WordPress Vulnerability Report

WordPress Vulnerability Report — February 11, 2026

Since last week, 467 new vulnerabilities have emerged in the WordPress ecosystem, including 448 plugins and 19 themes. Of those, 81 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 467 vulnerabilities have been publicly disclosed. Security patches for 386 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 81 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 372 Patched / 76 Unpatched

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SportsPress – Sports Club & League Manager

Plugin Slug:
sportspress
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AWCA – The Great Analytics Insights for Your eStore

Plugin Slug:
advance-wc-analytics
Installations
3,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Country Blocker

Plugin Slug:
advanced-country-blocker
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin BlueX for WooCommerce

Plugin Slug:
bluex-for-woocommerce
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cliengo – Chatbot

Plugin Slug:
cliengo
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GA4WP – Analytics Dashboard for the Website

Plugin Slug:
ga-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Addonify – Compare Products For WooCommerce

Plugin Slug:
addonify-compare-products
Installations
1,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Addonify Floating Cart For WooCommerce

Plugin Slug:
addonify-floating-cart
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Addonify – WooCommerce Wishlist

Plugin Slug:
addonify-wishlist
Installations
1,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Duplicate – WordPress Migration Plugin

Plugin Slug:
local-sync
Installations
200+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Contact Manager

Plugin Slug:
contact-manager
Installations
100+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Court Reservation – Manage Your Court Bookings Online

Plugin Slug:
court-reservation
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RVCFDI para Woocommerce

Plugin Slug:
rvcfdi-para-woocommerce
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Retail Menus

Plugin Slug:
simple-retail-menus
Installations
90+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iContact for Gravity Forms

Plugin Slug:
gravity-forms-icontact
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Optimize More! – Images

Plugin Slug:
optimize-more-images
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPshop 2 – E-Commerce

Plugin Slug:
wpshop
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin:
All push notification for WP
Plugin Slug:
all-push-notification
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Edit Post Titles

Plugin:
Bulk Edit Post Titles
Plugin Slug:
bulk-edit-post-titles
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buy one click WooCommerce

Plugin:
Buy one click WooCommerce
Plugin Slug:
buy-one-click-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buy one click WooCommerce

Plugin:
Buy one click WooCommerce
Plugin Slug:
buy-one-click-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Catch Popup

Plugin:
Catch Popup
Plugin Slug:
catch-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chapa Payment Gateway Plugin for WooCommerce

Plugin:
Chapa Payment Gateway Plugin for WooCommerce
Plugin Slug:
chapa-payment-gateway-for-woocommerce
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Code Explorer

Plugin:
Code Explorer
Plugin Slug:
code-explorer
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CommentTweets

Plugin:
CommentTweets
Plugin Slug:
commenttweets
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eleblog – Elementor Blog And Magazine Addons

Plugin:
Eleblog – Elementor Blog And Magazine Addons
Plugin Slug:
ele-blog
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Elegant Addons for elementor

Plugin:
Elegant Addons for elementor
Plugin Slug:
elegant-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Extended Random Number Generator

Plugin:
Extended Random Number Generator
Plugin Slug:
extended-random-number-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:
Font Farsi
Plugin Slug:
font-farsi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fortis for WooCommerce

Plugin:
Fortis for WooCommerce
Plugin Slug:
fortis-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Image Hover Effects – Caption Hover with Carousel
Plugin Slug:
image-hover-effects-with-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin:
Infility Global
Plugin Slug:
infility-global
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin:
Login Logout Register Menu
Plugin Slug:
login-logout-register-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO Flow by LupsOnline

Plugin:
SEO Flow by LupsOnline
Plugin Slug:
lupsonline-link-netwerk
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Magic Import Document Extractor

Plugin Slug:
magic-import-document-extractor
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magic Import Document Extractor

Plugin Slug:
magic-import-document-extractor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:
Newsletter Popup
Plugin Slug:
newsletter-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Okay Toolkit

Plugin:
Okay Toolkit
Plugin Slug:
okay-toolkit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OMIGO

Plugin:
OMIGO
Plugin Slug:
omigo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Filter for WooCommerce

Plugin:
Product Filter for WooCommerce
Plugin Slug:
prdctfltr
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Redirects

Plugin:
Redirects
Plugin Slug:
redirects
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SIBS woocommerce payment gateway

Plugin:
SIBS woocommerce payment gateway
Plugin Slug:
sibs-woocommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Bible Verse via Shortcode

Plugin:
Simple Bible Verse via Shortcode
Plugin Slug:
simple-bible-verse-via-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart PopUp Blaster

Plugin:
Smart PopUp Blaster
Plugin Slug:
smart-popup-blaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Store Locator

Plugin:
Store Locator
Plugin Slug:
store-locator
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:
SVS Pricing Tables
Plugin Slug:
svs-pricing-tables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Builder

Plugin:
Portfolio Builder
Plugin Slug:
swp-portfolio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tabs Maker

Plugin:
Tabs Maker
Plugin Slug:
tabs-maker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Widget

Plugin:
Testimonials Widget
Plugin Slug:
testimonials-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Bucketlister

Plugin:
The Bucketlister
Plugin Slug:
the-bucketlister
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Bucketlister

Plugin:
The Bucketlister
Plugin Slug:
the-bucketlister
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Elementor

Plugin:
Themesflat Elementor
Plugin Slug:
themesflat-elementor
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:
Timeline Event History
Plugin Slug:
timeline-event-history
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TITLE ANIMATOR

Plugin:
TITLE ANIMATOR
Plugin Slug:
title-animator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

Plugin:
WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto
Plugin Slug:
tripetto
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UserPlus

Plugin:
UserPlus
Plugin Slug:
userplus
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video Onclick

Plugin:
Video Onclick
Plugin Slug:
video-onclick
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WebPurify Profanity Filter

Plugin:
WebPurify Profanity Filter
Plugin Slug:
webpurifytextreplace
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wikiloops Track Player

Plugin:
Wikiloops Track Player
Plugin Slug:
wikiloops-track-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wonka Slide

Plugin:
Wonka Slide
Plugin Slug:
wonka-slide
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woo File Dropzone

Plugin:
Woo File Dropzone
Plugin Slug:
woo-file-dropzone
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xendit Payment

Plugin:
Xendit Payment
Plugin Slug:
woo-xendit-virtual-accounts
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bulk Product Editor

Plugin:
WooCommerce Bulk Product Editor
Plugin Slug:
woocommerce-quick-product-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MyRewards

Plugin:
MyRewards
Plugin Slug:
woorewards
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Content Permission

Plugin:
WP Content Permission
Plugin Slug:
wp-content-permission
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Revive Adserver

Plugin:
WP-Revive Adserver
Plugin Slug:
wp-revive-adserver
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:
Upload Files Anywhere
Plugin Slug:
wp-upload-files-anywhere
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:
Upload Files Anywhere
Plugin Slug:
wp-upload-files-anywhere
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Code Snippets

Plugin Slug:
code-snippets
Installations
1,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.5.

Spectra Gutenberg Blocks – Website Builder for the Block Editor

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.19.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.19.18.

Spectra Gutenberg Blocks – Website Builder for the Block Editor

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.12.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.9.

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Plugin Slug:
kadence-blocks
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.38
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.38.

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Plugin Slug:
kadence-blocks
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.37.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.4.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.9.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.113
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.113.

SEOPress – On-site SEO & Analytics

Plugin Slug:
wp-seopress
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

FileOrganizer – WordPress File Manager

Plugin Slug:
fileorganizer
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.2.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.12.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.3.

Prime Slider – Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.2.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.4.3.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.14.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.14.2.

Menu Icons by ThemeIsle

Plugin Slug:
menu-icons
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.13.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.13.21.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.13.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.5.

WebSub (FKA. PubSubHubbub)

Plugin Slug:
pubsubhubbub
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.22.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.0.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.22.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.1.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.9.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.6.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.3.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.4.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.3.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.1.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.274
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.274.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.277
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.277.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.26.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.7.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.44.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.44
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.44.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.41.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.42.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.5.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
12.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.6.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

?????? ????? ??????? Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.6.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.1.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
40,000+
Vulnerability:
SQL Injection
Patched in Version:
12.3.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.3.20.

ACF Quick Edit Fields

Plugin Slug:
acf-quickedit-fields
Installations
30,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.3.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.29.

Post Grid

Plugin:
Post Grid
Plugin Slug:
post-grid
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.81.

Post Grid

Plugin:
Post Grid
Plugin Slug:
post-grid
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.81.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.0.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.4.

Subscribe2 – Form, Email Subscribers & Newsletters

Plugin Slug:
subscribe2
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.45.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

WCFM Marketplace – Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.25.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.25.1.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.25.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.25.1.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.1.

Essential Widgets

Plugin Slug:
essential-widgets
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

Child Theme Creator by Orbisius

Plugin Slug:
orbisius-child-theme-creator
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

OSM – OpenStreetMap

Plugin Slug:
osm
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.4.
Plugin Slug:
testimonials-carousel-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.0.

Ultimate Maps by Supsystic

Plugin Slug:
ultimate-maps-by-supsystic
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.16.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.8.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.8.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.7.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.7.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.8.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.4.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.2.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

LottieFiles

Plugin Slug:
lottiefiles
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.0.

OAuth Single Sign On – SSO (OAuth Client)

Plugin Slug:
miniorange-login-with-eve-online-google-facebook
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.26.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.26.15.

Schema App Structured Data

Plugin Slug:
schema-app-structured-data-for-schemaorg
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Schema App Structured Data

Plugin Slug:
schema-app-structured-data-for-schemaorg
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.5.

YayCurrency – WooCommerce Multi-Currency Switcher

Plugin Slug:
yaycurrency
Installations
7,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
3.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.1.

Export Media URLs

Plugin Slug:
export-media-urls
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.9.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.7.3.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.7.3.

Contact Form 7 Connector

Plugin Slug:
ari-cf7-connector
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.3.

Shortcodes for Elementor

Plugin Slug:
shortcode-elementor
Installations
5,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

Simple File List

Plugin Slug:
simple-file-list
Installations
5,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
6.1.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.16.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.2.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

Snippet Shortcodes

Plugin Slug:
shortcode-variables
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.7.

Payment Button for PayPal

Plugin Slug:
wp-paypal
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.3.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.3.42.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

Classic Addons – WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons
Installations
3,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Product Enquiry for WooCommerce

Plugin Slug:
gm-woocommerce-quote-popup
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.

Salon Booking System – Free Version

Plugin Slug:
salon-booking-system
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.6.3.

Tickera – Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.5.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.9.

WP-WebAuthn

Plugin Slug:
wp-webauthn
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

PeproDev WooCommerce Receipt Uploader

Plugin Slug:
pepro-bacs-receipt-upload-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Geo Controller

Plugin Slug:
cf-geoplugin
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
8.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.0.

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.1.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.7.

Web3 Crypto Payments by DePay for WooCommerce

Plugin Slug:
depay-payments-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.12.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.18.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

Flamix: Bitrix24 and Contact Form 7 integrations

Plugin Slug:
flamix-bitrix24-and-contact-forms-7-integrations
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
20240307
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20240307.

Gestpay for WooCommerce

Plugin Slug:
gestpay-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
20240307
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20240307.

Connector Wizard (formerly LC Wizard)

Plugin Slug:
ghl-wizard
Installations
1,000+
Vulnerability:
Settings Change
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Keap Official Opt-in Forms

Plugin Slug:
infusionsoft-official-opt-in-forms
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.12.

PDF Generator for WordPress Elementor

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Simple Popup Plugin

Plugin Slug:
simple-popup-plugin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.4.4.

Tutor LMS – Migration Tool

Plugin Slug:
tutor-lms-migration-tool
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Vayu Blocks – Website Builder for the Block Editor

Plugin Slug:
vayu-blocks
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.0.

WP AdCenter – Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.8.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.102
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.102.

Checkout Gateway for IRIS

Plugin Slug:
checkout-gateway-iris
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Ebook Store

Plugin Slug:
ebook-store
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8002
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8002.

ForumWP – Forum & Discussion Board

Plugin Slug:
forumwp
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

IdeaPush

Plugin:
IdeaPush
Plugin Slug:
ideapush
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
8.72
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.72.

Koalendar – Easy Appointment Scheduling & Booking Plugin

Plugin Slug:
koalendar-free-booking-widget
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Confetti Fall Animation

Plugin Slug:
confetti-fall-animation
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Integrate Firebase

Plugin Slug:
integrate-firebase
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.10.0.

PowerBI Embed Reports

Plugin Slug:
embed-power-bi-reports
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Dynamic Widget Content

Plugin Slug:
dynamic-widget-content
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

Library Viewer

Plugin Slug:
library-viewer
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.0.

SmartAgenda – Prise de rendez-vous en ligne

Plugin Slug:
smart-agenda-prise-de-rendez-vous-en-ligne
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.

WaveSurfer-WP

Plugin Slug:
wavesurfer-wp
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.4.

JSM file_get_contents() Shortcode

Plugin Slug:
wp-file-get-contents
Installations
400+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

WP Mailster

Plugin Slug:
wp-mailster
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.18.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.18.0.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.

Arena.IM – Live Blogging for real-time events

Plugin Slug:
arena-liveblog-and-chat-tool
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.4.0.

Bukza

Plugin:
Bukza
Plugin Slug:
bukza
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Eveeno

Plugin:
Eveeno
Plugin Slug:
eveeno
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

OS DataHub Maps

Plugin Slug:
os-datahub-maps
Installations
200+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.8.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.4.

Password for WP

Plugin Slug:
password-for-wp
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Plezi

Plugin:
Plezi
Plugin Slug:
plezi
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

WP GeoNames

Plugin Slug:
wp-geonames
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.1.

Add infos to The Events Calendar

Plugin Slug:
add-infos-to-the-events-calendar
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

IMS Countdown

Plugin Slug:
ims-countdown
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.
Plugin Slug:
my-idx-home-search
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata
Installations
100+
Vulnerability:
Path Traversal
Patched in Version:
4.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.9.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

GMap Targeting – Simple Targeting Inside Google Maps

Plugin Slug:
gmap-targeting
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

ONLYOFFICE DocSpace

Plugin Slug:
onlyoffice-docspace
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Pdf & Print to Post – Custom Post Type and Pages

Plugin Slug:
post-to-pdf
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

Ganohrs Toggle Shortcode

Plugin Slug:
ganohrs-toggle-shortcode
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.5.

Events Listing Widget

Plugin Slug:
events-listing-widget
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

GeoDataSource Country Region DropDown

Plugin Slug:
geodatasource-country-region-dropdown
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

NPS computy

Plugin Slug:
nps-computy
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.3.

Social Media Shortcodes

Plugin Slug:
social-media-shortcodes
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

Employee Directory – Staff Directory and Listing

Plugin Slug:
employee-staff-directory
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Sell BTC – Cryptocurrency Selling Calculator

Plugin Slug:
sell-btc-by-hayyatapps
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Docus – YouTube Video Playlist

Plugin Slug:
docus
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Orange Comfort+ accessibility toolbar for WordPress

Plugin Slug:
orange-confort-plus
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.1.

Peter’s Date Countdown

Plugin Slug:
peters-date-countdown
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

WP FOFT Loader

Plugin Slug:
wp-foft-loader
Installations
10+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.1.40
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.40.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Broken Access Control
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

ARMember Premium

Plugin:
ARMember Premium
Plugin Slug:
armember
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.1.

Bit Form

Plugin:
Bit Form
Plugin Slug:
bit-form
Vulnerability:
SQL Injection
Patched in Version:
2.13.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.13.10.

bodi0’s Easy Cache

Plugin:
bodi0’s Easy Cache
Plugin Slug:
bodi0s-easy-cache
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.

Bridge Core

Plugin:
Bridge Core
Plugin Slug:
bridge-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.

EventON-RSVP

Plugin:
EventON-RSVP
Plugin Slug:
eventon-rsvp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.5.

Fluent Forms Pro Add On Pack

Plugin:
Fluent Forms Pro Add On Pack
Plugin Slug:
fluentformpro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.13.

Integrate Google Drive

Plugin:
Integrate Google Drive
Plugin Slug:
integrate-google-drive
Vulnerability:
Broken Access Control
Patched in Version:
1.3.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.9.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.

Paid Memberships Pro

Plugin:
Paid Memberships Pro
Plugin Slug:
paid-memberships-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.12.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.8.

Community by PeepSo

Plugin:
Community by PeepSo
Plugin Slug:
peepso-core
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.2.

Community by PeepSo

Plugin:
Community by PeepSo
Plugin Slug:
peepso-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.6.0.

Porto Theme – Functionality

Plugin:
Porto Theme – Functionality
Plugin Slug:
porto-functionality
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.0.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Reflector

Plugin:
Reflector
Plugin Slug:
reflector-plugins
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.3.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.25.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.0.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
Broken Access Control
Patched in Version:
2.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.1.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.11.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.11.

Salient Core

Plugin:
Salient Core
Plugin Slug:
salient-core
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.8.

Salient Shortcodes

Plugin:
Salient Shortcodes
Plugin Slug:
salient-shortcodes
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

Salient Shortcodes

Plugin:
Salient Shortcodes
Plugin Slug:
salient-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

School Management

Plugin:
School Management
Plugin Slug:
school-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
92.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 92.0.0.

Simple Locator

Plugin:
Simple Locator
Plugin Slug:
simple-locator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Smart Appointment & Booking

Plugin Slug:
smart-appointment-booking
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Whizz Plugins

Plugin:
Whizz Plugins
Plugin Slug:
whizz-plugins
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Broken Authentication
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Broken Authentication
Patched in Version:
4.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.4.

WooCommerce Support Ticket System

Plugin:
WooCommerce Support Ticket System
Plugin Slug:
woocommerce-support-ticket-system
Vulnerability:
Arbitrary File Deletion
Patched in Version:
17.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 17.8.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.6.6.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.6.7.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 16.9.

WPB Show Core

Plugin:
WPB Show Core
Plugin Slug:
wpb-show-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.

WordPress Themes — 14 Patched / 5 Unpatched

WordPress Dating Theme

Theme:
WordPress Dating Theme
Theme Slug:
DA10
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cartify – WooCommerce Gutenberg WordPress Theme

Theme:
Cartify – WooCommerce Gutenberg WordPress Theme
Theme Slug:
cartify
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Meris

Theme:
Meris
Theme Slug:
meris
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SevenHills

Theme:
SevenHills
Theme Slug:
sevenhills
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

VidoRev

Theme:
VidoRev
Theme Slug:
vidorev
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Royal Elementor Kit

Theme Slug:
royal-elementor-kit
Downloads
986,469
Vulnerability:
Broken Access Control
Patched in Version:
1.0.117
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.117.

Besa

Theme:
Besa
Theme Slug:
besa
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.16.

CozyStay

Theme:
CozyStay
Theme Slug:
cozystay
Vulnerability:
Local File Inclusion
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Broken Access Control
Patched in Version:
1.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.5.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.5.

Grand Conference

Theme:
Grand Conference
Theme Slug:
grandconference
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.5.

Hara

Theme:
Hara
Theme Slug:
hara
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.18.

Nestin

Theme:
Nestin
Theme Slug:
nestin
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.6.

PatioTime

Theme:
PatioTime
Theme Slug:
patiotime
Vulnerability:
PHP Object Injection
Patched in Version:
2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.

PatioTime

Theme:
PatioTime
Theme Slug:
patiotime
Vulnerability:
Local File Inclusion
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

PhotoMe

Theme:
PhotoMe
Theme Slug:
photome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.7.2.

Travelicious

Theme:
Travelicious
Theme Slug:
travelicious
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.7.

Unicamp

Theme:
Unicamp
Theme Slug:
unicamp
Vulnerability:
Local File Inclusion
Patched in Version:
2.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.

Urna

Theme:
Urna
Theme Slug:
urna
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.13.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security