WordPress Vulnerability Report

WordPress Vulnerability Report — January 21, 2026

Since last week, 180 new vulnerabilities have emerged in the WordPress ecosystem, including 137 plugins and 43 themes. Of those, 118 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 180 vulnerabilities have been publicly disclosed. Security patches for 62 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 118 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025, adding Notes for block-level comments, an expanded Command Palette, and the new Abilities API to standardize permissions for future automation. It also includes performance improvements and new blocks and design tools to support faster, more flexible site building.

After any major release, don’t update live sites until you’ve taken backups and tested in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 57 Patched / 80 Unpatched

WP Test Email

Plugin Slug:
wp-test-email
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
related-posts-by-taxonomy
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CleverReach® WP

Plugin Slug:
cleverreach-wp
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

DK PDF – WordPress PDF Generator

Plugin Slug:
dk-pdf
Installations
3,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SEO Booster

Plugin Slug:
seo-booster
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Antideo Email Validator

Plugin Slug:
antideo-email-validator
Installations
900+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Event Espresso – Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf
Installations
700+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Mail

Plugin:
WP Mail
Plugin Slug:
wp-mail
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shipping Rate By Cities

Plugin Slug:
shipping-rate-by-cities
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

My Post Order

Plugin Slug:
my-posts-order
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shown Connector

Plugin Slug:
shown-connector
Installations
400+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Table of Contents Creator

Plugin Slug:
table-of-contents-creator
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Netcash WooCommerce Payment Gateway

Plugin Slug:
netcash-pay-now-payment-gateway-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quote Master

Plugin Slug:
quote-master
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Syntax Highlighter Compress

Plugin Slug:
syntax-highlighter-compress
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HDForms | Contact Form Builder

Plugin Slug:
hdforms
Installations
70+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dooodl

Plugin:
Dooodl
Plugin Slug:
dooodl
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Gotham Block Extra Light

Plugin Slug:
gotham-block-extra-light
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gotham Block Extra Light

Plugin Slug:
gotham-block-extra-light
Installations
60+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Redirect

Plugin Slug:
wp-simple-redirect
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bidorbuy Store Integrator

Plugin Slug:
bidorbuystoreintegrator
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ShoutOut

Plugin:
ShoutOut
Plugin Slug:
shoutout
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Accordion Slider PRO

Plugin:
Accordion Slider PRO
Plugin Slug:
accordion_slider_pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AJS Footnotes

Plugin:
AJS Footnotes
Plugin Slug:
ajs-footnotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Aplazo Payment Gateway

Plugin:
Aplazo Payment Gateway
Plugin Slug:
aplazo-payment-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SocialChamp with WordPress

Plugin:
SocialChamp with WordPress
Plugin Slug:
auto-post-to-social-media-wp-to-social-champ
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Page Permalink Extension
Plugin Slug:
change-wp-page-permalinks
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Omnichannel for WooCommerce

Plugin:
Omnichannel for WooCommerce
Plugin Slug:
codistoconnect
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Crush.pics Image Optimizer

Plugin:
Crush.pics Image Optimizer
Plugin Slug:
crush-pics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DASHBOARD BUILDER

Plugin:
DASHBOARD BUILDER
Plugin Slug:
dashboard-builder
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Reservation Plugin

Plugin:
Reservation Plugin
Plugin Slug:
dt-reservation-plugin
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Electric Studio Download Counter

Plugin:
Electric Studio Download Counter
Plugin Slug:
electric-studio-download-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shipping Rates by City for WooCommerce

Plugin:
Shipping Rates by City for WooCommerce
Plugin Slug:
flat-shipping-rate-by-city-for-woocommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Float Payment Gateway

Plugin:
Float Payment Gateway
Plugin Slug:
float-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GetContentFromURL

Plugin:
GetContentFromURL
Plugin Slug:
getcontentfromurl
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide My WP

Plugin:
Hide My WP
Plugin Slug:
hide_my_wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JNews – Frontend Submit

Plugin:
JNews – Frontend Submit
Plugin Slug:
jnews-frontend-submit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JNews – Pay Writer

Plugin:
JNews – Pay Writer
Plugin Slug:
jnews-pay-writer
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JNews – Video

Plugin:
JNews – Video
Plugin Slug:
jnews-video
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kunze Law

Plugin:
Kunze Law
Plugin Slug:
kunze-law
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LEAV Last Email Address Validator

Plugin:
LEAV Last Email Address Validator
Plugin Slug:
last-email-address-validator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LinkedIn SC

Plugin:
LinkedIn SC
Plugin Slug:
linkedin-sc
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

List Site Contributors

Plugin:
List Site Contributors
Plugin Slug:
list-site-contributors
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Makesweat

Plugin:
Makesweat
Plugin Slug:
makesweat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

News and Blog Designer Bundle

Plugin:
News and Blog Designer Bundle
Plugin Slug:
news-and-blog-designer-bundle
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PayHere Payment Gateway Plugin for WooCommerce

Plugin:
PayHere Payment Gateway Plugin for WooCommerce
Plugin Slug:
payhere-payment-gateway
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PDF Resume Parser

Plugin:
PDF Resume Parser
Plugin Slug:
pdf-resume-parser
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Perfit WooCommerce

Plugin:
Perfit WooCommerce
Plugin Slug:
perfit-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Real Post Slider Lite

Plugin:
Real Post Slider Lite
Plugin Slug:
real-post-slider-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Accordion Slider

Plugin:
Responsive Accordion Slider
Plugin Slug:
responsive-accordion-slider
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SearchWiz

Plugin:
SearchWiz
Plugin Slug:
searchwiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shabat Keeper

Plugin:
Shabat Keeper
Plugin Slug:
shabat-keeper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Short Link
Plugin Slug:
short-link
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sosh Share Buttons

Plugin:
Sosh Share Buttons
Plugin Slug:
sosh-share-buttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SpiceForms Form Builder

Plugin:
SpiceForms Form Builder
Plugin Slug:
spiceforms-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stopwords for comments

Plugin:
Stopwords for comments
Plugin Slug:
stopwords-for-comments
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Synergy Project Manager

Plugin Slug:
synergy-project-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Creator

Plugin:
Testimonials Creator
Plugin Slug:
testimonials-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

xPromoter

Plugin:
xPromoter
Plugin Slug:
top_bar_promoter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Viet contact

Plugin:
Viet contact
Plugin Slug:
viet-contact
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Frontend Manager – Ultimate

Plugin:
WooCommerce Frontend Manager – Ultimate
Plugin Slug:
wc-frontend-manager-ultimate
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WMF Mobile Redirector

Plugin:
WMF Mobile Redirector
Plugin Slug:
wmf-mobile-redirector
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Book Price

Plugin:
Woocommerce Book Price
Plugin Slug:
woo-book-price
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Integration Opvius AI for WooCommerce

Plugin:
Integration Opvius AI for WooCommerce
Plugin Slug:
woosa-ai-for-woocommerce
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Eli's WordCents adSense Widget with Analytics

Plugin:
Eli's WordCents adSense Widget with Analytics
Plugin Slug:
wordcents
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Workreap Core

Plugin:
Workreap Core
Plugin Slug:
workreap_core
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Allowed Hosts

Plugin:
WP Allowed Hosts
Plugin Slug:
wp-allow-hosts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Hello Bar

Plugin:
WP Hello Bar
Plugin Slug:
wp-hello-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:
WP Lead Capturing Pages
Plugin Slug:
wp-lead-capture
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPBlogSyn

Plugin:
WPBlogSyn
Plugin Slug:
wpblogsync
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPLMS

Plugin:
WPLMS
Plugin Slug:
wplms_plugin
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Breeze Cache

Plugin Slug:
breeze
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.22.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
2.0.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.16.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.11.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.11.0.

WooCommerce Square

Plugin Slug:
woocommerce-square
Installations
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.9.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.3.9.3.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.14.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.12.

WP Duplicate Page

Plugin Slug:
wp-duplicate-page
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.4.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.10.

Modular DS: Monitor, update, and backup multiple websites

Plugin Slug:
modular-connector
Installations
30,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.6.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.0.

Modular DS: Monitor, update, and backup multiple websites

Plugin Slug:
modular-connector
Installations
30,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.5.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.2.

Xpro Addons — 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons
Installations
30,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.4.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.20.
Plugin Slug:
final-tiles-grid-gallery-lite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.10.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.0.89
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.89.

AffiliateX – Amazon Affiliate Plugin

Plugin Slug:
affiliatex
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Demo Importer Plus

Plugin Slug:
demo-importer-plus
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.10.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.17.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.8.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.7.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
19.6.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 19.6.25.

Tickera – Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.6.3.

Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Plugin Slug:
wallet-system-for-woocommerce
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.
Plugin Slug:
ninja-gdpr-compliance
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

Quick Contact Form

Plugin Slug:
quick-contact-form
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.7.

Peach Payments Gateway

Plugin Slug:
wc-peach-payments-gateway
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.7.

Church Admin

Plugin Slug:
church-admin
Installations
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.0.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.29.

onepay Payment Gateway For WooCommerce

Plugin Slug:
onepay-payment-gateway-for-woocommerce
Installations
900+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Filr – Secure document library

Plugin Slug:
filr-protection
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.12.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.52.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.52.2.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.33.

g-FFL Checkout

Plugin Slug:
g-ffl-checkout
Installations
500+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.1.

User Registration Using Contact Form 7

Plugin Slug:
user-registration-using-contact-form-7
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.

RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress

Plugin Slug:
computer-repair-shop
Installations
400+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.1121
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1121.

Phrase TMS Integration for WordPress

Plugin Slug:
memsource-connector
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.6.

Thim Blocks

Plugin Slug:
thim-blocks
Installations
300+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

PAYGENT for WooCommerce

Plugin Slug:
woocommerce-for-paygent-payment-main
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Integrate Dynamics 365 CRM

Plugin Slug:
integrate-dynamics-365-crm
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.7.

CP Image Store with Slideshow

Plugin Slug:
cp-image-store
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

YouTube Feed Pro

Plugin:
YouTube Feed Pro
Plugin Slug:
youtube-feed-pro
Vulnerability:
Arbitrary File Download
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

WordPress Themes — 5 Patched / 38 Unpatched

Blogistic

Theme Slug:
blogistic
Downloads
6,185
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Blogzee

Theme:
Blogzee
Theme Slug:
blogzee
Downloads
6,598
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Solace

Theme:
Solace
Theme Slug:
solace
Downloads
45,016
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Anon

Theme:
Anon
Theme Slug:
anon2x
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anona

Theme:
Anona
Theme Slug:
anona
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anona

Theme:
Anona
Theme Slug:
anona
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anona

Theme:
Anona
Theme Slug:
anona
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Auto Repair

Theme:
Auto Repair
Theme Slug:
auto-repair
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AutoParts

Theme:
AutoParts
Theme Slug:
autoparts
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bajaar – Highly Customizable WooCommerce WordPress Theme

Theme:
Bajaar – Highly Customizable WooCommerce WordPress Theme
Theme Slug:
bajaar
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Barberry

Theme:
Barberry
Theme Slug:
barberry
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Brookside

Theme:
Brookside
Theme Slug:
brookside
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Consult Aid

Theme:
Consult Aid
Theme Slug:
consultaid
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Dreamer Blog

Theme:
Dreamer Blog
Theme Slug:
dreamer-blog
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Drone

Theme:
Drone
Theme Slug:
drone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Electron

Theme:
Electron
Theme Slug:
electron
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Hostme v2

Theme:
Hostme v2
Theme Slug:
hostmev2
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kids Heaven

Theme:
Kids Heaven
Theme Slug:
kids-world
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Melania

Theme:
Melania
Theme Slug:
melania
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Mella

Theme:
Mella
Theme Slug:
mella
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Miion

Theme:
Miion
Theme Slug:
miion
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Miion

Theme:
Miion
Theme Slug:
miion
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Myour

Theme:
Myour
Theme Slug:
myour
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

North

Theme:
North
Theme Slug:
north-wp
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

North

Theme:
North
Theme Slug:
north-wp
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OneLife

Theme:
OneLife
Theme Slug:
onelife
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Promo

Theme:
Promo
Theme Slug:
promo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

KenthaRadio

Theme:
KenthaRadio
Theme Slug:
qt-kentharadio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Reprizo

Theme:
Reprizo
Theme Slug:
reprizo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Restaurt

Theme:
Restaurt
Theme Slug:
restaurt
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Right Way

Theme:
Right Way
Theme Slug:
rightway
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Search & Go

Theme:
Search & Go
Theme Slug:
search-and-go
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Skillate

Theme:
Skillate
Theme Slug:
skillate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

TheNa

Theme:
TheNa
Theme Slug:
thena
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Vivagh

Theme:
Vivagh
Theme Slug:
vivagh
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Biagiotti

Theme:
Biagiotti
Theme Slug:
biagiotti
Vulnerability:
Local File Inclusion
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.

Kalium

Theme:
Kalium
Theme Slug:
kalium
Vulnerability:
Broken Access Control
Patched in Version:
3.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.30.

Powerlift

Theme:
Powerlift
Theme Slug:
powerlift
Vulnerability:
Local File Inclusion
Patched in Version:
3.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.1.

The Aisle

Theme:
The Aisle
Theme Slug:
theaisle
Vulnerability:
Local File Inclusion
Patched in Version:
2.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.1.

Werkstatt

Theme:
Werkstatt
Theme Slug:
werkstatt
Vulnerability:
Local File Inclusion
Patched in Version:
4.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security