WordPress Vulnerability Report

WordPress Vulnerability Report — July 16, 2025

Since last week, 109 new vulnerabilities have emerged in the WordPress ecosystem, including 89 plugins and 20 themes. 44 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 109 vulnerabilities have been publicly disclosed. Security patches for 65 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 44 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 is now available! This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 56 Patched / 33 Unpatched

URL Shortener Plugin For WordPress

Plugin Slug:
exact-links
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener Plugin For WordPress

Plugin Slug:
exact-links
Installations
600+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Editor Button

Plugin Slug:
cf7-editor-button
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tennis Court Bookings

Plugin Slug:
tennis-court-bookings
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dot html,php,xml etc pages

Plugin Slug:
dot-htmlphpxml-etc-pages
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SMu Manual DoFollow

Plugin Slug:
manuall-dofollow
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Folder

Plugin Slug:
media-folder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More

Plugin Slug:
ultimate-push-notifications
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress-WPJobBoard

Plugin Slug:
click-pledge-wpjobboard
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Pakke Envíos

Plugin Slug:
pakke
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)

Plugin:
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)
Plugin Slug:
azon-addon-js-composer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GoZen Forms

Plugin:
GoZen Forms
Plugin Slug:
gozen-forms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Human Resource Management

Plugin:
WP Human Resource Management
Plugin Slug:
hrm
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LoginWP – Pro

Plugin:
LoginWP – Pro
Plugin Slug:
loginwp-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Medical Prescription Attachment Plugin for WooCommerce

Plugin:
Medical Prescription Attachment Plugin for WooCommerce
Plugin Slug:
medical-prescription-attachment-plugin-for-woocommerce
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Premium SEO Pack

Plugin:
Premium SEO Pack
Plugin Slug:
premium-seo-pack
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Profiler – What Slowing Down Your WP

Plugin:
Profiler – What Slowing Down Your WP
Plugin Slug:
profiler-what-slowing-down
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The E-Commerce ERP

Plugin:
The E-Commerce ERP
Plugin Slug:
profitori
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Multi-language Responsive Contact Form

Plugin:
Multi-language Responsive Contact Form
Plugin Slug:
responsive-contact-form
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Short URL

Plugin:
Short URL
Plugin Slug:
shorten-url
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Simple Featured Image
Plugin Slug:
simple-featured-image
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

smart SEO

Plugin:
smart SEO
Plugin Slug:
smartSEO
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Coming Soon Landing Page / Holding Page for WordPress

Plugin:
Responsive Coming Soon Landing Page / Holding Page for WordPress
Plugin Slug:
wordpress-flat-countdown
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auto Spinner

Plugin:
WordPress Auto Spinner
Plugin Slug:
wp-auto-spinner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Firebase Push Notification

Plugin:
WP Firebase Push Notification
Plugin Slug:
wp-push-notification-firebase
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Database Addon – CFDB7

Plugin Slug:
contact-form-cfdb7
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.2.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.5.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.12.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.4.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.4.

WPC Smart Compare for WooCommerce

Plugin Slug:
woo-smart-compare
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.7.

Companion Auto Update

Plugin Slug:
companion-auto-update
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
3.11.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.0.

Gwolle Guestbook

Plugin Slug:
gwolle-gb
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.3.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.6.8.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.
Plugin Slug:
portfolio-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.5.3.

RSFirewall!

Plugin Slug:
rsfirewall
Installations
4,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.1.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.43.

Contact Form Plugin

Plugin Slug:
contact-form-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.29.
Plugin Slug:
internal-linking-of-related-contents
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Lana Downloads Manager

Plugin Slug:
lana-downloads-manager
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.11.0.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Custom Post Carousels with Owl

Plugin Slug:
dd-post-carousel
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.12.
Plugin Slug:
broken-link-notifier
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.
Plugin Slug:
broken-link-notifier
Installations
1,000+
Vulnerability:
CSV Injection
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
26.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 26.0.7.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
26.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 26.0.9.

Friends

Plugin:
Friends
Plugin Slug:
friends
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.

WP Register Profile With Shortcode

Plugin Slug:
wp-register-profile-with-shortcode
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Easy restaurant menu manager

Plugin Slug:
easy-pdf-restaurant-menu-upload
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

PW WooCommerce On Sale!

Plugin Slug:
pw-woocommerce-on-sale
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.40
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.40.

Sharable Password Protected Posts

Plugin Slug:
sharable-password-protected-posts
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.9.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.8.

GB Forms DB

Plugin Slug:
gb-forms-db
Installations
30+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.3.

Site Chat on Telegram

Plugin Slug:
site-chat-on-telegram
Installations
30+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.6.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
30+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
30+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.

BeeTeam368 Extensions

Plugin:
BeeTeam368 Extensions
Plugin Slug:
beeteam368-extensions
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.3.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.6.

CSS3 Compare Pricing Tables for WordPress

Plugin:
CSS3 Compare Pricing Tables for WordPress
Plugin Slug:
css3_web_pricing_tables_grids
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.7.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.7.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.1.1.

HTML5 Radio Player – WPBakery Page Builder Addon

Plugin:
HTML5 Radio Player – WPBakery Page Builder Addon
Plugin Slug:
lbg-cleverbakery
Vulnerability:
Arbitrary File Download
Patched in Version:
2.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.3.

Modern Events Calendar Lite

Plugin:
Modern Events Calendar Lite
Plugin Slug:
modern-events-calendar-lite
Vulnerability:
SQL Injection
Patched in Version:
6.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.4.0.

Order Delivery Date for WP e-Commerce

Plugin:
Order Delivery Date for WP e-Commerce
Plugin Slug:
order-delivery-date
Vulnerability:
Sensitive Data Exposure
Patched in Version:
12.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.6.0.

Support Board

Plugin:
Support Board
Plugin Slug:
supportboard
Vulnerability:
Broken Access Control
Patched in Version:
3.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.1.

Support Board

Plugin:
Support Board
Plugin Slug:
supportboard
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

WP File Download

Plugin:
WP File Download
Plugin Slug:
wp-file-download
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.6.

WordPress Themes — 9 Patched / 11 Unpatched

Electrician – Electrical Service WordPress

Theme:
Electrician – Electrical Service WordPress
Theme Slug:
electrician
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Easy Video Player WordPress & WooCommerce

Theme:
Easy Video Player WordPress & WooCommerce
Theme Slug:
fwdevp
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hillter

Theme:
Hillter
Theme Slug:
hillter
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Invico – WordPress Consulting Business Theme

Theme:
Invico – WordPress Consulting Business Theme
Theme Slug:
invico
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingEasy

Theme:
ListingEasy
Theme Slug:
listingeasy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nuss

Theme:
Nuss
Theme Slug:
nuss
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ofiz – WordPress Business Consulting Theme

Theme:
Ofiz – WordPress Business Consulting Theme
Theme Slug:
ofiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pro Bulk Watermark Plugin for WordPress

Theme:
Pro Bulk Watermark Plugin for WordPress
Theme Slug:
pro-watermark
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Sala

Theme:
Sala
Theme Slug:
sala
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Sala

Theme:
Sala
Theme Slug:
sala
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yogi

Theme:
Yogi
Theme Slug:
yogi
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alone

Theme:
Alone
Theme Slug:
alone
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.8.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.8.5.

Alone

Theme:
Alone
Theme Slug:
alone
Vulnerability:
Arbitrary File Deletion
Patched in Version:
7.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.8.5.

Noisa

Theme:
Noisa
Theme Slug:
noisa
Vulnerability:
PHP Object Injection
Patched in Version:
2.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.2.

Nokri

Theme:
Nokri
Theme Slug:
nokri
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.4.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
SQL Injection
Patched in Version:
3.2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.2.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Broken Access Control
Patched in Version:
8.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.6.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Content Injection
Patched in Version:
8.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.4.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.4.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Local File Inclusion
Patched in Version:
8.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security