WordPress Vulnerability Report

WordPress Vulnerability Report — December 3, 2025

Since last week, 106 new vulnerabilities have emerged in the WordPress ecosystem, including 102 plugins and 4 themes. Of those, 41 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 106 vulnerabilities have been publicly disclosed. Security patches for 65 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 41 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 63 Patched / 39 Unpatched

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist for WooCommerce

Plugin Slug:
th-wishlist
Installations
500+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Board by BestWebSoft

Plugin Slug:
job-board
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ace Post Type Builder

Plugin:
Ace Post Type Builder
Plugin Slug:
ace-post-type-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:
OrderConvo
Plugin Slug:
admin-and-client-message-after-order-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OrderConvo

Plugin:
OrderConvo
Plugin Slug:
admin-and-client-message-after-order-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Attention Bar

Plugin:
Attention Bar
Plugin Slug:
attention-bar
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Autochat Automatic Conversation

Plugin:
Autochat Automatic Conversation
Plugin Slug:
auyautochat-for-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bookme – Free Online Appointment Booking and Scheduling Plugin

Plugin:
Bookme – Free Online Appointment Booking and Scheduling Plugin
Plugin Slug:
bookme-free-appointment-booking-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chamber Dashboard Business Directory

Plugin:
Chamber Dashboard Business Directory
Plugin Slug:
chamber-dashboard-business-directory
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YouTube Subscribe

Plugin:
YouTube Subscribe
Plugin Slug:
easy-youtube-subscribe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EduKart Pro

Plugin:
EduKart Pro
Plugin Slug:
edukart-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms

Plugin:
Flo Forms
Plugin Slug:
flo-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Google Drive upload and download link
Plugin Slug:
google-drive-upload-and-download-link
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inline frame – Iframe

Plugin:
Inline frame – Iframe
Plugin Slug:
inline-frame-iframe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just Highlight

Plugin:
Just Highlight
Plugin Slug:
just-highlight
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AI Engine for WordPress: ChatGPT, GPT Content Generator

Plugin:
AI Engine for WordPress: ChatGPT, GPT Content Generator
Plugin Slug:
liquid-chatgpt
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Locker Content

Plugin Slug:
locker-content
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Conditionnal Maintenance Mode for WordPress

Plugin Slug:
maintenance-mode-based-on-user-roles
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:
Mstore Mobile App
Plugin Slug:
mstoreapp-mobile-app
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager

Plugin:
Frontend File Manager
Plugin Slug:
nmedia-user-file-uploader
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Peer Publish

Plugin:
Peer Publish
Plugin Slug:
peer-publish
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ProjectList

Plugin:
ProjectList
Plugin Slug:
projectlist
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ProjectList

Plugin:
ProjectList
Plugin Slug:
projectlist
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Realty Portal

Plugin:
Realty Portal
Plugin Slug:
realty-portal
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Refund Request for WooCommerce

Plugin:
Refund Request for WooCommerce
Plugin Slug:
refund-request-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reuters Direct

Plugin:
Reuters Direct
Plugin Slug:
reuters-direct
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reuters Direct

Plugin:
Reuters Direct
Plugin Slug:
reuters-direct
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shouty

Plugin:
Shouty
Plugin Slug:
shouty
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Images Widget

Plugin:
Social Images Widget
Plugin Slug:
social-images-widget
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SortTable Post

Plugin:
SortTable Post
Plugin Slug:
sorttable-post
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Soundslides

Plugin:
Soundslides
Plugin Slug:
soundslides
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mstore Mobile App

Plugin:
Mstore Mobile App
Plugin Slug:
woo-mstoreapp-mobile-app
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP AUDIO GALLERY
Plugin Slug:
wp-audio-gallery
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

wp-twitpic

Plugin:
wp-twitpic
Plugin Slug:
wp-twitpic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zweb Social Mobile

Plugin:
Zweb Social Mobile
Plugin Slug:
zweb-social-mobile
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Fastest Cache

Plugin Slug:
wp-fastest-cache
Installations
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Nextend Social Login and Register

Plugin Slug:
nextend-facebook-connect
Installations
200,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.1.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.22.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.1.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.1.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.3.

Search Exclude

Plugin Slug:
search-exclude
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.8.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations
40,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
11.15.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 11.15.3.

Visualizer: Tables and Charts Manager for WordPress

Plugin Slug:
visualizer
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
3.11.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.13.

QODE Wishlist for WooCommerce

Plugin Slug:
qode-wishlist-for-woocommerce
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.

Analytics Germanized for Google Analytics (GDPR / DSGVO)

Plugin Slug:
ga-germanized
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.5.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
19.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 19.12.1.

Customer Reviews Collector for WooCommerce

Plugin Slug:
customer-reviews-collector-for-woocommerce
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

Property Hive

Plugin Slug:
propertyhive
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.7.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.6.
Plugin Slug:
gallery-photo-gallery
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.9.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
3.6.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.14.

Vitepos – Point of Sale (POS) for WooCommerce

Plugin Slug:
vitepos-lite
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.1.

Quick View for WooCommerce

Plugin Slug:
woo-quickview
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.18.

CP Contact Form with PayPal

Plugin Slug:
cp-contact-form-with-paypal
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.57
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.57.

Featured Post Creative

Plugin Slug:
featured-post-creative
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Subscriptions & Memberships for PayPal

Plugin Slug:
subscriptions-memberships-for-paypal
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.1.

TNC Toolbox: Web Performance

Plugin Slug:
tnc-toolbox
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

Cart Weight for WooCommerce

Plugin Slug:
woo-cart-weight
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.12.

Telegram Bot & Channel

Plugin Slug:
telegram-bot
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.1.

AI ChatBot with ChatGPT and Content Generator by AYS

Plugin Slug:
ays-chatgpt-assistant
Installations
500+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.1.

AI ChatBot with ChatGPT and Content Generator by AYS

Plugin Slug:
ays-chatgpt-assistant
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

Show Variations as Single Products Woocommerce

Plugin Slug:
woo-show-single-variations-shop-category
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.2.

Simple User Registration

Plugin Slug:
wp-registration
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.7.

Hide Category by User Role for WooCommerce

Plugin Slug:
hide-category-by-user-role-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.2.

Zigaform – Price Calculator & Cost Estimation Form Builder Lite

Plugin Slug:
zigaform-calculator-cost-estimation-form-builder-lite
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.7.

EchBay Admin Security

Plugin Slug:
echbay-admin-security
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

StaffList

Plugin:
StaffList
Plugin Slug:
stafflist
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

CIBELES AI

Plugin:
CIBELES AI
Plugin Slug:
cibeles-ai
Installations
80+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.10.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.10.9.

AI Feeds

Plugin:
AI Feeds
Plugin Slug:
ai-feeds
Installations
60+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.12.

Simple Folio

Plugin Slug:
simple-folio
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

SKT PayPal for WooCommerce

Plugin Slug:
skt-paypal-for-woocommerce
Installations
10+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

atec Duplicate Page & Post

Plugin Slug:
atec-duplicate-page-post
Vulnerability:
Broken Access Control
Patched in Version:
1.2.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.21.

FindAll Membership

Plugin:
FindAll Membership
Plugin Slug:
findall-membership
Vulnerability:
Broken Authentication
Patched in Version:
1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.

Sneeit Framework

Plugin:
Sneeit Framework
Plugin Slug:
sneeit-framework
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
8.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.4.

Tiare Membership

Plugin:
Tiare Membership
Plugin Slug:
tiare-membership
Vulnerability:
Privilege Escalation
Patched in Version:
1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.

Unlimited Elements for Elementor (Premium)

Plugin:
Unlimited Elements for Elementor (Premium)
Plugin Slug:
unlimited-elements-for-elementor-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

WavePlayer

Plugin:
WavePlayer
Plugin Slug:
waveplayer
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.0.

WordPress Themes — 2 Patched / 2 Unpatched

Tiger

Theme:
Tiger
Theme Slug:
tiger
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Tiger

Theme:
Tiger
Theme Slug:
tiger
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
PHP Object Injection
Patched in Version:
4.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.7.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security