WordPress Vulnerability Report

WordPress Vulnerability Report — November 5, 2025

Since last week, 108 new vulnerabilities have emerged in the WordPress ecosystem, including 98 plugins and 10 themes. Of those, 31 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 108 vulnerabilities have been publicly disclosed. Security patches for 77 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 31 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.3 was released on September 30, 2025. This is a security release that features two fixes. As this is a security release, we recommend updating your sites immediately. For more information on WordPress 6.8.3, please visit the version page on the HelpHub site.

WordPress 6.9 Beta 3 is now ready for testing! This beta version of WordPress is still under development, so please avoid using it on production or mission-critical sites. Instead, test Beta 3 on a staging or test site.

The final release of WordPress 6.9 is scheduled for December 2, 2025. You can find the full release schedule and testing information on the WordPress Core blog. Your help testing Beta and RC versions is essential to ensuring a stable and powerful release.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 68 Patched / 30 Unpatched

WP Snow Effect

Plugin Slug:
wp-snow-effect
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi-language Responsive Portfolio

Plugin:
Multi-language Responsive Portfolio
Plugin Slug:
bootstrap-multi-language-responsive-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Associados Amazon

Plugin:
Associados Amazon
Plugin Slug:
brzon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CE21 Suite

Plugin:
CE21 Suite
Plugin Slug:
ce21-suite
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Centangle Team Showcase

Plugin:
Centangle Team Showcase
Plugin Slug:
centangle-team
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clubmember

Plugin:
Clubmember
Plugin Slug:
clubmember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crypto Payment Gateway with Payeer for WooCommerce

Plugin:
Crypto Payment Gateway with Payeer for WooCommerce
Plugin Slug:
crypto-payment-gateway-with-payeer-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DominoKit

Plugin:
DominoKit
Plugin Slug:
dominokit
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elegance Menu

Plugin:
Elegance Menu
Plugin Slug:
elegance-menu
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EM Beer Manager

Plugin:
EM Beer Manager
Plugin Slug:
em-beer-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Free Quotation

Plugin:
Free Quotation
Plugin Slug:
free-quotation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin:
Import Export For WooCommerce
Plugin Slug:
import-export-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Label Plugins

Plugin:
Label Plugins
Plugin Slug:
label-plugins
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn Resume

Plugin:
LinkedIn Resume
Plugin Slug:
linkedin-resume
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LMB^Box Smileys

Plugin:
LMB^Box Smileys
Plugin Slug:
lmbbox-smileys
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MapMap

Plugin:
MapMap
Plugin Slug:
mapmap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MeetingList

Plugin:
MeetingList
Plugin Slug:
meeting-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nari Accountant

Plugin:
Nari Accountant
Plugin Slug:
nari-accountant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NS Maintenance Mode for WP

Plugin:
NS Maintenance Mode for WP
Plugin Slug:
ns-maintenance-mode-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pagerank Tools

Plugin:
Pagerank Tools
Plugin Slug:
pagerank-tools
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Posts Navigation Links for Sections and Headings
Plugin Slug:
posts-navigation-links-for-sections-and-headings-free-by-wp-masters
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reuse Builder

Plugin:
Reuse Builder
Plugin Slug:
reuse-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SH Contextual Help

Plugin:
SH Contextual Help
Plugin Slug:
sh-contextual-help
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:
Simple User Capabilities
Plugin Slug:
simple-user-capabilities
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Capabilities

Plugin:
Simple User Capabilities
Plugin Slug:
simple-user-capabilities
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ViaAds

Plugin:
ViaAds
Plugin Slug:
viaads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Designer Pro

Plugin:
WooCommerce Designer Pro
Plugin Slug:
wc-designer-pro
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Carticon

Plugin:
WP Carticon
Plugin Slug:
wp-carticon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Global Screen Options

Plugin:
WP Global Screen Options
Plugin Slug:
wp-global-screen-options
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Media WPCF7 Stop Words

Plugin:
Social Media WPCF7 Stop Words
Plugin Slug:
wpcf7-stop-words
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiteSpeed Cache

Plugin Slug:
litespeed-cache
Installations
7,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.9.0.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.0.3.

Polylang

Plugin:
Polylang
Plugin Slug:
polylang
Installations
800,000+
Vulnerability:
Deserialization of untrusted data
Patched in Version:
3.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.4.

TablePress – Tables in WordPress made easy

Plugin Slug:
tablepress
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.5.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.15.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.15.10.

Facebook for WooCommerce

Plugin Slug:
facebook-for-woocommerce
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.8.

SiteSEO – SEO Simplified

Plugin Slug:
siteseo
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.3.2.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.0.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.13.

Advanced Database Cleaner

Plugin Slug:
advanced-database-cleaner
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Advanced Database Cleaner

Plugin Slug:
advanced-database-cleaner
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.7.

Anti-Malware Security and Brute-Force Firewall

Plugin Slug:
gotmls
Installations
100,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
4.23.83
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.23.83.

Insert PHP Code Snippet

Plugin Slug:
insert-php-code-snippet
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Schema & Structured Data for WP & AMP

Plugin Slug:
schema-and-structured-data-for-wp
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.52.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.7.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.7.2.

List category posts

Plugin Slug:
list-category-posts
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
0.93.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.93.0.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.2.8.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Translate WordPress and go Multilingual – Weglot

Plugin Slug:
weglot
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Smart Coupons For WooCommerce Coupons

Plugin Slug:
wt-smart-coupons-for-woocommerce
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Inactive Logout

Plugin Slug:
inactive-logout
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.10.

CSS & JavaScript Toolbox

Plugin Slug:
css-javascript-toolbox
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.0.6.

WPC Name Your Price for WooCommerce

Plugin Slug:
wpc-name-your-price
Installations
5,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.0.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.7.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.

Footnotes Made Easy

Plugin Slug:
footnotes-made-easy
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.8.

AppPresser – Mobile App Framework

Plugin Slug:
apppresser
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.1.

Range Slider Addon for Gravity Forms

Plugin Slug:
range-slider-addon-for-gravity-forms
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.7.

WP Discourse

Plugin Slug:
wp-discourse
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.6.0.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.15.

Easy Testimonial Slider and Form

Plugin Slug:
easy-testimonial-rotator
Installations
900+
Vulnerability:
SQL Injection
Patched in Version:
1.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.3.

Thumbnail Slider With Lightbox

Plugin Slug:
wp-responsive-slider-with-lightbox
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
1.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.5.

Doppler Forms

Plugin Slug:
doppler-form
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

RealPress – Real Estate Plugin

Plugin Slug:
realpress
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Schema Scalpel

Plugin Slug:
schema-scalpel
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Simple Payment

Plugin Slug:
simple-payment
Installations
30+
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

Simple Payment

Plugin Slug:
simple-payment
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.7.

ERI File Library

Plugin Slug:
eri-file-library
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Folderly

Plugin:
Folderly
Plugin Slug:
folderly
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
0.3.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 0.3.1.

Consulting Elementor Widgets

Plugin:
Consulting Elementor Widgets
Plugin Slug:
consulting-elementor-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

Consulting Elementor Widgets

Plugin:
Consulting Elementor Widgets
Plugin Slug:
consulting-elementor-widgets
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

Doccure Core

Plugin:
Doccure Core
Plugin Slug:
doccure
Vulnerability:
Privilege Escalation
Patched in Version:
1.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.4.

Jannah – Extensions

Plugin:
Jannah – Extensions
Plugin Slug:
jannah-extensions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

K Elements

Plugin:
K Elements
Plugin Slug:
k-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.0.

Ohio Extra

Plugin:
Ohio Extra
Plugin Slug:
ohio-extra
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Analytify Pro

Plugin:
Analytify Pro
Plugin Slug:
wp-analytify-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.0.4.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Arbitrary File Deletion
Patched in Version:
16.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 16.8.

Zombify

Plugin:
Zombify
Plugin Slug:
zombify
Vulnerability:
Arbitrary File Download
Patched in Version:
1.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.6.

WordPress Themes — 9 Patched / 1 Unpatched

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Consulting

Theme Slug:
consulting
Downloads
427,663
Vulnerability:
Local File Inclusion
Patched in Version:
6.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.7.5.

Kallyas

Theme:
Kallyas
Theme Slug:
kallyas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.24.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.24.0.

Kleo

Theme:
Kleo
Theme Slug:
kleo
Vulnerability:
Local File Inclusion
Patched in Version:
5.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.5.0.

Masterstudy

Theme:
Masterstudy
Theme Slug:
masterstudy
Vulnerability:
Local File Inclusion
Patched in Version:
4.8.126
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.126.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Broken Authentication
Patched in Version:
4.8.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.8.2.

Sahifa

Theme:
Sahifa
Theme Slug:
sahifa
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8.6.

SmartMag

Theme:
SmartMag
Theme Slug:
smart-mag
Vulnerability:
Local File Inclusion
Patched in Version:
10.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.3.1.

SmartMag

Theme:
SmartMag
Theme Slug:
smart-mag
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.3.2.

wpresidence

Theme:
wpresidence
Theme Slug:
wpresidence
Vulnerability:
Broken Access Control
Patched in Version:
5.3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.2.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security