WordPress Vulnerability Report

WordPress Vulnerability Report — February 25, 2026

Since last week, 244 new vulnerabilities have emerged in the WordPress ecosystem, including 205 plugins and 39 themes. Of those, 80 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 244 vulnerabilities have been publicly disclosed. Security patches for 164 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 80 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 7.0 Beta 1 is now available for testing. As this is a pre-release version, it is intended for testing and development only and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

The full release of WordPress 7.0 is currently scheduled for April 9, 2026. You can find the complete release schedule and technical testing details in the official announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 156 Patched / 49 Unpatched

SiteGuard WP Plugin

Plugin Slug:
siteguard
Installations
500,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premmerce

Plugin:
Premmerce
Plugin Slug:
premmerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Prodigy Commerce

Plugin Slug:
prodigy-commerce
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

TalkJS

Plugin:
TalkJS
Plugin Slug:
talkjs
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Filestack

Plugin:
Filestack
Plugin Slug:
filepicker-media-uploader
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Address Bar Ads

Plugin:
Address Bar Ads
Plugin Slug:
address-bar-ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advance Block Extend

Plugin:
Advance Block Extend
Plugin Slug:
advance-block-extend
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Applay – Shortcodes

Plugin:
Applay – Shortcodes
Plugin Slug:
applay-shortcodes
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BlueSnap Payment Gateway for WooCommerce

Plugin:
BlueSnap Payment Gateway for WooCommerce
Plugin Slug:
bluesnap-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clasifico Listing

Plugin:
Clasifico Listing
Plugin Slug:
clasifico-listing
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Country Blocker for AdSense

Plugin Slug:
country-blocker-for-adsense
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dealia – Request a quote

Plugin Slug:
dealia-request-a-quote
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dealia – Request a quote

Plugin Slug:
dealia-request-a-quote
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Booking Manager

Plugin:
DesignThemes Booking Manager
Plugin Slug:
designthemes-booking-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Directory Addon

Plugin:
DesignThemes Directory Addon
Plugin Slug:
designthemes-directory-addon
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Directory Pro

Plugin:
Directory Pro
Plugin Slug:
directory-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Eagle Booking

Plugin:
Eagle Booking
Plugin Slug:
eagle-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Author Image

Plugin:
Easy Author Image
Plugin Slug:
easy-author-image
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Geo Widget

Plugin:
Geo Widget
Plugin Slug:
geowidget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iXML

Plugin:
iXML
Plugin Slug:
ixml
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MP-Ukagaka

Plugin:
MP-Ukagaka
Plugin Slug:
mp-ukagaka
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

News Element Elementor Blog Magazine

Plugin:
News Element Elementor Blog Magazine
Plugin Slug:
news-element
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Title, Description & Open Graph Updater

Plugin:
Page Title, Description & Open Graph Updater
Plugin Slug:
page-title-description-open-graph-updater
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

personal-authors-category

Plugin:
personal-authors-category
Plugin Slug:
personal-authors-category
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Profile Builder Pro

Plugin:
Profile Builder Pro
Plugin Slug:
profile-builder-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Really Simple Security Pro

Plugin:
Really Simple Security Pro
Plugin Slug:
really-simple-ssl-pro
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Remove Post Type Slug

Plugin:
Remove Post Type Slug
Plugin Slug:
remove-post-type-slug
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

salavat counter

Plugin:
salavat counter
Plugin Slug:
salavat-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slider Future

Plugin:
Slider Future
Plugin Slug:
slider-future
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Slidorion

Plugin:
Slidorion
Plugin Slug:
slidorion
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StyleBidet

Plugin:
StyleBidet
Plugin Slug:
stylebidet
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Subitem AL Slider

Plugin:
Subitem AL Slider
Plugin Slug:
subitem-al-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Simple Contact Form

Plugin:
Super Simple Contact Form
Plugin Slug:
super-simple-contact-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tennis Court Bookings

Plugin:
Tennis Court Bookings
Plugin Slug:
tennis-court-bookings
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Toret Manager

Plugin:
Toret Manager
Plugin Slug:
toret-manager
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WeDesignTech Ultimate Booking Addon

Plugin:
WeDesignTech Ultimate Booking Addon
Plugin Slug:
wedesigntech-ultimate-booking-addon
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WeDesignTech Ultimate Booking Addon

Plugin:
WeDesignTech Ultimate Booking Addon
Plugin Slug:
wedesigntech-ultimate-booking-addon
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Whatsiplus Scheduled Notification for Woocommerce

Plugin:
Whatsiplus Scheduled Notification for Woocommerce
Plugin Slug:
whatsiplus-scheduled-notification-for-woocommerce
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Wholesale Lead Capture

Plugin:
Woocommerce Wholesale Lead Capture
Plugin Slug:
woocommerce-wholesale-lead-capture
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Wholesale Lead Capture

Plugin:
Woocommerce Wholesale Lead Capture
Plugin Slug:
woocommerce-wholesale-lead-capture
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP AUDIO GALLERY
Plugin Slug:
wp-audio-gallery
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Client Testimonial Slider

Plugin:
Client Testimonial Slider
Plugin Slug:
wp-client-testimonial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LiquidPoll

Plugin:
LiquidPoll
Plugin Slug:
wp-poll
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

xmlrpc attacks blocker

Plugin:
xmlrpc attacks blocker
Plugin Slug:
xmlrpc-attacks-blocker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XO Event Calendar

Plugin:
XO Event Calendar
Plugin Slug:
xo-event-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.4.

Breadcrumb NavXT

Plugin Slug:
breadcrumb-navxt
Installations
800,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.1.

Easy Table of Contents

Plugin Slug:
easy-table-of-contents
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.79
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.79.

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Plugin Slug:
kadence-blocks
Installations
600,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

BackWPup – WordPress Backup & Restore Plugin

Plugin Slug:
backwpup
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.3.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.2.0.2.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.2.0.1.

Converter for Media – Optimize images | Convert WebP & AVIF

Plugin Slug:
webp-converter-for-media
Installations
500,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.2.

Ally – Web Accessibility & Usability

Plugin Slug:
pojo-accessibility
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
400,000+
Vulnerability:
Content Injection
Patched in Version:
1.71.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.71.0.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.0.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.15.

Advanced Custom Fields: Font Awesome Field

Plugin Slug:
advanced-custom-fields-font-awesome
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.2.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.3.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Backup Migration

Plugin Slug:
backup-backup
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.0.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.47
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.47.

Brevo – Email, SMS, Web Push, Chat, and more.

Plugin Slug:
mailin
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.112.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.112.4.

Razorpay for WooCommerce

Plugin Slug:
woo-razorpay
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.9.

Checkout Field Manager (Checkout Manager) for WooCommerce

Plugin Slug:
woocommerce-checkout-manager
Installations
90,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
7.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.8.6.

Checkout Field Manager (Checkout Manager) for WooCommerce

Plugin Slug:
woocommerce-checkout-manager
Installations
90,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.2.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.98.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.98.0.

StatCounter – Free Real Time Visitor Stats

Plugin Slug:
official-statcounter-plugin-for-wordpress
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Mailchimp List Subscribe Form

Plugin Slug:
mailchimp
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Mesmerize Companion

Plugin Slug:
mesmerize-companion
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.162
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.162.
Plugin Slug:
navz-photo-gallery
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.

Zarinpal Gateway

Plugin Slug:
zarinpal-woocommerce-payment-gateway
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.17.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.5.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
10.14.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.15.

Printful Integration for WooCommerce

Plugin Slug:
printful-shipping-for-woocommerce
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.

Advanced AJAX Product Filters

Plugin Slug:
woocommerce-ajax-filters
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.9.7.

Super Page Cache

Plugin Slug:
wp-cloudflare-page-cache
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.3.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.

YayMail – WooCommerce Email Customizer

Plugin Slug:
yaymail
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.3.3.

YayMail – WooCommerce Email Customizer

Plugin Slug:
yaymail
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 4.3.3.

YayMail – WooCommerce Email Customizer

Plugin Slug:
yaymail
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.3.

YayMail – WooCommerce Email Customizer

Plugin Slug:
yaymail
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.3.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.4.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.4.2.

Easy SVG Support

Plugin Slug:
easy-svg
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.

OneClick Chat to Order

Plugin Slug:
oneclick-whatsapp-order
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.1.0.

Simple Membership

Plugin Slug:
simple-membership
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.1.

Image Hotspot by DevVN

Plugin Slug:
devvn-image-hotspot
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
12.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.4.15.

WP 404 Auto Redirect to Similar Post

Plugin Slug:
wp-404-auto-redirect-to-similar-post
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Apollo13 Framework Extensions

Plugin Slug:
apollo13-framework-extensions
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.
Plugin Slug:
final-tiles-grid-gallery-lite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.11.

Kali Forms — Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.9.

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar

Plugin Slug:
mp3-music-player-by-sonaar
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.1.8.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.

Smartsupp – live chat, AI shopping assistant and chatbots

Plugin Slug:
smartsupp-live-chat
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

Video Conferencing with Zoom

Plugin Slug:
video-conferencing-with-zoom-api
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.6.

WP Customer Reviews

Plugin Slug:
wp-customer-reviews
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.6.

WP Import – Ultimate CSV XML Importer for WordPress

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
7.38
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.38.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.15.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.4.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.14.

Web Accessibility by accessiBe

Plugin Slug:
accessibe
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.
Plugin Slug:
gdpr-cookie-consent
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.3.

Groups

Plugin:
Groups
Plugin Slug:
groups
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.0.

Open User Map

Plugin Slug:
open-user-map
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.17.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.19.

Two Factor (2FA) Authentication via Email

Plugin Slug:
two-factor-2fa-via-email
Installations
10,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.9.

URL Shortify – Simple and Easy URL Shortener

Plugin Slug:
url-shortify
Installations
10,000+
Vulnerability:
Open Redirection
Patched in Version:
1.12.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.2.

URL Shortify – Simple and Easy URL Shortener

Plugin Slug:
url-shortify
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.12.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.4.

Product Table and List Builder for WooCommerce Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.3.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.60.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.60.29.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.41.
Plugin Slug:
album-and-image-gallery-plus-lightbox
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.8.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.5.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.4.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.5.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress
Installations
7,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.2.

Cart All In One For WooCommerce

Plugin Slug:
woo-cart-all-in-one
Installations
6,000+
Vulnerability:
Content Injection
Patched in Version:
1.1.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.22.

Popup Box – Easily Create WordPress Popups

Plugin Slug:
popup-box
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.13.

Import Eventbrite Events

Plugin Slug:
import-eventbrite-events
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.5.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.

Tickera – Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.6.5.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager
Installations
3,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.69.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.69.1.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager
Installations
3,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.69.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 1.69.1.

IMGspider – ????????

Plugin Slug:
imgspider
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.3.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.11.

Simple Ajax Chat – Add a Fast, Secure Chat Box

Plugin Slug:
simple-ajax-chat
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
20260217
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20260217.

Virusdie – One-click website security

Plugin Slug:
virusdie
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

WP-Lister Lite for eBay

Plugin Slug:
wp-lister-for-ebay
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

WowRevenue – Product Bundles & Bulk Discounts

Plugin Slug:
revenue
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.4.

Taskbuilder – Project & Task Management with Kanban

Plugin Slug:
taskbuilder
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.3.

Dam Spam

Plugin:
Dam Spam
Plugin Slug:
dam-spam
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

My Tickets – Accessible Event Ticketing

Plugin Slug:
my-tickets
Installations
700+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.1.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.0.

Build App Online

Plugin Slug:
build-app-online
Installations
500+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.23.

Library Management System

Plugin Slug:
library-management-system
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
3.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.

Order Splitter for WooCommerce

Plugin Slug:
woo-order-splitter
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.6.

Bookster – WordPress Appointment Booking Plugin

Plugin Slug:
bookster
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.0.

Display During Conditional Shortcode

Plugin Slug:
display-during-conditional-shortcode
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Video Share VOD – Turnkey Video Site Builder Script

Plugin Slug:
video-share-vod
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.12.

Private Comment

Plugin Slug:
private-comment
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.0.5.

Frontend User Notes

Plugin Slug:
frontend-user-notes
Installations
50+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Activity Log for WordPress

Plugin Slug:
winterlock
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Keybase.io Verification

Plugin Slug:
wp-keybase-verification
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.

InteractiveCalculator for WordPress

Plugin Slug:
interactivecalculator
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Rent Fetch

Plugin:
Rent Fetch
Plugin Slug:
rentfetch
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.32.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.32.7.

Ads Pro

Plugin:
Ads Pro
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
Broken Access Control
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

ARForms Form Builder

Plugin:
ARForms Form Builder
Plugin Slug:
arforms-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.9.

Lizza LMS Pro

Plugin:
Lizza LMS Pro
Plugin Slug:
lizza-lms-pro
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.4.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.

Truelysell Core

Plugin:
Truelysell Core
Plugin Slug:
truelysell-core
Vulnerability:
Privilege Escalation
Patched in Version:
1.8.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.8.

Uni CPO (Premium)

Plugin:
Uni CPO (Premium)
Plugin Slug:
uni-woo-custom-product-options-premium
Vulnerability:
Broken Access Control
Patched in Version:
4.9.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.61.

Wolmart Core

Plugin:
Wolmart Core
Plugin Slug:
wolmart-core
Vulnerability:
SQL Injection
Patched in Version:
1.9.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.7.

WordPress Themes — 8 Patched / 31 Unpatched

Drift

Theme:
Drift
Theme Slug:
drift
Downloads
30,869
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Mega Store Woocommerce

Theme Slug:
mega-store-woocommerce
Downloads
42,273
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

NewsBlogger

Theme Slug:
newsblogger
Downloads
155,250
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Renden

Theme:
Renden
Theme Slug:
renden
Downloads
328,852
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

A-Mart

Theme:
A-Mart
Theme Slug:
a-mart
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Blabber

Theme:
Blabber
Theme Slug:
blabber
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Buyent

Theme:
Buyent
Theme Slug:
buyent
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Coworking

Theme:
Coworking
Theme Slug:
coworking
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Dentario

Theme:
Dentario
Theme Slug:
dentario
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Fooddy

Theme:
Fooddy
Theme Slug:
fooddy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gustavo

Theme:
Gustavo
Theme Slug:
gustavo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Impacto Patronus

Theme:
Impacto Patronus
Theme Slug:
impacto-patronus
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ironfit

Theme:
Ironfit
Theme Slug:
ironfit
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Isida

Theme:
Isida
Theme Slug:
isida
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jude

Theme:
Jude
Theme Slug:
jude
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kingler

Theme:
Kingler
Theme Slug:
kingler
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Marveland

Theme:
Marveland
Theme Slug:
marveland
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Netmix

Theme:
Netmix
Theme Slug:
netmix
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Parkivia

Theme:
Parkivia
Theme Slug:
parkivia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:
PawFriends – Pet Shop and Veterinary WordPress Theme
Theme Slug:
pawfriends
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PawFriends – Pet Shop and Veterinary WordPress Theme

Theme:
PawFriends – Pet Shop and Veterinary WordPress Theme
Theme Slug:
pawfriends
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photolia

Theme:
Photolia
Theme Slug:
photolia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Redy

Theme:
Redy
Theme Slug:
redy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rhodos

Theme:
Rhodos
Theme Slug:
rhodos
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Saveo

Theme:
Saveo
Theme Slug:
saveo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SevenTrees

Theme:
SevenTrees
Theme Slug:
seventrees
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Soleng

Theme:
Soleng
Theme Slug:
soleng
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tennis Club

Theme:
Tennis Club
Theme Slug:
tennis-sportclub
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

UnlimHost

Theme:
UnlimHost
Theme Slug:
unlimhost
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Valenti

Theme:
Valenti
Theme Slug:
valenti
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zio Alberto

Theme:
Zio Alberto
Theme Slug:
zioalberto
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Context Blog

Theme Slug:
context-blog
Downloads
84,231
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Shopire

Theme:
Shopire
Theme Slug:
shopire
Downloads
89,293
Vulnerability:
Broken Access Control
Patched in Version:
1.0.58
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.58.

Spa and Salon

Theme Slug:
spa-and-salon
Downloads
165,530
Vulnerability:
Broken Access Control
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Grand Restaurant

Theme:
Grand Restaurant
Theme Slug:
grandrestaurant
Vulnerability:
PHP Object Injection
Patched in Version:
7.0.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 7.0.11.

Ippsum

Theme:
Ippsum
Theme Slug:
ippsum
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.1.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
Broken Access Control
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

Sweet Date

Theme:
Sweet Date
Theme Slug:
sweetdate
Vulnerability:
PHP Object Injection
Patched in Version:
4.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.1.

Wiguard

Theme:
Wiguard
Theme Slug:
wiguard
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security