WordPress Vulnerability Report

WordPress Vulnerability Report — December 17, 2025

Since last week, 293 new vulnerabilities have emerged in the WordPress ecosystem, including 274 plugins and 19 themes. Of those, 135 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 293 vulnerabilities have been publicly disclosed. Security patches for 158 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 135 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 141 Patched / 133 Unpatched

Health Check & Troubleshooting

Plugin Slug:
health-check
Installations
300,000+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page View Count

Plugin Slug:
page-views-count
Installations
20,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pochipp

Plugin:
Pochipp
Plugin Slug:
pochipp
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WCFM Marketplace – Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Read More & Accordion

Plugin Slug:
expand-maker
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Protect WP Admin

Plugin Slug:
protect-wp-admin
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP User Manager – User Profile Builder & Membership

Plugin Slug:
wp-user-manager
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blaze Demo Importer

Plugin Slug:
blaze-demo-importer
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin Slug:
essential-real-estate
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Real Estate

Plugin Slug:
essential-real-estate
Installations
8,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Property Listings

Plugin Slug:
easy-property-listings
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility by AudioEye

Plugin Slug:
accessibility-by-audioeye
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eupago Gateway For Woocommerce

Plugin Slug:
eupago-gateway-for-woocommerce
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Photo Fetcher

Plugin Slug:
facebook-photo-fetcher
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Freshchat

Plugin:
Freshchat
Plugin Slug:
freshchat
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Import external attachments

Plugin Slug:
import-external-attachments
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just TinyMCE Custom Styles

Plugin Slug:
just-tinymce-styles
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meks Quick Plugin Disabler

Plugin Slug:
meks-quick-plugin-disabler
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RTL Tester

Plugin:
RTL Tester
Plugin Slug:
rtl-tester
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Semrush Content Toolkit

Plugin Slug:
semrush-contentshake
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fix Media Library

Plugin Slug:
wow-media-library-fix
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Coupons and Deals – Click to Copy Coupons

Plugin Slug:
wp-coupons-and-deals
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Flashy Marketing Automation

Plugin Slug:
wp-flashy-marketing-automation
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Views Counter

Plugin Slug:
wpecounter
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yaad Sarig Payment Gateway For WC

Plugin Slug:
yaad-sarig-payment-gateway-for-wc
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate WordPress Auction Plugin

Plugin Slug:
ultimate-auction
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leaky Paywall

Plugin Slug:
leaky-paywall
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Restrict Elementor Widgets, Columns and Sections

Plugin Slug:
restrict-elementor-widgets
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Notify Lite

Plugin Slug:
easy-notify-lite
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FAPI Member

Plugin Slug:
fapi-member
Installations
500+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flex QR Code Generator

Plugin Slug:
flex-qr-code-generator
Installations
40+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Animated Pixel Marquee Creator

Plugin:
Animated Pixel Marquee Creator
Plugin Slug:
animated-pixel-marquee-creator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AnnunciFunebri Impresa

Plugin:
AnnunciFunebri Impresa
Plugin Slug:
annuncifunebri-onoranza
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

App Landing Template Blocks for WPBakery (Visual Composer) Page Builder

Plugin:
App Landing Template Blocks for WPBakery (Visual Composer) Page Builder
Plugin Slug:
app-template-blocks-for-wpbakery-page-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Application Passwords

Plugin:
Application Passwords
Plugin Slug:
application-passwords
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ayo Shortcodes

Plugin:
Ayo Shortcodes
Plugin Slug:
ayo-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Plugin:
Better Elementor Addons
Plugin Slug:
better-elementor-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide Email Address

Plugin:
Hide Email Address
Plugin Slug:
bg-hide-email-address
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BMLT WordPress Plugin

Plugin:
BMLT WordPress Plugin
Plugin Slug:
bmlt-wordpress-satellite-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BUKAZU Search widget

Plugin:
BUKAZU Search widget
Plugin Slug:
bukazu-search-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buttoner for Elementor

Plugin:
Buttoner for Elementor
Plugin Slug:
buttoner-elementor
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Campay Woocommerce Payment Gateway

Plugin:
Campay Woocommerce Payment Gateway
Plugin Slug:
campay-api
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coder for Elementor

Plugin:
Coder for Elementor
Plugin Slug:
coder-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coding Blocks

Plugin:
Coding Blocks
Plugin Slug:
coding-blocks
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

?????

Plugin:
?????
Plugin Slug:
comments-secretary
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 with ChatWork

Plugin:
Contact Form 7 with ChatWork
Plugin Slug:
contact-form-7-with-chatwork
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CountDown With Image or Video Background

Plugin:
CountDown With Image or Video Background
Plugin Slug:
countdown_with_background
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV Sumotto

Plugin:
CSV Sumotto
Plugin Slug:
csv-sumotto
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CSV to SortTable

Plugin:
CSV to SortTable
Plugin Slug:
csv-to-sorttable
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Admin Menu

Plugin:
Custom Admin Menu
Plugin Slug:
custom-admin-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Frames

Plugin:
Custom Frames
Plugin Slug:
custom-frames
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Data Visualizer

Plugin:
Data Visualizer
Plugin Slug:
data-visualizer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DebateMaster

Plugin:
DebateMaster
Plugin Slug:
debatemaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Devs CRM

Plugin:
Devs CRM
Plugin Slug:
devs-crm
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Devs CRM

Plugin:
Devs CRM
Plugin Slug:
devs-crm
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Directory Pro

Plugin:
Directory Pro
Plugin Slug:
directory-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Donation

Plugin:
Donation
Plugin Slug:
donation
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Resource Library for Logged In Users

Plugin:
Resource Library for Logged In Users
Plugin Slug:
doubledome-resource-link-library
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category Dropdown List

Plugin:
Category Dropdown List
Plugin Slug:
dropdown-category-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Map Creator

Plugin:
Easy Map Creator
Plugin Slug:
easy-map-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Theme Options

Plugin:
Easy Theme Options
Plugin Slug:
easy-theme-options
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eyewear prescription form

Plugin:
Eyewear prescription form
Plugin Slug:
eyewear-prescription-form
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flow-Flow Social Stream

Plugin:
Flow-Flow Social Stream
Plugin Slug:
flow-flow-social-streams
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Uploader for Gravity Forms

Plugin:
Multi Uploader for Gravity Forms
Plugin Slug:
gf-multi-uploader
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GPXpress

Plugin:
GPXpress
Plugin Slug:
gpxpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Grider for Elementor

Plugin:
Grider for Elementor
Plugin Slug:
grider-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Huger for Elementor

Plugin:
Huger for Elementor
Plugin Slug:
huger-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IMAQ CORE

Plugin:
IMAQ CORE
Plugin Slug:
imaq-core
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin:
Infility Global
Plugin Slug:
infility-global
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Kirim.Email WooCommerce Integration

Plugin:
Kirim.Email WooCommerce Integration
Plugin Slug:
kirimemail-woocommerce-integration
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Laser

Plugin:
Laser
Plugin Slug:
laser
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Like DisLike Voting

Plugin:
Like DisLike Voting
Plugin Slug:
like-dislike-voting
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Listar – Directory Listing & Classifieds

Plugin:
Listar – Directory Listing & Classifieds
Plugin Slug:
listar-directory-listing
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LJUsers

Plugin:
LJUsers
Plugin Slug:
ljusers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Visitor Logic Lite

Plugin:
Visitor Logic Lite
Plugin Slug:
logic-pro
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Lottier for Elementor

Plugin:
Lottier for Elementor
Plugin Slug:
lottier-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lottier

Plugin:
Lottier
Plugin Slug:
lottier-gutenberg
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lottier for WPBakery

Plugin:
Lottier for WPBakery
Plugin Slug:
lottier-wpbakery
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LS Google Map Router

Plugin:
LS Google Map Router
Plugin Slug:
ls-gmap-route
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LT Unleashed

Plugin:
LT Unleashed
Plugin Slug:
lt-unleashed
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lucky Draw Contests

Plugin:
Lucky Draw Contests
Plugin Slug:
lucky-draw
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Masker for Elementor

Plugin:
Masker for Elementor
Plugin Slug:
masker-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Modalier for Elementor

Plugin:
Modalier for Elementor
Plugin Slug:
modalier-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

myLCO

Plugin:
myLCO
Plugin Slug:
mylco
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NewStatPress

Plugin:
NewStatPress
Plugin Slug:
newstatpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Complag

Plugin:
Complag
Plugin Slug:
omplag
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Paypal Payment Shortcode

Plugin:
Paypal Payment Shortcode
Plugin Slug:
paypal-payments-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popover Windows

Plugin:
Popover Windows
Plugin Slug:
popover-windows
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popover Windows

Plugin:
Popover Windows
Plugin Slug:
popover-windows
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Purchase and Expense Manager

Plugin:
Purchase and Expense Manager
Plugin Slug:
purchase-and-expense-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Testimonials

Plugin:
Quick Testimonials
Plugin Slug:
quick-testimonials
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rabbit Hole

Plugin:
Rabbit Hole
Plugin Slug:
rabbit-hole
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reformer for Elementor

Plugin:
Reformer for Elementor
Plugin Slug:
reformer-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reviews Sorted

Plugin:
Reviews Sorted
Plugin Slug:
reviews-sorted
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcode Ajax

Plugin:
Shortcode Ajax
Plugin Slug:
shortcode-ajax
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Nivo Slider

Plugin:
Simple Nivo Slider
Plugin Slug:
simple-nivo-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple post listing

Plugin:
Simple post listing
Plugin Slug:
simple-post-listing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Theme Changer

Plugin:
Simple Theme Changer
Plugin Slug:
simple-theme-changer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Theme Changer

Plugin:
Simple Theme Changer
Plugin Slug:
simple-theme-changer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SimplyConvert

Plugin:
SimplyConvert
Plugin Slug:
simplyconvert
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Solutions Ad Manager

Plugin:
Solutions Ad Manager
Plugin Slug:
solutions-ad-manager
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spoter for Elementor

Plugin:
Spoter for Elementor
Plugin Slug:
spoter-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SurveyFunnel

Plugin:
SurveyFunnel
Plugin Slug:
surveyfunnel-lite
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SurveyFunnel

Plugin:
SurveyFunnel
Plugin Slug:
surveyfunnel-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

xPromoter

Plugin:
xPromoter
Plugin Slug:
top_bar_promoter
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Truefy Embed

Plugin:
Truefy Embed
Plugin Slug:
truefy-embed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TWW Protein Calculator

Plugin:
TWW Protein Calculator
Plugin Slug:
twwc-protein
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL Media Uploader

Plugin:
URL Media Uploader
Plugin Slug:
url-media-uploader
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Userback

Plugin:
Userback
Plugin Slug:
userback
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video Merchant

Plugin:
Video Merchant
Plugin Slug:
video-merchant
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
VigLink SpotLight By ShortCode
Plugin Slug:
viglink-spotlight-by-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Vimeo SimpleGallery

Plugin:
Vimeo SimpleGallery
Plugin Slug:
vimeo-simplegallery
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WatchTowerHQ

Plugin:
WatchTowerHQ
Plugin Slug:
watchtowerhq
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:
Live Sales Notification for Woocommerce – Woomotiv
Plugin Slug:
woomotiv
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Dropzone

Plugin:
WP Dropzone
Plugin Slug:
wp-dropzone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Flot

Plugin:
WP Flot
Plugin Slug:
wp-flot
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Plugin:
WP Job Portal
Plugin Slug:
wp-job-portal
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Plugin:
WP Job Portal
Plugin Slug:
wp-job-portal
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPGancio

Plugin:
WPGancio
Plugin Slug:
wpgancio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wpik WordPress Basic Ajax Form

Plugin:
Wpik WordPress Basic Ajax Form
Plugin Slug:
wpik-wordpress-basic-ajax-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPLG Default Mail From

Plugin:
WPLG Default Mail From
Plugin Slug:
wplg-default-mail-from
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Zenost Shortcodes

Plugin:
Zenost Shortcodes
Plugin Slug:
zenost-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type UI

Plugin Slug:
custom-post-type-ui
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.18.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.18.2.

Redux Framework

Plugin Slug:
redux-framework
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.9.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations
800,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 13.2.2.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations
800,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.2.5.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.0.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.1.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 8.1.0.

GenerateBlocks

Plugin Slug:
generateblocks
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

a3 Lazy Load

Plugin Slug:
a3-lazy-load
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.14.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.4.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.9.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.1.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.342
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.342.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.4.

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist
Installations
100,000+
Vulnerability:
Content Injection
Patched in Version:
2.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.0.

Rich Shortcodes for Google Reviews

Plugin Slug:
widget-google-reviews
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.8.1.

YITH WooCommerce Quick View

Plugin Slug:
yith-woocommerce-quick-view
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

MailerLite – Signup forms (official)

Plugin Slug:
official-mailerlite-sign-up-forms
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.17.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.

List category posts

Plugin Slug:
list-category-posts
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
0.92.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.92.0.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
5.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.4.

OneSignal – Web Push Notifications

Plugin Slug:
onesignal-free-web-push-notifications
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.7.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.17.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
70,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
7.2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.2.3.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.2.3.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.34.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.7.

Advanced Product Fields (Product Addons) for WooCommerce

Plugin Slug:
advanced-product-fields-for-woocommerce
Installations
50,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.18.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.3.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
40,000+
Vulnerability:
SQL Injection
Patched in Version:
3.13.1.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.13.1.6.

InstaWP Connect – 1-click WP Staging & Migration

Plugin Slug:
instawp-connect
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.2.0.

HT Slider For Elementor

Plugin Slug:
ht-slider-for-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.5.

Login Security, FireWall, Malware removal by CleanTalk

Plugin Slug:
security-malware-firewall
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.169
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.169.

Themify Portfolio Post

Plugin Slug:
themify-portfolio-post
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.4.

Livemesh SiteOrigin Widgets

Plugin Slug:
livemesh-siteorigin-widgets
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

My Calendar – Accessible Event Manager

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.17.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.3.

404 Solution

Plugin Slug:
404-solution
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.1.

Store Locator WordPress

Plugin Slug:
agile-store-locator
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.3.

CC Child Pages

Plugin Slug:
cc-child-pages
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Reviews Widget for Google, Yelp & Recommendations

Plugin Slug:
fb-reviews-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.

HandL UTM Grabber / Tracker

Plugin Slug:
handl-utm-grabber
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.

Head Meta Data

Plugin Slug:
head-meta-data
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
20251118
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20251118.

JetWidgets For Elementor

Plugin Slug:
jetwidgets-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.21.

Lightweight Accordion

Plugin Slug:
lightweight-accordion
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

WP-ShowHide

Plugin Slug:
wp-showhide
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.06.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.13.

rtMedia for WordPress, BuddyPress and bbPress

Plugin Slug:
buddypress-media
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.4
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.7.4.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.7.

Multi-Step Checkout for WooCommerce

Plugin Slug:
wp-multi-step-checkout
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.34.

BSK PDF Manager

Plugin Slug:
bsk-pdf-manager
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.31.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.1.

WPGraphQL Smart Cache

Plugin Slug:
wpgraphql-smart-cache
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Magical Posts Display – Elementor Advanced Posts widgets

Plugin Slug:
magical-posts-display
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.55
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.55.

Sitewide Notice WP

Plugin Slug:
sitewide-notice-wp
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

WPMasterToolKit (WPMTK) – All in one plugin

Plugin Slug:
wpmastertoolkit
Installations
3,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.13.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.13.1.

UseStrict’s Calendly Embedder

Plugin Slug:
cal-embedder-lite
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations
2,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.3.
Plugin Slug:
simple-link-directory
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.4.
Plugin Slug:
simple-link-directory
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.4.

Tableberg – Simple Gutenberg Table Block

Plugin Slug:
tableberg
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.10.

VK Google Job Posting Manager

Plugin Slug:
vk-google-job-posting-manager
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.23.

Email Marketing Plugin – WP Email Capture

Plugin Slug:
wp-email-capture
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.12.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.5.

CWW Companion

Plugin Slug:
cww-companion
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

Hippoo Mobile App for WooCommerce

Plugin Slug:
hippoo
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.2.

Hippoo Mobile App for WooCommerce

Plugin Slug:
hippoo
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

Nelio Popups

Plugin Slug:
nelio-popups
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Highlight and Share – Social Text and Image Sharing

Plugin Slug:
highlight-and-share
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

WP eBay Product Feeds

Plugin Slug:
ebay-feeds-for-wordpress
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.10.

VikRentItems Flexible Rental Management System

Plugin Slug:
vikrentitems
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Appointment Booking and Scheduler Plugin – Truebooker

Plugin Slug:
truebooker-appointment-booking
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Easy Invoice – PDF Invoice Generator & Quote Builder

Plugin Slug:
easy-invoice
Installations
500+
Vulnerability:
Local File Inclusion
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Wbcom Designs – Private Community for BuddyPress

Plugin Slug:
lock-my-bp
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

PDF for Contact Form 7 + Drag and Drop Template Builder

Plugin Slug:
pdf-for-contact-form-7
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
6.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.4.

Rencontre – Dating Site

Plugin Slug:
rencontre
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.13.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.8.
Plugin Slug:
ays-slider
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

BuddyTask

Plugin:
BuddyTask
Plugin Slug:
buddytask
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Upcoming for Calendly

Plugin Slug:
upcoming-for-calendly
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

AI Feeds

Plugin:
AI Feeds
Plugin Slug:
ai-feeds
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.23.

Guest Support

Plugin Slug:
guest-support
Installations
40+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Simple Folio

Plugin Slug:
simple-folio
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Divelogs Widget

Plugin Slug:
divelogs-widget
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

FX Currency Converter

Plugin Slug:
fx-currency-converter
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.1.

Player Leaderboard

Plugin Slug:
player-leaderboard
Installations
20+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.3.

HAPPY – Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.10.

Mailgun Subscriptions

Plugin Slug:
mailgun-subscriptions
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Simple CSV Table

Plugin Slug:
simple-csv-table
Installations
10+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Accordion Slider PRO

Plugin:
Accordion Slider PRO
Plugin Slug:
accordion_slider_pro
Vulnerability:
SQL Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Dokan Pro

Plugin:
Dokan Pro
Plugin Slug:
dokan-pro
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Elated Membership

Plugin:
Elated Membership
Plugin Slug:
eltdf-membership
Vulnerability:
Broken Authentication
Patched in Version:
1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.0.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.0.

Homey Core

Plugin:
Homey Core
Plugin Slug:
homey-core
Vulnerability:
Broken Access Control
Patched in Version:
2.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.4.

Image Caption Hover Pro

Plugin:
Image Caption Hover Pro
Plugin Slug:
image-caption-hover-pro
Vulnerability:
Broken Access Control
Patched in Version:
20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20.0.

Jobmonster Elementor Addon

Plugin:
Jobmonster Elementor Addon
Plugin Slug:
jobmonster-addon
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Simple Bike Rental

Plugin Slug:
simple-bike-rental
Vulnerability:
Broken Access Control
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

WP CarDealer

Plugin:
WP CarDealer
Plugin Slug:
wp-cardealer
Vulnerability:
Privilege Escalation
Patched in Version:
1.2.17
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.17.

WP Fastest Cache Premium

Plugin:
WP Fastest Cache Premium
Plugin Slug:
wp-fastest-cache-premium
Vulnerability:
Broken Access Control
Patched in Version:
1.7.5
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.7.5.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Broken Access Control
Patched in Version:
16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.9.

WordPress Themes — 17 Patched / 2 Unpatched

EduMall

Theme:
EduMall
Theme Slug:
edumall
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MinimogWP

Theme:
MinimogWP
Theme Slug:
minimog
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kingcabs

Theme:
Kingcabs
Theme Slug:
kingcabs
Downloads
38,008
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.10.

Mavix Education

Theme Slug:
mavix-education
Downloads
2,776
Vulnerability:
Broken Access Control
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

Besa

Theme:
Besa
Theme Slug:
besa
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.16.

Digiqole

Theme:
Digiqole
Theme Slug:
digiqole
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.7.

ekommart

Theme:
ekommart
Theme Slug:
ekommart
Vulnerability:
Local File Inclusion
Patched in Version:
4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.1.

Exhibz

Theme:
Exhibz
Theme Slug:
exhibz
Vulnerability:
Local File Inclusion
Patched in Version:
3.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.10.

Fashion

Theme:
Fashion
Theme Slug:
fashion2
Vulnerability:
Local File Inclusion
Patched in Version:
5.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.0.

Hara

Theme:
Hara
Theme Slug:
hara
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.18.

Kerge

Theme:
Kerge
Theme Slug:
kerge
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.4.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Local File Inclusion
Patched in Version:
4.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.3.

PenNews

Theme:
PenNews
Theme Slug:
pennews
Vulnerability:
Broken Access Control
Patched in Version:
6.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.4.

Sailing

Theme:
Sailing
Theme Slug:
sailing
Vulnerability:
Broken Access Control
Patched in Version:
4.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.

Sailing

Theme:
Sailing
Theme Slug:
sailing
Vulnerability:
Local File Inclusion
Patched in Version:
4.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.6.

Sober

Theme:
Sober
Theme Slug:
sober
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.5.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.12.

Turitor

Theme:
Turitor
Theme Slug:
turitor
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Urna

Theme:
Urna
Theme Slug:
urna
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.13.

Wilmër

Theme:
Wilmër
Theme Slug:
wilmer
Vulnerability:
Local File Inclusion
Patched in Version:
3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security