WordPress Vulnerability Report

WordPress Vulnerability Report — March 11, 2026

Since last week, 209 new vulnerabilities have emerged in the WordPress ecosystem, including 98 plugins and 111 themes. Of those, 134 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 209 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 134 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.3 is now available and is a mandatory security and maintenance update. This release follows version 6.9.2, which addressed 10 security vulnerabilities but introduced a “blank screen” bug for certain themes. Version 6.9.3 includes all previous security patches while resolving the front-end display issues.

It is recommended that you update your sites to version 6.9.3 immediately to ensure they are protected. For sites supporting automatic background updates, the process will begin shortly. You can find more technical details and the full list of fixes in the official announcement.

The next major release of WordPress will be version 7.0, which is planned for April 9, 2026.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 69 Patched / 29 Unpatched

Bus Ticket Booking with Seat Reservation

Plugin Slug:
bus-ticket-booking-with-seat-reservation
Installations
900+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Carta Online

Plugin Slug:
carta-online
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Secudeal Payments for Ecommerce

Plugin Slug:
secudeal-payments-for-ecommerce
Installations
10+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Super Stage WP

Plugin Slug:
super-stage-wp
Installations
10+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Consensus Embed

Plugin:
Consensus Embed
Plugin Slug:
consensus-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DA Media GigList

Plugin:
DA Media GigList
Plugin Slug:
damedia-giglist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Handmade Framework

Plugin:
Handmade Framework
Plugin Slug:
handmade-framework
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Infomaniak Connect for OpenID

Plugin:
Infomaniak Connect for OpenID
Plugin Slug:
infomaniak-connect-openid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lisfinity Core

Plugin:
Lisfinity Core
Plugin Slug:
lisfinity-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LMS Elementor Pro

Plugin:
LMS Elementor Pro
Plugin Slug:
lms-elementor-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

LotekMedia Popup Form

Plugin:
LotekMedia Popup Form
Plugin Slug:
ltm-popup-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media Library Alt Text Editor

Plugin:
Media Library Alt Text Editor
Plugin Slug:
media-library-alt-text-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
My Album Gallery
Plugin Slug:
my-album-gallery
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyQtip – easy qTip2

Plugin:
MyQtip – easy qTip2
Plugin Slug:
myqtip-easy-qtip2
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Purchase Button For Affiliate Link
Plugin Slug:
purchase-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

True Ranker

Plugin:
True Ranker
Plugin Slug:
seo-local-rank
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Show YouTube video

Plugin:
Show YouTube video
Plugin Slug:
show-youtube-video
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Guardian News Feed

Plugin:
The Guardian News Feed
Plugin Slug:
the-guardian-news-feed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin:
WP App Bar
Plugin Slug:
wp-app-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Font Pairing Preview For Landing Pages

Plugin:
Font Pairing Preview For Landing Pages
Plugin Slug:
wp-font-pairing-preview
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wueen

Plugin:
Wueen
Plugin Slug:
wueen
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.5.3.

Enable Media Replace

Plugin Slug:
enable-media-replace
Installations
600,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.8.

Meta Box

Plugin:
Meta Box
Plugin Slug:
meta-box
Installations
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.11.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.11.2.

Page Builder by SiteOrigin

Plugin Slug:
siteorigin-panels
Installations
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.34.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.34.0.

WP Mail Logging

Plugin Slug:
wp-mail-logging
Installations
300,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.16
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.16.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.7.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.8.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
12.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.8.4.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
12.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.8.4.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.8.6.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.34.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.9.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.9.6.

Fast Page & Post Duplicator

Plugin Slug:
page-or-post-clone
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations
60,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.28.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.28.15.

Seraphinite Accelerator

Plugin Slug:
seraphinite-accelerator
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.28.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.28.15.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Privilege Escalation
Patched in Version:
5.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.3.

OoohBoi Steroids for Elementor

Plugin Slug:
ooohboi-steroids-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.25.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
3.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.6.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.5.

My Calendar – Accessible Event Manager

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.4.

WP Booking System – Booking Calendar

Plugin Slug:
wp-booking-system
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.19.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.19.13.

WPZOOM Addons for Elementor – Starter Templates & Widgets

Plugin Slug:
wpzoom-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.2.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.21.

JS Help Desk – AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket
Installations
8,000+
Vulnerability:
SQL Injection
Patched in Version:
2.8.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.3.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.8.2.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.9.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.8.3.

Podlove Web Player

Plugin Slug:
podlove-web-player
Installations
4,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.2.

JS Archive List

Plugin Slug:
jquery-archive-list-widget
Installations
3,000+
Vulnerability:
PHP Object Injection
Patched in Version:
6.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.0.

Stock Ticker

Plugin Slug:
stock-ticker
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.26.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.26.2.

Easy PHP Settings

Plugin Slug:
easy-php-settings
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.5.

Morkva UA Shipping

Plugin Slug:
morkva-ua-shipping
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.10.

All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login

Plugin Slug:
login-with-azure
Installations
600+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.6.

AI ChatBot with ChatGPT and Content Generator by AYS

Plugin Slug:
ays-chatgpt-assistant
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.6.

Apocalypse Meow

Plugin Slug:
apocalypse-meow
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
23.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 23.0.0.

ionCube Tester Plus

Plugin Slug:
ioncube-tester-plus
Installations
300+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

MailArchiver

Plugin Slug:
mailarchiver
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.0.

WP Frontend Profile

Plugin Slug:
wp-front-end-profile
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Hammas Calendar

Plugin Slug:
hammas-calendar
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.12.

MDJM Event Management

Plugin Slug:
mobile-dj-manager
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.8.2.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
1.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.9.

Paid Videochat Turnkey Site – HTML5 PPV Live Webcams

Plugin Slug:
ppv-live-webcams
Installations
30+
Vulnerability:
Privilege Escalation
Patched in Version:
7.3.21
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.3.21.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

ZIP Code Based Content Protection

Plugin Slug:
zip-code-based-content-protection
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.3.

Fluent Forms Pro Add On Pack

Plugin:
Fluent Forms Pro Add On Pack
Plugin Slug:
fluentformpro
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
6.1.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.18.

Fluent Forms Pro Add On Pack

Plugin:
Fluent Forms Pro Add On Pack
Plugin Slug:
fluentformpro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.18.

Master Addons for Elementor Premium

Plugin:
Master Addons for Elementor Premium
Plugin Slug:
master-addons-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.4.

pixfort Core

Plugin:
pixfort Core
Plugin Slug:
pixfort-core
Vulnerability:
Broken Access Control
Patched in Version:
3.2.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.26.

pixfort Core

Plugin:
pixfort Core
Plugin Slug:
pixfort-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.26.

WPSubscription

Plugin:
WPSubscription
Plugin Slug:
subscription
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.8.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.11.

WordPress Themes — 6 Patched / 105 Unpatched

Estate

Theme:
Estate
Theme Slug:
estate
Downloads
58,132
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

OsTende

Theme:
OsTende
Theme Slug:
ostende
Downloads
8,317
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Agrofood

Theme:
Agrofood
Theme Slug:
agrofood
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Aldo

Theme:
Aldo
Theme Slug:
aldo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Amoli

Theme:
Amoli
Theme Slug:
amoli
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Askka

Theme:
Askka
Theme Slug:
askka
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Au Pair Agency – Babysitting & Nanny Theme

Theme:
Au Pair Agency – Babysitting & Nanny Theme
Theme Slug:
au-pair-agency
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Avventure

Theme:
Avventure
Theme Slug:
avventure
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Beelove

Theme:
Beelove
Theme Slug:
beelove
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Berger

Theme:
Berger
Theme Slug:
berger
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bonbon

Theme:
Bonbon
Theme Slug:
bonbon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

BuddyApp

Theme:
BuddyApp
Theme Slug:
buddyapp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Car Zone

Theme:
Car Zone
Theme Slug:
carzone
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CasaMia | Property Rental Real Estate WordPress Theme

Theme:
CasaMia | Property Rental Real Estate WordPress Theme
Theme Slug:
casamia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Chroma

Theme:
Chroma
Theme Slug:
chroma
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Classter

Theme:
Classter
Theme Slug:
classter
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Coinpress

Theme:
Coinpress
Theme Slug:
coinpress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ColorFolio – Freelance Designer WordPress Theme

Theme:
ColorFolio – Freelance Designer WordPress Theme
Theme Slug:
colorfolio
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ConFix

Theme:
ConFix
Theme Slug:
confix
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cookiteer

Theme:
Cookiteer
Theme Slug:
cookiteer
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Craftis

Theme:
Craftis
Theme Slug:
craftis
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

DeepDigital

Theme:
DeepDigital
Theme Slug:
deepdigital
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Dental Clinic

Theme:
Dental Clinic
Theme Slug:
dental
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Dentalux

Theme:
Dentalux
Theme Slug:
dentalux
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Don Peppe

Theme:
Don Peppe
Theme Slug:
donpeppe
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

DroneX

Theme:
DroneX
Theme Slug:
dronex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Edifice

Theme:
Edifice
Theme Slug:
edifice
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

EmojiNation

Theme:
EmojiNation
Theme Slug:
emojination
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Equadio

Theme:
Equadio
Theme Slug:
equadio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Equestrian Centre

Theme:
Equestrian Centre
Theme Slug:
equestrian-centre
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Etchy

Theme:
Etchy
Theme Slug:
etchy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Felizia

Theme:
Felizia
Theme Slug:
felizia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FindAll

Theme:
FindAll
Theme Slug:
findall
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FlashMart

Theme:
FlashMart
Theme Slug:
flashmart
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Foodie

Theme:
Foodie
Theme Slug:
foodie
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gaspard

Theme:
Gaspard
Theme Slug:
gaspard
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gioia

Theme:
Gioia
Theme Slug:
gioia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Global Logistics

Theme:
Global Logistics
Theme Slug:
globallogistics
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Good Homes

Theme:
Good Homes
Theme Slug:
good-homes
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grand Wedding

Theme:
Grand Wedding
Theme Slug:
grandwedding
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Green Thumb

Theme:
Green Thumb
Theme Slug:
greenthumb
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Greenville

Theme:
Greenville
Theme Slug:
greenville
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gridiron

Theme:
Gridiron
Theme Slug:
gridiron
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grit

Theme:
Grit
Theme Slug:
grit
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Handyman

Theme:
Handyman
Theme Slug:
handyman-services
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Healer – Doctor, Clinic & Medical WordPress Theme

Theme:
Healer – Doctor, Clinic & Medical WordPress Theme
Theme Slug:
healer
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Helion

Theme:
Helion
Theme Slug:
helion
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hoverex

Theme:
Hoverex
Theme Slug:
hoverex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Humanum

Theme:
Humanum
Theme Slug:
humanum
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Hypnotherapy

Theme:
Hypnotherapy
Theme Slug:
hypnotherapy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Invetex

Theme:
Invetex
Theme Slug:
invetex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jardi

Theme:
Jardi
Theme Slug:
jardi
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Justitia

Theme:
Justitia
Theme Slug:
justitia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kayon

Theme:
Kayon
Theme Slug:
kayon
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kratz

Theme:
Kratz
Theme Slug:
kratz
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Laurent

Theme:
Laurent
Theme Slug:
laurent
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Law Office

Theme:
Law Office
Theme Slug:
law-office
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lella

Theme:
Lella
Theme Slug:
lella
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lingvico

Theme:
Lingvico
Theme Slug:
lingvico
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Listify

Theme:
Listify
Theme Slug:
listify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Luxury Wine

Theme:
Luxury Wine
Theme Slug:
luxury-wine
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

m2 | Construction and Tools Store

Theme:
m2 | Construction and Tools Store
Theme Slug:
m2-ce
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Manoir

Theme:
Manoir
Theme Slug:
manoir
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Maxify

Theme:
Maxify
Theme Slug:
maxify
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Meals & Wheels

Theme:
Meals & Wheels
Theme Slug:
meals-wheels
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Melody

Theme:
Melody
Theme Slug:
melodyschool
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MoneyFlow

Theme:
MoneyFlow
Theme Slug:
moneyflow
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Morning Records

Theme:
Morning Records
Theme Slug:
morning-records
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Motorix

Theme:
Motorix
Theme Slug:
motorix
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Mounthood

Theme:
Mounthood
Theme Slug:
mounthood
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Mr. Cobbler

Theme:
Mr. Cobbler
Theme Slug:
mr-cobbler
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

N7 | Golf Club Sports & Events

Theme:
N7 | Golf Club Sports & Events
Theme Slug:
n7-golf-club
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nelson

Theme:
Nelson
Theme Slug:
nelson
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

NeoBeat

Theme:
NeoBeat
Theme Slug:
neobeat
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nuts

Theme:
Nuts
Theme Slug:
nuts
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pets Club

Theme:
Pets Club
Theme Slug:
petclub
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Printy

Theme:
Printy
Theme Slug:
printy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Progress

Theme:
Progress
Theme Slug:
progress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ProLingua

Theme:
ProLingua
Theme Slug:
prolingua
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Prowess

Theme:
Prowess
Theme Slug:
prowess
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Quanzo

Theme:
Quanzo
Theme Slug:
quanzo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ratatouille

Theme:
Ratatouille
Theme Slug:
ratatouille
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Roisin

Theme:
Roisin
Theme Slug:
roisin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Scientia

Theme:
Scientia
Theme Slug:
scientia
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ShiftCV

Theme:
ShiftCV
Theme Slug:
shift-cv
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Solaris

Theme:
Solaris
Theme Slug:
solaris
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Stargaze

Theme:
Stargaze
Theme Slug:
stargaze
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tediss

Theme:
Tediss
Theme Slug:
tediss
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

The Qlean

Theme:
The Qlean
Theme Slug:
the-qlean
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Thebe

Theme:
Thebe
Theme Slug:
thebe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

TheBi

Theme:
TheBi
Theme Slug:
thebi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Thecs

Theme:
Thecs
Theme Slug:
thecs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Translogic

Theme:
Translogic
Theme Slug:
translogic
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Triompher

Theme:
Triompher
Theme Slug:
triompher
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tripgo

Theme:
Tripgo
Theme Slug:
tripgo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tuning

Theme:
Tuning
Theme Slug:
tuning
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Unica

Theme:
Unica
Theme Slug:
unica
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

VegaDays

Theme:
VegaDays
Theme Slug:
vegadays
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Victo

Theme:
Victo
Theme Slug:
victo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Vixus

Theme:
Vixus
Theme Slug:
vixus
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wanderland

Theme:
Wanderland
Theme Slug:
wanderland
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme

Theme:
AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme
Theme Slug:
window-ac-services
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wizor’s

Theme:
Wizor’s
Theme Slug:
wizors-investments
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yottis

Theme:
Yottis
Theme Slug:
yottis
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yungen

Theme:
Yungen
Theme Slug:
yungen
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:
Blocksy
Theme Slug:
blocksy
Downloads
6,399,494
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.31.

Charety

Theme:
Charety
Theme Slug:
charety
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.2.

Keenarch

Theme:
Keenarch
Theme Slug:
keenarch
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Lendiz

Theme:
Lendiz
Theme Slug:
lendiz
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Nutrie

Theme:
Nutrie
Theme Slug:
nutrie
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Remons

Theme:
Remons
Theme Slug:
remons
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security