WordPress Vulnerability Report

WordPress Vulnerability Report — June 18, 2025

Since last week, 138 new vulnerabilities emerged in the WordPress ecosystem, including 101 plugins and 37 themes. 63 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 138 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 63 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 55 Patched / 46 Unpatched

Woocommerce Partial Shipment

Plugin Slug:
wc-partial-shipment
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Track, Analyze & Optimize by WP Tao

Plugin Slug:
wp-tao
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IndieBlocks

Plugin Slug:
indieblocks
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

One-Login

Plugin:
One-Login
Plugin Slug:
one-login
Installations
70+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PostaPanduri

Plugin Slug:
postapanduri
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

AI Image Lab

Plugin:
AI Image Lab
Plugin Slug:
ai-image-generator-lab
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Attachments

Plugin:
Auto Attachments
Plugin Slug:
auto-attachments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Axle Demo Importer

Plugin:
Axle Demo Importer
Plugin Slug:
axle-demo-importer
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bunny’s Print CSS

Plugin:
Bunny’s Print CSS
Plugin Slug:
bunnys-print-css
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Color Palette

Plugin:
Color Palette
Plugin Slug:
color-palette
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Us page – Contact people LITE

Plugin:
Contact Us page – Contact people LITE
Plugin Slug:
contact-us-page-contact-people
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Digital Marketing and Agency Templates Addons for Elementor

Plugin:
Digital Marketing and Agency Templates Addons for Elementor
Plugin Slug:
digital-marketing-agency-templates-for-elementor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Flashcards

Plugin:
Easy Flashcards
Plugin Slug:
easy-flashcards
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DIOT SCADA with MQTT

Plugin:
DIOT SCADA with MQTT
Plugin Slug:
ecava-diot-scada
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elite Video Player

Plugin:
Elite Video Player
Plugin Slug:
elite-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FW Food Menu

Plugin:
FW Food Menu
Plugin Slug:
fw-food-menu
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FW Gallery
Plugin Slug:
fw-gallery
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image Resizer On The Fly

Plugin:
Image Resizer On The Fly
Plugin Slug:
image-resizer-on-the-fly
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

REST API | Custom API Generator For Cross Platform And Import Export In WP

Plugin:
REST API | Custom API Generator For Cross Platform And Import Export In WP
Plugin Slug:
import-export-with-custom-rest-api
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

IRM Newsroom

Plugin:
IRM Newsroom
Plugin Slug:
irm-newsroom
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

kk Youtube Video

Plugin:
kk Youtube Video
Plugin Slug:
kk-youtube-video
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CLEVER

Plugin:
CLEVER
Plugin Slug:
lbg-audio11-html5-shoutcast_history
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Nasa Core

Plugin:
Nasa Core
Plugin Slug:
nasa-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ovatheme Events Manager

Plugin:
Ovatheme Events Manager
Plugin Slug:
ova-events-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Reformer for Elementor

Plugin:
Reformer for Elementor
Plugin Slug:
reformer-elementor
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Restrict File Access

Plugin:
Restrict File Access
Plugin Slug:
restrict-file-access
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Smart Notification

Plugin:
Smart Notification
Plugin Slug:
smio-push-notification
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Telegram for WP

Plugin:
Telegram for WP
Plugin Slug:
telegram-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widget Logic

Plugin:
Widget Logic
Plugin Slug:
widget-logic
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WidgetKit Pro

Plugin:
WidgetKit Pro
Plugin Slug:
widgetkit-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Employee Attendance System

Plugin:
WP Employee Attendance System
Plugin Slug:
wp-employee-attendance-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Sliding Login/Dashboard Panel

Plugin:
WP Sliding Login/Dashboard Panel
Plugin Slug:
wp-sliding-logindashboard-panel
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP URL Shortener

Plugin:
WP URL Shortener
Plugin Slug:
wp-url-shortener
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP2HTML

Plugin:
WP2HTML
Plugin Slug:
wp2html
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:
WPCRM – CRM for Contact form CF7 & WooCommerce
Plugin Slug:
wpcrm
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

XiSearch bar

Plugin:
XiSearch bar
Plugin Slug:
xisearch-bar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yougler Blogger Profile Page

Plugin:
Yougler Blogger Profile Page
Plugin Slug:
yougler-blogger-profile-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zen Sticky Social

Plugin:
Zen Sticky Social
Plugin Slug:
zen-social-sticky
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zotpress

Plugin:
Zotpress
Plugin Slug:
zotpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.11.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.11.9.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.13.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.13.2.1.

File Manager Pro – Filester

Plugin Slug:
filester
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.9.

Social Sharing Plugin – Sassy Social Share

Plugin Slug:
sassy-social-share
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.76
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.76.

Slim SEO – Fast & Automated WordPress SEO Plugin

Plugin Slug:
slim-seo
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
4.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.5.

Meks Flexible Shortcodes

Plugin Slug:
meks-flexible-shortcodes
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Simple Newsletter Plugin – Noptin

Plugin Slug:
newsletter-optin-box
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal

Plugin Slug:
wp-malware-removal
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.9.

Arconix FAQ

Plugin Slug:
arconix-faq
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.7.

If-So Dynamic Content Personalization

Plugin Slug:
if-so
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.2.

WP Dummy Content Generator

Plugin Slug:
wp-dummy-content-generator
Installations
8,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

Xagio SEO – AI Powered SEO

Plugin Slug:
xagio-seo
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.1.0.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.1.0.17.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.9.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.5.3.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.18.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.24.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.24.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

CubeWP Forms – All-in-One Form Builder

Plugin Slug:
cubewp-forms
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager
Installations
3,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.68.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.68.11.

WP Views Counter

Plugin Slug:
wpecounter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

YITH PayPal Express Checkout for WooCommerce

Plugin Slug:
yith-paypal-express-checkout-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.49.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.49.1.

Advanced Sermons

Plugin Slug:
advanced-sermons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.

Ebook Store

Plugin Slug:
ebook-store
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8009
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8009.

Kama Click Counter

Plugin Slug:
kama-clic-counter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.

Membership For WooCommerce

Plugin Slug:
membership-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.2.

AFS Analytics

Plugin Slug:
addfreestats
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
4.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.51.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.51.8.

Traffic Monitor

Plugin Slug:
traffic-monitor
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Ultimate Reviews

Plugin Slug:
ultimate-reviews
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.15.

Advanced Settings 3

Plugin Slug:
advanced-settings
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.2.

ACF Onyx Poll

Plugin Slug:
acf-onyx-poll
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Game Review Block

Plugin Slug:
game-review-block
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.2.

TicketBAI Facturas para WooCommerce

Plugin Slug:
wp-ticketbai
Installations
90+
Vulnerability:
SQL Injection
Patched in Version:
3.21
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.21.

OAuth Single Sign On – SSO (OAuth Client)

Plugin:
OAuth Single Sign On – SSO (OAuth Client)
Plugin Slug:
miniorange-oauth-oidc-single-sign-on
Vulnerability:
Sensitive Data Exposure
Patched in Version:
18.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 18.5.4.

NewsLetter

Plugin:
NewsLetter
Plugin Slug:
plugin-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.5.

Abandoned Cart Pro for WooCommerce

Plugin:
Abandoned Cart Pro for WooCommerce
Plugin Slug:
woocommerce-abandon-cart-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
9.17.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.17.0.

Workreap (theme’s plugin)

Plugin:
Workreap (theme’s plugin)
Plugin Slug:
workreap
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.3.

Workreap (theme’s plugin)

Plugin:
Workreap (theme’s plugin)
Plugin Slug:
workreap
Vulnerability:
Broken Authentication
Patched in Version:
3.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.2.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.116.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.116.0.

eForm – WordPress Form Builder

Plugin:
eForm – WordPress Form Builder
Plugin Slug:
wp-fsqm-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.19.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.19.1.

WordPress Themes — 20 Patched / 17 Unpatched

BodyCenter – Gym, Fitness WooCommerce WordPress Theme

Theme:
BodyCenter – Gym, Fitness WooCommerce WordPress Theme
Theme Slug:
bodycenter
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CraftXtore

Theme:
CraftXtore
Theme Slug:
bw-craftxtore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Fitrush

Theme:
Fitrush
Theme Slug:
bw-fitrush
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

GiftXtore

Theme:
GiftXtore
Theme Slug:
bw-giftxtore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Petito

Theme:
Petito
Theme Slug:
bw-petito
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zagg

Theme:
Zagg
Theme Slug:
bw-zagg
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

DSK

Theme:
DSK
Theme Slug:
dsk
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:
Themify Edmin
Theme Slug:
edmin
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Inset

Theme:
Inset
Theme Slug:
inset
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

SNS Anton

Theme:
SNS Anton
Theme Slug:
snsanton
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Avaz

Theme:
Avaz
Theme Slug:
snsavaz
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Evon

Theme:
Evon
Theme Slug:
snsevon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nitan

Theme:
Nitan
Theme Slug:
snsnitan
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Simen

Theme:
Simen
Theme Slug:
snssimen
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Spare

Theme:
Spare
Theme Slug:
spare
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Valen – Sport, Fashion WooCommerce WordPress Theme

Theme:
Valen – Sport, Fashion WooCommerce WordPress Theme
Theme Slug:
valen
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Aora

Theme:
Aora
Theme Slug:
aora
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.10.

Besa

Theme:
Besa
Theme Slug:
besa
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.10.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
PHP Object Injection
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

Diza

Theme:
Diza
Theme Slug:
diza
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Fana

Theme:
Fana
Theme Slug:
fana
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.29.

Flozen

Theme:
Flozen
Theme Slug:
flozen-theme
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.1.

GrandPrix

Theme:
GrandPrix
Theme Slug:
grandprix
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Grill and Chow

Theme:
Grill and Chow
Theme Slug:
grillandchow
Vulnerability:
Local File Inclusion
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Hara

Theme:
Hara
Theme Slug:
hara
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.11.

Lasa

Theme:
Lasa
Theme Slug:
lasa
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

Maia

Theme:
Maia
Theme Slug:
maia
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.16.

MediClinic

Theme:
MediClinic
Theme Slug:
mediclinic
Vulnerability:
Local File Inclusion
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Nika

Theme:
Nika
Theme Slug:
nika
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.9.

RealHomes

Theme:
RealHomes
Theme Slug:
realhomes
Vulnerability:
Privilege Escalation
Patched in Version:
4.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.1.

Ruza

Theme:
Ruza
Theme Slug:
ruza
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Sapa

Theme:
Sapa
Theme Slug:
sapa
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.15.

TinySalt

Theme:
TinySalt
Theme Slug:
tinysalt
Vulnerability:
PHP Object Injection
Patched in Version:
3.10.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.10.0.

TinySalt

Theme:
TinySalt
Theme Slug:
tinysalt
Vulnerability:
Local File Inclusion
Patched in Version:
3.10.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.10.0.

Zota

Theme:
Zota
Theme Slug:
zota
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security