WordPress Vulnerability Report

WordPress Vulnerability Report — January 7, 2026

Since last week, 333 new vulnerabilities have emerged in the WordPress ecosystem, including 253 plugins and 80 themes. Of those, 236 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 333 vulnerabilities have been publicly disclosed. Security patches for 97 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 236 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 83 Patched / 170 Unpatched

EasyTest – Simplify A/B Testing

Plugin Slug:
convertpro
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Snippets – Custom WordPress Code Snippets Customizer

Plugin Slug:
post-snippets
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cookies and Content Security Policy

Plugin Slug:
cookies-and-content-security-policy
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Five Star Restaurant Reservations – WordPress Booking Plugin

Plugin Slug:
restaurant-reservations
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Like Page Plugin

Plugin Slug:
simple-facebook-plugin
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
grand-media
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QuadLayers TikTok Feed

Plugin Slug:
wp-tiktok-feed
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

All in One Accessibility

Plugin Slug:
all-in-one-accessibility
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tooltips for WordPress

Plugin Slug:
wordpress-tooltips
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hotel Booking

Plugin Slug:
nd-booking
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zoho ZeptoMail

Plugin Slug:
transmail
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Beaver Builder

Plugin Slug:
addons-for-beaver-builder
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AnyComment

Plugin:
AnyComment
Plugin Slug:
anycomment
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GS Portfolio for Envato

Plugin Slug:
gs-envato-portfolio
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Attachments

Plugin Slug:
wp-attachments
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
carousel-horizontal-posts-content-slider
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
civic-cookie-control-8
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Curator.io

Plugin:
Curator.io
Plugin Slug:
curatorio
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
featured-image-generator
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Calendar.online / Kalender.digital – Plugin

Plugin Slug:
kalender-digital
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MAS Videos

Plugin:
MAS Videos
Plugin Slug:
masvideos
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Menu In Post

Plugin Slug:
menu-in-post
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Series

Plugin:
Series
Plugin Slug:
series
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Moneytizer

Plugin Slug:
the-moneytizer
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Specific Content

Plugin Slug:
user-specific-content
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Web and WooCommerce Addons for WPBakery Builder

Plugin Slug:
vc-addons-by-bit14
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Plugin Slug:
wallet-system-for-woocommerce
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WebMan Amplifier

Plugin Slug:
webman-amplifier
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
accordion-slider-gallery
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AdWords Conversion Tracking Code

Plugin Slug:
adwords-conversion-tracking-code
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AI Content Writing Assistant

Plugin Slug:
ai-content-writing-assistant
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payment Gateway Authorize.Net CIM for WooCommerce

Plugin Slug:
authnet-cim-for-woo
Installations
1,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AweBooking – Hotel Booking System

Plugin Slug:
awebooking
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bootstrap Modals

Plugin Slug:
bootstrap-modals
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Co-marquage service-public.fr

Plugin Slug:
co-marquage-service-public
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CodeColorer

Plugin Slug:
codecolorer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Core Web Vitals & PageSpeed Booster

Plugin Slug:
core-web-vitals-pagespeed-booster
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Background Changer

Plugin Slug:
custom-background-changer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
custom-url-to-featured-image
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DMCA Protection Badge

Plugin Slug:
dmca-badge
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Download Media Library

Plugin Slug:
download-media-library
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EasyIndex

Plugin:
EasyIndex
Plugin Slug:
easyindex
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Extra Shortcodes

Plugin Slug:
extra-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FormFacade – Embed Google Forms in your website

Plugin Slug:
formfacade
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-portfolio
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GLS Shipping for WooCommerce

Plugin Slug:
gls-shipping-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hide Plugins

Plugin Slug:
hide-plugins
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Locatoraid Store Locator

Plugin Slug:
locatoraid
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MX Time Zone Clocks

Plugin Slug:
mx-time-zone-clocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Widget

Plugin Slug:
new-contact-form-widget
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
owl-carousel-wp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Title Splitter

Plugin Slug:
page-title-splitter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

?????? ?????? ??????

Plugin Slug:
pardakht-delkhah
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Delivery Date for WooCommerce – Lite

Plugin Slug:
product-delivery-date-for-woocommerce-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Realbig For WordPress

Plugin Slug:
realbig-media
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RestroPress – Online Food Ordering System

Plugin Slug:
restropress
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Robots.txt rewrite

Plugin Slug:
robotstxt-rewrite
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO Slider

Plugin:
SEO Slider
Plugin Slug:
seo-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slider Templates

Plugin Slug:
slider-templates
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tasty Recipes Lite

Plugin Slug:
tasty-recipes-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tasty Recipes Lite

Plugin Slug:
tasty-recipes-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tc-logo-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Terms descriptions

Plugin Slug:
terms-descriptions
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OpenHook

Plugin:
OpenHook
Plugin Slug:
thesis-openhook
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Trash Duplicate and 301 Redirect

Plugin Slug:
trash-duplicate-and-301-redirect
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cincopa video and media plug-in

Plugin Slug:
video-playlist-and-gallery-plugin
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cincopa video and media plug-in

Plugin Slug:
video-playlist-and-gallery-plugin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Gmail SMTP

Plugin Slug:
wp-gmail-smtp
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Post Signature

Plugin Slug:
wp-post-signature
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Varnish/Nginx Proxy Caching

Plugin Slug:
vcaching
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Notes for WP Dashboard

Plugin Slug:
wb-sticky-notes
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Advanced PDF

Plugin Slug:
wp-advanced-pdf
Installations
900+
Vulnerability:
Other Vulnerability Type
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iNext Woo Pincode Checker

Plugin Slug:
inext-woo-pincode-checker
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mergado Pack

Plugin Slug:
mergado-marketing-pack
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wiremo – Product Reviews for WooCommerce

Plugin Slug:
woo-reviews-by-wiremo
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BoomDevs WordPress Coming Soon Plugin

Plugin Slug:
coming-soon-by-boomdevs
Installations
700+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Upload Files During Checkout

Plugin Slug:
easy-upload-files-during-checkout
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live Shopping & Shoppable Videos For WooCommerce

Plugin Slug:
live-shopping-video-streams
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live Shopping & Shoppable Videos For WooCommerce

Plugin Slug:
live-shopping-video-streams
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Efí Bank

Plugin:
Efí Bank
Plugin Slug:
woo-gerencianet-official
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Export Categories & Taxonomies

Plugin Slug:
wp-export-categories-taxonomies
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-CalDav2ICS

Plugin Slug:
wp-caldav2ics
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Audiomack

Plugin:
Audiomack
Plugin Slug:
audiomack
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Fetcher

Plugin Slug:
content-fetcher
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sell Downloads

Plugin Slug:
sell-downloads
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Press

Plugin Slug:
ilogic-accessibility
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MyD Delivery

Plugin Slug:
myd-delivery
Installations
100+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Orders Chat for WooCommerce

Plugin Slug:
orders-chat-for-woocommerce
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple XML Sitemap

Plugin Slug:
simple-xml-sitemap
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Order Cancellation & Returns for WooCommerce

Plugin Slug:
wc-order-cancellation-return
Installations
100+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Effect Maker

Plugin Slug:
effect-maker
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Password Reset

Plugin Slug:
flaming-password-reset
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PRIMER by chloédigital

Plugin Slug:
primer-by-chloedigital
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Visitor Stats Widget

Plugin Slug:
visitor-stats-widget
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Style

Plugin Slug:
custom-style
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

e-shops???2

Plugin Slug:
e-shops-cart2
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Noindex by Path

Plugin Slug:
noindex-by-path
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pinpoll

Plugin:
Pinpoll
Plugin Slug:
pinpoll
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Recent Posts From Each Category

Plugin Slug:
recent-posts-from-each-category
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Scroll rss excerpt

Plugin Slug:
scroll-rss-excerpt
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SensitiveTagCloud

Plugin Slug:
sensitive-tag-cloud
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Archive Generator

Plugin Slug:
simple-archive-generator
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Profilr

Plugin Slug:
social-profilr-display-social-network-profile
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin:
WP App Bar
Plugin Slug:
wp-app-bar
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-EasyArchives

Plugin Slug:
wp-easyarchives
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Status

Plugin Slug:
custom-post-status
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Direct Payments WP

Plugin Slug:
direct-payments-wp
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Direct Payments WP

Plugin Slug:
direct-payments-wp
Installations
40+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flowbox

Plugin:
Flowbox
Plugin Slug:
flowbox
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Beacon

Plugin Slug:
wp-dashboard-beacon
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
10+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advance WP Query Search Filter

Plugin:
Advance WP Query Search Filter
Plugin Slug:
advance-wp-query-search-filter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advance WP Query Search Filter

Plugin:
Advance WP Query Search Filter
Plugin Slug:
advance-wp-query-search-filter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Appender

Plugin:
Appender
Plugin Slug:
appender
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin:
Appointify
Plugin Slug:
appointify
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin:
Appointify
Plugin Slug:
appointify
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wawp

Plugin:
Wawp
Plugin Slug:
automation-web-platform
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BM Content Builder

Plugin:
BM Content Builder
Plugin Slug:
bm-builder
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Conformer for Elementor

Plugin:
Conformer for Elementor
Plugin Slug:
conformer-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Countdowner for Elementor

Plugin:
Countdowner for Elementor
Plugin Slug:
countdowner-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Couponer for Elementor

Plugin:
Couponer for Elementor
Plugin Slug:
couponer-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Criptopayer for Elementor

Plugin:
Criptopayer for Elementor
Plugin Slug:
criptopayer-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dental Care CPT

Plugin:
Dental Care CPT
Plugin Slug:
dentalcare-cpt
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gmaper for Elementor

Plugin:
Gmaper for Elementor
Plugin Slug:
gmaper-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Select Graphist for Elementor Graphist for Elementor

Plugin:
Select Graphist for Elementor Graphist for Elementor
Plugin Slug:
graphist-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Headinger for Elementor

Plugin:
Headinger for Elementor
Plugin Slug:
headinger-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hotel Listing

Plugin:
Hotel Listing
Plugin Slug:
hotel-listing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iRecco Core

Plugin:
iRecco Core
Plugin Slug:
irecco-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JobBank

Plugin:
JobBank
Plugin Slug:
jobbank
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingPro Reviews

Plugin:
ListingPro Reviews
Plugin Slug:
listingpro-reviews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Logger for Elementor

Plugin:
Logger for Elementor
Plugin Slug:
logger-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Movies Bulk Importer

Plugin:
WordPress Movies Bulk Importer
Plugin Slug:
movies importer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Questionar for Elementor

Plugin:
Questionar for Elementor
Plugin Slug:
questionar-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Registration & Login with Mobile Phone Number for WooCommerce

Plugin:
Registration & Login with Mobile Phone Number for WooCommerce
Plugin Slug:
registration-login-with-mobile-phone-number
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Reuters Direct

Plugin:
Reuters Direct
Plugin Slug:
reuters-direct
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SearchAzon

Plugin:
SearchAzon
Plugin Slug:
searchazon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sermon Manager

Plugin:
Sermon Manager
Plugin Slug:
sermon-manager-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sliper for Elementor

Plugin:
Sliper for Elementor
Plugin Slug:
sliper-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Super Logos Showcase

Plugin:
Super Logos Showcase
Plugin Slug:
superlogoshowcase-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tech Life CPT

Plugin:
Tech Life CPT
Plugin Slug:
techlife-cpt
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UnGrabber

Plugin:
UnGrabber
Plugin Slug:
ungrabber
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:
Universal Video Player
Plugin Slug:
universal-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Universal Video Player

Plugin:
Universal Video Player
Plugin Slug:
universal-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Valenti Engine

Plugin:
Valenti Engine
Plugin Slug:
valenti-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Walker for Elementor

Plugin:
Walker for Elementor
Plugin Slug:
walker-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Watcher for Elementor

Plugin:
Watcher for Elementor
Plugin Slug:
watcher-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WING WordPress Migrator

Plugin:
WING WordPress Migrator
Plugin Slug:
wing-migrator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Parcelas

Plugin:
WooCommerce Parcelas
Plugin Slug:
woocommerce-parcelas
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Worker for Elementor

Plugin:
Worker for Elementor
Plugin Slug:
worker-elementor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Worker for WPBakery

Plugin:
Worker for WPBakery
Plugin Slug:
worker-wpbakery
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress & WooCommerce Scraper Plugin, Import Data from Any Site

Plugin:
WordPress & WooCommerce Scraper Plugin, Import Data from Any Site
Plugin Slug:
wp_scraper
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
11.1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.1.5.1.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.0.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.15.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

Depicter — Popup & Slider Builder

Plugin Slug:
depicter
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

Depicter — Popup & Slider Builder

Plugin Slug:
depicter
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.5.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.19.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.1.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Privilege Escalation
Patched in Version:
7.6.40
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.6.40.

Table Field Add-on for ACF and SCF

Plugin Slug:
advanced-custom-fields-table-field
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.31.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.8.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.8.9.

Ultimate Post Kit Addons for Elementor

Plugin Slug:
ultimate-post-kit
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.16.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.41.

Icegram Engage – Popups, Optins, CTAs & lot more…

Plugin Slug:
icegram
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.36.

WP Import – Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.36.

AffiliateX – Amazon Affiliate Plugin

Plugin Slug:
affiliatex
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Demo Importer Plus

Plugin Slug:
demo-importer-plus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Form Vibes – Database Manager for Forms

Plugin Slug:
form-vibes
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Plugin Organizer

Plugin Slug:
plugin-organizer
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
10.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.2.4.

Postie

Plugin:
Postie
Plugin Slug:
postie
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.74
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.74.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
5.0.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.11.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6.40
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.40.

Blog Filter Post Filtering

Plugin Slug:
blog-filter
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Customer Email Verification for WooCommerce

Plugin Slug:
emails-verification-for-woocommerce
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

ShopBuilder – WooCommerce Builder For Elementor

Plugin Slug:
shopbuilder
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.

FlexTable – Data Table Sync with Google Sheets

Plugin Slug:
sheets-to-wp-table-live-sync
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.2.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.8.

Free Shipping Bar: Amount Left for Free Shipping for WooCommerce

Plugin Slug:
amount-left-free-shipping-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

BuddyPress Activity Shortcode

Plugin Slug:
bp-activity-shortcode
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

Newsletters

Plugin Slug:
newsletters-lite
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.12.
Plugin Slug:
videographywp
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.20.

Wishlist for WooCommerce: Multi Wishlists Per Customer

Plugin Slug:
wish-list-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Combo Offers WooCommerce

Plugin Slug:
woo-combo-offers
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.

Email Marketing Plugin – WP Email Capture

Plugin Slug:
wp-email-capture
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.12.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.6.

Yada Wiki

Plugin:
Yada Wiki
Plugin Slug:
yada-wiki
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.

Import into Easy Property Listings

Plugin Slug:
easy-property-listings-xml-csv-import
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Signature Add-On for Gravity Forms

Plugin Slug:
gravity-signature-forms-add-on
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

Maximum Products per User for WooCommerce

Plugin Slug:
maximum-products-per-user-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.4.

Lucky Wheel for WooCommerce – Spin a Sale

Plugin Slug:
woo-lucky-wheel
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.1.14
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.14.

WPCal.io – Easy Meeting Scheduler

Plugin Slug:
wpcal
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9.5.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.5.10.

Serial Codes Generator and Validator with WooCommerce Support

Plugin Slug:
serial-codes-generator-and-validator
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.3.

URL Image Importer

Plugin Slug:
url-image-importer
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

ilGhera Support System for WooCommerce

Plugin Slug:
wc-support-system
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Knowband Mobile App Builder

Plugin Slug:
knowband-mobile-app-builder-for-woocommerce
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Page Expire Popup/Redirection for WordPress

Plugin Slug:
page-expire-popup
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.

Automotive Listings

Plugin:
Automotive Listings
Plugin Slug:
automotive
Vulnerability:
SQL Injection
Patched in Version:
18.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 18.7.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.

Follow My Blog Post

Plugin:
Follow My Blog Post
Plugin Slug:
follow-my-blog-post
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

FooEvents for WooCommerce

Plugin:
FooEvents for WooCommerce
Plugin Slug:
fooevents
Vulnerability:
SQL Injection
Patched in Version:
1.20.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.20.5.
Plugin:
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Plugin Slug:
gdpr-cookie-consent
Vulnerability:
Broken Access Control
Patched in Version:
4.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.4.

JetBlog

Plugin:
JetBlog
Plugin Slug:
jet-blog
Vulnerability:
Broken Access Control
Patched in Version:
2.4.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.1.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Broken Access Control
Patched in Version:
3.8.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.1.2.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.8.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.0.20.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.20.2.

JetSearch

Plugin:
JetSearch
Plugin Slug:
jet-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.16.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.16.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Broken Access Control
Patched in Version:
2.2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.1.

WBC907 Core

Plugin:
WBC907 Core
Plugin Slug:
wbc907-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

WeDesignTech Ultimate Booking Addon

Plugin:
WeDesignTech Ultimate Booking Addon
Plugin Slug:
wedesigntech-ultimate-booking-addon
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.4.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.31.

WordPress Themes — 14 Patched / 66 Unpatched

Black Rider

Theme Slug:
black-rider
Downloads
45,140
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Consulting

Theme Slug:
consulting
Downloads
428,660
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Melos

Theme:
Melos
Theme Slug:
melos
Downloads
438,193
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Minamaze

Theme:
Minamaze
Theme Slug:
minamaze
Downloads
1,015,028
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Shuttle

Theme:
Shuttle
Theme Slug:
shuttle
Downloads
555,266
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Vireo

Theme:
Vireo
Theme Slug:
vireo
Downloads
23,014
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Arcane

Theme:
Arcane
Theme Slug:
arcane
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Arlo

Theme:
Arlo
Theme Slug:
arlo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Backpack Traveler

Theme:
Backpack Traveler
Theme Slug:
backpacktraveler
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Bailly

Theme:
Bailly
Theme Slug:
bailly
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bfres

Theme:
Bfres
Theme Slug:
bfres
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hope

Theme:
Hope
Theme Slug:
charity-is-hope
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cocco

Theme:
Cocco
Theme Slug:
cocco
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Curly

Theme:
Curly
Theme Slug:
curly
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Dekoro

Theme:
Dekoro
Theme Slug:
dekoro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

DiveIt

Theme:
DiveIt
Theme Slug:
diveit
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Dolcino

Theme:
Dolcino
Theme Slug:
dolcino
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Eldon

Theme:
Eldon
Theme Slug:
eldon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Electrician – Electrical Service WordPress

Theme:
Electrician – Electrical Service WordPress
Theme Slug:
electrician
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Fiorello

Theme:
Fiorello
Theme Slug:
fiorello
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

FiveStar

Theme:
FiveStar
Theme Slug:
fivestar
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Fleur

Theme:
Fleur
Theme Slug:
fleur
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Frappé

Theme:
Frappé
Theme Slug:
frappe
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FreeAgent

Theme:
FreeAgent
Theme Slug:
freeagent
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Freshio

Theme:
Freshio
Theme Slug:
freshio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gecko

Theme:
Gecko
Theme Slug:
gecko
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Genemy

Theme:
Genemy
Theme Slug:
genemy
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hobo

Theme:
Hobo
Theme Slug:
hobo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Holmes

Theme:
Holmes
Theme Slug:
holmes
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hyori

Theme:
Hyori
Theme Slug:
hyori
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Indoor Plants

Theme:
Indoor Plants
Theme Slug:
indoor-plants
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Innovio

Theme:
Innovio
Theme Slug:
innovio
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Issabella

Theme:
Issabella
Theme Slug:
issabella
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Justicia

Theme:
Justicia
Theme Slug:
justicia
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Lekker

Theme:
Lekker
Theme Slug:
lekker
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lindo

Theme:
Lindo
Theme Slug:
lindo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Malta

Theme:
Malta
Theme Slug:
malta
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Modern Housewife

Theme:
Modern Housewife
Theme Slug:
modernhousewife
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MoveMe

Theme:
MoveMe
Theme Slug:
moveme
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Muji

Theme:
Muji
Theme Slug:
muji
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sound | Musical Instruments Online Store

Theme:
Sound | Musical Instruments Online Store
Theme Slug:
musicplace
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Overton

Theme:
Overton
Theme Slug:
overton
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Overworld

Theme:
Overworld
Theme Slug:
overworld
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PartyMaker

Theme:
PartyMaker
Theme Slug:
partymaker
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:
PawFriends – Pet Shop and Veterinary WordPress Theme
Theme Slug:
pawfriends
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Pearson Specter

Theme:
Pearson Specter
Theme Slug:
pearsonspecter
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pets Land

Theme:
Pets Land
Theme Slug:
petsland
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pippo

Theme:
Pippo
Theme Slug:
pippo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Piqes

Theme:
Piqes
Theme Slug:
piqes
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Prider

Theme:
Prider
Theme Slug:
prider
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rashy

Theme:
Rashy
Theme Slug:
rashy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Roam

Theme:
Roam
Theme Slug:
roam
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Snow Mountain

Theme:
Snow Mountain
Theme Slug:
snowmountain
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Struktur

Theme:
Struktur
Theme Slug:
struktur
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

MaxShop

Theme:
MaxShop
Theme Slug:
sw_maxshop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sweet Jane

Theme:
Sweet Jane
Theme Slug:
sweetjane
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Tails

Theme:
Tails
Theme Slug:
tails
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

TanTum

Theme:
TanTum
Theme Slug:
tantum
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Töbel

Theme:
Töbel
Theme Slug:
tobel
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tornados

Theme:
Tornados
Theme Slug:
tornados
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Triply

Theme:
Triply
Theme Slug:
triply
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

uReach

Theme:
uReach
Theme Slug:
ureach
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Vango

Theme:
Vango
Theme Slug:
vango
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Verdure

Theme:
Verdure
Theme Slug:
verdure
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Weedles

Theme:
Weedles
Theme Slug:
weedles
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yolox

Theme:
Yolox
Theme Slug:
yolox
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Oneline Lite

Theme Slug:
oneline-lite
Downloads
411,275
Vulnerability:
Broken Access Control
Patched in Version:
6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.

Phlox

Theme:
Phlox
Theme Slug:
phlox
Downloads
1,709,830
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.11.

Bookory

Theme:
Bookory
Theme Slug:
bookory
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

Calafate

Theme:
Calafate
Theme Slug:
calafate
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.8.

Corpkit

Theme:
Corpkit
Theme Slug:
corpkit
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Corpkit

Theme:
Corpkit
Theme Slug:
corpkit
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Grand Restaurant

Theme:
Grand Restaurant
Theme Slug:
grandrestaurant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.9.

Jobify

Theme:
Jobify
Theme Slug:
jobify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.1.

Lobo

Theme:
Lobo
Theme Slug:
lobo
Vulnerability:
SQL Injection
Patched in Version:
2.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.6.

Neo Ocular

Theme:
Neo Ocular
Theme Slug:
neoocular
Vulnerability:
Local File Inclusion
Patched in Version:
1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
Local File Inclusion
Patched in Version:
7.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.7.5.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

VidMov

Theme:
VidMov
Theme Slug:
vidmov
Vulnerability:
Path Traversal
Patched in Version:
2.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.9.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.31.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security