WordPress Vulnerability Report

WordPress Vulnerability Report — August 13, 2025

Since last week, 83 new vulnerabilities have emerged in the WordPress ecosystem, including 77 plugins and 6 themes. Of those, 32 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 83 vulnerabilities have been publicly disclosed. Security patches for 51 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 32 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 46 Patched / 31 Unpatched

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Porn Videos Embed

Plugin Slug:
porn-videos-embed
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flex Guten – Multile Blocks

Plugin Slug:
flex-guten
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMM API

Plugin:
SMM API
Plugin Slug:
smm-api
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Project Cost Calculator

Plugin Slug:
project-cost-calculator
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-jScrollPane

Plugin Slug:
wp-jscrollpane
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BaiduXZH Submit(?????)

Plugin Slug:
i3geek-baiduxzh
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:
????????
Plugin Slug:
duoshuo
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin Slug:
user-language-switch
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Visit Counter

Plugin Slug:
visit-counter
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for KingComposer

Plugin Slug:
premium-addons-for-kingcomposer
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Slider

Plugin:
Simple Responsive Slider
Plugin Slug:
addi-simple-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CBX Restaurant Booking

Plugin:
CBX Restaurant Booking
Plugin Slug:
cbx-restaurant-booking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:
CleverReach® WP
Plugin Slug:
cleverreach-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:
CleverReach® WP
Plugin Slug:
cleverreach-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

esri-map-view

Plugin:
esri-map-view
Plugin Slug:
esri-map-view
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GMap Generator

Plugin:
GMap Generator
Plugin Slug:
gmap-venturit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IDonatePro

Plugin:
IDonatePro
Plugin Slug:
idonate-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Inline Stock Quotes

Plugin:
Inline Stock Quotes
Plugin Slug:
inline-stock-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:
WP Lead Capturing Pages
Plugin Slug:
leadcapture
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mmm Unity Loader

Plugin:
Mmm Unity Loader
Plugin Slug:
mmm-unity-loader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mosaic Generator

Plugin:
Mosaic Generator
Plugin Slug:
mosaic-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder – Advanced addons for Elementor

Plugin:
RT Easy Builder – Advanced addons for Elementor
Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer)

Plugin:
OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer)
Plugin Slug:
stepbyteservice-openstreetmap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Purchase Orders

Plugin:
WooCommerce Purchase Orders
Plugin Slug:
wc-purchase-orders
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp chart generator

Plugin:
Wp chart generator
Plugin Slug:
wp-chart-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:
WP Private Content Plus
Plugin Slug:
wp-private-content-plus
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Tournament Registration

Plugin:
WP Tournament Registration
Plugin Slug:
wp-tournament-registration
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF®)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.5.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.5.2.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Simple Local Avatars

Plugin Slug:
simple-local-avatars
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.

Ocean Social Sharing

Plugin Slug:
ocean-social-sharing
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.5.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.9.30
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.30.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.9.29
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.29.

UiCore Elements – Free Elementor widgets and templates

Plugin Slug:
uicore-elements
Installations
40,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

Coupon Affiliates – Affiliate Plugin for WooCommerce

Plugin Slug:
woo-coupon-usage
Installations
4,000+
Vulnerability:
Settings Change
Patched in Version:
6.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.

GravityWP – Merge Tags

Plugin Slug:
gravitywp-merge-tags
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro
Installations
1,000+
Vulnerability:
CSV Injection
Patched in Version:
0.16.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.16.18.

Prevent files / folders access

Plugin Slug:
prevent-file-access
Installations
1,000+
Vulnerability:
Path Traversal
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

FundEngine – Donation and Crowdfunding Platform

Plugin Slug:
wp-fundraising-donation
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.5.

B Blocks – The ultimate block collection

Plugin Slug:
b-blocks
Installations
800+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.7.

Code Engine

Plugin Slug:
code-engine
Installations
600+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
0.3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.3.4.

Form Block

Plugin:
Form Block
Plugin Slug:
form-block
Installations
200+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.5.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.6.

RentSyst – CRM solution for fleet management

Plugin Slug:
rentsyst
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.101
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.101.

Download Counter

Plugin Slug:
download-counter
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Brave Conversion Engine (PRO)

Plugin:
Brave Conversion Engine (PRO)
Plugin Slug:
bravepopup-pro
Vulnerability:
Broken Authentication
Patched in Version:
0.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.8.0.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:
WordPress Event Manager, Event Calendar and Booking Plugin
Plugin Slug:
eventin-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.25.
Plugin:
Global Gallery
Plugin Slug:
global-gallery
Vulnerability:
Broken Access Control
Patched in Version:
9.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.2.4.

Groundhogg

Plugin:
Groundhogg
Plugin Slug:
groundhogg
Vulnerability:
PHP Object Injection
Patched in Version:
4.2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.1.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.

Multimedia Playlist Slider Addon for WPBakery Page Builder

Plugin:
Multimedia Playlist Slider Addon for WPBakery Page Builder
Plugin Slug:
lbg_vp_youtube_vimeo_addon_visual_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

MapSVG

Plugin:
MapSVG
Plugin Slug:
mapsvg
Vulnerability:
SQL Injection
Patched in Version:
8.7.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.7.4.

Cost Calculator

Plugin:
Cost Calculator
Plugin Slug:
ql-cost-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7 .5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7 .5.

Reveal Listing

Plugin:
Reveal Listing
Plugin Slug:
reveal-listing
Vulnerability:
Privilege Escalation
Patched in Version:
3.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.

Use-your-Drive

Plugin:
Use-your-Drive
Plugin Slug:
use-your-drive
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.2.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.4.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.27.

WordPress Themes — 5 Patched / 1 Unpatched

Shopo

Theme:
Shopo
Theme Slug:
shopo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Zakra

Theme:
Zakra
Theme Slug:
zakra
Downloads
1,935,472
Vulnerability:
Broken Access Control
Patched in Version:
4.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.6.

Betheme

Theme:
Betheme
Theme Slug:
betheme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
28.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 28.1.4.

The7

Theme:
The7
Theme Slug:
dt-the7
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.7.0.

Urna

Theme:
Urna
Theme Slug:
urna
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.8.

Xinterio

Theme:
Xinterio
Theme Slug:
xinterio
Vulnerability:
Local File Inclusion
Patched in Version:
4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security