WordPress Vulnerability Report

WordPress Vulnerability Report — April 23, 2025

Since last week, 304 new vulnerabilities emerged in the WordPress ecosystem, including 279 plugins and 25 themes. 142 of the vulnerable plugins remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 304 vulnerabilities have been publicly disclosed. Security patches for 162 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 142 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8 “Cecil” is here! Launched April 15, 2025, it honors jazz legend Cecil Taylor, whose pioneering piano fused chaos and harmony. Explore its bold features with the same experimental spirit.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 153 Patched / 126 Unpatched

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Sitemap – Create a Responsive HTML Sitemap

Plugin Slug:
simple-sitemap
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scriptless Social Sharing

Plugin Slug:
scriptless-social-sharing
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
logo-carousel-slider
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Checkout Files Upload for WooCommerce

Plugin Slug:
checkout-files-upload-woocommerce
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

License For Envato

Plugin Slug:
license-envato
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hotel Booking

Plugin Slug:
nd-booking
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACF: Google Font Selector

Plugin Slug:
acf-google-font-selector-field
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Anything Popup

Plugin Slug:
anything-popup
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Directory Listings WordPress plugin – uListing

Plugin Slug:
ulisting
Installations
2,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ActiveDEMAND

Plugin Slug:
activedemand
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Basic Interactive World Map

Plugin Slug:
basic-interactive-world-map
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rescue Shortcodes

Plugin Slug:
rescue-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Attendance Manager

Plugin Slug:
attendance-manager
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs
Installations
800+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Movylo Marketing Automation

Plugin Slug:
movylo-widget
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Flipclock

Plugin Slug:
wp-flipclock
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
700+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG – Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps
Installations
700+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Question Answer

Plugin Slug:
question-answer
Installations
600+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spice Blocks

Plugin Slug:
spice-blocks
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooMS

Plugin:
WooMS
Plugin Slug:
wooms
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Author WIP Progress Bar

Plugin Slug:
author-work-in-progress-bar
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Term Editor

Plugin Slug:
bulk-term-editor
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-advanced-search
Installations
500+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Page Stub Creator

Plugin Slug:
bulk-page-stub-creator
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rating by BestWebSoft

Plugin Slug:
rating-bws
Installations
400+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Site Search 360

Plugin Slug:
site-search-360
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form vCard Generator

Plugin Slug:
contact-form-vcard-generator
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Projectopia – WordPress Project Management

Plugin Slug:
projectopia-core
Installations
300+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BruteGuard – Brute Force Login Protection

Plugin Slug:
bruteguard
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Post

Plugin Slug:
dynamic-post
Installations
200+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Starfish Review Generation & Marketing for WordPress

Plugin Slug:
starfish-reviews
Installations
200+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Capturly

Plugin:
Capturly
Plugin Slug:
capturly-optimize-your-website
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Course Booking System

Plugin Slug:
course-booking-system
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HelpGent – The Ultimate Form Builder & TypeForm Alternative on WordPress | Craft Conversational Multi Step Form with Video, Voice, Screen Recording, & Text Messaging

Plugin Slug:
helpgent
Installations
100+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Local Magic

Plugin Slug:
local-magic
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PDF 2 Post

Plugin:
PDF 2 Post
Plugin Slug:
pdf2post
Installations
100+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Slazzer Background Changer

Plugin Slug:
slazzer-background-changer
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Changer

Plugin Slug:
theme-changer
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
woocommerce-products-without-featured-images
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
80+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Checkout Field Visibility for WooCommerce

Plugin Slug:
checkout-field-visibility-for-woocommerce
Installations
80+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Lister for eBay

Plugin Slug:
product-lister-ebay
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tp-gallery-slider
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP_DEBUG Toggle

Plugin Slug:
enable-wp-debug-toggle
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Appsero Helper

Plugin Slug:
appsero-helper
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Office Locator

Plugin Slug:
office-locator
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Donate

Plugin:
WP Donate
Plugin Slug:
wp-donate
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ShopApper: Mobile App for WooCommerce

Plugin Slug:
mobile-app-for-woocommerce
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BMA Lite – Appointment Booking and Scheduling Plugin

Plugin Slug:
bma-lite-appointment-booking-and-scheduling
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Event Espresso – Custom Email Template Shortcode

Plugin Slug:
email-shortcode
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZooEffect

Plugin:
ZooEffect
Plugin Slug:
1-jquery-photo-gallery-slideshow-flash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add to Header

Plugin:
Add to Header
Plugin Slug:
add-to-header
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Showcase WordPress Plugin

Plugin:
Amazon Showcase WordPress Plugin
Plugin Slug:
amazon-showcase-wordpress-widget
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AnalyticsWP

Plugin:
AnalyticsWP
Plugin Slug:
analyticswp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AnalyticsWP

Plugin:
AnalyticsWP
Plugin Slug:
analyticswp
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Anthologize

Plugin:
Anthologize
Plugin Slug:
anthologize
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Avatar

Plugin:
Avatar
Plugin Slug:
avatar
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Avatar

Plugin:
Avatar
Plugin Slug:
avatar
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bbPress2 shortcode whitelist

Plugin:
bbPress2 shortcode whitelist
Plugin Slug:
bbpress2-shortcode-whitelist
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bknewsticker

Plugin:
Bknewsticker
Plugin Slug:
bknewsticker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Broken Links Remover
Plugin Slug:
broken-links-remover
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Login Manager

Plugin:
Login Manager
Plugin Slug:
customized-login
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Notepads

Plugin:
Dashboard Notepads
Plugin Slug:
dashboard-notepads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:
FAT Services Booking
Plugin Slug:
fat-services-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Foodbakery Sticky Cart

Plugin:
Foodbakery Sticky Cart
Plugin Slug:
foodbakery-sticky-cart
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Grand Conference

Plugin:
Grand Conference
Plugin Slug:
grandconference
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gravity Forms CSS Themes with Fontawesome and Placeholders

Plugin:
Gravity Forms CSS Themes with Fontawesome and Placeholders
Plugin Slug:
gravity-forms-css-themes-with-fontawesome-and-placeholder-support
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

hockeydata LOS

Plugin:
hockeydata LOS
Plugin Slug:
hockeydata-los
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

I Draw

Plugin:
I Draw
Plugin Slug:
idraw
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple Maps

Plugin:
Simple Maps
Plugin Slug:
interactive-maps
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
illow – Cookies Consent
Plugin Slug:
lgpd-compliant-cookie-banner
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Macro Calculator with Admin Email Optin & Data

Plugin:
Macro Calculator with Admin Email Optin & Data
Plugin Slug:
macro-admin-email-data-optin-calculator
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Memberpress

Plugin:
Memberpress
Plugin Slug:
memberpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

mLanguage

Plugin:
mLanguage
Plugin Slug:
mlanguage
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Modal Survey

Plugin:
Modal Survey
Plugin Slug:
modal-survey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Modal Survey

Plugin:
Modal Survey
Plugin Slug:
modal-survey
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Modal Survey

Plugin:
Modal Survey
Plugin Slug:
modal-survey
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

My auctions allegro

Plugin:
My auctions allegro
Plugin Slug:
my-auctions-allegro-free-edition
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Marginalia

Plugin:
My Marginalia
Plugin Slug:
my-marginalia
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Redirect wordpress to welcome or landing page

Plugin:
Redirect wordpress to welcome or landing page
Plugin Slug:
redirect-to-welcome-or-landing-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Review Wave – Google Places Reviews

Plugin:
Review Wave – Google Places Reviews
Plugin Slug:
review-wave-google-places-reviews
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Revision Diet

Plugin:
Revision Diet
Plugin Slug:
revision-diet
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:
Revy
Plugin Slug:
revy
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SUMO Reward Points

Plugin:
SUMO Reward Points
Plugin Slug:
rewardsystem
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RSS Manager

Plugin:
RSS Manager
Plugin Slug:
rss-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Media Links
Plugin Slug:
social-media-links
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

spam-stopper

Plugin:
spam-stopper
Plugin Slug:
spam-stopper
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Style Manager

Plugin:
Style Manager
Plugin Slug:
style-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Széchenyi 2020 Logo
Plugin Slug:
szechenyi-2020-logo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Slider And Showcase Pro

Plugin:
Testimonial Slider And Showcase Pro
Plugin Slug:
testimonial-slider-showcase-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

translit it!

Plugin:
translit it!
Plugin Slug:
translit-it
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TuriTop Booking System

Plugin:
TuriTop Booking System
Plugin Slug:
turitop-booking-system
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Sections Theme Builder – WPBakery Page Builder Addon

Plugin:
Smart Sections Theme Builder – WPBakery Page Builder Addon
Plugin Slug:
visucom-smart-sections
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Post to PDF Enhanced

Plugin:
WP Post to PDF Enhanced
Plugin Slug:
wp-post-to-pdf-enhanced
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Bookmarking

Plugin:
WP Social Bookmarking
Plugin Slug:
wp-social-bookmarking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Sticky Side Buttons

Plugin:
WP Sticky Side Buttons
Plugin Slug:
wp-sticky-side-buttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Syntax

Plugin:
WP Syntax
Plugin Slug:
wp-syntax
Vulnerability:
Denial of Service Attack
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

WP Twitter Button

Plugin:
WP Twitter Button
Plugin Slug:
wp-twitter-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Video Robot – The Ultimate Video Importer

Plugin:
WordPress Video Robot – The Ultimate Video Importer
Plugin Slug:
wp-video-robot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wpLike2Get

Plugin:
wpLike2Get
Plugin Slug:
wplike2get
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WhatsApp Click to Chat Plugin for WordPress

Plugin:
WhatsApp Click to Chat Plugin for WordPress
Plugin Slug:
wpt-whatsapp
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xelion Webchat

Plugin:
Xelion Webchat
Plugin Slug:
xelion-webchat
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7

Plugin Slug:
contact-form-7
Installations
10,000,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
6.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.6.
Plugin Slug:
essential-addons-for-elementor-lite
Installations
2,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.10.
Plugin Slug:
essential-addons-for-elementor-lite
Installations
2,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.10.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Content Injection
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.979
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.979.

Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more

Plugin Slug:
password-protected
Installations
300,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.8.

Insert Headers And Footers

Plugin Slug:
wp-headers-and-footers
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.2.

Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.29.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.3.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.13.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.13.

Kadence WooCommerce Email Designer

Plugin Slug:
kadence-woocommerce-email-designer
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.5.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.15.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Open Redirection
Patched in Version:
3.3.74
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.74.

WordPress Button Plugin MaxButtons

Plugin Slug:
maxbuttons
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.4.

Widget for Social Page Feeds

Plugin Slug:
facebook-pagelike-widget
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
11.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.4.6.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.28.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.94.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.94.10.

Contact Form & SMTP Plugin for WordPress by PirateForms

Plugin Slug:
pirate-forms
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.68
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.68.

Social Slider Feed

Plugin Slug:
instagram-slider-widget
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.9.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.9.18.

WP Editor

Plugin:
WP Editor
Plugin Slug:
wp-editor
Installations
30,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.2.

WP Editor

Plugin:
WP Editor
Plugin Slug:
wp-editor
Installations
30,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.2.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.9.2.

Advanced Dynamic Pricing for WooCommerce

Plugin Slug:
advanced-dynamic-pricing-for-woocommerce
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.5.

Docket Cache – Object Cache Accelerator

Plugin Slug:
docket-cache
Installations
20,000+
Vulnerability:
Local File Inclusion
Patched in Version:
24.07.03
Severity Score:
High
The vulnerability has been patched, so you should update to version 24.07.03.

WordPress REST API Authentication

Plugin Slug:
wp-rest-api-authentication
Installations
20,000+
Vulnerability:
Settings Change
Patched in Version:
3.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.

WP Simple Booking Calendar

Plugin Slug:
wp-simple-booking-calendar
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.14.

AFI – The Easiest Integration Plugin

Plugin Slug:
advanced-form-integration
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.100.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.100.0.

Conditional Payments for WooCommerce

Plugin Slug:
conditional-payments-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Conditional Shipping for WooCommerce

Plugin Slug:
conditional-shipping-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

HTML5 Audio Player- Best WordPress Audio Player Plugin

Plugin Slug:
html5-audio-player
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.

Klarna Checkout for WooCommerce

Plugin Slug:
klarna-checkout-for-woocommerce
Installations
10,000+
Vulnerability:
Denial of Service Attack
Patched in Version:
2.13.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.13.5.

Mediavine Control Panel

Plugin Slug:
mediavine-control-panel
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.10.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.7.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.6.

Themify Shortcodes

Plugin Slug:
themify-shortcodes
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.4.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.30.

Debug Log Manager

Plugin Slug:
debug-log-manager
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.5.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.4.9.

Drag and Drop Multiple File Upload for WooCommerce

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce
Installations
6,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.5.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.1.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
awesome-logo-carousel-block
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.6.3.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.
Plugin Slug:
wp-posts-carousel
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.11.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.30.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.30.1.

Property Hive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

GoodBarber

Plugin:
GoodBarber
Plugin Slug:
goodbarber
Installations
2,000+
Vulnerability:
Open Redirection
Patched in Version:
1.0.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.27.

MelaPress Login Security

Plugin Slug:
melapress-login-security
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.8.

Membership For WooCommerce

Plugin Slug:
membership-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.1.

Most And Least Read Posts Widget

Plugin Slug:
most-and-least-read-posts-widget
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.21.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Smart Maintenance Mode

Plugin Slug:
smart-maintenance-mode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

Tourfic Toolkit

Plugin Slug:
travelfic-toolkit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.

Ever Accounting – WordPress Accounting and Invoice Plugin

Plugin Slug:
wp-ever-accounting
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Integration for WooCommerce and QuickBooks

Plugin Slug:
wp-woocommerce-quickbooks
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

WPCasa

Plugin:
WPCasa
Plugin Slug:
wpcasa
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.201
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.201.

Arigato Autoresponder and Newsletter

Plugin Slug:
bft-autoresponder
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.5.

Church Admin

Plugin Slug:
church-admin
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.10.

Church Admin

Plugin Slug:
church-admin
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.24.

Checkout for PayPal

Plugin Slug:
checkout-for-paypal
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.39
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.39.

OTP-less one tap Sign in

Plugin Slug:
otpless
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.59
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.59.

BERTHA AI. Your AI co-pilot for WordPress and Chrome

Plugin Slug:
bertha-ai-free
Installations
600+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
1.12.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.12.11.

Bring Fraktguiden for WooCommerce

Plugin Slug:
bring-fraktguiden-for-woocommerce
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
1.11.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.5.

Verge3D Publishing and E-Commerce

Plugin Slug:
verge3d
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

Cloak Front End Email

Plugin Slug:
cloak-front-end-email
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.6.

Quentn WP

Plugin:
Quentn WP
Plugin Slug:
quentn-wp
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
1.2.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.9.

Quentn WP

Plugin:
Quentn WP
Plugin Slug:
quentn-wp
Installations
500+
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.9.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.9.

Administrator Z

Plugin Slug:
administrator-z
Installations
400+
Vulnerability:
Directory Traversal
Patched in Version:
2025.03.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2025.03.30.

Administrator Z

Plugin Slug:
administrator-z
Installations
400+
Vulnerability:
Privilege Escalation
Patched in Version:
2025.03.27
Severity Score:
High
The vulnerability has been patched, so you should update to version 2025.03.27.

Custom CSS, JS & PHP

Plugin Slug:
custom-css
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.2.

Uix Shortcodes

Plugin Slug:
uix-shortcodes
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

Sell access, Automate, and add Engaging Exclusive Discord Access: Introducing the MemberPress Discord Addon — Elevate Your Community!

Plugin Slug:
expresstechsoftwares-memberpress-discord-add-on
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Fast eBay Listings

Plugin Slug:
fast-ebay-listings
Installations
300+
Vulnerability:
Open Redirection
Patched in Version:
2.12.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.16.

TableOn – WordPress Posts Table Filterable 

Plugin Slug:
posts-table-filterable
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

SB Chart block

Plugin Slug:
sb-chart-block
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Tax Switch for WooCommerce

Plugin Slug:
tax-switch-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

WP Logger

Plugin:
WP Logger
Plugin Slug:
wp-data-logger
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

AdminQuickbar

Plugin Slug:
adminquickbar
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.2.

Feedify – Web Push Notifications

Plugin Slug:
push-notification-by-feedify
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.6.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.7.

Dashi

Plugin:
Dashi
Plugin Slug:
dashi
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.9.
Plugin Slug:
internal-link-finder
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.4.

IP2Location Variables

Plugin Slug:
ip2location-variables
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.6.

Right Click Disable OR Ban

Plugin Slug:
right-click-disable-or-ban
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Verowa Connect

Plugin Slug:
verowa-connect
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.5.

Email Notifications for Updates

Plugin Slug:
wp-update-mail-notification
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

Material Dashboard

Plugin Slug:
material-dashboard
Installations
80+
Vulnerability:
Privilege Escalation
Patched in Version:
1.4.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.7.

AI Text to Speech – TTS Plugin For WordPress

Plugin Slug:
ai-text-to-speech
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
60+
Vulnerability:
SQL Injection
Patched in Version:
1.1.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.7.

StoreContrl Woocommerce

Plugin Slug:
storecontrl-wp-connection
Installations
60+
Vulnerability:
Arbitrary File Download
Patched in Version:
4.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.4.

Smart Agreements

Plugin Slug:
smart-agreements
Installations
40+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

Payment Form for PayPal Pro

Plugin Slug:
payment-form-for-paypal-pro
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.73
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.73.

AnalyticsWP

Plugin:
AnalyticsWP
Plugin Slug:
analyticswp
Vulnerability:
SQL Injection
Patched in Version:
2.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.5.

Booster Plus for WooCommerce

Plugin:
Booster Plus for WooCommerce
Plugin Slug:
booster-plus-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.5.

FS Poster

Plugin:
FS Poster
Plugin Slug:
fs-poster
Vulnerability:
Broken Access Control
Patched in Version:
7.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.8.

JetBlocks For Elementor

Plugin:
JetBlocks For Elementor
Plugin Slug:
jet-blocks
Vulnerability:
Broken Access Control
Patched in Version:
1.3.16.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.16.1.

JetBlog

Plugin:
JetBlog
Plugin Slug:
jet-blog
Vulnerability:
Broken Access Control
Patched in Version:
2.4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.3.1.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Broken Access Control
Patched in Version:
2.7.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.2.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.2.

JetMenu

Plugin:
JetMenu
Plugin Slug:
jet-menu
Vulnerability:
Broken Access Control
Patched in Version:
2.4.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.9.1.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Broken Access Control
Patched in Version:
2.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.12.

JetReviews

Plugin:
JetReviews
Plugin Slug:
jet-reviews
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.7.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

JetTricks

Plugin:
JetTricks
Plugin Slug:
jet-tricks
Vulnerability:
Broken Access Control
Patched in Version:
1.5.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.1.

JetWooBuilder

Plugin:
JetWooBuilder
Plugin Slug:
jet-woo-builder
Vulnerability:
Broken Access Control
Patched in Version:
2.1.18.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.18.1.

CLEVER

Plugin:
CLEVER
Plugin Slug:
lbg-audio11-html5-shoutcast_history
Vulnerability:
Path Traversal
Patched in Version:
2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.

Live Forms

Plugin:
Live Forms
Plugin Slug:
liveforms
Vulnerability:
Broken Access Control
Patched in Version:
4.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.5.

Smart Product Review

Plugin:
Smart Product Review
Plugin Slug:
smart-product-review
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
SQL Injection
Patched in Version:
7.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.5.

Tourmaster

Plugin:
Tourmaster
Plugin Slug:
tourmaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.1.

Unlimited Timeline

Plugin:
Unlimited Timeline
Plugin Slug:
unlimited-timeline
Vulnerability:
Broken Access Control
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

UrbanGo Membership

Plugin:
UrbanGo Membership
Plugin Slug:
urbango-membership
Vulnerability:
Privilege Escalation
Patched in Version:
1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.

User Registration & Membership Pro

Plugin:
User Registration & Membership Pro
Plugin Slug:
user-registration-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.0.

Vitepos

Plugin:
Vitepos
Plugin Slug:
vitepos-lite
Vulnerability:
Broken Authentication
Patched in Version:
3.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.8.

Advanced Google Maps

Plugin:
Advanced Google Maps
Plugin Slug:
wp-google-map-gold
Vulnerability:
Broken Access Control
Patched in Version:
5.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.5.

Wp Staging Pro

Plugin:
Wp Staging Pro
Plugin Slug:
wp-staging-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.3.

WordPress Themes — 9 Patched / 16 Unpatched

Arrival

Theme:
Arrival
Theme Slug:
arrival
Downloads
126,390
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CWW Portfolio

Theme Slug:
cww-portfolio
Downloads
85,610
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grace Mag

Theme Slug:
grace-mag
Downloads
70,093
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Opstore

Theme:
Opstore
Theme Slug:
opstore
Downloads
82,183
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sirat

Theme:
Sirat
Theme Slug:
sirat
Downloads
355,294
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Xews Lite

Theme Slug:
xews-lite
Downloads
14,599
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Altair

Theme:
Altair
Theme Slug:
altair
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Celestial Aura

Theme:
Celestial Aura
Theme Slug:
celestial-aura
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

CiyaShop

Theme:
CiyaShop
Theme Slug:
ciyashop
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Eximius

Theme:
Eximius
Theme Slug:
eximius
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Grip

Theme:
Grip
Theme Slug:
grip
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
28.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 28.0.4.

Dessau

Theme:
Dessau
Theme Slug:
dessau
Vulnerability:
Local File Inclusion
Patched in Version:
1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.

Dør

Theme:
Dør
Theme Slug:
dor
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

Eduma

Theme:
Eduma
Theme Slug:
eduma
Vulnerability:
Broken Access Control
Patched in Version:
5.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.5.

Foton

Theme:
Foton
Theme Slug:
foton
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

Ivy School

Theme:
Ivy School
Theme Slug:
ivy-school
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Real Estate 7

Theme:
Real Estate 7
Theme Slug:
realestate-7
Vulnerability:
Privilege Escalation
Patched in Version:
3.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.3.

Tastyc

Theme:
Tastyc
Theme Slug:
tastyc
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.2.

Wanderland

Theme:
Wanderland
Theme Slug:
wanderland
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security