WordPress Vulnerability Report

WordPress Vulnerability Report — July 23, 2025

Since last week, 167 new vulnerabilities have emerged in the WordPress ecosystem, including 162 plugins and 5 themes. 42 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 167 vulnerabilities have been publicly disclosed. Security patches for 125 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 42 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 is now available! This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 121 Patched / 41 Unpatched

URL Shortener Plugin For WordPress

Plugin Slug:
exact-links
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DB Backup

Plugin:
DB Backup
Plugin Slug:
db-backup
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nginx Cache Purge Preload

Plugin Slug:
fastcgi-cache-purge-and-preload-nginx
Installations
80+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
block-editor-gallery-slider
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

aapanel WP Toolkit

Plugin:
aapanel WP Toolkit
Plugin Slug:
aapanel-wp-toolkit
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Reviews

Plugin:
Affiliate Reviews
Plugin Slug:
affiliate-reviews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alike – WordPress Custom Post Comparison

Plugin:
Alike – WordPress Custom Post Comparison
Plugin Slug:
alike
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Attachment Manager

Plugin:
Attachment Manager
Plugin Slug:
attachment-manager
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Avishi WP PayPal Payment Button

Plugin:
Avishi WP PayPal Payment Button
Plugin Slug:
avishi-wp-paypal-payment-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)

Plugin:
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)
Plugin Slug:
azon-addon-js-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

B1.lt for WooCommerce

Plugin:
B1.lt for WooCommerce
Plugin Slug:
b1-accounting
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Birth Chart Compatibility

Plugin:
Birth Chart Compatibility
Plugin Slug:
birth-chart-compatibility
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Biteship

Plugin:
Biteship
Plugin Slug:
biteship
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brandfolder

Plugin:
Brandfolder
Plugin Slug:
brandfolder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bSecure – Your Universal Checkout

Plugin:
bSecure – Your Universal Checkout
Plugin Slug:
bsecure
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Copymatic

Plugin:
Copymatic
Plugin Slug:
copymatic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Counter live visitors for WooCommerce

Plugin:
Counter live visitors for WooCommerce
Plugin Slug:
counter-visitor-for-woocommerce
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Crowdfunding for WooCommerce

Plugin:
Crowdfunding for WooCommerce
Plugin Slug:
crowdfunding-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FoodMenu

Plugin:
FoodMenu
Plugin Slug:
dzs-restaurantmenu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Shop Page Builder

Plugin:
WooCommerce Shop Page Builder
Plugin Slug:
dzs-wootable
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EPay.bg Payments

Plugin:
EPay.bg Payments
Plugin Slug:
epaybg-payments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IDonatePro

Plugin:
IDonatePro
Plugin Slug:
idonate-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Latest Post Accordian Slider

Plugin:
Latest Post Accordian Slider
Plugin Slug:
latest-post-accordian-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin:
Multimedia Playlist Slider Addon for WPBakery Page Builder
Plugin Slug:
lbg_vp_youtube_vimeo_addon_visual_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Like & Share My Site

Plugin:
Like & Share My Site
Plugin Slug:
like-share-my-site
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Listly

Plugin:
Listly
Plugin Slug:
listly
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live Stream Badger

Plugin:
Live Stream Badger
Plugin Slug:
live-stream-badger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Map My Locations

Plugin:
Map My Locations
Plugin Slug:
map-my-locations
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Partnerský systém Martinus

Plugin:
Partnerský systém Martinus
Plugin Slug:
martinus-partnersky-system
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mediabay – WordPress Media Library Folders

Plugin:
Mediabay – WordPress Media Library Folders
Plugin Slug:
mediabay
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Orion Login with SMS

Plugin:
Orion Login with SMS
Plugin Slug:
orion-login-with-sms
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The E-Commerce ERP

Plugin:
The E-Commerce ERP
Plugin Slug:
profitori
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Restrict File Access

Plugin:
Restrict File Access
Plugin Slug:
restrict-file-access
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ruven Themes: Shortcodes

Plugin:
Ruven Themes: Shortcodes
Plugin Slug:
ruven-themes-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Temporarily Hidden Content

Plugin:
Temporarily Hidden Content
Plugin Slug:
temporarily-hidden-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Terms descriptions

Plugin:
Terms descriptions
Plugin Slug:
terms-descriptions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Post type

Plugin:
Testimonial Post type
Plugin Slug:
testimonial-post-type
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Useful Tab Block

Plugin:
Useful Tab Block
Plugin Slug:
useful-tab-block-responsive-amp-compatible
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Vertical scroll image slideshow gallery
Plugin Slug:
vertical-scroll-image-slideshow-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zuppler Online Ordering

Plugin:
Zuppler Online Ordering
Plugin Slug:
zuppler-online-ordering
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.3.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.3.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
Broken Authentication
Patched in Version:
3.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.0.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.12.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.27.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.2.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.2.

Companion Auto Update

Plugin Slug:
companion-auto-update
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.3.

Stop User Enumeration

Plugin Slug:
stop-user-enumeration
Installations
50,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.3.

SMTP2GO for WordPress – Email Made Easy

Plugin Slug:
smtp2go
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.12.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.2.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.17.

Videopack

Plugin:
Videopack
Plugin Slug:
video-embed-thumbnail-generator
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.4.

Malcure Malware Scanner — #1 Toolset for Malware Removal

Plugin Slug:
wp-malware-removal
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.9.

Malcure Malware Scanner — #1 Toolset for Malware Removal

Plugin Slug:
wp-malware-removal
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
17.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 17.1.

AntiSpam for Contact Form 7

Plugin Slug:
cf7-antispam
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.4.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.5.5.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage
Installations
5,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.1.

WPAdverts – Classifieds Plugin

Plugin Slug:
wpadverts
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)

Plugin Slug:
elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

GSheetConnector for WC

Plugin Slug:
wc-gsheetconnector
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Restaurant Menu and Food Ordering

Plugin Slug:
mp-restaurant-menu
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Newsletters

Plugin Slug:
newsletters-lite
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.11.

Animator – Scroll Triggered Animations

Plugin Slug:
scroll-triggered-animations
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.17.

SMTP for Amazon SES – YaySMTP

Plugin Slug:
smtp-amazon-ses
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

Theme Builder For Elementor

Plugin Slug:
theme-builder-for-elementor
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Wallet System for WooCommerce

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.

WP Post Hide

Plugin Slug:
wp-post-hide
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Widget for Google Reviews

Plugin Slug:
business-reviews-wp
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.16.

Custom API for WP

Plugin Slug:
custom-api-for-wp
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
4.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.3.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

Ebook Store

Plugin Slug:
ebook-store
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8013
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8013.

SMTP for SendGrid – YaySMTP

Plugin Slug:
smtp-sendgrid
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.

YayExtra – WooCommerce Extra Product Options

Plugin Slug:
yayextra
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.6.

FG Drupal to WordPress

Plugin Slug:
fg-drupal-to-wp
Installations
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.90.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.90.1.

Ultimate WP Mail

Plugin Slug:
ultimate-wp-mail
Installations
900+
Vulnerability:
Privilege Escalation
Patched in Version:
1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.7.

Maya Business Plugin

Plugin Slug:
paymaya-checkout-for-woocommerce
Installations
600+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

Stop and Block bots plugin Anti bots

Plugin Slug:
antibots
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.50
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.50.

Chatbox Manager

Plugin Slug:
wa-chatbox-manager
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

SMTP for Sendinblue – YaySMTP

Plugin Slug:
smtp-sendinblue
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Formality

Plugin:
Formality
Plugin Slug:
formality
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.10.

Image Wall

Plugin:
Image Wall
Plugin Slug:
image-wall
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.

Residential Address Detection

Plugin Slug:
residential-address-detection
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.10.

Cloud SAML SSO – Single Sign On Login

Plugin Slug:
cloud-sso-single-sign-on
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.19.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

Import CDN-Remote Images

Plugin Slug:
import-cdn-remote-images
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Knowledge Base

Plugin Slug:
knowledgebase
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

MORKVA Vchasno Kasa Integration

Plugin Slug:
mrkv-vchasno-kasa
Installations
30+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

MORKVA Vchasno Kasa Integration

Plugin Slug:
mrkv-vchasno-kasa
Installations
30+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Bears Backup

Plugin:
Bears Backup
Plugin Slug:
bears-backup
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.0.

Foxypress

Plugin:
Foxypress
Plugin Slug:
foxypress
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.4.2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.4.2.2.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.2.

GymBase Theme Classes

Plugin:
GymBase Theme Classes
Plugin Slug:
gymbase_classes
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

JetBlocks For Elementor

Plugin:
JetBlocks For Elementor
Plugin Slug:
jet-blocks
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.19.

JetBlocks For Elementor

Plugin:
JetBlocks For Elementor
Plugin Slug:
jet-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.19.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.19.1.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.1.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.1.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.7.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.1.

JetMenu

Plugin:
JetMenu
Plugin Slug:
jet-menu
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.11.2.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.15.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.15.1.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.16.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.15.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.15.1.

JetSearch

Plugin:
JetSearch
Plugin Slug:
jet-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.11.

JetSmartFilters

Plugin:
JetSmartFilters
Plugin Slug:
jet-smart-filters
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.6.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.7.1.

JetSmartFilters

Plugin:
JetSmartFilters
Plugin Slug:
jet-smart-filters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.8.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.1.

JetTricks

Plugin:
JetTricks
Plugin Slug:
jet-tricks
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.2.

JetTricks

Plugin:
JetTricks
Plugin Slug:
jet-tricks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.2.

JetWooBuilder

Plugin:
JetWooBuilder
Plugin Slug:
jet-woo-builder
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.20.1.

Radio Player Shoutcast & Icecast

Plugin:
Radio Player Shoutcast & Icecast
Plugin Slug:
lbg-audio4-html5-shoutcast
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.8.

Apollo – Sticky Full Width HTML5 Audio Player

Plugin:
Apollo – Sticky Full Width HTML5 Audio Player
Plugin Slug:
lbg-audio5-html5-shoutcast-sticky
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.4.

SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Support

Plugin:
SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Support
Plugin Slug:
lbg-audio8-html5-radio-ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.5.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:
Universal Video Player – Addon for WPBakery Page Builder
Plugin Slug:
lbg-universal-video-player-addon-visual-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.0.

HTML5 Radio Player – WPBakery Page Builder Addon

Plugin:
HTML5 Radio Player – WPBakery Page Builder Addon
Plugin Slug:
lbg_radio_player_addon_visual_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.2.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:
Universal Video Player – Addon for WPBakery Page Builder
Plugin Slug:
lbg_universal_video_player_addon_visual_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.0.

LoginPress Pro

Plugin:
LoginPress Pro
Plugin Slug:
loginpress-pro
Vulnerability:
Broken Authentication
Patched in Version:
5.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.2.

Madara – Responsive Manga Site

Plugin:
Madara – Responsive Manga Site
Plugin Slug:
madara-core
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.4.

MasterStudy LMS Pro

Plugin:
MasterStudy LMS Pro
Plugin Slug:
masterstudy-lms-learning-management-system-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.7.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.7.10.

Modern Events Calendar Lite

Plugin:
Modern Events Calendar Lite
Plugin Slug:
modern-events-calendar-lite
Vulnerability:
SQL Injection
Patched in Version:
6.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.4.0.
Plugin:
Simple Link Directory
Plugin Slug:
qc-simple-link-directory
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 14.8.1.

Cost Calculator

Plugin:
Cost Calculator
Plugin Slug:
ql-cost-calculator
Vulnerability:
Broken Access Control
Patched in Version:
7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.

Revolution Video Player With Bottom Playlist

Plugin:
Revolution Video Player With Bottom Playlist
Plugin Slug:
revolution-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.3.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Local File Inclusion
Patched in Version:
1.93.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.93.1.

The Plus Addons for Elementor Pro

Plugin:
The Plus Addons for Elementor Pro
Plugin Slug:
theplus_elementor_addon
Vulnerability:
Broken Access Control
Patched in Version:
6.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.7.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
Broken Access Control
Patched in Version:
1.0.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
SQL Injection
Patched in Version:
1.0.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.0.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.2.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Transposh WordPress Translation

Plugin:
Transposh WordPress Translation
Plugin Slug:
transposh-translation-filter-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.35.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.35.2.2.

Youtube Vimeo Video Player and Slider

Plugin:
Youtube Vimeo Video Player and Slider
Plugin Slug:
video_player_youtube_vimeo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.

WooCommerce Refund And Exchange with RMA

Plugin:
WooCommerce Refund And Exchange with RMA
Plugin Slug:
woocommerce-refund-and-exchange
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.2.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.7.

Pinterest Automatic Pin

Plugin:
Pinterest Automatic Pin
Plugin Slug:
wp-pinterest-automatic
Vulnerability:
SQL Injection
Patched in Version:
4.19.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.19.0.

WordPress Themes — 4 Patched / 1 Unpatched

Theme:
Visual Art | Gallery WordPress Theme
Theme Slug:
visual-arts
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hestia

Theme:
Hestia
Theme Slug:
hestia
Downloads
4,446,823
Vulnerability:
Broken Access Control
Patched in Version:
3.2.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.11.

Alone

Theme:
Alone
Theme Slug:
alone
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.8.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.8.5.

Alone

Theme:
Alone
Theme Slug:
alone
Vulnerability:
Arbitrary File Deletion
Patched in Version:
7.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.8.5.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Broken Access Control
Patched in Version:
4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security