WordPress Vulnerability Report — September 24, 2025
Since last week, 354 new vulnerabilities have emerged in the WordPress ecosystem, including 2 in WordPress Core, 339 plugins and 13 themes. Of those, 265 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

In this report, 354 vulnerabilities have been publicly disclosed. Security patches for 89 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 265 WordPress Core, plugin, and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
Patchstack’s bug-bounty program recently disclosed two WordPress Core vulnerabilities. Both are assessed as low severity and require an attacker to have a compromised Contributor-level account on the site to exploit, making widespread abuse unlikely. No virtual patch is available or required; the WordPress Core security team is actively investigating and coordinating fixes.
WordPress Core
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58246
WordPress Core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58674
WordPress Plugins — 85 Patched / 254 Unpatched
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
- Plugin Slug:
- all-in-one-seo-pack
- Installations
- 3,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58649
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
- Plugin Slug:
- all-in-one-seo-pack
- Installations
- 3,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58650
Sticky Header Effects for Elementor
- Plugin Slug:
- sticky-header-effects-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58251
Nextend Social Login and Register
- Plugin Slug:
- nextend-facebook-connect
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58031
TI WooCommerce Wishlist
- Plugin:
- TI WooCommerce Wishlist
- Plugin Slug:
- ti-woocommerce-wishlist
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58247
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
- Plugin Slug:
- interactive-3d-flipbook-powered-physics-engine
- Installations
- 80,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58226
Jupiter X Core
- Plugin:
- Jupiter X Core
- Plugin Slug:
- jupiterx-core
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58264
Master Slider – Responsive Touch Slider
- Plugin Slug:
- master-slider
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58025
Getwid – Gutenberg Blocks
- Plugin:
- Getwid – Gutenberg Blocks
- Plugin Slug:
- getwid
- Installations
- 50,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58252
Image Hover Effects – Elementor Addon
- Plugin Slug:
- image-hover-effects-addon-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57939
Perfect Brands for WooCommerce
- Plugin:
- Perfect Brands for WooCommerce
- Plugin Slug:
- perfect-woocommerce-brands
- Installations
- 50,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58686
Better Find and Replace – AI-Powered Suggestions
- Plugin Slug:
- real-time-auto-find-and-replace
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53466
DethemeKit for Elementor
- Plugin:
- DethemeKit for Elementor
- Plugin Slug:
- dethemekit-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57995
Page-list
- Plugin:
- Page-list
- Plugin Slug:
- page-list
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58030
Hubbub Lite – Fast, Reliable Social Sharing Buttons
- Plugin Slug:
- social-pug
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58007
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
- Plugin Slug:
- gutenkit-blocks-addon
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57900
Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor
- Plugin Slug:
- gutentor
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58680
Ads by Quads – Adsense Ads, Banner Ads, Popup Ads
- Plugin Slug:
- quick-adsense-reloaded
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53459
Trustpilot Reviews
- Plugin:
- Trustpilot Reviews
- Plugin Slug:
- trustpilot-reviews
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57997
WP Events Manager
- Plugin:
- WP Events Manager
- Plugin Slug:
- wp-events-manager
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57987
Accordion – AI FAQ, Accordion, Tabs, Image Accordion, Product FAQ, FAQ Builder, FAQ Grid
- Plugin Slug:
- accordions
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58678
Geolocation IP Detection
- Plugin:
- Geolocation IP Detection
- Plugin Slug:
- geoip-detect
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57993
Custom Block Builder – Lazy Blocks
- Plugin Slug:
- lazy-blocks
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58258
Quiz Maker
- Plugin:
- Quiz Maker
- Plugin Slug:
- quiz-maker
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58014
Quiz Maker
- Plugin:
- Quiz Maker
- Plugin Slug:
- quiz-maker
- Installations
- 20,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58015
Uncanny Toolkit for LearnDash
- Plugin:
- Uncanny Toolkit for LearnDash
- Plugin Slug:
- uncanny-learndash-toolkit
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57988
Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend
- Plugin Slug:
- wp-user-frontend
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58672
Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User Frontend
- Plugin Slug:
- wp-user-frontend
- Installations
- 20,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58673
Blog Designer
- Plugin:
- Blog Designer
- Plugin Slug:
- blog-designer
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57990
Passster – Password Protect Pages and Content
- Plugin Slug:
- content-protector
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57926
Translate WordPress with ConveyThis
- Plugin Slug:
- conveythis-translate
- Installations
- 10,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-57919
Dashboard Notepad
- Plugin:
- Dashboard Notepad
- Plugin Slug:
- dashboard-notepad
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57927
Gallery Lightbox
- Plugin:
- Gallery Lightbox
- Plugin Slug:
- gallery-lightbox-slider
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57966
FAQ / Accordion / Docs / KB – Helpie WordPress FAQ Accordion plugin
- Plugin Slug:
- helpie-faq
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58659
Open User Map
- Plugin:
- Open User Map
- Plugin Slug:
- open-user-map
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57953
Portfolio for Elementor & Image Gallery | PowerFolio
- Plugin Slug:
- portfolio-elementor
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57932
Qubely – Advanced Gutenberg Blocks
- Plugin Slug:
- qubely
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58249
Qubely – Advanced Gutenberg Blocks
- Plugin Slug:
- qubely
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58663
Team – Team Members Showcase Plugin
- Plugin Slug:
- tlp-team
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57975
WP Subtitle
- Plugin:
- WP Subtitle
- Plugin Slug:
- wp-subtitle
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57986
WPeMatico RSS Feed Fetcher
- Plugin:
- WPeMatico RSS Feed Fetcher
- Plugin Slug:
- wpematico
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57937
Convert WordPress to app | AppMySite
- Plugin Slug:
- appmysite
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58679
No External Links
- Plugin:
- No External Links
- Plugin Slug:
- mihdan-no-external-links
- Installations
- 9,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53451
WP Compress – Instant Performance & Speed Optimization
- Plugin Slug:
- wp-compress-image-optimizer
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57899
WP Mailto Links – Protect Email Addresses
- Plugin Slug:
- wp-mailto-links
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53464
Awesome Support – WordPress HelpDesk & Support Plugin
- Plugin Slug:
- awesome-support
- Installations
- 8,000+
- Vulnerability:
- Deserialization of untrusted data
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58662
Participants Database
- Plugin:
- Participants Database
- Plugin Slug:
- participants-database
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58008
Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager
- Plugin Slug:
- wedevs-project-manager
- Installations
- 8,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58269
Poll Maker – Versus Polls, Anonymous Polls, Image Polls
- Plugin Slug:
- poll-maker
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57954
CoDesigner – All in One Elementor WooCommerce Builder
- Plugin Slug:
- woolementor
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57961
Flexible PDF Invoices for WooCommerce & WordPress
- Plugin Slug:
- flexible-invoices
- Installations
- 6,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-57977
Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
- Plugin:
- Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization
- Plugin Slug:
- metasync
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58019
WP Social Widget
- Plugin:
- WP Social Widget
- Plugin Slug:
- wp-social-widget
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57981
WPKoi Templates for Elementor
- Plugin:
- WPKoi Templates for Elementor
- Plugin Slug:
- wpkoi-templates-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57999
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds
- Plugin Slug:
- another-wordpress-classifieds-plugin
- Installations
- 4,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57928
Mail Subscribe List
- Plugin:
- Mail Subscribe List
- Plugin Slug:
- mail-subscribe-list
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58018
Post Carousel Slider for Elementor
- Plugin Slug:
- post-carousel-slider-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57955
Simple JWT Login – Allows you to use JWT on REST endpoints.
- Plugin Slug:
- simple-jwt-login
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58648
Ultimate Store Kit – Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder
- Plugin:
- Ultimate Store Kit – Elementor powered WooCommerce Builder, 80+ Widgets and Template Builder
- Plugin Slug:
- ultimate-store-kit
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58017
Cecabank WooCommerce Plugin
- Plugin:
- Cecabank WooCommerce Plugin
- Plugin Slug:
- cecabank-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58685
E-namad & Shamed Logo Manager
- Plugin:
- E-namad & Shamed Logo Manager
- Plugin Slug:
- e-namad-shamed-logo-manager
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57998
Interact: Embed A Quiz On Your Site
- Plugin Slug:
- interact-quiz-embed
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58675
Login-Logout
- Plugin:
- Login-Logout
- Plugin Slug:
- login-logout
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53467
Plugin Ongkos Kirim JNE Tiki Sicepat Wahana J&T POS for Woocommerce
- Plugin Slug:
- ongkoskirim-id
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57949
Designil PDPA Thailand
- Plugin:
- Designil PDPA Thailand
- Plugin Slug:
- pdpa-thailand
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58028
Piotnet Forms
- Plugin:
- Piotnet Forms
- Plugin Slug:
- piotnetforms
- Installations
- 3,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57933
Podlove Subscribe button
- Plugin:
- Podlove Subscribe button
- Plugin Slug:
- podlove-subscribe-button
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58227
Text To Speech TTS Accessibility
- Plugin:
- Text To Speech TTS Accessibility
- Plugin Slug:
- text-to-audio
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58664
CardCom Payment Gateway
- Plugin:
- CardCom Payment Gateway
- Plugin Slug:
- woo-cardcom-payment-gateway
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57976
Compact Archives
- Plugin:
- Compact Archives
- Plugin Slug:
- compact-archives
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58001
Estonian Shipping Methods for WooCommerce
- Plugin Slug:
- estonian-shipping-methods-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58656
Photo Gallery by Ays – Responsive Image Gallery
- Plugin Slug:
- gallery-photo-gallery
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57947
GD bbPress Tools
- Plugin:
- GD bbPress Tools
- Plugin Slug:
- gd-bbpress-tools
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58002
Import Markdown – Versatile Markdown Importer
- Plugin Slug:
- import-markdown
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57901
Sitekit
- Plugin:
- Sitekit
- Plugin Slug:
- sitekit
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58229
Quick View for WooCommerce
- Plugin:
- Quick View for WooCommerce
- Plugin Slug:
- woo-quickview
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58228
Bitly’s WordPress Plugin
- Plugin:
- Bitly’s WordPress Plugin
- Plugin Slug:
- wp-bitly
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58231
Advance Portfolio Grid, Slider and Gallery – Showcase Projects, Images and Videos
- Plugin Slug:
- advance-portfolio-grid
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57982
Advanced Appointment Booking & Scheduling
- Plugin Slug:
- advanced-appointment-booking-scheduling
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57978
Append extensions on Pages
- Plugin:
- Append extensions on Pages
- Plugin Slug:
- append-extensions-on-pages
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57940
Append Link on Copy
- Plugin:
- Append Link on Copy
- Plugin Slug:
- append-link-on-copy
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57941
AuthorSure
- Plugin:
- AuthorSure
- Plugin Slug:
- authorsure
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57979
BP Disable Activation Reloaded
- Plugin:
- BP Disable Activation Reloaded
- Plugin Slug:
- bp-disable-activation-reloaded
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57983
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more
- Plugin:
- CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more
- Plugin Slug:
- cf7-submissions
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58016
Clariti
- Plugin:
- Clariti
- Plugin Slug:
- clariti
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57991
Classic Widgets with Block-based Widgets
- Plugin Slug:
- classic-widgets-with-block-based-widgets
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58029
Content Mask
- Plugin:
- Content Mask
- Plugin Slug:
- content-mask
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58011
Content Mask
- Plugin:
- Content Mask
- Plugin Slug:
- content-mask
- Installations
- 1,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Low
- CVE:
- 2025-58012
CP Multi View Event Calendar
- Plugin:
- CP Multi View Event Calendar
- Plugin Slug:
- cp-multi-view-calendar
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Low
- CVE:
- 2025-58009
Double the Donation – A workplace giving tool to help your fundraising efforts
- Plugin Slug:
- double-the-donation
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57929
Double the Donation – A workplace giving tool to help your fundraising efforts
- Plugin Slug:
- double-the-donation
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57930
Emergency Password Reset
- Plugin:
- Emergency Password Reset
- Plugin Slug:
- emergency-password-reset
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57942
Fastly
- Plugin:
- Fastly
- Plugin Slug:
- fastly
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58199
Flexible FAQ
- Plugin:
- Flexible FAQ
- Plugin Slug:
- flexible-faq
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58200
Force Update Translations
- Plugin:
- Force Update Translations
- Plugin Slug:
- force-update-translations
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58236
Genesis Club Lite
- Plugin:
- Genesis Club Lite
- Plugin Slug:
- genesis-club-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58691
Connector Wizard (formerly LC Wizard)
- Plugin Slug:
- ghl-wizard
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58237
Hide WP Toolbar
- Plugin:
- Hide WP Toolbar
- Plugin Slug:
- hide-wp-toolbar
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57969
HT Mega – Absolute Addons for WPBakery Page Builder
- Plugin Slug:
- ht-mega-for-wpbakery
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53463
Beaf – Photo Comparison Block
- Plugin:
- Beaf – Photo Comparison Block
- Plugin Slug:
- image-compare-block
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53461
Kama Click Counter
- Plugin:
- Kama Click Counter
- Plugin Slug:
- kama-clic-counter
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58682
Last Updated Shortcode
- Plugin:
- Last Updated Shortcode
- Plugin Slug:
- last-updated-shortcode
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58683
Logo Showcase – Responsive Logo Carousel, Grid, List & Ticker for WordPress
- Plugin Slug:
- logo-showcase
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58684
MakeStories (for Google Web Stories)
- Plugin Slug:
- makestories-helper
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57984
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution
- Plugin Slug:
- marketking-multivendor-marketplace-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58702
Memberful – Membership Plugin
- Plugin:
- Memberful – Membership Plugin
- Plugin Slug:
- memberful-wp
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58000
Frontend File Manager Plugin
- Plugin:
- Frontend File Manager Plugin
- Plugin Slug:
- nmedia-user-file-uploader
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57921
PilotPress
- Plugin:
- PilotPress
- Plugin Slug:
- pilotpress
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58221
PilotPress
- Plugin:
- PilotPress
- Plugin Slug:
- pilotpress
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58238
Plugin Security Scanner
- Plugin:
- Plugin Security Scanner
- Plugin Slug:
- plugin-security-scanner
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57950
Product Addons and Product Options With Custom Fields – WowAddons
- Plugin Slug:
- product-addons
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57958
Quantities and Units for WooCommerce
- Plugin Slug:
- quantities-and-units-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58917
Safety Exit
- Plugin:
- Safety Exit
- Plugin Slug:
- safety-exit
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57980
SALESmanago & Leadoo
- Plugin:
- SALESmanago & Leadoo
- Plugin Slug:
- salesmanago
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57970
SALESmanago & Leadoo
- Plugin:
- SALESmanago & Leadoo
- Plugin Slug:
- salesmanago
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57971
SiteNarrator Text-to-Speech Widget
- Plugin Slug:
- sitespeaker-widget
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57951
Skimlinks Affiliate Marketing Tool
- Plugin Slug:
- skimlinks
- Installations
- 1,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57943
Skimlinks Affiliate Marketing Tool
- Plugin Slug:
- skimlinks
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57944
Skyword XMLRPC publishing
- Plugin:
- Skyword XMLRPC publishing
- Plugin Slug:
- skyword-plugin
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58703
Slightly troublesome permalink
- Plugin:
- Slightly troublesome permalink
- Plugin Slug:
- slightly-troublesome-permalink
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57959
SV Proven Expert
- Plugin:
- SV Proven Expert
- Plugin Slug:
- sv-provenexpert
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58010
Travel Map
- Plugin:
- Travel Map
- Plugin Slug:
- travelmap-blog
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57960
Ultimate Watermark – Advanced Image Watermarking
- Plugin Slug:
- ultimate-watermark
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57985
Upcoming Events Lists
- Plugin:
- Upcoming Events Lists
- Plugin Slug:
- upcoming-events-lists
- Installations
- 1,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57994
Draft – Tailwind CSS for WordPress.
- Plugin Slug:
- website-builder
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58033
Website Chat Button: Kommo integration
- Plugin Slug:
- website-chat-button-kommo-integration
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58666
WPB Quick View Popup for WooCommerce
- Plugin Slug:
- woocommerce-lightbox
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57967
WP Advanced PDF
- Plugin:
- WP Advanced PDF
- Plugin Slug:
- wp-advanced-pdf
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57945
Category Dropdown by GCS Design
- Plugin:
- Category Dropdown by GCS Design
- Plugin Slug:
- wp-category-dropdown
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58239
WP Compiler
- Plugin:
- WP Compiler
- Plugin Slug:
- wp-compiler
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58032
WP Delete User Accounts
- Plugin:
- WP Delete User Accounts
- Plugin Slug:
- wp-delete-user-accounts
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58704
Subresource Integrity (SRI) Manager
- Plugin Slug:
- wp-sri
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57936
Team Manager – Team Member Showcase with grid, slider, table Elementor widget & shortcode
- Plugin Slug:
- wp-team-manager
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58222
xili-tidy-tags
- Plugin:
- xili-tidy-tags
- Plugin Slug:
- xili-tidy-tags
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58240
ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns
- Plugin Slug:
- zoloblocks
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58230
BMI Adult & Kid Calculator
- Plugin:
- BMI Adult & Kid Calculator
- Plugin Slug:
- bmi-adultkid-calculator
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53469
Bot Block – Stop Spam Referrals in Google Analytics
- Plugin Slug:
- bot-block-stop-spam-google-analytics-referrals
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57935
CashBill.pl – P?atno?ci WooCommerce
- Plugin Slug:
- cashbill-payment-method
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53455
Developer
- Plugin:
- Developer
- Plugin Slug:
- developer
- Installations
- 900+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57924
Highlight and Share – Social Text and Image Sharing
- Plugin Slug:
- highlight-and-share
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58260
LWS Affiliation
- Plugin:
- LWS Affiliation
- Plugin Slug:
- lws-affiliation
- Installations
- 900+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57934
Mail Baby SMTP
- Plugin:
- Mail Baby SMTP
- Plugin Slug:
- mail-baby-smtp
- Installations
- 900+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57992
PlayerJS
- Plugin:
- PlayerJS
- Plugin Slug:
- playerjs
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58651
SEO Backlink Monitor
- Plugin:
- SEO Backlink Monitor
- Plugin Slug:
- seo-backlink-monitor
- Installations
- 900+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53456
SEO Backlink Monitor
- Plugin:
- SEO Backlink Monitor
- Plugin Slug:
- seo-backlink-monitor
- Installations
- 900+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53457
TOCHAT.BE
- Plugin:
- TOCHAT.BE
- Plugin Slug:
- tochat-be
- Installations
- 900+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57915
Ultimate WP Mail
- Plugin:
- Ultimate WP Mail
- Plugin Slug:
- ultimate-wp-mail
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53454
WP System Information
- Plugin:
- WP System Information
- Plugin Slug:
- wp-system-info
- Installations
- 900+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57916
BuddyPress Notification Widget
- Plugin:
- BuddyPress Notification Widget
- Plugin Slug:
- buddypress-notifications-widget
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58263
Category Featured Images
- Plugin:
- Category Featured Images
- Plugin Slug:
- category-featured-images
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58655
StylePress for Elementor
- Plugin:
- StylePress for Elementor
- Plugin Slug:
- full-site-builder-for-elementor
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58254
Gianism
- Plugin:
- Gianism
- Plugin Slug:
- gianism
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58266
Image Editor by Pixo
- Plugin:
- Image Editor by Pixo
- Plugin Slug:
- image-editor-by-pixo
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58232
Pinterest Pinboard Widget
- Plugin:
- Pinterest Pinboard Widget
- Plugin Slug:
- pinterest-pinboard-widget
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58248
Real Estate Manager – Property Listing and Agent Management
- Plugin Slug:
- real-estate-manager
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58253
Events Manager – OpenStreetMaps
- Plugin:
- Events Manager – OpenStreetMaps
- Plugin Slug:
- stonehenge-em-osm
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58265
xili-language
- Plugin:
- xili-language
- Plugin Slug:
- xili-language
- Installations
- 800+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58654
Carousel Ultimate
- Plugin:
- Carousel Ultimate
- Plugin Slug:
- carousel
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58652
JS Job Manager
- Plugin:
- JS Job Manager
- Plugin Slug:
- js-jobs
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58234
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress
- Plugin Slug:
- portfolio
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58245
SQL Chart Builder
- Plugin:
- SQL Chart Builder
- Plugin Slug:
- sql-chart-builder
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58233
Buckets
- Plugin:
- Buckets
- Plugin Slug:
- buckets
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57996
Easy Quotes
- Plugin:
- Easy Quotes
- Plugin Slug:
- easy-quotes
- Installations
- 600+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58681
Genealogical Tree – WordPress Family Tree
- Plugin Slug:
- genealogical-tree
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58023
Shortcode
- Plugin:
- Shortcode
- Plugin Slug:
- shortcode
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58022
SnapWidget Social Photo Feed Widget
- Plugin Slug:
- snapwidget-wp-instagram-widget
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58241
Theater for WordPress
- Plugin:
- Theater for WordPress
- Plugin Slug:
- theatre
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58020
VikRestaurants Table Reservations and Take-Away
- Plugin Slug:
- vikrestaurants
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57962
VikRestaurants Table Reservations and Take-Away
- Plugin Slug:
- vikrestaurants
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-57968
WooMS
- Plugin:
- WooMS
- Plugin Slug:
- wooms
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57956
WooMS
- Plugin:
- WooMS
- Plugin Slug:
- wooms
- Installations
- 600+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57957
WordPress Widgets Shortcode
- Plugin:
- WordPress Widgets Shortcode
- Plugin Slug:
- wp-widgets-shortcode
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57989
AgreeMe Checkboxes For WooCommerce
- Plugin Slug:
- agreeme-checkboxes-for-woocommerce
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57905
Card Elements for WPBakery
- Plugin:
- Card Elements for WPBakery
- Plugin Slug:
- card-elements-for-wpbakery
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58220
Category Featured Images Extended
- Plugin Slug:
- category-featured-images-extended
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57920
Envíos Coordinadora Woocommerce (Oficial) – WordPress plugin
- Plugin Slug:
- coordinadora
- Installations
- 500+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57922
DELUCKS SEO
- Plugin:
- DELUCKS SEO
- Plugin Slug:
- delucks-seo
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53570
WP Frontend Admin – Display WP Admin Pages in the Frontend
- Plugin Slug:
- display-admin-page-on-frontend
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57898
Easy Hotel Booking – Powerful Hotel Booking Plugin
- Plugin Slug:
- easy-hotel
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57938
Epeken All Kurir Plugin for Woocommerce Full Version
- Plugin Slug:
- epeken-all-kurir
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57906
Front End Users
- Plugin:
- Front End Users
- Plugin Slug:
- front-end-only-users
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58235
Heureka
- Plugin:
- Heureka
- Plugin Slug:
- heureka
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57907
Library Bookshelves
- Plugin:
- Library Bookshelves
- Plugin Slug:
- library-bookshelves
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57964
Maps for WP
- Plugin:
- Maps for WP
- Plugin Slug:
- maps-for-wp
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57952
NGG Smart Image Search
- Plugin:
- NGG Smart Image Search
- Plugin Slug:
- ngg-smart-image-search
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58027
payOS
- Plugin:
- payOS
- Plugin Slug:
- payos
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57946
Behance Portfolio Manager
- Plugin:
- Behance Portfolio Manager
- Plugin Slug:
- portfolio-manager-powered-by-behance
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57913
Product Time Countdown for WooCommerce
- Plugin Slug:
- product-countdown-for-woocommerce
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57908
Tapfiliate
- Plugin:
- Tapfiliate
- Plugin Slug:
- tapfiliate
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58689
UK Address Postcode Validation
- Plugin:
- UK Address Postcode Validation
- Plugin Slug:
- uk-address-postcode-validation
- Installations
- 500+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57923
Deliver via Shipos for WooCommerce
- Plugin Slug:
- wc-shipos-delivery
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57914
JSM file_get_contents() Shortcode
- Plugin Slug:
- wp-file-get-contents
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58653
WP Proposals
- Plugin:
- WP Proposals
- Plugin Slug:
- wp-proposals
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57965
Zoho Billing – Embed Payment Form
- Plugin Slug:
- zoho-subscriptions
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57963
WP Gravity Forms Keap/Infusionsoft
- Plugin Slug:
- gf-infusionsoft
- Installations
- 400+
- Vulnerability:
- Open Redirection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58006
Helpdesk Support Ticket System for WooCommerce
- Plugin Slug:
- support-ticket-system-for-woocommerce
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57972
TZ Plus Gallery
- Plugin:
- TZ Plus Gallery
- Plugin Slug:
- tz-plus-gallery
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57974
Sales Count Manager for WooCommerce
- Plugin Slug:
- wc-sales-count-manager
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57904
Additional Fees For WooCommerce Checkout (Free)
- Plugin Slug:
- woo-additional-fees-on-checkout-wordpress
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57903
Goracash
- Plugin:
- Goracash
- Plugin Slug:
- goracash
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53458
AnyClip Luminous Studio
- Plugin:
- AnyClip Luminous Studio
- Plugin Slug:
- anyclip-media
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57910
AnyClip Luminous Studio
- Plugin:
- AnyClip Luminous Studio
- Plugin Slug:
- anyclip-media
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58271
Easy Pricing Table WP
- Plugin:
- Easy Pricing Table WP
- Plugin Slug:
- easy-pricing-table-wp
- Installations
- 200+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53450
Form Generator for WordPress
- Plugin:
- Form Generator for WordPress
- Plugin Slug:
- form-generator-powered-by-jotform
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58665
immonex Kickstart Team
- Plugin:
- immonex Kickstart Team
- Plugin Slug:
- immonex-kickstart-team
- Installations
- 200+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-57925
VoucherPress
- Plugin:
- VoucherPress
- Plugin Slug:
- voucherpress
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58223
Auction Feed
- Plugin:
- Auction Feed
- Plugin Slug:
- auction-feed
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58671
Editor Custom Color Palette
- Plugin:
- Editor Custom Color Palette
- Plugin Slug:
- editor-custom-color-palette
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57909
Magento 2 WordPress Integration
- Plugin:
- Magento 2 WordPress Integration
- Plugin Slug:
- m2wp
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58669
Mavis HTTPS to HTTP Redirection
- Plugin:
- Mavis HTTPS to HTTP Redirection
- Plugin Slug:
- mavis-https-to-http-redirect
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58261
NIX Anti-Spam Light
- Plugin:
- NIX Anti-Spam Light
- Plugin Slug:
- nix-anti-spam-light
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58270
eZee Online Hotel Booking Engine
- Plugin:
- eZee Online Hotel Booking Engine
- Plugin Slug:
- online-booking-engine
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58661
Printcart Web to Print Product Designer for WooCommerce
- Plugin Slug:
- printcart-integration
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57917
Proof Factor – Social Proof Notifications
- Plugin Slug:
- proof-factor-social-proof-notifications
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58658
Sweet Energy Efficiency
- Plugin:
- Sweet Energy Efficiency
- Plugin Slug:
- sweet-energy-efficiency
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58262
Verowa Connect
- Plugin:
- Verowa Connect
- Plugin Slug:
- verowa-connect
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58257
LinkedInclude
- Plugin:
- LinkedInclude
- Plugin Slug:
- linkedinclude
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-57918
Mobi2Go
- Plugin:
- Mobi2Go
- Plugin Slug:
- mobi2go
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58646
GSheets Connector
- Plugin:
- GSheets Connector
- Plugin Slug:
- sheetlink
- Installations
- 90+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53465
Stock Message
- Plugin:
- Stock Message
- Plugin Slug:
- stock-message
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58267
WP Content Protection
- Plugin:
- WP Content Protection
- Plugin Slug:
- wp-content-protection
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58670
WPMK PDF Generator
- Plugin:
- WPMK PDF Generator
- Plugin Slug:
- wpmk-pdf-generator
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58268
WordPress Adverts Plugin – Adverts Click Tracker
- Plugin Slug:
- adverts-click-tracker
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57911
Current Age Plugin
- Plugin:
- Current Age Plugin
- Plugin Slug:
- current-age
- Installations
- 80+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58687
Grid
- Plugin:
- Grid
- Plugin Slug:
- grid
- Installations
- 80+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58657
HORIZONTAL SLIDER
- Plugin:
- HORIZONTAL SLIDER
- Plugin Slug:
- horizontal-slider
- Installations
- 80+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58676
ShrinkTheWeb (STW) Website Previews Plugin
- Plugin Slug:
- shrinktheweb-website-preview-plugin
- Installations
- 80+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58677
Casengo Live Chat Support
- Plugin:
- Casengo Live Chat Support
- Plugin Slug:
- the-casengo-chat-widget
- Installations
- 80+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58688
Show Pages List
- Plugin:
- Show Pages List
- Plugin Slug:
- show-pages-list
- Installations
- 70+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58219
Simple Restaurant Menu
- Plugin:
- Simple Restaurant Menu
- Plugin Slug:
- simple-restaurant-menu
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58647
Doliconnect
- Plugin:
- Doliconnect
- Plugin Slug:
- doliconnect
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58690
RIS Version Switcher – Downgrade or Upgrade WP Versions Easily
- Plugin Slug:
- ris-version-switcher
- Installations
- 50+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57902
Wide Banner
- Plugin:
- Wide Banner
- Plugin Slug:
- wide-banner
- Installations
- 50+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58919
DOAJ Export
- Plugin:
- DOAJ Export
- Plugin Slug:
- doaj-export
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58256
Gravitate Automated Tester
- Plugin:
- Gravitate Automated Tester
- Plugin Slug:
- gravitate-automated-tester
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58645
SAPO Feed
- Plugin:
- SAPO Feed
- Plugin Slug:
- sapo-feed
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53462
Bg Church Memos
- Plugin:
- Bg Church Memos
- Plugin Slug:
- bg-church-memos
- Installations
- 30+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58242
Wp tabber widget
- Plugin:
- Wp tabber widget
- Plugin Slug:
- wp-tabber-widget
- Installations
- 20+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-53468
Custom Post Type Images
- Plugin:
- Custom Post Type Images
- Plugin Slug:
- custom-post-types-image
- Installations
- 10+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-58255
Dialogity Free Live Chat
- Plugin:
- Dialogity Free Live Chat
- Plugin Slug:
- dialogity-website-chat
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57912
Service Finder SMS System
- Plugin:
- Service Finder SMS System
- Plugin Slug:
- aone-sms
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-5955
Browser Sniff
- Plugin:
- Browser Sniff
- Plugin Slug:
- browser-sniff
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-9883
Custom Login And Signup Widget
- Plugin:
- Custom Login And Signup Widget
- Plugin Slug:
- custom-login-and-signup-widget
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-9887
Directory Pro
- Plugin:
- Directory Pro
- Plugin Slug:
- directory-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-57948
Event Rocket
- Plugin:
- Event Rocket
- Plugin Slug:
- event-rocket
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-53452
Printeers Print & Ship
- Plugin:
- Printeers Print & Ship
- Plugin Slug:
- invition-print-ship
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58224
Javo Core
- Plugin:
- Javo Core
- Plugin Slug:
- javo-core
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58003
ListingPro Reviews
- Plugin:
- ListingPro Reviews
- Plugin Slug:
- listingpro-reviews
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58667
Miniorange OTP Verification with Firebase
- Plugin:
- Miniorange OTP Verification with Firebase
- Plugin Slug:
- miniorange-firebase-sms-otp-verification
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-7665
Oshine Core
- Plugin:
- Oshine Core
- Plugin Slug:
- oshine-core
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58660
osTicket WP Bridge
- Plugin:
- osTicket WP Bridge
- Plugin Slug:
- osticket-wp-bridge
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-9882
Accordion FAQ
- Plugin:
- Accordion FAQ
- Plugin Slug:
- pressapps-accordion-faq
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58024
Robcore Netatmo
- Plugin:
- Robcore Netatmo
- Plugin Slug:
- robcore-netatmo
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-10652
Service Finder Booking
- Plugin:
- Service Finder Booking
- Plugin Slug:
- sf-booking
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-5948
The Events Calendar
- Plugin:
- The Events Calendar
- Plugin Slug:
- the-events-calendar
- Installations
- 700,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.15.3
- Severity Score:
- Medium
- CVE:
- 2025-9808
Blocksy Companion
- Plugin:
- Blocksy Companion
- Plugin Slug:
- blocksy-companion
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.11
- Severity Score:
- Medium
- CVE:
- 2025-9565
SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more
- Plugin:
- SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more
- Plugin Slug:
- sureforms
- Installations
- 300,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.12.1
- Severity Score:
- Medium
- CVE:
- 2025-10489
Admin and Site Enhancements (ASE)
- Plugin Slug:
- admin-site-enhancements
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.9.8
- Severity Score:
- Medium
- CVE:
- 2025-9487
Colibri Page Builder
- Plugin:
- Colibri Page Builder
- Plugin Slug:
- colibri-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.334
- Severity Score:
- Medium
- CVE:
- 2025-59593
Download Manager
- Plugin:
- Download Manager
- Plugin Slug:
- download-manager
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.24
- Severity Score:
- High
- CVE:
- 2025-10146
Kubio AI Page Builder
- Plugin:
- Kubio AI Page Builder
- Plugin Slug:
- kubio
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.5
- Severity Score:
- Medium
- CVE:
- 2025-8487
Make Column Clickable for Elementor
- Plugin Slug:
- make-column-clickable-elementor
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.1
- Severity Score:
- Medium
- CVE:
- 2025-59592
Comments – wpDiscuz
- Plugin:
- Comments – wpDiscuz
- Plugin Slug:
- wpdiscuz
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.6.34
- Severity Score:
- Medium
- CVE:
- 2025-59591
Media Library Assistant
- Plugin:
- Media Library Assistant
- Plugin Slug:
- media-library-assistant
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.29
- Severity Score:
- Medium
- CVE:
- 2025-59590
WP-Members Membership Plugin
- Plugin:
- WP-Members Membership Plugin
- Plugin Slug:
- wp-members
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.4.3
- Severity Score:
- Medium
- CVE:
- 2025-57973
Ajax Load More – Infinite Scroll
- Plugin:
- Ajax Load More – Infinite Scroll
- Plugin Slug:
- ajax-load-more
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 7.6.1
- Severity Score:
- Medium
- CVE:
- 2025-59582
Ibtana – WordPress Website Builder
- Plugin Slug:
- ibtana-visual-editor
- Installations
- 20,000+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 1.2.5.4
- Severity Score:
- Medium
- CVE:
- 2025-59581
Quiz Maker
- Plugin:
- Quiz Maker
- Plugin Slug:
- quiz-maker
- Installations
- 20,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 6.7.0.57
- Severity Score:
- Critical
- CVE:
- 2025-10042
WP Import – Ultimate CSV XML Importer for WordPress
- Plugin Slug:
- wp-ultimate-csv-importer
- Installations
- 20,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 7.29
- Severity Score:
- Critical
- CVE:
- 2025-10057
WP Import – Ultimate CSV XML Importer for WordPress
- Plugin Slug:
- wp-ultimate-csv-importer
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 7.28
- Severity Score:
- High
- CVE:
- 2025-10058
Blaze Demo Importer
- Plugin:
- Blaze Demo Importer
- Plugin Slug:
- blaze-demo-importer
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.13
- Severity Score:
- Medium
- CVE:
- 2025-8446
MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Plugin Slug:
- masterstudy-lms-learning-management-system
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.21
- Severity Score:
- Medium
- CVE:
- 2025-59576
MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Plugin Slug:
- masterstudy-lms-learning-management-system
- Installations
- 10,000+
- Vulnerability:
- Race Condition
- Patched in Version:
- 3.6.21
- Severity Score:
- Medium
- CVE:
- 2025-59577
Internal Links Manager
- Plugin:
- Internal Links Manager
- Plugin Slug:
- seo-automated-link-building
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.0.2
- Severity Score:
- Medium
- CVE:
- 2025-9949
SupportCandy – Helpdesk & Customer Support Ticket System
- Plugin Slug:
- supportcandy
- Installations
- 10,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 3.3.8
- Severity Score:
- Medium
- CVE:
- 2025-10658
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages
- Plugin Slug:
- wplegalpages
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.4
- Severity Score:
- Medium
- CVE:
- 2025-8565
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
- Plugin:
- WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
- Plugin Slug:
- wte-elementor-widgets
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.3
- Severity Score:
- Medium
- CVE:
- 2025-59574
Cozy Blocks – All-in-One Page Builder Blocks for Gutenberg and Full Site Editing (FSE)
- Plugin Slug:
- cozy-addons
- Installations
- 9,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 2.1.30
- Severity Score:
- Medium
- CVE:
- 2025-59573
WP Hotel Booking
- Plugin:
- WP Hotel Booking
- Plugin Slug:
- wp-hotel-booking
- Installations
- 8,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 2.2.3
- Severity Score:
- Medium
- CVE:
- 2025-8942
Ghost Kit – Page Builder Blocks, Motion Effects & Extensions
- Plugin Slug:
- ghostkit
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.4.4
- Severity Score:
- Medium
- CVE:
- 2025-9992
Email Marketing, Email Automation, Newsletter & Cart Abandonment for WordPress and WooCommerce – Mail Mint
- Plugin Slug:
- mail-mint
- Installations
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.18.7
- Severity Score:
- High
- CVE:
- 2025-59570
CubeWP – All-in-One Dynamic Content Framework
- Plugin Slug:
- cubewp-framework
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.27
- Severity Score:
- Medium
- CVE:
- 2025-59569
Termageddon: Cookie Consent & Privacy Compliance
- Plugin Slug:
- termageddon-usercentrics
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.2
- Severity Score:
- Medium
- CVE:
- 2025-58026
Coupon Affiliates – Affiliate Plugin for WooCommerce
- Plugin Slug:
- woo-coupon-usage
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.8.1
- Severity Score:
- Medium
- CVE:
- 2025-59567
Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automation
- Plugin Slug:
- zoho-flow
- Installations
- 5,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.14.2
- Severity Score:
- Medium
- CVE:
- 2025-59568
Etsy Shop
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 4,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.2.7
- Severity Score:
- Critical
- CVE:
- 2025-10147
Upsell Funnel Builder for WooCommerce – New Marketing Funnel Builder and Sales Funnel Builder tailored for your store.
- Plugin Slug:
- upsell-order-bump-offer-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.8
- Severity Score:
- Medium
- CVE:
- 2025-59565
YouTube Showcase – Responsive YouTube Video Gallery Plugin for WordPress
- Plugin Slug:
- youtube-showcase
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.1
- Severity Score:
- Medium
- CVE:
- 2025-58915
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
- Plugin Slug:
- academy
- Installations
- 2,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.3.5
- Severity Score:
- Medium
- CVE:
- 2025-59562
Advanced Views – Display Posts, Custom Fields, and More
- Plugin Slug:
- acf-views
- Installations
- 2,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 3.7.20
- Severity Score:
- High
- CVE:
- 2025-10380
Media Player Addons for Elementor – Audio and Video Widgets for Elementor
- Plugin Slug:
- media-player-addons-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2025-9203
Smart Blocks
- Plugin:
- Smart Blocks
- Plugin Slug:
- smart-blocks
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.5
- Severity Score:
- Medium
- CVE:
- 2025-59561
Payrexx Payment Gateway for WooCommerce
- Plugin Slug:
- woo-payrexx-gateway
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.1.6
- Severity Score:
- Medium
- CVE:
- 2025-59559
Password Reset with Code for WordPress REST API
- Plugin Slug:
- bdvs-password-reset
- Installations
- 1,000+
- Vulnerability:
- Other Vulnerability Type
- Patched in Version:
- 0.0.17
- Severity Score:
- High
- CVE:
- 2025-5305
Chained Quiz
- Plugin:
- Chained Quiz
- Plugin Slug:
- chained-quiz
- Installations
- 1,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2025-10493
Custom iFrame for Elementor – Embed Pdf, Maps, Videos, & Websites Easily
- Plugin Slug:
- custom-iframe
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.14
- Severity Score:
- Medium
- CVE:
- 2025-59553
Custom Login URL
- Plugin:
- Custom Login URL
- Plugin Slug:
- custom-login-url
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.3
- Severity Score:
- Medium
- CVE:
- 2025-58969
Easy Elementor Addons
- Plugin:
- Easy Elementor Addons
- Plugin Slug:
- easy-elementor-addons
- Installations
- 1,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.2.9
- Severity Score:
- High
- CVE:
- 2025-58973
GetResponse Forms by Optin Cat
- Plugin:
- GetResponse Forms by Optin Cat
- Plugin Slug:
- getresponse
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.1
- Severity Score:
- Medium
- CVE:
- 2025-59549
Markup Markdown
- Plugin:
- Markup Markdown
- Plugin Slug:
- markup-markdown
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.20.10
- Severity Score:
- Medium
- CVE:
- 2025-9540
Product Catalog Simple
- Plugin:
- Product Catalog Simple
- Plugin Slug:
- post-type-x
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.3
- Severity Score:
- Medium
- CVE:
- 2025-58992
Request a Quote Form Plugin – Price Quote Request Management Made Easy
- Plugin Slug:
- request-a-quote
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.1
- Severity Score:
- Medium
- CVE:
- 2025-58915
Revive.so – Bulk Rewrite and Republish Blog Posts
- Plugin Slug:
- revive-so
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.7
- Severity Score:
- Medium
- CVE:
- 2025-59551
Save as PDF Plugin by PDFCrowd
- Plugin:
- Save as PDF Plugin by PDFCrowd
- Plugin Slug:
- save-as-pdf-by-pdfcrowd
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.3
- Severity Score:
- Medium
- CVE:
- 2025-59552
WPCasa
WPComplete
- Plugin:
- WPComplete
- Plugin Slug:
- wpcomplete
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.5.3
- Severity Score:
- Medium
- CVE:
- 2025-58974
AffiliateWP – External Referral Links
- Plugin Slug:
- affiliatewp-external-referral-links
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2025-53460
MaxiBlocks: 2300+ Patterns, 280+ Pages, 14.3K Icons & 100 Styles
- Plugin Slug:
- maxi-blocks
- Installations
- 900+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.4
- Severity Score:
- Medium
- CVE:
- 2025-58968
ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages
- Plugin:
- ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages
- Plugin Slug:
- clickwhale
- Installations
- 800+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.5.1
- Severity Score:
- High
- CVE:
- 2025-10002
Fusion Page Builder : Extension – Gallery
- Plugin Slug:
- fusion-extension-gallery
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.7
- Severity Score:
- Medium
- CVE:
- 2025-58965
List Child Pages Shortcode
- Plugin:
- List Child Pages Shortcode
- Plugin Slug:
- list-child-pages-shortcode
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.4.0
- Severity Score:
- Medium
- CVE:
- 2025-58021
Employee Spotlight – Team Member Showcase & Meet the Team Plugin
- Plugin Slug:
- employee-spotlight
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.1
- Severity Score:
- Medium
- CVE:
- 2025-58915
Publitio
- Plugin:
- Publitio
- Plugin Slug:
- publitio
- Installations
- 500+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.2.2
- Severity Score:
- Medium
- CVE:
- 2025-58962
Customer Support Ticket System & Helpdesk Plugin for WordPress
- Plugin Slug:
- wp-ticket
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.0.1
- Severity Score:
- Medium
- CVE:
- 2025-58915
The Hack Repair Guy’s Plugin Archiver
- Plugin Slug:
- hackrepair-plugin-archiver
- Installations
- 400+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.1.1
- Severity Score:
- Medium
- CVE:
- 2025-10188
IP Based Login
- Plugin:
- IP Based Login
- Plugin Slug:
- ip-based-login
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.4
- Severity Score:
- Medium
- CVE:
- 2025-58960
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More
- Plugin Slug:
- storeengine
- Installations
- 400+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 1.5.1
- Severity Score:
- Medium
- CVE:
- 2025-9215
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More
- Plugin Slug:
- storeengine
- Installations
- 400+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2025-9216
Developer Loggers for Simple History
- Plugin Slug:
- developer-loggers-for-simple-history
- Installations
- 300+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 0.5.1
- Severity Score:
- Medium
- CVE:
- 2025-10050
Secure Passkeys
- Plugin:
- Secure Passkeys
- Plugin Slug:
- secure-passkeys
- Installations
- 300+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2025-10305
VPSUForm – No-Code Custom Form Builder – Contact Forms, Conversion Form & More
- Plugin Slug:
- v-form
- Installations
- 300+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.21
- Severity Score:
- Medium
- CVE:
- 2025-58957
User Sync
Appointmind
- Plugin:
- Appointmind
- Plugin Slug:
- appointmind
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.0
- Severity Score:
- Medium
- CVE:
- 2025-9851
Catch Dark Mode
- Plugin:
- Catch Dark Mode
- Plugin Slug:
- catch-dark-mode
- Installations
- 50+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.0.1
- Severity Score:
- High
- CVE:
- 2025-10143
Draft List
- Plugin:
- Draft List
- Plugin Slug:
- simple-draft-list
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.1
- Severity Score:
- Medium
- CVE:
- 2025-10181
Social Media Shortcodes
- Plugin:
- Social Media Shortcodes
- Plugin Slug:
- social-media-shortcodes
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2025-10166
USS Upyun
Embed PDF for WPForms
- Plugin:
- Embed PDF for WPForms
- Plugin Slug:
- embed-pdf-wpforms
- Installations
- 40+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.6
- Severity Score:
- Critical
- CVE:
- 2025-10647
Productive Style – Optimisations & Content Publishing Support
- Plugin Slug:
- productive-style
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.25
- Severity Score:
- Medium
- CVE:
- 2025-8394
Widget Options – Extended
- Plugin:
- Widget Options – Extended
- Plugin Slug:
- extended-widget-options
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.2.2
- Severity Score:
- Medium
- CVE:
- 2025-8902
Penci Filter Everything
- Plugin:
- Penci Filter Everything
- Plugin Slug:
- penci-filter-everything
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7
- Severity Score:
- Medium
- CVE:
- 2025-59583
Penci Podcast
- Plugin:
- Penci Podcast
- Plugin Slug:
- penci-podcast
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7
- Severity Score:
- Medium
- CVE:
- 2025-59584
Penci Portfolio
- Plugin:
- Penci Portfolio
- Plugin Slug:
- penci-portfolio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6
- Severity Score:
- Medium
- CVE:
- 2025-59586
Penci Recipe
- Plugin:
- Penci Recipe
- Plugin Slug:
- penci-recipe
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1
- Severity Score:
- Medium
- CVE:
- 2025-59585
Penci Shortcodes & Performance
- Plugin:
- Penci Shortcodes & Performance
- Plugin Slug:
- penci-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.1
- Severity Score:
- Medium
- CVE:
- 2025-59587
Uni CPO (Premium)
- Plugin:
- Uni CPO (Premium)
- Plugin Slug:
- uni-woo-custom-product-options-premium
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.9.55
- Severity Score:
- Critical
- CVE:
- 2025-10412
WorkScout-Core
- Plugin:
- WorkScout-Core
- Plugin Slug:
- workscout-core
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.7.06
- Severity Score:
- High
- CVE:
- 2025-59572
WP Attractive Donations System
- Plugin:
- WP Attractive Donations System
- Plugin Slug:
- wp-attractive-donations-system-easy-stripe-paypal-donations
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.29
- Severity Score:
- High
- CVE:
- 2025-58956
WordPress Themes — 4 Patched / 9 Unpatched
Constructo
- Theme:
- Constructo
- Theme Slug:
- constructo
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58244
CouponXxL
- Theme:
- CouponXxL
- Theme Slug:
- couponxxl
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58013
DriCub
- Theme:
- DriCub
- Theme Slug:
- dricub-driving-school
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58004
DriCub
- Theme:
- DriCub
- Theme Slug:
- dricub-driving-school
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58005
Entrada
- Theme:
- Entrada
- Theme Slug:
- entrada
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58918
Findgo
- Theme:
- Findgo
- Theme Slug:
- fingo
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58250
imEvent
- Theme:
- imEvent
- Theme Slug:
- imevent
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58243
Nokri
- Theme:
- Nokri
- Theme Slug:
- nokri
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-58259
WPLMS
- Theme:
- WPLMS
- Theme Slug:
- wplms
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-58668
Sydney
Leblix
- Theme:
- Leblix
- Theme Slug:
- leblix
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.5
- Severity Score:
- High
- CVE:
- 2025-58995
Soledad
- Theme:
- Soledad
- Theme Slug:
- soledad
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 8.6.9
- Severity Score:
- High
- CVE:
- 2025-59588
Soledad
- Theme:
- Soledad
- Theme Slug:
- soledad
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.6.9
- Severity Score:
- Medium
- CVE:
- 2025-59589
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed