Slug:
- aiomatic-automatic-ai-content-writer
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.3.9
- Severity Score:
- High
- CVE:
- 2024-13882
Aiomatic
- Plugin:
- Aiomatic
- Plugin Slug:
- aiomatic-automatic-ai-content-writer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3.7
- Severity Score:
- Medium
- CVE:
- 2024-13816
Animation Addons for Elementor Pro
- Plugin:
- Animation Addons for Elementor Pro
- Plugin Slug:
- animation-addons-for-elementor-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7
- Severity Score:
- High
- CVE:
- 2025-1639
CS Framework
- Plugin:
- CS Framework
- Plugin Slug:
- cs-framework
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 7.1
- Severity Score:
- High
- CVE:
- 2024-12035
Edd Google Sheet Connector Pro
- Plugin:
- Edd Google Sheet Connector Pro
- Plugin Slug:
- edd-google-sheet-connector-pro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.4
- Severity Score:
- Medium
- CVE:
- 2023-2334
Easy Digital Downloads Google Sheet Connector
- Plugin Slug:
- gsheetconnector-easy-digital-downloads
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.6.6
- Severity Score:
- Medium
- CVE:
- 2023-2334
Gtbabel
- Plugin:
- Gtbabel
- Plugin Slug:
- gtbabel
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 6.6.9
- Severity Score:
- High
- CVE:
- 2024-11638
Javo Core
- Plugin:
- Javo Core
- Plugin Slug:
- javo-core
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.0.0.266
- Severity Score:
- Critical
- CVE:
- 2025-0177
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- SQL Injection
- Patched in Version:
- 93.0.0
- Severity Score:
- High
- CVE:
- 2024-12607
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- SQL Injection
- Patched in Version:
- 93.0.0
- Severity Score:
- High
- CVE:
- 2024-12609
Social Share And Social Locker
- Plugin:
- Social Share And Social Locker
- Plugin Slug:
- social-share-and-social-locker-arsocial
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2024-11189
WooCommerce Multi Currency – Currency Switcher
- Plugin:
- WooCommerce Multi Currency – Currency Switcher
- Plugin Slug:
- woocommerce-multi-currency
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.3.7
- Severity Score:
- Critical
- CVE:
- 2024-13320
WordPress Themes — 8 Patched / 6 Unpatched
Sparkling
- Theme:
- Sparkling
- Theme Slug:
- sparkling
- Downloads
- 1,345,012
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13423
Homey
- Theme:
- Homey
- Theme Slug:
- homey
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-12281
Lafka
- Theme:
- Lafka
- Theme Slug:
- lafka
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13811
Listingo
- Theme:
- Listingo
- Theme Slug:
- listingo
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13815
VEDA
- Theme:
- VEDA
- Theme Slug:
- veda
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13787
Zass
- Theme:
- Zass
- Theme Slug:
- zass
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13810
Newscrunch
- Theme:
- Newscrunch
- Theme Slug:
- newscrunch
- Downloads
- 177,662
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.8.4.1
- Severity Score:
- Critical
- CVE:
- 2025-1307
Newscrunch
- Theme:
- Newscrunch
- Theme Slug:
- newscrunch
- Downloads
- 177,662
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.8.4.1
- Severity Score:
- High
- CVE:
- 2025-1306
VW Storefront
- Theme:
- VW Storefront
- Theme Slug:
- vw-storefront
- Downloads
- 60,192
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.0
- Severity Score:
- Medium
- CVE:
- 2024-13686
Flex Mag
- Theme:
- Flex Mag
- Theme Slug:
- flex-mag
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.0
- Severity Score:
- High
- CVE:
- 2024-13655
Golo
- Theme:
- Golo
- Theme Slug:
- golo
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.11
- Severity Score:
- Critical
- CVE:
- 2024-12876
Homey
- Theme:
- Homey
- Theme Slug:
- homey
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.4.4
- Severity Score:
- Medium
- CVE:
- 2025-0748
Homey
- Theme:
- Homey
- Theme Slug:
- homey
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.4.4
- Severity Score:
- High
- CVE:
- 2025-0749
JNews
- Theme:
- JNews
- Theme Slug:
- jnews
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 11.6.7
- Severity Score:
- Medium
- CVE:
- 2024-8682
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
