In this report, 467 vulnerabilities have been publicly disclosed. Security patches for 386 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Currently, 81 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.
The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.
WordPress Plugins — 372 Patched / 76 Unpatched
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12159
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-13463
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15267
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-12803
SportsPress – Sports Club & League Manager
- Plugin Slug:
- sportspress
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-15368
AWCA – The Great Analytics Insights for Your eStore
- Plugin Slug:
- advance-wc-analytics
- Installations
- 3,000+
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68032
Advanced Country Blocker
- Plugin:
- Advanced Country Blocker
- Plugin Slug:
- advanced-country-blocker
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1675
Plugin BlueX for WooCommerce
- Plugin:
- Plugin BlueX for WooCommerce
- Plugin Slug:
- bluex-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68022
Cliengo – Chatbot
- Plugin:
- Cliengo – Chatbot
- Plugin Slug:
- cliengo
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69388
GA4WP – Analytics Dashboard for the Website
- Plugin Slug:
- ga-for-wp
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68028
Addonify – Compare Products For WooCommerce
- Plugin Slug:
- addonify-compare-products
- Installations
- 1,000+
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68023
Addonify Floating Cart For WooCommerce
- Plugin Slug:
- addonify-floating-cart
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68025
Addonify – WooCommerce Wishlist
- Plugin:
- Addonify – WooCommerce Wishlist
- Plugin Slug:
- addonify-wishlist
- Installations
- 1,000+
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68024
TopperPack – Complete Elementor Addons, Theme & CPT Builder
- Plugin Slug:
- topper-pack
- Installations
- 300+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68841
WP Duplicate – WordPress Migration Plugin
- Plugin Slug:
- local-sync
- Installations
- 200+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-1499
Contact Manager
- Plugin:
- Contact Manager
- Plugin Slug:
- contact-manager
- Installations
- 100+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68853
Court Reservation – Manage Your Court Bookings Online
- Plugin Slug:
- court-reservation
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68852
RVCFDI para Woocommerce
- Plugin:
- RVCFDI para Woocommerce
- Plugin Slug:
- rvcfdi-para-woocommerce
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69386
Simple Retail Menus
- Plugin:
- Simple Retail Menus
- Plugin Slug:
- simple-retail-menus
- Installations
- 90+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69387
iContact for Gravity Forms
- Plugin:
- iContact for Gravity Forms
- Plugin Slug:
- gravity-forms-icontact
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68863
Optimize More! – Images
- Plugin:
- Optimize More! – Images
- Plugin Slug:
- optimize-more-images
- Installations
- 80+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-67624
WPshop 2 – E-Commerce
- Plugin:
- WPshop 2 – E-Commerce
- Plugin Slug:
- wpshop
- Installations
- 70+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69383
All push notification for WP
- Plugin:
- All push notification for WP
- Plugin Slug:
- all-push-notification
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-0816
Bulk Edit Post Titles
- Plugin:
- Bulk Edit Post Titles
- Plugin Slug:
- bulk-edit-post-titles
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-0369
Buy one click WooCommerce
- Plugin:
- Buy one click WooCommerce
- Plugin Slug:
- buy-one-click-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-10853
Buy one click WooCommerce
- Plugin:
- Buy one click WooCommerce
- Plugin Slug:
- buy-one-click-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-10854
Catch Popup
- Plugin:
- Catch Popup
- Plugin Slug:
- catch-popup
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-11427
Chapa Payment Gateway Plugin for WooCommerce
- Plugin:
- Chapa Payment Gateway Plugin for WooCommerce
- Plugin Slug:
- chapa-payment-gateway-for-woocommerce
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15482
Code Explorer
- Plugin:
- Code Explorer
- Plugin Slug:
- code-explorer
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15487
CommentTweets
- Plugin:
- CommentTweets
- Plugin Slug:
- commenttweets
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2023-6845
Eleblog – Elementor Blog And Magazine Addons
- Plugin:
- Eleblog – Elementor Blog And Magazine Addons
- Plugin Slug:
- ele-blog
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69374
Elegant Addons for elementor
- Plugin:
- Elegant Addons for elementor
- Plugin Slug:
- elegant-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5092
Extended Random Number Generator
- Plugin:
- Extended Random Number Generator
- Plugin Slug:
- extended-random-number-generator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-0681
Font Farsi
- Plugin:
- Font Farsi
- Plugin Slug:
- font-farsi
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-2657
Fortis for WooCommerce
- Plugin:
- Fortis for WooCommerce
- Plugin Slug:
- fortis-for-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-0679
Image Hover Effects – Caption Hover with Carousel
- Plugin:
- Image Hover Effects – Caption Hover with Carousel
- Plugin Slug:
- image-hover-effects-with-carousel
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-5001
Infility Global
- Plugin:
- Infility Global
- Plugin Slug:
- infility-global
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-15268
Login Logout Register Menu
- Plugin:
- Login Logout Register Menu
- Plugin Slug:
- login-logout-register-menu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3726
SEO Flow by LupsOnline
- Plugin:
- SEO Flow by LupsOnline
- Plugin Slug:
- lupsonline-link-netwerk
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-15285
Magic Import Document Extractor
- Plugin:
- Magic Import Document Extractor
- Plugin Slug:
- magic-import-document-extractor
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15508
Magic Import Document Extractor
- Plugin:
- Magic Import Document Extractor
- Plugin Slug:
- magic-import-document-extractor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15507
Newsletter Popup
- Plugin:
- Newsletter Popup
- Plugin Slug:
- newsletter-popup
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-3641
Okay Toolkit
- Plugin:
- Okay Toolkit
- Plugin Slug:
- okay-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68851
OMIGO
- Plugin:
- OMIGO
- Plugin Slug:
- omigo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1573
Product Filter for WooCommerce
- Plugin:
- Product Filter for WooCommerce
- Plugin Slug:
- prdctfltr
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69378
Redirects
- Plugin:
- Redirects
- Plugin Slug:
- redirects
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-1566
SIBS woocommerce payment gateway
- Plugin:
- SIBS woocommerce payment gateway
- Plugin Slug:
- sibs-woocommerce
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-1370
Simple Bible Verse via Shortcode
- Plugin:
- Simple Bible Verse via Shortcode
- Plugin Slug:
- simple-bible-verse-via-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1570
Smart PopUp Blaster
- Plugin:
- Smart PopUp Blaster
- Plugin Slug:
- smart-popup-blaster
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12458
SP Project & Document Manager
- Plugin:
- SP Project & Document Manager
- Plugin Slug:
- sp-client-document-manager
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-3749
Store Locator
- Plugin:
- Store Locator
- Plugin Slug:
- store-locator
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-12571
SVS Pricing Tables
- Plugin:
- SVS Pricing Tables
- Plugin Slug:
- svs-pricing-tables
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-2960
Portfolio Builder
- Plugin:
- Portfolio Builder
- Plugin Slug:
- swp-portfolio
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69375
Tabs Maker
- Plugin:
- Tabs Maker
- Plugin Slug:
- tabs-maker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-11865
Testimonials Widget
- Plugin:
- Testimonials Widget
- Plugin Slug:
- testimonials-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-4705
The Bucketlister
- Plugin:
- The Bucketlister
- Plugin Slug:
- the-bucketlister
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15476
The Bucketlister
- Plugin:
- The Bucketlister
- Plugin Slug:
- the-bucketlister
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-15477
Themesflat Elementor
- Plugin:
- Themesflat Elementor
- Plugin Slug:
- themesflat-elementor
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-69382
Timeline Event History
- Plugin:
- Timeline Event History
- Plugin Slug:
- timeline-event-history
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69384
TITLE ANIMATOR
- Plugin:
- TITLE ANIMATOR
- Plugin Slug:
- title-animator
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1082
WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto
- Plugin:
- WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto
- Plugin Slug:
- tripetto
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-10260
UserPlus
- Plugin:
- UserPlus
- Plugin Slug:
- userplus
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-9520
Video Onclick
- Plugin:
- Video Onclick
- Plugin Slug:
- video-onclick
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1608
WebPurify Profanity Filter
- Plugin:
- WebPurify Profanity Filter
- Plugin Slug:
- webpurifytextreplace
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-0572
Wikiloops Track Player
- Plugin:
- Wikiloops Track Player
- Plugin Slug:
- wikiloops-track-player
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1611
Wonka Slide
- Plugin:
- Wonka Slide
- Plugin Slug:
- wonka-slide
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1613
Woo File Dropzone
- Plugin:
- Woo File Dropzone
- Plugin Slug:
- woo-file-dropzone
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68862
Xendit Payment
- Plugin:
- Xendit Payment
- Plugin Slug:
- woo-xendit-virtual-accounts
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-14461
WooCommerce Bulk Product Editor
- Plugin:
- WooCommerce Bulk Product Editor
- Plugin Slug:
- woocommerce-quick-product-editor
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69381
MyRewards
- Plugin:
- MyRewards
- Plugin Slug:
- woorewards
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15260
WP Content Permission
- Plugin:
- WP Content Permission
- Plugin Slug:
- wp-content-permission
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-0743
WP-Revive Adserver
- Plugin:
- WP-Revive Adserver
- Plugin Slug:
- wp-revive-adserver
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12461
Upload Files Anywhere
- Plugin:
- Upload Files Anywhere
- Plugin Slug:
- wp-upload-files-anywhere
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69380
Upload Files Anywhere
- Plugin:
- Upload Files Anywhere
- Plugin Slug:
- wp-upload-files-anywhere
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69379
User Extra Fields
- Plugin:
- User Extra Fields
- Plugin Slug:
- wp-user-extra-fields
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69377
User Extra Fields
- Plugin:
- User Extra Fields
- Plugin Slug:
- wp-user-extra-fields
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69376
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
- Plugin Slug:
- wordpress-seo
- Installations
- 10,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 26.9
- Severity Score:
- Medium
- CVE:
- 2026-1293
Essential Addons for Elementor – Popular Elementor Templates & Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.12
- Severity Score:
- Medium
- CVE:
- 2024-2650
Essential Addons for Elementor – Popular Elementor Templates & Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.16
- Severity Score:
- Medium
- CVE:
- 2024-3728
Essential Addons for Elementor – Popular Elementor Templates & Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.20
- Severity Score:
- Medium
- CVE:
- 2024-4448
Essential Addons for Elementor – Popular Elementor Templates & Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.9.20
- Severity Score:
- Medium
- CVE:
- 2024-4449
Essential Addons for Elementor – Popular Elementor Templates & Widgets
- Plugin Slug:
- essential-addons-for-elementor-lite
- Installations
- 2,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.0.4
- Severity Score:
- Medium
- CVE:
- 2024-8742
Code Snippets
- Plugin:
- Code Snippets
- Plugin Slug:
- code-snippets
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.9.5
- Severity Score:
- Medium
- CVE:
- 2026-1785
Spectra Gutenberg Blocks – Website Builder for the Block Editor
- Plugin Slug:
- ultimate-addons-for-gutenberg
- Installations
- 1,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.19.18
- Severity Score:
- Medium
- CVE:
- 2026-0950
Spectra Gutenberg Blocks – Website Builder for the Block Editor
- Plugin Slug:
- ultimate-addons-for-gutenberg
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.12.9
- Severity Score:
- Medium
- CVE:
- 2024-1815
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.29
- Severity Score:
- Medium
- CVE:
- 2024-3647
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.32
- Severity Score:
- Medium
- CVE:
- 2024-4376
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.10.32
- Severity Score:
- Medium
- CVE:
- 2024-4379
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Plugin Slug:
- fluentform
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.20
- Severity Score:
- Medium
- CVE:
- 2024-6518
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Plugin Slug:
- fluentform
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.20
- Severity Score:
- Medium
- CVE:
- 2024-6521
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.88
- Severity Score:
- Medium
- CVE:
- 2024-0516
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.88
- Severity Score:
- Medium
- CVE:
- 2024-0515
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.88
- Severity Score:
- Medium
- CVE:
- 2024-0514
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.3.88
- Severity Score:
- Medium
- CVE:
- 2024-0513
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.972
- Severity Score:
- Medium
- CVE:
- 2024-2798
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.972
- Severity Score:
- Medium
- CVE:
- 2024-2799
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.972
- Severity Score:
- Medium
- CVE:
- 2024-3889
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.976
- Severity Score:
- Medium
- CVE:
- 2024-4087
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1002
- Severity Score:
- Medium
- CVE:
- 2024-9059
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1002
- Severity Score:
- Medium
- CVE:
- 2024-9668
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
- Plugin:
- Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
- Plugin Slug:
- easy-wp-smtp
- Installations
- 500,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.3.1
- Severity Score:
- Low
- CVE:
- 2024-3073
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Plugin Slug:
- kadence-blocks
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.38
- Severity Score:
- Medium
- CVE:
- 2024-4208
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Plugin Slug:
- kadence-blocks
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.37
- Severity Score:
- Medium
- CVE:
- 2024-4209
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.20.8
- Severity Score:
- Medium
- CVE:
- 2026-1210
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.4
- Severity Score:
- Medium
- CVE:
- 2024-1498
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
- 2024-2786
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
- 2024-2787
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
- 2024-2788
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
- 2024-2789
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.5
- Severity Score:
- Medium
- CVE:
- 2024-3724
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.8
- Severity Score:
- Medium
- CVE:
- 2024-4391
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.11.0
- Severity Score:
- Medium
- CVE:
- 2024-5041
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.10.9
- Severity Score:
- Medium
- CVE:
- 2024-5088
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.5
- Severity Score:
- Medium
- CVE:
- 2024-0334
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.5
- Severity Score:
- Medium
- CVE:
- 2024-3161
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
- Plugin Slug:
- jeg-elementor-kit
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.4
- Severity Score:
- Medium
- CVE:
- 2024-3162
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
- Plugin Slug:
- post-smtp
- Installations
- 300,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.8.7
- Severity Score:
- High
- CVE:
- 2023-6620
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
- Plugin Slug:
- shortpixel-image-optimiser
- Installations
- 300,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 6.4.3
- Severity Score:
- Medium
- CVE:
- 2026-1246
Unlimited Elements For Elementor
- Plugin:
- Unlimited Elements For Elementor
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.2
- Severity Score:
- Medium
- CVE:
- 2025-14274
Unlimited Elements For Elementor
- Plugin:
- Unlimited Elements For Elementor
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.113
- Severity Score:
- Medium
- CVE:
- 2024-6170
SEOPress – On-site SEO & Analytics
- Plugin Slug:
- wp-seopress
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6
- Severity Score:
- Medium
- CVE:
- 2024-1134
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
- Plugin Slug:
- essential-blocks
- Installations
- 200,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.4.3
- Severity Score:
- High
- CVE:
- 2023-6623
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
- Plugin Slug:
- essential-blocks
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5.4
- Severity Score:
- Medium
- CVE:
- 2024-2255
FileOrganizer – WordPress File Manager
- Plugin Slug:
- fileorganizer
- Installations
- 200,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.0.8
- Severity Score:
- High
- CVE:
- 2024-5599
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
- Plugin Slug:
- 3d-flipbook-dflip-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.27
- Severity Score:
- Medium
- CVE:
- 2024-0895
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.2
- Severity Score:
- Medium
- CVE:
- 2024-10310
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.1
- Severity Score:
- Medium
- CVE:
- 2024-1426
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.1
- Severity Score:
- Medium
- CVE:
- 2024-1429
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.12
- Severity Score:
- Medium
- CVE:
- 2024-5554
Element Pack Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.10.3
- Severity Score:
- Medium
- CVE:
- 2024-9867
Prime Slider – Addons for Elementor
- Plugin Slug:
- bdthemes-prime-slider-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.14.2
- Severity Score:
- Medium
- CVE:
- 2024-3997
Beaver Builder Page Builder – Drag and Drop Website Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.4.3
- Severity Score:
- Medium
- CVE:
- 2024-0896
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
- Plugin Slug:
- embedpress
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9.11
- Severity Score:
- Medium
- CVE:
- 2024-1565
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
- Plugin Slug:
- embedpress
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9.13
- Severity Score:
- Medium
- CVE:
- 2024-2688
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
- Plugin Slug:
- embedpress
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9.15
- Severity Score:
- Medium
- CVE:
- 2024-3245
Gallery by FooGallery
- Plugin:
- Gallery by FooGallery
- Plugin Slug:
- foogallery
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.15
- Severity Score:
- Medium
- CVE:
- 2024-2081
GiveWP – Donation Plugin and Fundraising Platform
- Plugin Slug:
- give
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.14.2
- Severity Score:
- Critical
- CVE:
- 2024-5932
LatePoint – Calendar Booking Plugin for Appointments and Events
- Plugin Slug:
- latepoint
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.2.6
- Severity Score:
- High
- CVE:
- 2026-0617
Menu Icons by ThemeIsle
- Plugin:
- Menu Icons by ThemeIsle
- Plugin Slug:
- menu-icons
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.13.21
- Severity Score:
- Medium
- CVE:
- 2026-1755
Modula Image Gallery – Photo Grid & Video Gallery
- Plugin Slug:
- modula-best-grid-gallery
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.13.5
- Severity Score:
- Medium
- CVE:
- 2026-23976
WebSub (FKA. PubSubHubbub)
- Plugin:
- WebSub (FKA. PubSubHubbub)
- Plugin Slug:
- pubsubhubbub
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
- 2024-0688
Relevanssi – A Better Search
- Plugin:
- Relevanssi – A Better Search
- Plugin Slug:
- relevanssi
- Installations
- 100,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 4.22.0
- Severity Score:
- Medium
- CVE:
- 2023-7199
Relevanssi – A Better Search
- Plugin:
- Relevanssi – A Better Search
- Plugin Slug:
- relevanssi
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.22.1
- Severity Score:
- Medium
- CVE:
- 2024-1380
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
- Plugin Slug:
- robin-image-optimizer
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.3
- Severity Score:
- Medium
- CVE:
- 2026-1319
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-0445
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 5.4.2
- Severity Score:
- High
- CVE:
- 2024-2210
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.5
- Severity Score:
- Medium
- CVE:
- 2024-2784
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-2785
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3197
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3199
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.3
- Severity Score:
- Medium
- CVE:
- 2024-4484
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.3
- Severity Score:
- Medium
- CVE:
- 2024-4485
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.3
- Severity Score:
- Medium
- CVE:
- 2024-6575
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.6.3
- Severity Score:
- Medium
- CVE:
- 2024-5583
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
- Plugin Slug:
- themeisle-companion
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.10.31
- Severity Score:
- Medium
- CVE:
- 2024-1497
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.9.6
- Severity Score:
- High
- CVE:
- 2026-1375
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.9.6
- Severity Score:
- Medium
- CVE:
- 2026-1371
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
- Plugin Slug:
- wp-all-import
- Installations
- 100,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 3.7.3
- Severity Score:
- Critical
- CVE:
- 2023-7082
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13
- Severity Score:
- Medium
- CVE:
- 2024-1391
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13
- Severity Score:
- Medium
- CVE:
- 2024-1392
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.3
- Severity Score:
- Medium
- CVE:
- 2024-2091
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.4
- Severity Score:
- Medium
- CVE:
- 2024-2092
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.6
- Severity Score:
- Medium
- CVE:
- 2024-4570
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.6
- Severity Score:
- Medium
- CVE:
- 2024-4401
Addon Elements for Elementor (formerly Elementor Addon Elements)
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.13.7
- Severity Score:
- Medium
- CVE:
- 2024-7122
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.17.3
- Severity Score:
- Medium
- CVE:
- 2024-12588
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.15.8
- Severity Score:
- Medium
- CVE:
- 2024-1348
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.15.8
- Severity Score:
- Medium
- CVE:
- 2024-1357
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.15.8
- Severity Score:
- Medium
- CVE:
- 2024-1396
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.15.8
- Severity Score:
- Medium
- CVE:
- 2024-1533
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.15.8
- Severity Score:
- Medium
- CVE:
- 2024-3341
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.17.1
- Severity Score:
- Medium
- CVE:
- 2024-9545
Colibri Page Builder
- Plugin:
- Colibri Page Builder
- Plugin Slug:
- colibri-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.274
- Severity Score:
- Medium
- CVE:
- 2024-3337
Colibri Page Builder
- Plugin:
- Colibri Page Builder
- Plugin Slug:
- colibri-page-builder
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.277
- Severity Score:
- Medium
- CVE:
- 2024-4451
ShopLentor – All-in-One WooCommerce Builder Solution for Elementor & Gutenberg
- Plugin Slug:
- woolentor-addons
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.2
- Severity Score:
- Medium
- CVE:
- 2024-1057
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.7
- Severity Score:
- Medium
- CVE:
- 2024-2084
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.0
- Severity Score:
- Medium
- CVE:
- 2024-3308
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.1
- Severity Score:
- Medium
- CVE:
- 2024-3989
HT Mega – Absolute Addons For Elementor
- Plugin Slug:
- ht-mega-for-elementor
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.6
- Severity Score:
- Medium
- CVE:
- 2024-5173
Import and export users and customers
- Plugin Slug:
- import-users-from-csv-with-meta
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.26.7
- Severity Score:
- Medium
- CVE:
- 2024-4734
Advanced Contact form 7 DB
- Plugin:
- Advanced Contact form 7 DB
- Plugin Slug:
- advanced-cf7-db
- Installations
- 70,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.0.3
- Severity Score:
- Medium
- CVE:
- 2024-3723
Brizy – Page Builder
- Plugin:
- Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.44
- Severity Score:
- Medium
- CVE:
- 2024-1164
Brizy – Page Builder
- Plugin:
- Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.44
- Severity Score:
- Medium
- CVE:
- 2024-1161
Brizy – Page Builder
- Plugin:
- Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.41
- Severity Score:
- Medium
- CVE:
- 2024-1293
Brizy – Page Builder
- Plugin:
- Brizy – Page Builder
- Plugin Slug:
- brizy
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.42
- Severity Score:
- Medium
- CVE:
- 2024-1940
WP ULike – Like & Dislike Buttons for Engagement and Feedback
- Plugin Slug:
- wp-ulike
- Installations
- 70,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 5.0.0
- Severity Score:
- Medium
- CVE:
- 2026-0909
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
- Plugin Slug:
- email-subscribers
- Installations
- 60,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.7.18
- Severity Score:
- Medium
- CVE:
- 2024-3626
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.9.3
- Severity Score:
- Medium
- CVE:
- 2024-2503
Exclusive Addons for Elementor
- Plugin:
- Exclusive Addons for Elementor
- Plugin Slug:
- exclusive-addons-for-elementor
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.9.5
- Severity Score:
- Medium
- CVE:
- 2024-3985
Greenshift – animation and page builder blocks
- Plugin Slug:
- greenshift-animation-and-page-builder-blocks
- Installations
- 60,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 12.6
- Severity Score:
- Medium
- CVE:
- 2026-1927
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
- Plugin Slug:
- post-and-page-builder
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.26.7
- Severity Score:
- Medium
- CVE:
- 2024-6848
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
- Plugin Slug:
- ays-popup-box
- Installations
- 50,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.1.2
- Severity Score:
- Medium
- CVE:
- 2026-1165
Bold Page Builder
- Plugin:
- Bold Page Builder
- Plugin Slug:
- bold-page-builder
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.9
- Severity Score:
- Medium
- CVE:
- 2024-3266
Getwid – Gutenberg Blocks
- Plugin:
- Getwid – Gutenberg Blocks
- Plugin Slug:
- getwid
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.11
- Severity Score:
- Medium
- CVE:
- 2024-6489
?????? ????? ??????? Persian WooCommerce SMS
- Plugin Slug:
- persian-woocommerce-sms
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.0.6
- Severity Score:
- High
- CVE:
- 2024-10046
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin:
- Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin Slug:
- popup-builder-block
- Installations
- 50,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2025-14895
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin:
- Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin Slug:
- popup-builder-block
- Installations
- 50,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.1
- Severity Score:
- High
- CVE:
- 2025-13192
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
- Plugin Slug:
- profile-builder
- Installations
- 50,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.15.2
- Severity Score:
- Critical
- CVE:
- 2025-15030
Sina Extension for Elementor
- Plugin:
- Sina Extension for Elementor
- Plugin Slug:
- sina-extension-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.4
- Severity Score:
- Medium
- CVE:
- 2024-4333
Themesflat Addons For Elementor
- Plugin:
- Themesflat Addons For Elementor
- Plugin Slug:
- themesflat-addons-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.3
- Severity Score:
- Medium
- CVE:
- 2024-2922
Themesflat Addons For Elementor
- Plugin:
- Themesflat Addons For Elementor
- Plugin Slug:
- themesflat-addons-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.3
- Severity Score:
- Medium
- CVE:
- 2024-4458
Themesflat Addons For Elementor
- Plugin:
- Themesflat Addons For Elementor
- Plugin Slug:
- themesflat-addons-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.3
- Severity Score:
- Medium
- CVE:
- 2024-4459
Themesflat Addons For Elementor
- Plugin:
- Themesflat Addons For Elementor
- Plugin Slug:
- themesflat-addons-for-elementor
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.3
- Severity Score:
- Medium
- CVE:
- 2024-4212
Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor
- Plugin Slug:
- ultimate-blocks
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
- 2024-4268
WP Recipe Maker
- Plugin:
- WP Recipe Maker
- Plugin Slug:
- wp-recipe-maker
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.1.1
- Severity Score:
- Medium
- CVE:
- 2024-0383
WP Recipe Maker
- Plugin:
- WP Recipe Maker
- Plugin Slug:
- wp-recipe-maker
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.1.1
- Severity Score:
- Medium
- CVE:
- 2024-0381
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.6
- Severity Score:
- Medium
- CVE:
- 2024-1458
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.6
- Severity Score:
- Medium
- CVE:
- 2024-1461
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.6
- Severity Score:
- Medium
- CVE:
- 2024-1464
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.6
- Severity Score:
- Medium
- CVE:
- 2024-1465
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.3.6
- Severity Score:
- Medium
- CVE:
- 2024-1466
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.4
- Severity Score:
- Medium
- CVE:
- 2024-2926
Livemesh Addons by Elementor
- Plugin:
- Livemesh Addons by Elementor
- Plugin Slug:
- addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.4
- Severity Score:
- Medium
- CVE:
- 2024-3639
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
- Plugin Slug:
- contact-form-plugin
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.9
- Severity Score:
- High
- CVE:
- 2024-2200
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
- Plugin Slug:
- easy-digital-downloads
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.3
- Severity Score:
- Medium
- CVE:
- 2024-6691
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.36
- Severity Score:
- High
- CVE:
- 2026-1058
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.36
- Severity Score:
- High
- CVE:
- 2026-1065
SEO Plugin by Squirrly SEO
- Plugin:
- SEO Plugin by Squirrly SEO
- Plugin Slug:
- squirrly-seo
- Installations
- 40,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 12.3.20
- Severity Score:
- High
- CVE:
- 2024-6497
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
- Plugin Slug:
- ultimate-post
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.1.3
- Severity Score:
- High
- CVE:
- 2024-5326
ACF Quick Edit Fields
- Plugin:
- ACF Quick Edit Fields
- Plugin Slug:
- acf-quickedit-fields
- Installations
- 30,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2023-7286
Piotnet Addons For Elementor
- Plugin:
- Piotnet Addons For Elementor
- Plugin Slug:
- piotnet-addons-for-elementor
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.29
- Severity Score:
- Medium
- CVE:
- 2024-4262
Post Grid
Post Grid
Hubbub Lite – Fast, free social sharing and follow buttons
- Plugin Slug:
- social-pug
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.32.0
- Severity Score:
- Medium
- CVE:
- 2023-7154
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin
- Plugin Slug:
- thirstyaffiliates
- Installations
- 30,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.11.10
- Severity Score:
- Medium
- CVE:
- 2026-25024
Tutor LMS Elementor Addons
- Plugin:
- Tutor LMS Elementor Addons
- Plugin Slug:
- tutor-lms-elementor-addons
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.6
- Severity Score:
- Medium
- CVE:
- 2024-10897
Tutor LMS Elementor Addons
- Plugin:
- Tutor LMS Elementor Addons
- Plugin Slug:
- tutor-lms-elementor-addons
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.5
- Severity Score:
- Medium
- CVE:
- 2024-5576
Print Invoice & Delivery Notes for WooCommerce
- Plugin Slug:
- woocommerce-delivery-notes
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.9.0
- Severity Score:
- Medium
- CVE:
- 2026-24946
All-in-One Video Gallery
- Plugin:
- All-in-One Video Gallery
- Plugin Slug:
- all-in-one-video-gallery
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.6.4
- Severity Score:
- Critical
- CVE:
- 2025-12957
Subscribe2 – Form, Email Subscribers & Newsletters
- Plugin Slug:
- subscribe2
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 10.45
- Severity Score:
- Medium
- CVE:
- 2026-24944
The Events Calendar Shortcode & Block
- Plugin Slug:
- the-events-calendar-shortcode
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.3
- Severity Score:
- Medium
- CVE:
- 2026-1922
The Events Calendar Shortcode & Block
- Plugin Slug:
- the-events-calendar-shortcode
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.2
- Severity Score:
- Medium
- CVE:
- 2026-24988
Ultimate Addons for Beaver Builder – Lite
- Plugin Slug:
- ultimate-addons-for-beaver-builder-lite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.8
- Severity Score:
- Medium
- CVE:
- 2024-2140
Ultimate Addons for Beaver Builder – Lite
- Plugin Slug:
- ultimate-addons-for-beaver-builder-lite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.8
- Severity Score:
- Medium
- CVE:
- 2024-2142
Ultimate Addons for Beaver Builder – Lite
- Plugin Slug:
- ultimate-addons-for-beaver-builder-lite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.8
- Severity Score:
- Medium
- CVE:
- 2024-2143
Ultimate Addons for Beaver Builder – Lite
- Plugin Slug:
- ultimate-addons-for-beaver-builder-lite
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.8
- Severity Score:
- Medium
- CVE:
- 2024-2144
WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
- Plugin:
- WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible
- Plugin Slug:
- wc-frontend-manager
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.7.25
- Severity Score:
- High
- CVE:
- 2026-0845
WCFM Marketplace – Multivendor Marketplace for WooCommerce
- Plugin Slug:
- wc-multivendor-marketplace
- Installations
- 20,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.7.1
- Severity Score:
- Medium
- CVE:
- 2026-1722
Frontend Admin by DynamiApps
- Plugin:
- Frontend Admin by DynamiApps
- Plugin Slug:
- acf-frontend-form-element
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.25.1
- Severity Score:
- High
- CVE:
- 2024-11720
Frontend Admin by DynamiApps
- Plugin:
- Frontend Admin by DynamiApps
- Plugin Slug:
- acf-frontend-form-element
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.25.1
- Severity Score:
- High
- CVE:
- 2024-11721
BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor
- Plugin Slug:
- blockspare
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.5
- Severity Score:
- Medium
- CVE:
- 2024-8325
Content Blocks (Custom Post Widget)
- Plugin Slug:
- custom-post-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.1
- Severity Score:
- Medium
- CVE:
- 2024-3565
WP Customer Area
- Plugin:
- WP Customer Area
- Plugin Slug:
- customer-area
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.2.1
- Severity Score:
- Medium
- CVE:
- 2023-6741
Essential Widgets
- Plugin:
- Essential Widgets
- Plugin Slug:
- essential-widgets
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.1
- Severity Score:
- Medium
- CVE:
- 2026-0867
LA-Studio Element Kit for Elementor
- Plugin Slug:
- lastudio-element-kit
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.9
- Severity Score:
- High
- CVE:
- 2024-5349
Child Theme Creator by Orbisius
- Plugin:
- Child Theme Creator by Orbisius
- Plugin Slug:
- orbisius-child-theme-creator
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.6
- Severity Score:
- Medium
- CVE:
- 2024-12263
OSM – OpenStreetMap
- Plugin:
- OSM – OpenStreetMap
- Plugin Slug:
- osm
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.0.4
- Severity Score:
- Medium
- CVE:
- 2024-3603
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.11.2
- Severity Score:
- Medium
- CVE:
- 2024-1389
SupportCandy – Helpdesk & Customer Support Ticket System
- Plugin Slug:
- supportcandy
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.4.5
- Severity Score:
- High
- CVE:
- 2026-0683
Testimonial Carousel For Elementor
- Plugin Slug:
- testimonials-carousel-elementor
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.2.0
- Severity Score:
- Medium
- CVE:
- 2024-4698
Ultimate Maps by Supsystic
- Plugin:
- Ultimate Maps by Supsystic
- Plugin Slug:
- ultimate-maps-by-supsystic
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.16
- Severity Score:
- Medium
- CVE:
- 2023-6732
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace
- Plugin Slug:
- wc-multivendor-membership
- Installations
- 10,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.11.9
- Severity Score:
- Medium
- CVE:
- 2025-15147
Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered)
- Plugin:
- Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered)
- Plugin Slug:
- wp-event-solution
- Installations
- 10,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 4.0.9
- Severity Score:
- High
- CVE:
- 2024-7149
Ultimate Coming Soon & Maintenance
- Plugin Slug:
- ultimate-coming-soon
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.0
- Severity Score:
- Medium
- CVE:
- 2024-9705
Ultimate Coming Soon & Maintenance
- Plugin Slug:
- ultimate-coming-soon
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.0
- Severity Score:
- Medium
- CVE:
- 2024-9706
GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync)
- Plugin Slug:
- gsheetconnector-wpforms
- Installations
- 8,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 4.0.2
- Severity Score:
- Critical
- CVE:
- 2025-67979
NEX-Forms – Ultimate Forms Plugin for WordPress
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.1.8
- Severity Score:
- High
- CVE:
- 2025-69326
NEX-Forms – Ultimate Forms Plugin for WordPress
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.1.8
- Severity Score:
- High
- CVE:
- 2025-69324
NEX-Forms – Ultimate Forms Plugin for WordPress
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.5.7
- Severity Score:
- Medium
- CVE:
- 2024-0907
NEX-Forms – Ultimate Forms Plugin for WordPress
- Plugin Slug:
- nex-forms-express-wp-form-builder
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.5.7
- Severity Score:
- Medium
- CVE:
- 2024-1129
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.5
- Severity Score:
- High
- CVE:
- 2026-24941
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.3
- Severity Score:
- High
- CVE:
- 2024-11710
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.3
- Severity Score:
- Critical
- CVE:
- 2024-11711
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.3
- Severity Score:
- Medium
- CVE:
- 2024-11712
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.3
- Severity Score:
- High
- CVE:
- 2024-11713
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.2.3
- Severity Score:
- High
- CVE:
- 2024-11714
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website
- Plugin Slug:
- wp-job-portal
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.3
- Severity Score:
- Medium
- CVE:
- 2024-11715
Awesome Support – WordPress HelpDesk & Support Plugin
- Plugin Slug:
- awesome-support
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.1.8
- Severity Score:
- Medium
- CVE:
- 2024-0596
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.4
- Severity Score:
- Medium
- CVE:
- 2024-1125
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.2
- Severity Score:
- Medium
- CVE:
- 2024-1127
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.4.3
- Severity Score:
- Medium
- CVE:
- 2024-1321
LottieFiles
- Plugin:
- LottieFiles
- Plugin Slug:
- lottiefiles
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.1.0
- Severity Score:
- High
- CVE:
- 2025-68043
OAuth Single Sign On – SSO (OAuth Client)
- Plugin Slug:
- miniorange-login-with-eve-online-google-facebook
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.26.15
- Severity Score:
- Medium
- CVE:
- 2025-10753
Schema App Structured Data
- Plugin:
- Schema App Structured Data
- Plugin Slug:
- schema-app-structured-data-for-schemaorg
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-0893
Schema App Structured Data
- Plugin:
- Schema App Structured Data
- Plugin Slug:
- schema-app-structured-data-for-schemaorg
- Installations
- 7,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.5
- Severity Score:
- High
- CVE:
- 2024-11279
YayCurrency – WooCommerce Multi-Currency Switcher
- Plugin Slug:
- yaycurrency
- Installations
- 7,000+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 3.3.1
- Severity Score:
- High
- CVE:
- 2025-67994
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
- Plugin Slug:
- chatbot
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.6
- Severity Score:
- Medium
- CVE:
- 2024-0453
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
- Plugin Slug:
- chatbot
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.3.6
- Severity Score:
- Medium
- CVE:
- 2024-0451
ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support
- Plugin Slug:
- erp
- Installations
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.13.1
- Severity Score:
- High
- CVE:
- 2024-0913
Export Media URLs
- Plugin:
- Export Media URLs
- Plugin Slug:
- export-media-urls
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3
- Severity Score:
- High
- CVE:
- 2025-68037
Mail Mint – Newsletters, Email Marketing, Automation, WooCommerce Emails, Post Notification, and more
- Plugin Slug:
- mail-mint
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.19.3
- Severity Score:
- High
- CVE:
- 2026-1447
ProfileGrid – User Profiles, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 6,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 5.9.7.3
- Severity Score:
- Medium
- CVE:
- 2026-1271
ProfileGrid – User Profiles, Groups and Communities
- Plugin Slug:
- profilegrid-user-profiles-groups-and-communities
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.9.7.3
- Severity Score:
- Medium
- CVE:
- 2025-13416
Contact Form 7 Connector
- Plugin:
- Contact Form 7 Connector
- Plugin Slug:
- ari-cf7-connector
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.3
- Severity Score:
- High
- CVE:
- 2024-0239
easy.jobs – AI powered Job Listing, Job Board, Career Page, Recruitment & Hiring Solution
- Plugin Slug:
- easyjobs
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.7
- Severity Score:
- Medium
- CVE:
- 2023-6843
Shortcodes for Elementor
- Plugin:
- Shortcodes for Elementor
- Plugin Slug:
- shortcode-elementor
- Installations
- 5,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.0.5
- Severity Score:
- Medium
- CVE:
- 2024-10690
Simple File List
- Plugin:
- Simple File List
- Plugin Slug:
- simple-file-list
- Installations
- 5,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 6.1.16
- Severity Score:
- Medium
- CVE:
- 2026-24953
Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor
- Plugin Slug:
- ultimate-store-kit
- Installations
- 5,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.0.0
- Severity Score:
- Critical
- CVE:
- 2024-5335
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2024-12059
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.2
- Severity Score:
- Medium
- CVE:
- 2026-25028
HelloAsso
Snippet Shortcodes
- Plugin:
- Snippet Shortcodes
- Plugin Slug:
- shortcode-variables
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.1.7
- Severity Score:
- Medium
- CVE:
- 2024-12018
Payment Button for PayPal
- Plugin:
- Payment Button for PayPal
- Plugin Slug:
- wp-paypal
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.3.42
- Severity Score:
- Medium
- CVE:
- 2025-14463
WPZOOM Addons for Beaver Builder
- Plugin:
- WPZOOM Addons for Beaver Builder
- Plugin Slug:
- wpzoom-addons-for-beaver-builder
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-2181
WPZOOM Addons for Beaver Builder
- Plugin:
- WPZOOM Addons for Beaver Builder
- Plugin Slug:
- wpzoom-addons-for-beaver-builder
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-2185
WPZOOM Addons for Beaver Builder
- Plugin:
- WPZOOM Addons for Beaver Builder
- Plugin Slug:
- wpzoom-addons-for-beaver-builder
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-2186
WPZOOM Addons for Beaver Builder
- Plugin:
- WPZOOM Addons for Beaver Builder
- Plugin Slug:
- wpzoom-addons-for-beaver-builder
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2024-2187
Classic Addons – WPBakery Page Builder
- Plugin Slug:
- classic-addons-wpbakery-page-builder-addons
- Installations
- 3,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.1
- Severity Score:
- High
- CVE:
- 2024-11952
Product Enquiry for WooCommerce
- Plugin:
- Product Enquiry for WooCommerce
- Plugin Slug:
- gm-woocommerce-quote-popup
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1
- Severity Score:
- Medium
- CVE:
- 2023-6626
Salon Booking System – Free Version
- Plugin Slug:
- salon-booking-system
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.6.3
- Severity Score:
- High
- CVE:
- 2024-2102
Tickera – Sell Tickets & Manage Events
- Plugin Slug:
- tickera-event-ticketing-system
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.5.4.9
- Severity Score:
- Medium
- CVE:
- 2024-12578
Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines)
- Plugin Slug:
- timeline-block-block
- Installations
- 3,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.3.4
- Severity Score:
- Medium
- CVE:
- 2026-1228
WP-WebAuthn
- Plugin:
- WP-WebAuthn
- Plugin Slug:
- wp-webauthn
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.4
- Severity Score:
- Medium
- CVE:
- 2024-9023
WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More
- Plugin:
- WPB Addons for Elementor – News Ticker, Timeline, Team, Services, Testimonials, and Much More
- Plugin Slug:
- wpb-elementor-addons
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2
- Severity Score:
- Medium
- CVE:
- 2024-3063
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
- Plugin:
- Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
- Plugin Slug:
- funnelforms-free
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.7.4.1
- Severity Score:
- Medium
- CVE:
- 2024-5857
GS Pinterest Portfolio – Pins Grid, Masonry, User Profile, Popup & Board Widgets
- Plugin Slug:
- gs-pinterest-portfolio
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.9
- Severity Score:
- Medium
- CVE:
- 2024-11453
PeproDev WooCommerce Receipt Uploader
- Plugin Slug:
- pepro-bacs-receipt-upload-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.0
- Severity Score:
- High
- CVE:
- 2024-8873
PDF Builder for WooCommerce. Create invoices,packing slips and more
- Plugin Slug:
- woo-pdf-invoice-builder
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.137
- Severity Score:
- High
- CVE:
- 2024-11276
WPBITS Addons For Elementor Page Builder
- Plugin Slug:
- wpbits-addons-for-elementor
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5
- Severity Score:
- Medium
- CVE:
- 2024-2129
Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim
- Plugin Slug:
- atarim-visual-collaboration
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.2.2
- Severity Score:
- Medium
- CVE:
- 2025-67993
Authorsy – Author Box, Multiple Authors, Guest Authors & Post Rating
- Plugin Slug:
- authorsy
- Installations
- 1,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.0.7
- Severity Score:
- High
- CVE:
- 2026-24950
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment
- Plugin Slug:
- booking-and-rental-manager-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.6.0
- Severity Score:
- High
- CVE:
- 2025-69328
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-0385
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1650
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1652
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1653
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1907
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1909
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1910
Categorify – WordPress Media Library Category & File Manager
- Plugin Slug:
- categorify
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.7.5
- Severity Score:
- Medium
- CVE:
- 2024-1912
Geo Controller
- Plugin:
- Geo Controller
- Plugin Slug:
- cf-geoplugin
- Installations
- 1,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 8.7.0
- Severity Score:
- Medium
- CVE:
- 2024-7381
Message Filter for Contact Form 7
- Plugin Slug:
- cf7-message-filter
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.3.1
- Severity Score:
- Medium
- CVE:
- 2024-12026
Smart Online Order for Clover
- Plugin:
- Smart Online Order for Clover
- Plugin Slug:
- clover-online-orders
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.7
- Severity Score:
- Medium
- CVE:
- 2024-7030
Web3 Crypto Payments by DePay for WooCommerce
- Plugin Slug:
- depay-payments-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.12.18
- Severity Score:
- Medium
- CVE:
- 2024-12265
Enter Addons – Ultimate Template Builder for Elementor
- Plugin Slug:
- enteraddons
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.6
- Severity Score:
- Medium
- CVE:
- 2024-3680
Enter Addons – Ultimate Template Builder for Elementor
- Plugin Slug:
- enteraddons
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.9
- Severity Score:
- Medium
- CVE:
- 2024-7611
Flamix: Bitrix24 and Contact Form 7 integrations
- Plugin Slug:
- flamix-bitrix24-and-contact-forms-7-integrations
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.2.0
- Severity Score:
- Medium
- CVE:
- 2024-6568
Gestpay for WooCommerce
- Plugin:
- Gestpay for WooCommerce
- Plugin Slug:
- gestpay-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 20240307
- Severity Score:
- Medium
- CVE:
- 2024-0433
Gestpay for WooCommerce
- Plugin:
- Gestpay for WooCommerce
- Plugin Slug:
- gestpay-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 20240307
- Severity Score:
- Medium
- CVE:
- 2024-0432
Connector Wizard (formerly LC Wizard)
- Plugin Slug:
- ghl-wizard
- Installations
- 1,000+
- Vulnerability:
- Settings Change
- Patched in Version:
- 2.1.2
- Severity Score:
- Medium
- CVE:
- 2025-68026
Keap Official Opt-in Forms
- Plugin:
- Keap Official Opt-in Forms
- Plugin Slug:
- infusionsoft-official-opt-in-forms
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.12
- Severity Score:
- Medium
- CVE:
- 2023-6941
PDF Generator for WordPress Elementor
- Plugin Slug:
- pdf-generator-addon-for-elementor-page-builder
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 2.0.1
- Severity Score:
- High
- CVE:
- 2024-9935
Simple Popup Plugin
- Plugin:
- Simple Popup Plugin
- Plugin Slug:
- simple-popup-plugin
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6
- Severity Score:
- Medium
- CVE:
- 2024-8547
Squelch Tabs and Accordions Shortcodes
- Plugin Slug:
- squelch-tabs-and-accordions-shortcodes
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.4.4
- Severity Score:
- Medium
- CVE:
- 2024-2499
Tutor LMS – Migration Tool
- Plugin:
- Tutor LMS – Migration Tool
- Plugin Slug:
- tutor-lms-migration-tool
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2024-1804
Vayu Blocks – Website Builder for the Block Editor
- Plugin Slug:
- vayu-blocks
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.0
- Severity Score:
- Critical
- CVE:
- 2024-10124
Views for WPForms – Display & Edit WPForms Entries on your site frontend
- Plugin Slug:
- views-for-wpforms-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2024-0374
Views for WPForms – Display & Edit WPForms Entries on your site frontend
- Plugin Slug:
- views-for-wpforms-lite
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2024-0373
Views for WPForms – Display & Edit WPForms Entries on your site frontend
- Plugin Slug:
- views-for-wpforms-lite
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2024-0372
Views for WPForms – Display & Edit WPForms Entries on your site frontend
- Plugin Slug:
- views-for-wpforms-lite
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.3
- Severity Score:
- Medium
- CVE:
- 2024-0371
WP AdCenter – Ad Manager & Adsense Ads
- Plugin Slug:
- wpadcenter
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.8
- Severity Score:
- Medium
- CVE:
- 2024-10113
Zephyr Project Manager
- Plugin:
- Zephyr Project Manager
- Plugin Slug:
- zephyr-project-manager
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.3.102
- Severity Score:
- High
- CVE:
- 2024-7624
Checkout Gateway for IRIS
- Plugin:
- Checkout Gateway for IRIS
- Plugin Slug:
- checkout-gateway-iris
- Installations
- 900+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4
- Severity Score:
- Medium
- CVE:
- 2025-68542
Ebook Store
- Plugin:
- Ebook Store
- Plugin Slug:
- ebook-store
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.8002
- Severity Score:
- High
- CVE:
- 2024-11287
ForumWP – Forum & Discussion Board
- Plugin Slug:
- forumwp
- Installations
- 900+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.3
- Severity Score:
- High
- CVE:
- 2024-11204
IdeaPush
- Plugin:
- IdeaPush
- Plugin Slug:
- ideapush
- Installations
- 800+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.72
- Severity Score:
- Medium
- CVE:
- 2024-11844
Koalendar – Easy Appointment Scheduling & Booking Plugin
- Plugin Slug:
- koalendar-free-booking-widget
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.3
- Severity Score:
- Medium
- CVE:
- 2024-11855
Confetti Fall Animation
- Plugin:
- Confetti Fall Animation
- Plugin Slug:
- confetti-fall-animation
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2024-8919
Integrate Firebase
- Plugin:
- Integrate Firebase
- Plugin Slug:
- integrate-firebase
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.10.0
- Severity Score:
- Medium
- CVE:
- 2024-11785
PowerBI Embed Reports
- Plugin:
- PowerBI Embed Reports
- Plugin Slug:
- embed-power-bi-reports
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.8
- Severity Score:
- Medium
- CVE:
- 2024-11901
GS Books Showcase – Display Books in Grid, Slider & More | Library for WordPress
- Plugin Slug:
- gs-books-showcase
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.2
- Severity Score:
- Medium
- CVE:
- 2024-11766
Sync Master Sheet – Product Sync with Google Sheet for WooCommerce
- Plugin Slug:
- product-sync-master-sheet
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.4
- Severity Score:
- High
- CVE:
- 2025-68834
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses
- Plugin:
- WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses
- Plugin Slug:
- wp-courses
- Installations
- 500+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.2.22
- Severity Score:
- High
- CVE:
- 2024-12172
Dynamic Widget Content
- Plugin:
- Dynamic Widget Content
- Plugin Slug:
- dynamic-widget-content
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
- 2026-1268
Library Viewer
- Plugin:
- Library Viewer
- Plugin Slug:
- library-viewer
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.0
- Severity Score:
- High
- CVE:
- 2025-15396
SmartAgenda – Prise de rendez-vous en ligne
- Plugin Slug:
- smart-agenda-prise-de-rendez-vous-en-ligne
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7
- Severity Score:
- Medium
- CVE:
- 2024-11781
WaveSurfer-WP
- Plugin:
- WaveSurfer-WP
- Plugin Slug:
- wavesurfer-wp
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.4
- Severity Score:
- Medium
- CVE:
- 2026-1909
JSM file_get_contents() Shortcode
- Plugin Slug:
- wp-file-get-contents
- Installations
- 400+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 2.7.1
- Severity Score:
- Medium
- CVE:
- 2023-6991
WP Mailster
- Plugin:
- WP Mailster
- Plugin Slug:
- wp-mailster
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.18.0
- Severity Score:
- Medium
- CVE:
- 2024-11782
ELEX WordPress HelpDesk & Customer Ticketing System
- Plugin Slug:
- elex-helpdesk-customer-support-ticket-system
- Installations
- 300+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.3.6
- Severity Score:
- Medium
- CVE:
- 2025-14079
Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder.
- Plugin Slug:
- faq-and-answers
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.2
- Severity Score:
- Medium
- CVE:
- 2024-11882
GS Portfolio – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more
- Plugin Slug:
- gs-portfolio
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.4
- Severity Score:
- Medium
- CVE:
- 2024-11765
Accept Stripe Payments Using Contact Form 7
- Plugin Slug:
- accept-stripe-payments-using-contact-form-7
- Installations
- 200+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.6
- Severity Score:
- Medium
- CVE:
- 2024-12255
Arena.IM – Live Blogging for real-time events
- Plugin Slug:
- arena-liveblog-and-chat-tool
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.4.0
- Severity Score:
- Medium
- CVE:
- 2024-11384
Bukza
- Plugin:
- Bukza
- Plugin Slug:
- bukza
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.1
- Severity Score:
- Medium
- CVE:
- 2024-11759
Eveeno
- Plugin:
- Eveeno
- Plugin Slug:
- eveeno
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8
- Severity Score:
- Medium
- CVE:
- 2024-11752
All In One Image Viewer Block – Gutenberg block to create image viewer with hyperlink
- Plugin Slug:
- image-viewer
- Installations
- 200+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.0.3
- Severity Score:
- High
- CVE:
- 2026-1294
OS DataHub Maps
- Plugin:
- OS DataHub Maps
- Plugin Slug:
- os-datahub-maps
- Installations
- 200+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.8.4
- Severity Score:
- Critical
- CVE:
- 2026-1730
Password for WP
- Plugin:
- Password for WP
- Plugin Slug:
- password-for-wp
- Installations
- 200+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2024-11419
Plezi
- Plugin:
- Plezi
- Plugin Slug:
- plezi
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2024-11763
WP GeoNames
- Plugin:
- WP GeoNames
- Plugin Slug:
- wp-geonames
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.1
- Severity Score:
- Medium
- CVE:
- 2024-11757
Add infos to The Events Calendar
- Plugin:
- Add infos to The Events Calendar
- Plugin Slug:
- add-infos-to-the-events-calendar
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.0
- Severity Score:
- Medium
- CVE:
- 2024-11875
Run Contests, Raffles, and Giveaways with ContestsWP
- Plugin Slug:
- contest-code-checker
- Installations
- 100+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.1.1
- Severity Score:
- Medium
- CVE:
- 2026-25023
IMS Countdown
- Plugin:
- IMS Countdown
- Plugin Slug:
- ims-countdown
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.6
- Severity Score:
- Medium
- CVE:
- 2024-11755
Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
- Plugin:
- Kudos Donations: Easy Donations with Mollie | One-off & Recurring | PDF Invoices | Buttons & Forms
- Plugin Slug:
- kudos-donations
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.0
- Severity Score:
- High
- CVE:
- 2024-11685
My IDX Home Search
- Plugin:
- My IDX Home Search
- Plugin Slug:
- my-idx-home-search
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.2
- Severity Score:
- Medium
- CVE:
- 2024-11889
Primer MyData for Woocommerce
- Plugin:
- Primer MyData for Woocommerce
- Plugin Slug:
- primer-mydata
- Installations
- 100+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 4.2.9
- Severity Score:
- Medium
- CVE:
- 2025-69325
Sigmize: A/B Testing, Session Recordings, Heatmaps & Revenue Tracking for WooCommerce, SureCart & EDD
- Plugin Slug:
- sigmize
- Installations
- 100+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 0.0.10
- Severity Score:
- Medium
- CVE:
- 2026-24962
WP To Do
WP To Do
WP To Do
GMap Targeting – Simple Targeting Inside Google Maps
- Plugin Slug:
- gmap-targeting
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.8
- Severity Score:
- High
- CVE:
- 2025-67990
ONLYOFFICE DocSpace
- Plugin:
- ONLYOFFICE DocSpace
- Plugin Slug:
- onlyoffice-docspace
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.2
- Severity Score:
- Medium
- CVE:
- 2024-11750
Pdf & Print to Post – Custom Post Type and Pages
- Plugin Slug:
- post-to-pdf
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1
- Severity Score:
- Medium
- CVE:
- 2024-12446
Ganohrs Toggle Shortcode
- Plugin:
- Ganohrs Toggle Shortcode
- Plugin Slug:
- ganohrs-toggle-shortcode
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.2.5
- Severity Score:
- Medium
- CVE:
- 2024-12459
Events Listing Widget
- Plugin:
- Events Listing Widget
- Plugin Slug:
- events-listing-widget
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2026-1252
GeoDataSource Country Region DropDown
- Plugin Slug:
- geodatasource-country-region-dropdown
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.2
- Severity Score:
- Medium
- CVE:
- 2024-12474
NPS computy
- Plugin:
- NPS computy
- Plugin Slug:
- nps-computy
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.8.3
- Severity Score:
- High
- CVE:
- 2025-67984
Social Media Shortcodes
- Plugin:
- Social Media Shortcodes
- Plugin Slug:
- social-media-shortcodes
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- Medium
- CVE:
- 2024-11871
Employee Directory – Staff Directory and Listing
- Plugin Slug:
- employee-staff-directory
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- Medium
- CVE:
- 2026-1279
Sell BTC – Cryptocurrency Selling Calculator
- Plugin Slug:
- sell-btc-by-hayyatapps
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2025-14554
Docus – YouTube Video Playlist
- Plugin:
- Docus – YouTube Video Playlist
- Plugin Slug:
- docus
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.7
- Severity Score:
- Medium
- CVE:
- 2026-1888
Orange Comfort+ accessibility toolbar for WordPress
- Plugin Slug:
- orange-confort-plus
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.7.1
- Severity Score:
- Medium
- CVE:
- 2026-1808
Peter’s Date Countdown
- Plugin:
- Peter’s Date Countdown
- Plugin Slug:
- peters-date-countdown
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.1
- Severity Score:
- High
- CVE:
- 2026-1654
WP FOFT Loader
- Plugin:
- WP FOFT Loader
- Plugin Slug:
- wp-foft-loader
- Installations
- 10+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.1.40
- Severity Score:
- High
- CVE:
- 2026-1756
Aiomatic
- Plugin:
- Aiomatic
- Plugin Slug:
- aiomatic-automatic-ai-content-writer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.6
- Severity Score:
- Medium
- CVE:
- 2024-5969
ARMember Premium
- Plugin:
- ARMember Premium
- Plugin Slug:
- armember
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.7.1
- Severity Score:
- Medium
- CVE:
- 2024-5596
Bit Form
- Plugin:
- Bit Form
- Plugin Slug:
- bit-form
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.13.10
- Severity Score:
- High
- CVE:
- 2024-7780
bodi0’s Easy Cache
- Plugin:
- bodi0’s Easy Cache
- Plugin Slug:
- bodi0s-easy-cache
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.9
- Severity Score:
- Medium
- CVE:
- 2024-12628
Bridge Core
- Plugin:
- Bridge Core
- Plugin Slug:
- bridge-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3
- Severity Score:
- Medium
- CVE:
- 2024-9292
EventON-RSVP
- Plugin:
- EventON-RSVP
- Plugin Slug:
- eventon-rsvp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.5
- Severity Score:
- High
- CVE:
- 2023-7170
Fluent Forms Pro Add On Pack
- Plugin:
- Fluent Forms Pro Add On Pack
- Plugin Slug:
- fluentformpro
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 6.1.13
- Severity Score:
- Medium
- CVE:
- 2026-0632
Integrate Google Drive
- Plugin:
- Integrate Google Drive
- Plugin Slug:
- integrate-google-drive
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.9
- Severity Score:
- Critical
- CVE:
- 2024-2086
WPBakery Page Builder
- Plugin:
- WPBakery Page Builder
- Plugin Slug:
- js_composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6
- Severity Score:
- Medium
- CVE:
- 2024-1841
WPBakery Page Builder
- Plugin:
- WPBakery Page Builder
- Plugin Slug:
- js_composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.6
- Severity Score:
- Medium
- CVE:
- 2024-1842
WPBakery Page Builder
- Plugin:
- WPBakery Page Builder
- Plugin Slug:
- js_composer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.7
- Severity Score:
- Medium
- CVE:
- 2024-5265
Paid Memberships Pro
- Plugin:
- Paid Memberships Pro
- Plugin Slug:
- paid-memberships-pro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.12.8
- Severity Score:
- Medium
- CVE:
- 2024-0624
Community by PeepSo
- Plugin:
- Community by PeepSo
- Plugin Slug:
- peepso-core
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.3.1.2
- Severity Score:
- Medium
- CVE:
- 2023-7125
Community by PeepSo
- Plugin:
- Community by PeepSo
- Plugin Slug:
- peepso-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.6.0
- Severity Score:
- Medium
- CVE:
- 2024-7655
Porto Theme – Functionality
- Plugin:
- Porto Theme – Functionality
- Plugin Slug:
- porto-functionality
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.1.0
- Severity Score:
- High
- CVE:
- 2024-3809
Premium Addons PRO
- Plugin:
- Premium Addons PRO
- Plugin Slug:
- premium-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.13
- Severity Score:
- Medium
- CVE:
- 2024-1997
Premium Addons PRO
- Plugin:
- Premium Addons PRO
- Plugin Slug:
- premium-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.13
- Severity Score:
- Medium
- CVE:
- 2024-2000
Premium Addons PRO
- Plugin:
- Premium Addons PRO
- Plugin Slug:
- premium-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.13
- Severity Score:
- Medium
- CVE:
- 2024-2237
Premium Addons PRO
- Plugin:
- Premium Addons PRO
- Plugin Slug:
- premium-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.13
- Severity Score:
- Medium
- CVE:
- 2024-2238
Premium Addons PRO
- Plugin:
- Premium Addons PRO
- Plugin Slug:
- premium-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.13
- Severity Score:
- Medium
- CVE:
- 2024-2239
Reflector
- Plugin:
- Reflector
- Plugin Slug:
- reflector-plugins
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.3
- Severity Score:
- High
- CVE:
- 2026-24948
Relevanssi Premium
- Plugin:
- Relevanssi Premium
- Plugin Slug:
- relevanssi-premium
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.25.0
- Severity Score:
- Medium
- CVE:
- 2023-7199
Relevanssi Premium
- Plugin:
- Relevanssi Premium
- Plugin Slug:
- relevanssi-premium
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.25.1
- Severity Score:
- Medium
- CVE:
- 2024-1380
Slider Revolution
- Plugin:
- Slider Revolution
- Plugin Slug:
- revslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.7.11
- Severity Score:
- Medium
- CVE:
- 2024-4581
Slider Revolution
- Plugin:
- Slider Revolution
- Plugin Slug:
- revslider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.7.11
- Severity Score:
- Medium
- CVE:
- 2024-4637
Salient Core
- Plugin:
- Salient Core
- Plugin Slug:
- salient-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.0.8
- Severity Score:
- High
- CVE:
- 2024-3812
Salient Shortcodes
- Plugin:
- Salient Shortcodes
- Plugin Slug:
- salient-shortcodes
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.5.4
- Severity Score:
- High
- CVE:
- 2024-3810
Salient Shortcodes
- Plugin:
- Salient Shortcodes
- Plugin Slug:
- salient-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.4
- Severity Score:
- Medium
- CVE:
- 2024-3811
School Management
- Plugin:
- School Management
- Plugin Slug:
- school-management
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 92.0.0
- Severity Score:
- Critical
- CVE:
- 2024-9660
Simple Locator
- Plugin:
- Simple Locator
- Plugin Slug:
- simple-locator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.4
- Severity Score:
- Medium
- CVE:
- 2024-12501
Smart Appointment & Booking
- Plugin:
- Smart Appointment & Booking
- Plugin Slug:
- smart-appointment-booking
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.8
- Severity Score:
- Medium
- CVE:
- 2026-0742
Ultimate Addons for WPBakery Page Builder
- Plugin:
- Ultimate Addons for WPBakery Page Builder
- Plugin Slug:
- ultimate_vc_addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.19.20.1
- Severity Score:
- Medium
- CVE:
- 2024-5252
Ultimate Addons for WPBakery Page Builder
- Plugin:
- Ultimate Addons for WPBakery Page Builder
- Plugin Slug:
- ultimate_vc_addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.19.20.1
- Severity Score:
- Medium
- CVE:
- 2024-5253
Ultimate Addons for WPBakery Page Builder
- Plugin:
- Ultimate Addons for WPBakery Page Builder
- Plugin Slug:
- ultimate_vc_addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.19.20.1
- Severity Score:
- Medium
- CVE:
- 2024-5254
Ultimate Addons for WPBakery Page Builder
- Plugin:
- Ultimate Addons for WPBakery Page Builder
- Plugin Slug:
- ultimate_vc_addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.19.20.1
- Severity Score:
- Medium
- CVE:
- 2024-5255
Whizz Plugins
- Plugin:
- Whizz Plugins
- Plugin Slug:
- whizz-plugins
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.0
- Severity Score:
- High
- CVE:
- 2026-24955
WooCommerce Social Login
- Plugin:
- WooCommerce Social Login
- Plugin Slug:
- woo-social-login
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.7.4
- Severity Score:
- High
- CVE:
- 2024-6635
WooCommerce Social Login
- Plugin:
- WooCommerce Social Login
- Plugin Slug:
- woo-social-login
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.7.4
- Severity Score:
- Critical
- CVE:
- 2024-6636
WooCommerce Social Login
- Plugin:
- WooCommerce Social Login
- Plugin Slug:
- woo-social-login
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.7.4
- Severity Score:
- High
- CVE:
- 2024-6637
WooCommerce PDF Vouchers
- Plugin:
- WooCommerce PDF Vouchers
- Plugin Slug:
- woocommerce-pdf-vouchers
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 4.9.4
- Severity Score:
- High
- CVE:
- 2024-7027
WooCommerce Support Ticket System
- Plugin:
- WooCommerce Support Ticket System
- Plugin Slug:
- woocommerce-support-ticket-system
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 17.8
- Severity Score:
- High
- CVE:
- 2024-10626
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5281
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5282
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5283
Affiliate Manager
- Plugin:
- Affiliate Manager
- Plugin Slug:
- wp-affiliate-platform
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.1
- Severity Score:
- High
- CVE:
- 2024-5286
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.5
- Severity Score:
- High
- CVE:
- 2024-6073
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.5
- Severity Score:
- High
- CVE:
- 2024-6074
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.5
- Severity Score:
- High
- CVE:
- 2024-6076
WP eStore
- Plugin:
- WP eStore
- Plugin Slug:
- wp-cart-for-digital-products
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.6
- Severity Score:
- High
- CVE:
- 2024-6134
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.6
- Severity Score:
- High
- CVE:
- 2024-5075
WP eMember
- Plugin:
- WP eMember
- Plugin Slug:
- wp-eMember
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.6.7
- Severity Score:
- High
- CVE:
- 2024-5744
User Extra Fields
- Plugin:
- User Extra Fields
- Plugin Slug:
- wp-user-extra-fields
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 16.9
- Severity Score:
- High
- CVE:
- 2025-67991
WPB Show Core
- Plugin:
- WPB Show Core
- Plugin Slug:
- wpb-show-core
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7
- Severity Score:
- High
- CVE:
- 2024-1958
WordPress Themes — 14 Patched / 5 Unpatched
WordPress Dating Theme
- Theme:
- WordPress Dating Theme
- Theme Slug:
- DA10
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-22343
Cartify – WooCommerce Gutenberg WordPress Theme
- Theme:
- Cartify – WooCommerce Gutenberg WordPress Theme
- Theme Slug:
- cartify
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69385
Meris
- Theme:
- Meris
- Theme Slug:
- meris
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2023-7194
SevenHills
- Theme:
- SevenHills
- Theme Slug:
- sevenhills
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-69372
VidoRev
- Theme:
- VidoRev
- Theme Slug:
- vidorev
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-69373
Royal Elementor Kit
- Theme:
- Royal Elementor Kit
- Theme Slug:
- royal-elementor-kit
- Downloads
- 986,469
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.117
- Severity Score:
- Medium
- CVE:
- 2024-0835
Besa
- Theme:
- Besa
- Theme Slug:
- besa
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.3.16
- Severity Score:
- High
- CVE:
- 2025-67981
CozyStay
- Theme:
- CozyStay
- Theme Slug:
- cozystay
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.9.1
- Severity Score:
- High
- CVE:
- 2025-67988
Golo
- Theme:
- Golo
- Theme Slug:
- golo
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.5
- Severity Score:
- Medium
- CVE:
- 2026-23974
Golo
- Theme:
- Golo
- Theme Slug:
- golo
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.7.5
- Severity Score:
- High
- CVE:
- 2026-23975
Grand Conference
- Theme:
- Grand Conference
- Theme Slug:
- grandconference
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.5
- Severity Score:
- High
- CVE:
- 2026-24943
Hara
- Theme:
- Hara
- Theme Slug:
- hara
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.18
- Severity Score:
- High
- CVE:
- 2025-67980
Nestin
- Theme:
- Nestin
- Theme Slug:
- nestin
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.2.6
- Severity Score:
- Critical
- CVE:
- 2025-67996
PatioTime
- Theme:
- PatioTime
- Theme Slug:
- patiotime
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.1
- Severity Score:
- Critical
- CVE:
- 2025-67995
PatioTime
- Theme:
- PatioTime
- Theme Slug:
- patiotime
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.1
- Severity Score:
- High
- CVE:
- 2025-67992
PhotoMe
- Theme:
- PhotoMe
- Theme Slug:
- photome
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.7.2
- Severity Score:
- High
- CVE:
- 2026-24949
Travelicious
- Theme:
- Travelicious
- Theme Slug:
- travelicious
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6.7
- Severity Score:
- Critical
- CVE:
- 2025-67997
Unicamp
- Theme:
- Unicamp
- Theme Slug:
- unicamp
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.7.2
- Severity Score:
- High
- CVE:
- 2026-25027
Urna
- Theme:
- Urna
- Theme Slug:
- urna
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.5.13
- Severity Score:
- High
- CVE:
- 2025-67982
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
