In this report, 213 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 149 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.
WordPress Plugins — 49 Patched / 126 Unpatched
Mollie Payments for WooCommerce
- Plugin:
- Mollie Payments for WooCommerce
- Plugin Slug:
- mollie-payments-for-woocommerce
- Installations
- 100,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-39362
WP Edit
- Plugin:
- WP Edit
- Plugin Slug:
- wp-edit
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53253
Cyrlitera – transliteration of links and file names
- Plugin Slug:
- cyrlitera
- Installations
- 40,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53254
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
- Plugin Slug:
- hurrytimer
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53255
YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
- Plugin:
- YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service
- Plugin Slug:
- yaysmtp
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53256
Gmedia Photo Gallery
- Plugin:
- Gmedia Photo Gallery
- Plugin Slug:
- grand-media
- Installations
- 9,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53257
Hover Effects – easily create any hover effect
- Plugin Slug:
- hover-effects
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53258
Additional Order Filters for WooCommerce
- Plugin Slug:
- additional-order-filters-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53271
Cron Logger
- Plugin:
- Cron Logger
- Plugin Slug:
- cron-logger
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53266
WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons
- Plugin Slug:
- easy-sticky-sidebar
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53270
Address Autocomplete via Google for Gravity Forms
- Plugin Slug:
- gf-google-address-autocomplete
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53263
Hide Admin Bar From Front End
- Plugin:
- Hide Admin Bar From Front End
- Plugin Slug:
- hide-admin-bar-from-front-end
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53267
Image Cleanup
- Plugin:
- Image Cleanup
- Plugin Slug:
- image-cleanup
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53272
Import external attachments
- Plugin:
- Import external attachments
- Plugin Slug:
- import-external-attachments
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53268
Leyka
- Plugin:
- Leyka
- Plugin Slug:
- leyka
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53275
My Wp Brand – Hide menu & Hide Plugin
- Plugin Slug:
- my-wp-brand
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53269
ONet Regenerate Thumbnails
- Plugin:
- ONet Regenerate Thumbnails
- Plugin Slug:
- onet-regenerate-thumbnails
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53264
Slickstream: Engagement and Conversions
- Plugin Slug:
- slick-engagement
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53273
Virusdie – One-click website security
- Plugin Slug:
- virusdie
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53265
WP Permalink Translator
- Plugin:
- WP Permalink Translator
- Plugin Slug:
- wp-permalink-translator
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53274
WP YouTube Live
- Plugin:
- WP YouTube Live
- Plugin Slug:
- wp-youtube-live
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53261
Writesonic
- Plugin:
- Writesonic
- Plugin Slug:
- writesonic
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53262
Omnipress
- Plugin:
- Omnipress
- Plugin Slug:
- omnipress
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53276
IS-theme-companion
- Plugin:
- IS-theme-companion
- Plugin Slug:
- weblizar-companion
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53277
Football Pool
- Plugin:
- Football Pool
- Plugin Slug:
- football-pool
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53280
WPB Category Slider for WooCommerce – Product Categories Carousel Slider & Grid with Icon and Images
- Plugin:
- WPB Category Slider for WooCommerce – Product Categories Carousel Slider & Grid with Icon and Images
- Plugin Slug:
- wpb-woocommerce-category-slider
- Installations
- 900+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53281
PlatiOnline Payments
- Plugin:
- PlatiOnline Payments
- Plugin Slug:
- plationline
- Installations
- 800+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53288
Spreadconnect
- Plugin:
- Spreadconnect
- Plugin Slug:
- wc-spod
- Installations
- 800+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53291
Add & Replace Affiliate Links for Amazon
- Plugin Slug:
- add-replace-affiliate-links-for-amazon
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53285
Thumbnail Editor
- Plugin:
- Thumbnail Editor
- Plugin Slug:
- thumbnail-editor
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53282
Trusty Whistleblowing Solution
- Plugin:
- Trusty Whistleblowing Solution
- Plugin Slug:
- trusty-whistleblowing-solution
- Installations
- 600+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52818
WP DataTable
- Plugin:
- WP DataTable
- Plugin Slug:
- wp-datatable
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53292
Dashboard Widget Sidebar
- Plugin:
- Dashboard Widget Sidebar
- Plugin Slug:
- dashboard-widget-sidebar
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53293
iCount Payment Gateway
- Plugin:
- iCount Payment Gateway
- Plugin Slug:
- icount
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53295
MobiLoud – WordPress Mobile Apps – Convert your WordPress Website to Native Mobile Apps
- Plugin Slug:
- mobiloud-mobile-app-plugin
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52813
EC Stars Rating
- Plugin:
- EC Stars Rating
- Plugin Slug:
- ec-stars-rating
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53296
Theme Junkie Team Content
- Plugin:
- Theme Junkie Team Content
- Plugin Slug:
- theme-junkie-team-content
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53301
Abandoned Contact Form 7
- Plugin:
- Abandoned Contact Form 7
- Plugin Slug:
- abandoned-contact-form-7
- Installations
- 200+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52817
Accept Stripe Payments Using Contact Form 7
- Plugin Slug:
- accept-stripe-payments-using-contact-form-7
- Installations
- 200+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53309
Aviation Weather from NOAA
- Plugin:
- Aviation Weather from NOAA
- Plugin Slug:
- aviation-weather-from-noaa
- Installations
- 200+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28980
Osom Blocks
- Plugin:
- Osom Blocks
- Plugin Slug:
- osomblocks
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5940
Accept Authorize.NET Payments Using Contact Form 7
- Plugin Slug:
- accept-authorize-net-payments-using-contact-form-7
- Installations
- 100+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53322
Content Manager Light
- Plugin:
- Content Manager Light
- Plugin Slug:
- content-manager-light
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24771
WP Forum Server
- Plugin:
- WP Forum Server
- Plugin Slug:
- forum-server
- Installations
- 100+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53306
WP Forum Server
- Plugin:
- WP Forum Server
- Plugin Slug:
- forum-server
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53305
HidePost
- Plugin:
- HidePost
- Plugin Slug:
- hidepost
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53310
National Weather Service Alerts
- Plugin:
- National Weather Service Alerts
- Plugin Slug:
- national-weather-service-alerts
- Installations
- 100+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52809
Navayan Subscribe
- Plugin:
- Navayan Subscribe
- Plugin Slug:
- navayan-subscribe
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53311
OnionBuzz
- Plugin:
- OnionBuzz
- Plugin Slug:
- onionbuzz-viral-quiz
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53312
Pre-Publish Post Checklist
- Plugin:
- Pre-Publish Post Checklist
- Plugin Slug:
- pre-publish-post-checklist
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53323
Raise The Money
- Plugin:
- Raise The Money
- Plugin Slug:
- raise-the-money
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53321
Relocate Upload
- Plugin:
- Relocate Upload
- Plugin Slug:
- relocate-upload
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53315
Twitch TV Embed Suite
- Plugin:
- Twitch TV Embed Suite
- Plugin Slug:
- twitch-tv-embed-suite
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53313
Video List Manager
- Plugin:
- Video List Manager
- Plugin Slug:
- video-list-manager
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52776
WP DB Booster
- Plugin:
- WP DB Booster
- Plugin Slug:
- wp-db-booster
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53318
WP Optimizer
- Plugin:
- WP Optimizer
- Plugin Slug:
- wp-optimizer
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-53314
WPShapere Lite
- Plugin:
- WPShapere Lite
- Plugin Slug:
- wpshapere-lite
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53317
xili-dictionary
- Plugin:
- xili-dictionary
- Plugin Slug:
- xili-dictionary
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52778
Infility Global
- Plugin:
- Infility Global
- Plugin Slug:
- infility-global
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52774
MDJM Event Management
- Plugin:
- MDJM Event Management
- Plugin Slug:
- mobile-dj-manager
- Installations
- 90+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52824
Track Everything
- Plugin:
- Track Everything
- Plugin Slug:
- track-everything
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53332
Photo Express for Google
- Plugin:
- Photo Express for Google
- Plugin Slug:
- photo-express-for-google
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-27361
My Resume Builder
- Plugin:
- My Resume Builder
- Plugin Slug:
- my-resume-builder
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53336
DirectIQ Email Marketing
- Plugin:
- DirectIQ Email Marketing
- Plugin Slug:
- directiq-wp
- Installations
- 40+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-52829
A/B Testing for WordPress
- Plugin:
- A/B Testing for WordPress
- Plugin Slug:
- ab-testing-for-wp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-4587
Aioseo Multibyte Descriptions
- Plugin:
- Aioseo Multibyte Descriptions
- Plugin Slug:
- aioseo-multibyte-descriptions
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53327
Backwp
- Plugin:
- Backwp
- Plugin Slug:
- backwp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28956
Beauty Contact Popup Form
- Plugin:
- Beauty Contact Popup Form
- Plugin Slug:
- beauty-contact-popup-form
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53325
CMS Blocks
- Plugin:
- CMS Blocks
- Plugin Slug:
- cms-blocks
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53284
Contact Form – 7 : Hide Success Message
- Plugin:
- Contact Form – 7 : Hide Success Message
- Plugin Slug:
- contact-form-7-hide-success-message
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53304
CTUsers
- Plugin:
- CTUsers
- Plugin Slug:
- ctuser
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-32298
Davenport – Versatile Blog and Magazine WordPress Theme
- Plugin:
- Davenport – Versatile Blog and Magazine WordPress Theme
- Plugin Slug:
- davenport
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52811
Devnex Addons For Elementor
- Plugin:
- Devnex Addons For Elementor
- Plugin Slug:
- devnex-addons-for-elementor
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53339
Drive Folder Embedder
- Plugin:
- Drive Folder Embedder
- Plugin Slug:
- drive-folder-embeder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6546
enigma-buttons
- Plugin:
- enigma-buttons
- Plugin Slug:
- e.nigma buttons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5535
Evangelische Termine
- Plugin:
- Evangelische Termine
- Plugin Slug:
- evangtermine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28960
File Manager Plugin For WordPress
- Plugin:
- File Manager Plugin For WordPress
- Plugin Slug:
- file-manager-plugin-for-wordpress
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-53260
FL3R Accessibility Suite
- Plugin:
- FL3R Accessibility Suite
- Plugin Slug:
- fl3r-accessibility-suite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6689
Flexo Counter
- Plugin:
- Flexo Counter
- Plugin Slug:
- flexo-countdown
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-50052
Free Downloads EDD
- Plugin:
- Free Downloads EDD
- Plugin Slug:
- free-downloads-edd
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53320
FW Food Menu
- Plugin:
- FW Food Menu
- Plugin Slug:
- fw-food-menu
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-49448
FW Gallery
- Plugin:
- FW Gallery
- Plugin Slug:
- fw-gallery
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-49414
FW Gallery
- Plugin:
- FW Gallery
- Plugin Slug:
- fw-gallery
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-49416
Game Users Share Buttons
- Plugin:
- Game Users Share Buttons
- Plugin Slug:
- game-users-share-buttons
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-6755
GC Social Wall
- Plugin:
- GC Social Wall
- Plugin Slug:
- gc-social-wall
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5564
GG Bought Together for WooCommerce
- Plugin:
- GG Bought Together for WooCommerce
- Plugin Slug:
- gg-bought-together
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23967
Homerunner
- Plugin:
- Homerunner
- Plugin Slug:
- homerunner-smartcheckout
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5932
Image Shadow
- Plugin:
- Image Shadow
- Plugin Slug:
- image-shadow
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24765
Image Slider With Description
- Plugin:
- Image Slider With Description
- Plugin Slug:
- image-slider-with-description
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53308
Amazon Products to WooCommerce
- Plugin:
- Amazon Products to WooCommerce
- Plugin Slug:
- import-products-to-wc
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5813
Namasha By Mdesign
- Plugin:
- Namasha By Mdesign
- Plugin Slug:
- namasha-by-mdesign
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6537
Opal Estate Pro
- Plugin:
- Opal Estate Pro
- Plugin Slug:
- opal-estate-pro
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-6934
Plugin Inspector
- Plugin:
- Plugin Inspector
- Plugin Slug:
- plugin-inspector
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53298
Podcast Feed Player Widget and Shortcode
- Plugin:
- Podcast Feed Player Widget and Shortcode
- Plugin Slug:
- podcast-feed-player-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53300
Post Rating and Review
- Plugin:
- Post Rating and Review
- Plugin Slug:
- post-rating-and-review
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6538
PT Project Notebooks
- Plugin:
- PT Project Notebooks
- Plugin Slug:
- project-notebooks
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-5304
Simple Link Directory
- Plugin:
- Simple Link Directory
- Plugin Slug:
- qc-simple-link-directory
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-32297
Quick Favicon
- Plugin:
- Quick Favicon
- Plugin Slug:
- quick-favicon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53287
re.place
- Plugin:
- re.place
- Plugin Slug:
- replace
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53338
Responsive Food and Drink Menu
- Plugin:
- Responsive Food and Drink Menu
- Plugin Slug:
- responsive-food-and-drink-menu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6378
Owl carousel responsive
- Plugin:
- Owl carousel responsive
- Plugin Slug:
- responsive-owl-carousel
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-5590
RSS Digest
- Plugin:
- RSS Digest
- Plugin Slug:
- rss-digest
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53331
SB Breadcrumbs
- Plugin:
- SB Breadcrumbs
- Plugin Slug:
- sb-breadcrumbs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28978
WP SmartPay
- Plugin:
- WP SmartPay
- Plugin Slug:
- smartpay
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-25171
Spo?eczno?ciowa 6 PL 2013
- Plugin:
- Spo?eczno?ciowa 6 PL 2013
- Plugin Slug:
- spolecznosciowa-6-pl-2013
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53329
The Countdown – Block Countdown Timer
- Plugin:
- The Countdown – Block Countdown Timer
- Plugin Slug:
- the-countdown
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5929
The Pack Elementor addons
- Plugin:
- The Pack Elementor addons
- Plugin Slug:
- the-pack-addon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6550
TimeZoneCalculator
- Plugin:
- TimeZoneCalculator
- Plugin Slug:
- timezonecalculator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5559
Tournament Bracket Generator
- Plugin:
- Tournament Bracket Generator
- Plugin Slug:
- tournament-bracket-generator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6290
Rankie
- Plugin:
- Rankie
- Plugin Slug:
- valvepress-rankie
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-39487
VG WORT METIS
- Plugin:
- VG WORT METIS
- Plugin Slug:
- vgw-metis
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5812
VG WORT METIS
- Plugin:
- VG WORT METIS
- Plugin Slug:
- vgw-metis
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-50039
VR Calendar
- Plugin:
- VR Calendar
- Plugin Slug:
- vr-calendar-sync
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5936
web-cam
- Plugin:
- web-cam
- Plugin Slug:
- web-cam
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6540
Email Address Security by WebEmailProtector
- Plugin:
- Email Address Security by WebEmailProtector
- Plugin Slug:
- webemailprotector
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-28976
Event RSVP and Simple Event Management Plugin
- Plugin:
- Event RSVP and Simple Event Management Plugin
- Plugin Slug:
- wp-easy-events
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-5540
WP GDPR Cookie Consent
- Plugin:
- WP GDPR Cookie Consent
- Plugin Slug:
- wp-gdpr-cookie-consen
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53316
JobSearch
- Plugin:
- JobSearch
- Plugin Slug:
- wp-jobsearch
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52798
WP Optimize By xTraffic
- Plugin:
- WP Optimize By xTraffic
- Plugin Slug:
- wp-optimize-by-xtraffic
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-28970
WP-PhotoNav
- Plugin:
- WP-PhotoNav
- Plugin Slug:
- wp-photonav
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6383
WP-Recall
- Plugin:
- WP-Recall
- Plugin Slug:
- wp-recall
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52796
WP SoundSystem
- Plugin:
- WP SoundSystem
- Plugin Slug:
- wp-soundsystem
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-6258
WP Visual Sitemap
- Plugin:
- WP Visual Sitemap
- Plugin Slug:
- wp-visual-sitemap
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53290
WP Wall
- Plugin:
- WP Wall
- Plugin Slug:
- wp-wall
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28968
WPCRM – CRM for Contact form CF7 & WooCommerce
- Plugin:
- WPCRM – CRM for Contact form CF7 & WooCommerce
- Plugin Slug:
- wpcrm
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24774
WPKit For Elementor
- Plugin:
- WPKit For Elementor
- Plugin Slug:
- wpkit-elementor
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-32281
Ninja Forms – The Contact Form Builder That Grows With You
- Plugin Slug:
- ninja-forms
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.2.2
- Severity Score:
- Medium
- CVE:
- 2025-5398
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1025
- Severity Score:
- Medium
- CVE:
- 2025-5338
SiteOrigin Widgets Bundle
- Plugin:
- SiteOrigin Widgets Bundle
- Plugin Slug:
- so-widgets-bundle
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.69.0
- Severity Score:
- Medium
- CVE:
- 2025-5585
Burst Statistics – Privacy-Friendly Analytics for WordPress
- Plugin Slug:
- burst-statistics
- Installations
- 300,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.0.8
- Severity Score:
- Medium
- CVE:
- 2025-53193
Firelight Lightbox
- Plugin:
- Firelight Lightbox
- Plugin Slug:
- easy-fancybox
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.16
- Severity Score:
- Medium
- CVE:
- 2025-5035
Qi Addons For Elementor
- Plugin:
- Qi Addons For Elementor
- Plugin Slug:
- qi-addons-for-elementor
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.2
- Severity Score:
- Medium
- CVE:
- 2025-6252
Usercentrics Cookiebot – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode
- Plugin Slug:
- cookiebot
- Installations
- 100,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.5.9
- Severity Score:
- Medium
- CVE:
- 2025-53197
Responsive Lightbox & Gallery
- Plugin:
- Responsive Lightbox & Gallery
- Plugin Slug:
- responsive-lightbox
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.2
- Severity Score:
- Medium
- CVE:
- 2025-5093
Ninja Tables – Easy Data Table Builder
- Plugin Slug:
- ninja-tables
- Installations
- 80,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 5.0.19
- Severity Score:
- High
- CVE:
- 2025-2940
Ultra Addons for Contact Form 7
- Plugin:
- Ultra Addons for Contact Form 7
- Plugin Slug:
- ultimate-addons-for-contact-form-7
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.22
- Severity Score:
- Medium
- CVE:
- 2025-6756
Ultra Addons for Contact Form 7
- Plugin:
- Ultra Addons for Contact Form 7
- Plugin Slug:
- ultimate-addons-for-contact-form-7
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.20
- Severity Score:
- High
- CVE:
- 2025-6212
HT Slider For Elementor
- Plugin:
- HT Slider For Elementor
- Plugin Slug:
- ht-slider-for-elementor
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.6
- Severity Score:
- Medium
- CVE:
- 2025-53199
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks
- Plugin Slug:
- wp-map-block
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.3
- Severity Score:
- Medium
- CVE:
- 2025-5194
Frontend Admin by DynamiApps
- Plugin:
- Frontend Admin by DynamiApps
- Plugin Slug:
- acf-frontend-form-element
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 3.28.8
- Severity Score:
- Medium
- CVE:
- 2025-49303
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
- Plugin Slug:
- charitable
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.6.2
- Severity Score:
- Medium
- CVE:
- 2025-5275
Event Manager, Events Calendar, Booking, Registrations and Tickets – Eventin
- Plugin Slug:
- wp-event-solution
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.0.29
- Severity Score:
- High
- CVE:
- 2025-49321
BuddyPress Docs
- Plugin:
- BuddyPress Docs
- Plugin Slug:
- buddypress-docs
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.5
- Severity Score:
- Medium
- CVE:
- 2025-5526
AI ChatBot for WordPress – WPBot
- Plugin:
- AI ChatBot for WordPress – WPBot
- Plugin Slug:
- chatbot
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.7.5
- Severity Score:
- Medium
- CVE:
- 2025-53200
Hotel Booking
- Plugin:
- Hotel Booking
- Plugin Slug:
- nd-booking
- Installations
- 5,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.8
- Severity Score:
- High
- CVE:
- 2025-53259
Post Carousel Slider for Elementor
- Plugin Slug:
- post-carousel-slider-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.0
- Severity Score:
- Medium
- CVE:
- 2025-3863
Responsive Blocks – WordPress Gutenberg Blocks
- Plugin Slug:
- responsive-block-editor-addons
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.7
- Severity Score:
- Medium
- CVE:
- 2025-53202
PDF Builder for WooCommerce. Create invoices,packing slips and more
- Plugin Slug:
- woo-pdf-invoice-builder
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.149
- Severity Score:
- Medium
- CVE:
- 2025-53203
HT Mega – Absolute Addons for WPBakery Page Builder
- Plugin Slug:
- ht-mega-for-wpbakery
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.9
- Severity Score:
- Medium
- CVE:
- 2025-53206
Off-Canvas Sidebars & Menus (Slidebars)
- Plugin Slug:
- off-canvas-sidebars
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.5.8.5
- Severity Score:
- High
- CVE:
- 2025-49290
Popup addon for Ninja Forms
- Plugin:
- Popup addon for Ninja Forms
- Plugin Slug:
- popup-addon-for-ninja-forms
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5
- Severity Score:
- Medium
- CVE:
- 2025-53279
WP AdCenter – Ad Manager & Adsense Ads
- Plugin Slug:
- wpadcenter
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.1
- Severity Score:
- Medium
- CVE:
- 2025-53278
Image Editor by Pixo
- Plugin:
- Image Editor by Pixo
- Plugin Slug:
- image-editor-by-pixo
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.7
- Severity Score:
- Medium
- CVE:
- 2025-5588
Booking Calendar Contact Form
- Plugin:
- Booking Calendar Contact Form
- Plugin Slug:
- booking-calendar-contact-form
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.59
- Severity Score:
- Medium
- CVE:
- 2025-48231
SmartAgenda – Prise de rendez-vous en ligne
- Plugin Slug:
- smart-agenda-prise-de-rendez-vous-en-ligne
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.0
- Severity Score:
- Medium
- CVE:
- 2025-53294
Conference Scheduler
- Plugin:
- Conference Scheduler
- Plugin Slug:
- conference-scheduler
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.2
- Severity Score:
- Medium
- CVE:
- 2025-5258
Content No Cache | Serve uncached partial content even when you add it to a page that is fully cached.
- Plugin Slug:
- content-no-cache
- Installations
- 300+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 0.1.5
- Severity Score:
- High
- CVE:
- 2025-28993
Audio Editor & Recorder
- Plugin:
- Audio Editor & Recorder
- Plugin Slug:
- audio-editor-recorder
- Installations
- 200+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.2.4
- Severity Score:
- Medium
- CVE:
- 2025-53211
Euro FxRef Currency Converter
- Plugin:
- Euro FxRef Currency Converter
- Plugin Slug:
- euro-fxref-currency-converter
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.3
- Severity Score:
- Medium
- CVE:
- 2025-6257
Guest posting / Frontend Posting / Front Editor – WP Front User Submit
- Plugin Slug:
- front-editor
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.4
- Severity Score:
- High
- CVE:
- 2025-28988
SERPed.net
- Plugin:
- SERPed.net
- Plugin Slug:
- serped-net
- Installations
- 200+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.7
- Severity Score:
- High
- CVE:
- 2025-28998
WP Masonry & Infinite Scroll
- Plugin:
- WP Masonry & Infinite Scroll
- Plugin Slug:
- wp-masonry-infinite-scroll
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3
- Severity Score:
- Medium
- CVE:
- 2025-5488
isMobile() Shortcode for WordPress
- Plugin Slug:
- ismobile
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.2
- Severity Score:
- Medium
- CVE:
- 2025-6488
Modern Design Library
- Plugin:
- Modern Design Library
- Plugin Slug:
- mdl-shortcodes
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.5
- Severity Score:
- Medium
- CVE:
- 2025-5842
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet
- Plugin Slug:
- paid-membership
- Installations
- 40+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.2.1
- Severity Score:
- Medium
- CVE:
- 2025-5937
Simple Payment
- Plugin:
- Simple Payment
- Plugin Slug:
- simple-payment
- Installations
- 40+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 2.3.9
- Severity Score:
- Critical
- CVE:
- 2025-6688
Aiomatic
- Plugin:
- Aiomatic
- Plugin Slug:
- aiomatic-automatic-ai-content-writer
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.5.1
- Severity Score:
- High
- CVE:
- 2025-6206
BeeTeam368 Extensions
- Plugin:
- BeeTeam368 Extensions
- Plugin Slug:
- beeteam368-extensions
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 2.3.5
- Severity Score:
- High
- CVE:
- 2025-6381
BeeTeam368 Extensions Pro
- Plugin:
- BeeTeam368 Extensions Pro
- Plugin Slug:
- beeteam368-extensions-pro
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 2.3.5
- Severity Score:
- High
- CVE:
- 2025-6379
Drag and Drop Multiple File Upload (Pro) – WooCommerce
- Plugin:
- Drag and Drop Multiple File Upload (Pro) – WooCommerce
- Plugin Slug:
- drag-and-drop-file-upload-wc-pro
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 5.0.7
- Severity Score:
- Critical
- CVE:
- 2025-49885
Everest Forms Pro
- Plugin:
- Everest Forms Pro
- Plugin Slug:
- everest-forms-pro
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 1.9.5
- Severity Score:
- High
- CVE:
- 2025-5927
JetEngine
- Plugin:
- JetEngine
- Plugin Slug:
- jet-engine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.7.1.1
- Severity Score:
- Medium
- CVE:
- 2025-53195
BRW
- Plugin:
- BRW
- Plugin Slug:
- ova-brw
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.8.8
- Severity Score:
- High
- CVE:
- 2025-52814
Team Showcase
- Plugin:
- Team Showcase
- Plugin Slug:
- team-showcase-cm
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 25.05.13
- Severity Score:
- High
- CVE:
- 2025-49247
Zikzag Core
- Plugin:
- Zikzag Core
- Plugin Slug:
- zikzag-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.4.6
- Severity Score:
- High
- CVE:
- 2025-49886
WordPress Themes — 15 Patched / 23 Unpatched
Constructor
- Theme:
- Constructor
- Theme Slug:
- constructor
- Downloads
- 435,600
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53302
Zita
- Theme:
- Zita
- Theme Slug:
- zita
- Downloads
- 405,845
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52816
PrintXtore
- Theme:
- PrintXtore
- Theme Slug:
- bw-printxtore
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28946
Zenny
- Theme:
- Zenny
- Theme Slug:
- bw-zenny
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24769
CityGov
- Theme:
- CityGov
- Theme Slug:
- citygov
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52815
Domnoo
- Theme:
- Domnoo
- Theme Slug:
- domnoo
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52812
Homey
- Theme:
- Homey
- Theme Slug:
- homey
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-31037
Homey
- Theme:
- Homey
- Theme Slug:
- homey
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-52834
Katerio – Magazine
- Theme:
- Katerio – Magazine
- Theme Slug:
- katerio
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52810
LMS
- Theme:
- LMS
- Theme Slug:
- lms
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-52833
LMS
- Theme:
- LMS
- Theme Slug:
- lms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52799
LogisticsHub
- Theme:
- LogisticsHub
- Theme Slug:
- logistics-hub
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-30933
MagOne
- Theme:
- MagOne
- Theme Slug:
- magone
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-39488
MBStore – Digital WooCommerce WordPress Theme
- Theme:
- MBStore – Digital WooCommerce WordPress Theme
- Theme Slug:
- mbstore
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28947
Nuss
- Theme:
- Nuss
- Theme Slug:
- nuss
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52827
Pressroom – News Magazine WordPress Theme
- Theme:
- Pressroom – News Magazine WordPress Theme
- Theme Slug:
- pressroom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-32311
RealtyElite
- Theme:
- RealtyElite
- Theme Slug:
- realtyelite
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52808
Red Art
- Theme:
- Red Art
- Theme Slug:
- redart
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52828
Sala
- Theme:
- Sala
- Theme Slug:
- sala
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-52826
Samex – Clean, Minimal Shop WooCommerce WordPress Theme
- Theme:
- Samex – Clean, Minimal Shop WooCommerce WordPress Theme
- Theme Slug:
- samex
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-25998
Seven Stars
- Theme:
- Seven Stars
- Theme Slug:
- sevenstars
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-31067
SNS Vicky
- Theme:
- SNS Vicky
- Theme Slug:
- snsvicky
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-28990
Sofass
- Theme:
- Sofass
- Theme Slug:
- sofass
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24760
Blogbyte
- Theme:
- Blogbyte
- Theme Slug:
- blogbyte
- Downloads
- 5,082
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.2
- Severity Score:
- High
- CVE:
- 2025-49275
Blogmine
- Theme:
- Blogmine
- Theme Slug:
- blogmine
- Downloads
- 3,498
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.8
- Severity Score:
- High
- CVE:
- 2025-49276
Blogprise
- Theme:
- Blogprise
- Theme Slug:
- blogprise
- Downloads
- 5,171
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.10
- Severity Score:
- High
- CVE:
- 2025-49277
Blogty
- Theme:
- Blogty
- Theme Slug:
- blogty
- Downloads
- 3,128
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.12
- Severity Score:
- High
- CVE:
- 2025-49278
Blogvy
- Theme:
- Blogvy
- Theme Slug:
- blogvy
- Downloads
- 4,752
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.8
- Severity Score:
- High
- CVE:
- 2025-49279
Magty
- Theme:
- Magty
- Theme Slug:
- magty
- Downloads
- 2,670
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.7
- Severity Score:
- High
- CVE:
- 2025-49280
Magways
- Theme:
- Magways
- Theme Slug:
- magways
- Downloads
- 1,899
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.2
- Severity Score:
- High
- CVE:
- 2025-49281
Magze
- Theme:
- Magze
- Theme Slug:
- magze
- Downloads
- 3,707
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.0.10
- Severity Score:
- High
- CVE:
- 2025-49282
Neom Blog
- Theme:
- Neom Blog
- Theme Slug:
- neom-blog
- Downloads
- 22,211
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.1.0
- Severity Score:
- High
- CVE:
- 2025-49274
Amely
- Theme:
- Amely
- Theme Slug:
- amely
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.2.0
- Severity Score:
- Critical
- CVE:
- 2025-39474
DWT – Directory & Listing
- Theme:
- DWT – Directory & Listing
- Theme Slug:
- dwt-listing
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.3.7
- Severity Score:
- Critical
- CVE:
- 2024-12827
Elessi
- Theme:
- Elessi
- Theme Slug:
- elessi-theme
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.1
- Severity Score:
- High
- CVE:
- 2025-49873
Greenmart
- Theme:
- Greenmart
- Theme Slug:
- greenmart
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.2.4
- Severity Score:
- High
- CVE:
- 2025-49883
Litho
- Theme:
- Litho
- Theme Slug:
- litho
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 3.1
- Severity Score:
- High
- CVE:
- 2025-49879
Puca
- Theme:
- Puca
- Theme Slug:
- puca
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.6.34
- Severity Score:
- High
- CVE:
- 2025-30992
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
