WordPress Vulnerability Report

WordPress Vulnerability Report — August 20, 2025

Since last week, 191 new vulnerabilities have emerged in the WordPress ecosystem, including 174 plugins and 17 themes. Of those, 98 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 191 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 98 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 81 Patched / 93 Unpatched

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
8,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Login Log

Plugin Slug:
simple-login-log
Installations
6,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Emmet

Plugin:
WP Emmet
Plugin Slug:
wp-emmet
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Info Widget

Plugin Slug:
simple-contact-info-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StoryChief

Plugin:
StoryChief
Plugin Slug:
story-chief
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-warning
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-warning
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Transition

Plugin Slug:
page-transition
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Discord Post Plus – Supports Unlimited Channels

Plugin Slug:
wp-discord-post-plus
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AL Pack

Plugin:
AL Pack
Plugin Slug:
alpack
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DigitalOcean Spaces Sync

Plugin Slug:
do-spaces-sync
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inspectlet – User Session Recording and Heatmaps

Plugin Slug:
inspectlet-heatmaps-and-user-session-recording
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Terms of Service & Privacy Policy Generator

Plugin Slug:
terms-of-service-and-privacy-policy
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iframe Wrapper

Plugin Slug:
iframe-wrapper
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Doo Components for Visual Composer

Plugin Slug:
animated-icon-banner-for-visual-composer
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin Slug:
build-app-online
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Menu

Plugin Slug:
custom-menu
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide Text Shortcode

Plugin Slug:
hide-text-shortcode
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Laposta WooCommerce

Plugin Slug:
laposta-woocommerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeablePress: Simple Frontend Profile Picture Upload

Plugin Slug:
codeablepress-simple-frontend-profile-picture-upload
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Embed Bokun

Plugin Slug:
embed-bokun
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forms

Plugin:
Forms
Plugin Slug:
forms-by-made-it
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Netease Music

Plugin Slug:
netease-music
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Project Cost Calculator

Plugin Slug:
project-cost-calculator
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin Slug:
time-sheets
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-Database-Optimizer-Tools

Plugin Slug:
wp-database-optimizer-tools
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-dynamic-links
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Authentication and xmlrpc log writer

Plugin Slug:
authentication-and-xmlrpc-log-writer
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
80+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for KingComposer

Plugin Slug:
premium-addons-for-kingcomposer
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simplified Plugin

Plugin Slug:
simplified
Installations
70+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Voting

Plugin:
WP Voting
Plugin Slug:
wp-voting
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Jenga Payment Gateway for WooCommerce

Plugin Slug:
woo-jenga-payment-gateway
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress StoryMap Plugin

Plugin Slug:
wp-storymap
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AWStats Script

Plugin Slug:
awstats-script
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment

Plugin Slug:
customcomment
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Airdrop Manager

Plugin Slug:
airdrop
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elizaibots

Plugin:
Elizaibots
Plugin Slug:
elizaibot-chatbots
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
vertical-scroll-slideshow-gallery-v2
Installations
20+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dropshix

Plugin:
Dropshix
Plugin Slug:
dropshipping-xox
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Poll

Plugin Slug:
simple-poll
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
soundst-seo-search
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video Expander

Plugin Slug:
video-expander
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add User Meta

Plugin:
Add User Meta
Plugin Slug:
add-user-meta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Responsive Slider

Plugin:
Simple Responsive Slider
Plugin Slug:
addi-simple-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alobaidi Captcha

Plugin:
Alobaidi Captcha
Plugin Slug:
alobaidi-captcha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Anber Elementor Addon

Plugin:
Anber Elementor Addon
Plugin Slug:
anber-elementor-addon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Assistant for NextGEN Gallery
Plugin Slug:
assistant-for-nextgen-gallery
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bizcalendar-web

Plugin:
bizcalendar-web
Plugin Slug:
bizcalendar-web
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blog Designer PRO

Plugin:
Blog Designer PRO
Plugin Slug:
blog-designer-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CBX Restaurant Booking

Plugin:
CBX Restaurant Booking
Plugin Slug:
cbx-restaurant-booking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:
CleverReach® WP
Plugin Slug:
cleverreach-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin:
CleverReach® WP
Plugin Slug:
cleverreach-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Earnware Connect

Plugin:
Earnware Connect
Plugin Slug:
earnware-connect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
elink – Embed Content
Plugin Slug:
elink-embed-content
Vulnerability:
Other Vulnerability Type
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
flexo-social-gallery
Plugin Slug:
flexo-social-gallery
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Video Player

Plugin:
Ultimate Video Player
Plugin Slug:
fwduvp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gestion de tarifs

Plugin:
Gestion de tarifs
Plugin Slug:
gestion-tarifs
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GMap Generator

Plugin:
GMap Generator
Plugin Slug:
gmap-venturit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Icons Factory

Plugin:
Icons Factory
Plugin Slug:
icons-factory
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Inline Stock Quotes

Plugin:
Inline Stock Quotes
Plugin Slug:
inline-stock-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Intl DateTime Calendar

Plugin:
Intl DateTime Calendar
Plugin Slug:
intl-datetime-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Last.fm Recent Album Artwork

Plugin:
Last.fm Recent Album Artwork
Plugin Slug:
lastfm-recent-album-artwork
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LatestCheckins

Plugin:
LatestCheckins
Plugin Slug:
latestcheckins
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Linux Promotional Plugin

Plugin:
Linux Promotional Plugin
Plugin Slug:
linux-promotional-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mosaic Generator

Plugin:
Mosaic Generator
Plugin Slug:
mosaic-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NetInsight Analytics Implementation Plugin

Plugin:
NetInsight Analytics Implementation Plugin
Plugin Slug:
netinsight-analytics-implementation-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NetInsight Analytics Implementation Plugin

Plugin:
NetInsight Analytics Implementation Plugin
Plugin Slug:
netinsight-analytics-implementation-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pending Order Bot

Plugin Slug:
pending-order-bot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks

Plugin:
Radius Blocks
Plugin Slug:
radius-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RT Easy Builder – Advanced addons for Elementor

Plugin:
RT Easy Builder – Advanced addons for Elementor
Plugin Slug:
rt-easy-builder-advanced-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ServerBuddy by PluginBuddy.com

Plugin:
ServerBuddy by PluginBuddy.com
Plugin Slug:
serverbuddy-by-pluginbuddy
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Surbma | Recent Comments Shortcode

Plugin:
Surbma | Recent Comments Shortcode
Plugin Slug:
surbma-recent-comments-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Thim Core

Plugin:
Thim Core
Plugin Slug:
thim-core
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Thim Core

Plugin:
Thim Core
Plugin Slug:
thim-core
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Purchase Orders

Plugin:
WooCommerce Purchase Orders
Plugin Slug:
wc-purchase-orders
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

weichuncai(WP???)

Plugin:
weichuncai(WP???)
Plugin Slug:
weichuncai
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp chart generator

Plugin:
Wp chart generator
Plugin Slug:
wp-chart-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:
WP Private Content Plus
Plugin Slug:
wp-private-content-plus
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin README Parser

Plugin:
Plugin README Parser
Plugin Slug:
wp-readme-parser
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

File Manager Pro – Filester

Plugin Slug:
filester
Installations
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Kadence WooCommerce Email Designer

Plugin Slug:
kadence-woocommerce-email-designer
Installations
100,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.17.

Simple Local Avatars

Plugin Slug:
simple-local-avatars
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.28.

WPC Smart Compare for WooCommerce

Plugin Slug:
woo-smart-compare
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.8.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.1.

WP Table Builder – WordPress Table Plugin

Plugin Slug:
wp-table-builder
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.13.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2025.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2025.7.

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Visual Composer Website Builder

Plugin Slug:
visualcomposer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
45.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 45.15.0.

BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia, AI Support, Instant Answers

Plugin Slug:
betterdocs
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.2.

Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

Plugin Slug:
quiz-master-next
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.3.

UiCore Elements – Free Elementor widgets and templates

Plugin Slug:
uicore-elements
Installations
40,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
30,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.1.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.11.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.17.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.28.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.28.5.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Quttera Web Malware Scanner

Plugin Slug:
quttera-web-malware-scanner
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.5.2.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.5.2.1.

Shortcode Redirect

Plugin Slug:
shortcode-redirect
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.03
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.03.

Flexible Map

Plugin Slug:
wp-flexible-map
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.19.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.19.0.

Dynamic Pricing With Discount Rules for WooCommerce

Plugin Slug:
aco-woo-dynamic-pricing
Installations
7,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
4.5.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.5.10.

B Slider – Responsive Image Slider

Plugin Slug:
b-slider
Installations
5,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

B Slider – Responsive Image Slider

Plugin Slug:
b-slider
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Embedder for Google Reviews

Plugin Slug:
embedder-for-google-reviews
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

WP Shopify

Plugin:
WP Shopify
Plugin Slug:
wp-shopify
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

Premium Packages – Sell Digital Products Securely

Plugin Slug:
wpdm-premium-packages
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.3.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.5.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.5.5.

oik

Plugin:
oik
Plugin Slug:
oik
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.15.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.15.3.

Order Tip for WooCommerce

Plugin Slug:
order-tip-woo
Installations
2,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.5.

Easy Elementor Addons

Plugin Slug:
easy-elementor-addons
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

AnWP Football Leagues

Plugin Slug:
football-leagues-by-anwppro
Installations
1,000+
Vulnerability:
CSV Injection
Patched in Version:
0.16.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.16.18.

Injection Guard

Plugin Slug:
injection-guard
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.8.

Markup Markdown

Plugin Slug:
markup-markdown
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.7.

Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Dripping

Plugin Slug:
membership-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.0.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.3.8.

12 Step Meeting List

Plugin Slug:
12-step-meeting-list
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.18.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.18.4.

RSS Feed Pro

Plugin Slug:
rss-feed-pro
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

WordLift – AI powered SEO – Schema

Plugin Slug:
wordlift
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.54.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.54.6.

Easy restaurant menu manager

Plugin Slug:
easy-pdf-restaurant-menu-upload
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

WooCommerce Fortnox Integration

Plugin Slug:
woocommerce-fortnox-integration
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.7.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.6.

Neon Channel Product Customizer Free

Plugin Slug:
neon-channel-product-customizer-free
Installations
40+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.

Billplz Addon for Contact Form 7

Plugin Slug:
billplz-for-contact-form-7
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:
WordPress Event Manager, Event Calendar and Booking Plugin
Plugin Slug:
eventin-pro
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
4.0.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.25.

WordPress Event Manager, Event Calendar and Booking Plugin

Plugin:
WordPress Event Manager, Event Calendar and Booking Plugin
Plugin Slug:
eventin-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.25.

JetElements For Elementor

Plugin:
JetElements For Elementor
Plugin Slug:
jet-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.9.1.

JetProductGallery

Plugin:
JetProductGallery
Plugin Slug:
jet-woo-product-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.3.

Login with phone number

Plugin:
Login with phone number
Plugin Slug:
login-with-phone-number
Vulnerability:
Broken Authentication
Patched in Version:
1.8.48
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.48.

Real Estate Manager Pro

Plugin:
Real Estate Manager Pro
Plugin Slug:
real-estate-manager-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.7.4.
Plugin:
Responsive Posts Carousel WordPress Plugin
Plugin Slug:
responsive-posts-carousel-pro
Vulnerability:
Local File Inclusion
Patched in Version:
15.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 15.1.

Templatera

Plugin:
Templatera
Plugin Slug:
templatera
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
SQL Injection
Patched in Version:
3.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.1.

File Manager Pro

Plugin:
File Manager Pro
Plugin Slug:
wp-file-manager-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
8.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.3.

WP Membership

Plugin:
WP Membership
Plugin Slug:
wp-membership
Vulnerability:
Settings Change
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

WordPress Themes — 12 Patched / 5 Unpatched

modernize

Theme Slug:
modernize
Downloads
59,351
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

modernize

Theme Slug:
modernize
Downloads
59,351
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Kalium

Theme:
Kalium
Theme Slug:
kalium
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Stratus

Theme:
Stratus
Theme Slug:
stratus
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

WP Rentals

Theme:
WP Rentals
Theme Slug:
wprentals
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
4,877,063
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

OceanWP

Theme:
OceanWP
Theme Slug:
oceanwp
Downloads
8,737,187
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.2.

The7

Theme:
The7
Theme Slug:
dt-the7
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.7.0.

Findgo

Theme:
Findgo
Theme Slug:
findgo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.58
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.58.

Makeaholic

Theme:
Makeaholic
Theme Slug:
makeaholic
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.5.

Real Spaces

Theme:
Real Spaces
Theme Slug:
real-spaces
Vulnerability:
Privilege Escalation
Patched in Version:
3.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.1.

Real Spaces

Theme:
Real Spaces
Theme Slug:
real-spaces
Vulnerability:
Privilege Escalation
Patched in Version:
3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.

Savoy

Theme:
Savoy
Theme Slug:
savoy
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.9.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.8.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Local File Inclusion
Patched in Version:
8.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.6.8.

Soledad

Theme:
Soledad
Theme Slug:
soledad
Vulnerability:
Content Injection
Patched in Version:
8.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.6.8.

Unicamp

Theme:
Unicamp
Theme Slug:
unicamp
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security