WordPress Vulnerability Report

WordPress Vulnerability Report — March 25, 2026

Since last week, 331 new vulnerabilities have emerged in the WordPress ecosystem, including 275 plugins and 56 themes. Of those, 120 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 331 vulnerabilities have been publicly disclosed. Security patches for 211 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 120 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is now available, addressing 10 security issues and a bug that affected template file loading on a limited number of sites. Because this is a security release, it is recommended that you update your sites immediately.

Also, WordPress 7.0 RC1 is ready for download and testing! As this is a pre-release version, it is intended for testing and development only and should not be installed on production or mission-critical sites. Organizations should use local or staging environments to evaluate compatibility and new features before the final rollout.

WordPress 7.0 is scheduled for release on April 9, 2026.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 162 Patched / 113 Unpatched

Product Slider, Product Grid, Product Masonry

Plugin Slug:
woocommerce-products-slider
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Coinbase Commerce – Crypto Gateway for WooCommerce

Plugin Slug:
commerce-coinbase-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CP Multi View Events Calendar

Plugin Slug:
cp-multi-view-calendar
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TotalPoll for Polls and Contests

Plugin Slug:
totalpoll-lite
Installations
1,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gutenberg Blocks – Unlimited blocks For Gutenberg

Plugin Slug:
unlimited-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GZSEO

Plugin:
GZSEO
Plugin Slug:
gzseo
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ViaBill – WooCommerce

Plugin Slug:
viabill-woocommerce
Installations
500+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Rearrange for WooCommerce

Plugin Slug:
products-rearrange-woocommerce
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Product Rearrange for WooCommerce

Plugin Slug:
products-rearrange-woocommerce
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Remoji – Post/Comment Reaction and Enhancement

Plugin Slug:
remoji
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widget Wrangler

Plugin Slug:
widget-wrangler
Installations
200+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

File Uploader for WooCommerce

Plugin Slug:
file-uploader-for-woocommerce
Installations
100+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Admin Safety Guard — Login Security & 2FA

Plugin Slug:
admin-safety-guard
Installations
10+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ad Short

Plugin:
Ad Short
Plugin Slug:
ad-short
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Google Social Profiles to Knowledge Graph Box

Plugin:
Add Google Social Profiles to Knowledge Graph Box
Plugin Slug:
add-google-social-profiles-to-knowledge-graph-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACPT (Pro) – Custom Post Types Plugin for WordPress

Plugin:
ACPT (Pro) – Custom Post Types Plugin for WordPress
Plugin Slug:
advanced-custom-post-type
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Alfie

Plugin:
Alfie
Plugin Slug:
alfie-the-productfeedtool-wp-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Any Post Slider

Plugin:
Any Post Slider
Plugin Slug:
any-post-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:
App Builder
Plugin Slug:
app-builder
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reward Video Ad for WordPress

Plugin:
Reward Video Ad for WordPress
Plugin Slug:
applixir
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appmax

Plugin:
Appmax
Plugin Slug:
appmax
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ave Core

Plugin:
Ave Core
Plugin Slug:
ave-core
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin:
Build App Online
Plugin Slug:
build-app-online
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CMS Commander

Plugin:
CMS Commander
Plugin Slug:
cms-commander-client
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comment SPAM Wiper

Plugin:
Comment SPAM Wiper
Plugin Slug:
comment-spam-wiper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Company Posts for LinkedIn

Plugin:
Company Posts for LinkedIn
Plugin Slug:
company-posts-for-linkedin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Syndication Toolkit

Plugin:
Content Syndication Toolkit
Plugin Slug:
content-syndication-toolkit
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Curly Core

Plugin:
Curly Core
Plugin Slug:
curly-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:
e-shot
Plugin Slug:
e-shot-form-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Image Gallery
Plugin Slug:
easy-image-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ecover Builder For Dummies

Plugin:
Ecover Builder For Dummies
Plugin Slug:
ecover-builder-for-dummies
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Font Awesome

Plugin:
Ed’s Font Awesome
Plugin Slug:
eds-font-awesome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Social Share

Plugin:
Ed’s Social Share
Plugin Slug:
eds-social-share
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementCamp

Plugin:
ElementCamp
Plugin Slug:
element-camp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Expire Users

Plugin:
Expire Users
Plugin Slug:
expire-users
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin:
Fonts Manager | Custom Fonts
Plugin Slug:
fonts-manager-custom-fonts
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FuseDesk

Plugin:
FuseDesk
Plugin Slug:
fusedesk
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

fyyd podcast shortcodes

Plugin:
fyyd podcast shortcodes
Plugin Slug:
fyyd-podcast-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Go Night Pro

Plugin:
Go Night Pro
Plugin Slug:
go-night-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hr Press Lite

Plugin:
Hr Press Lite
Plugin Slug:
hr-press-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Integration with Hubspot Forms

Plugin:
Integration with Hubspot Forms
Plugin Slug:
integration-with-hubspot-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Invelity Product Feeds

Plugin:
Invelity Product Feeds
Plugin Slug:
invelity-products-feeds
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

itsukaita

Plugin:
itsukaita
Plugin Slug:
itsukaita
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iVysilani Shortcode

Plugin:
iVysilani Shortcode
Plugin Slug:
ivysilani-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Linksy Search and Replace

Plugin:
Linksy Search and Replace
Plugin Slug:
linksy-search-and-replace
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Listeo Core

Plugin:
Listeo Core
Plugin Slug:
listeo-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lobot Slider Administrator

Plugin:
Lobot Slider Administrator
Plugin Slug:
lobot-slider-administrator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

login_register

Plugin:
login_register
Plugin Slug:
login-register
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mandatory Field

Plugin:
Mandatory Field
Plugin Slug:
mandatory-fields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
MimeTypes Link Icons
Plugin Slug:
mimetypes-link-icons
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
MinhNhut Link Gateway
Plugin Slug:
minhnhut-link-gateway
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Modern Events Calendar

Plugin:
Modern Events Calendar
Plugin Slug:
modern-events-calendar
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Functional Flexi Lightbox

Plugin:
Multi Functional Flexi Lightbox
Plugin Slug:
multi-functional-flexi-lightbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Post Carousel by Category

Plugin:
Multi Post Carousel by Category
Plugin Slug:
multi-post-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

myLinksDump

Plugin:
myLinksDump
Plugin Slug:
mylinksdump
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Neos Connector for Fakturama

Plugin:
Neos Connector for Fakturama
Plugin Slug:
neos-connector-for-fakturama
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Outgrow

Plugin:
Outgrow
Plugin Slug:
outgrow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Paypal Shortcodes

Plugin:
Paypal Shortcodes
Plugin Slug:
paypal-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PQ Addons – Creative Elementor Widgets

Plugin:
PQ Addons – Creative Elementor Widgets
Plugin Slug:
peacefulqode-elementzplus-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:
Performance Monitor
Plugin Slug:
performance-monitor
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Flagger

Plugin:
Post Flagger
Plugin Slug:
post-flagger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Snippits

Plugin:
Post Snippits
Plugin Slug:
post-snippits
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Plugin:
Post Affiliate Pro
Plugin Slug:
postaffiliatepro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pre* Party Resource Hints

Plugin:
Pre* Party Resource Hints
Plugin Slug:
pre-party-browser-hints
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Punnel – Landing Page Builder

Plugin:
Punnel – Landing Page Builder
Plugin Slug:
punnel-landing-page-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quentn WP

Plugin:
Quentn WP
Plugin Slug:
quentn-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Redirect countdown

Plugin:
Redirect countdown
Plugin Slug:
redirect-countdown
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:
REST API TO MiniProgram
Plugin Slug:
rest-api-to-miniprogram
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Review Map by RevuKangaroo

Plugin:
Review Map by RevuKangaroo
Plugin Slug:
review-map-by-revukangaroo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Ricerca – advanced search
Plugin Slug:
ricerca-smart-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Infinite Scroll

Plugin:
WooCommerce Infinite Scroll
Plugin Slug:
sb-woocommerce-infinite-scroll
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Schema Shortcode

Plugin:
Schema Shortcode
Plugin Slug:
schema-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sheets2Table

Plugin:
Sheets2Table
Plugin Slug:
sheets2table
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sherk Custom Post Type Displays

Plugin:
Sherk Custom Post Type Displays
Plugin Slug:
sherk-custom-post-type-displays
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weaver Show Posts

Plugin:
Weaver Show Posts
Plugin Slug:
show-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Show Posts list

Plugin:
Show Posts list
Plugin Slug:
show-posts-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Football Scoreboard

Plugin:
Simple Football Scoreboard
Plugin Slug:
simple-football-score-board
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smarter Analytics

Plugin:
Smarter Analytics
Plugin Slug:
smarter-analytics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Speedup Optimization

Plugin:
Speedup Optimization
Plugin Slug:
speedup-optimization
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SR WP Minify HTML

Plugin:
SR WP Minify HTML
Plugin Slug:
sr-wp-minify-html
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Survey

Plugin:
Survey
Plugin Slug:
survey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:
Task Manager
Plugin Slug:
task-manager
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Text Toggle

Plugin:
Text Toggle
Plugin Slug:
text-toggle
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Aisle Core

Plugin:
The Aisle Core
Plugin Slug:
theaisle-core
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tour & Activity Operator Plugin for TourCMS

Plugin:
Tour & Activity Operator Plugin for TourCMS
Plugin Slug:
tour-operator-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feeds

Plugin:
Twitter Feeds
Plugin Slug:
twitter-feeds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elements for Elementor (Premium)

Plugin:
Unlimited Elements for Elementor (Premium)
Plugin Slug:
unlimited-elements-for-elementor-premium
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Vagaro Booking Widget

Plugin:
Vagaro Booking Widget
Plugin Slug:
vagaro-booking-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wikilookup

Plugin:
Wikilookup
Plugin Slug:
wikilookup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:
WishList Member X
Plugin Slug:
wishlist-member-x
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WishList Member X

Plugin:
WishList Member X
Plugin Slug:
wishlist-member-x
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WZone

Plugin:
WZone
Plugin Slug:
woozone
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress PayPal Donation

Plugin:
WordPress PayPal Donation
Plugin Slug:
wordpress-paypal-donation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Chatbot for Messenger

Plugin:
WP-Chatbot for Messenger
Plugin Slug:
wp-chatbot
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Games Embed

Plugin:
WP Games Embed
Plugin Slug:
wp-games-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP NG Weather

Plugin:
WP NG Weather
Plugin Slug:
wp-ng-weather
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Posts Re-order

Plugin:
WP Posts Re-order
Plugin Slug:
wp-posts-re-order
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Random Button

Plugin:
WP Random Button
Plugin Slug:
wp-random-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:
WPBookit Pro
Plugin Slug:
wpbookit-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:
WPBookit Pro
Plugin Slug:
wpbookit-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPFAQBlock

Plugin:
WPFAQBlock
Plugin Slug:
wpfaqblock
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Writeprint Stylometry

Plugin:
Writeprint Stylometry
Plugin Slug:
writeprint-stylometry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xhanch – My Advanced Settings

Plugin:
Xhanch – My Advanced Settings
Plugin Slug:
xhanch-my-advanced-settings
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoast Duplicate Post

Plugin Slug:
duplicate-post
Installations
4,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.

Autoptimize

Plugin Slug:
autoptimize
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.15.

Autoptimize

Plugin Slug:
autoptimize
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.15.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.0.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.0.06.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.50
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.50.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.5.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
90,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.5.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.6.2.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.0.

Online Scheduling and Appointment Booking System – Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
26.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 26.8.

EmailKit – Email Customizer for WooCommerce & WP

Plugin Slug:
emailkit
Installations
70,000+
Vulnerability:
Path Traversal
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

SMTP Mailer

Plugin Slug:
smtp-mailer
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.25.
Plugin Slug:
contextual-related-posts
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Privilege Escalation
Patched in Version:
5.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.3.

Visual Portfolio, Photo Gallery & Post Grid

Plugin Slug:
visual-portfolio
Installations
60,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.
Plugin Slug:
simply-gallery-block
Installations
40,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
3.3.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.2.1.

PPWP – Password Protect Pages

Plugin Slug:
password-protect-page
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.16.

Ultimate Post Kit Addons for Elementor

Plugin Slug:
ultimate-post-kit
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.22.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.0.0.

WP Custom Admin Interface

Plugin Slug:
wp-custom-admin-interface
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.43.

Kali Forms — Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms
Installations
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.4.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.10.

New User Approve

Plugin Slug:
new-user-approve
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.2.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.23.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Broken Authentication
Patched in Version:
3.2.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.25.

Review Schema – Review & Structure Data Schema Plugin

Plugin Slug:
review-schema
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

Code Embed

Plugin:
Code Embed
Plugin Slug:
simple-embed-code
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

Subscriptions for WooCommerce

Plugin Slug:
subscriptions-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.3.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.12.

Spam Protect for Contact Form 7

Plugin Slug:
wp-contact-form-7-spam-blocker
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.10.

WP REST Cache

Plugin Slug:
wp-rest-cache
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2026.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2026.1.1.

WPVulnerability

Plugin Slug:
wpvulnerability
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.1.1.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.64
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.64.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.5.

WP TripAdvisor Review Slider

Plugin Slug:
wp-tripadvisor-review-slider
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.2.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.8.4.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.2.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.8.1.

JS Help Desk – AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.10.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.1.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.10.

WP Review Slider

Plugin Slug:
wp-facebook-reviews
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.0.

Get Use APIs – JSON Content Importer

Plugin Slug:
json-content-importer
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.10.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.8.2.

User Verification by PickPlugins

Plugin Slug:
user-verification
Installations
5,000+
Vulnerability:
Broken Authentication
Patched in Version:
2.0.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.46.

Fraud Prevention For WooCommerce and EDD

Plugin Slug:
woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers
Installations
5,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
2.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.4.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

RSFirewall!

Plugin Slug:
rsfirewall
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.46
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.46.

Abandoned Cart Recovery for WooCommerce

Plugin Slug:
woo-abandoned-cart-recovery
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.11.

WPJAM Basic

Plugin Slug:
wpjam-basic
Installations
4,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
6.9.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.9.2.1.
Plugin Slug:
wptelegram-widget
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.14.

JS Archive List

Plugin Slug:
jquery-archive-list-widget
Installations
3,000+
Vulnerability:
PHP Object Injection
Patched in Version:
6.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.2.0.

Kargo Takip

Plugin Slug:
kargo-takip-turkiye
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.4.

Bit SMTP – Easy SMTP Solution with Email Logs

Plugin Slug:
bit-smtp
Installations
2,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.3.

Comments Import & Export

Plugin Slug:
comments-import-export-woocommerce
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.0.

Info Cards – Add Text and Media in Card Layouts

Plugin Slug:
info-cards
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.3.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.1.3.

Photo Engine (Media Organizer & Lightroom)

Plugin Slug:
wplr-sync
Installations
2,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
6.5.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.5.0.

avalex – Automatisch sichere Rechtstexte

Plugin Slug:
avalex
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Contact List – Online Staff Directory & Address Book

Plugin Slug:
contact-list
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.19.

Flexmls® IDX Plugin

Plugin Slug:
flexmls-idx
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.15.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.15.10.

Injection Guard

Plugin Slug:
injection-guard
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

My Tickets – Accessible Event Ticketing

Plugin Slug:
my-tickets
Installations
700+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Premmerce Redirect Manager

Plugin Slug:
premmerce-redirect-manager
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.13.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Taboola Pixel

Plugin Slug:
taboola-pixel
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Keep Backup Daily

Plugin Slug:
keep-backup-daily
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Keep Backup Daily

Plugin Slug:
keep-backup-daily
Installations
300+
Vulnerability:
Path Traversal
Patched in Version:
2.1.3
Severity Score:
Low
The vulnerability has been patched, so you should update to version 2.1.3.

Helpdesk Support Ticket System for WooCommerce

Plugin Slug:
support-ticket-system-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

ilGhera Carta Docente for WooCommerce

Plugin Slug:
wc-carta-docente
Installations
200+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.1.
Plugin Slug:
ays-slider
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.

Contact Manager

Plugin Slug:
contact-manager
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.1.

Creator LMS – Online Courses and eLearning Plugin

Plugin Slug:
creatorlms
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.19.

FAQ Builder AYS

Plugin Slug:
faq-builder-ays
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.3.

LearnPress – Sepay Payment

Plugin Slug:
learnpress-sepay-payment
Installations
100+
Vulnerability:
Broken Authentication
Patched in Version:
4.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.1.

Petitioner

Plugin:
Petitioner
Plugin Slug:
petitioner
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
0.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.7.4.

Product File Upload for WooCommerce

Plugin Slug:
products-file-upload-for-woocommerce
Installations
100+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Add Custom Fields to Media

Plugin Slug:
add-custom-fields-to-media
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Draft List

Plugin:
Draft List
Plugin Slug:
simple-draft-list
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.3.

Filestack WP Upload

Plugin Slug:
filestack-upload
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.0.

Activity Log for WordPress

Plugin Slug:
winterlock
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Scoreboard for HTML5 Games Lite

Plugin Slug:
scoreboard-for-html5-game-lite
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.
Plugin Slug:
crpaid-link-manager
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.6.

RockPress

Plugin:
RockPress
Plugin Slug:
ft-rockpress
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.18.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
WP_Estimation_Form
Vulnerability:
Broken Access Control
Patched in Version:
10.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.3.0.

Addon Jobsearch Chat

Plugin:
Addon Jobsearch Chat
Plugin Slug:
addon-jobsearch-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Addon Jobsearch Chat

Plugin:
Addon Jobsearch Chat
Plugin Slug:
addon-jobsearch-chat
Vulnerability:
SQL Injection
Patched in Version:
3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.

SUMO Affiliates Pro

Plugin:
SUMO Affiliates Pro
Plugin Slug:
affs
Vulnerability:
PHP Object Injection
Patched in Version:
11.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 11.4.0.

Aimogen Pro

Plugin:
Aimogen Pro
Plugin Slug:
aimogen-pro
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.6.

Elated Listing

Plugin:
Elated Listing
Plugin Slug:
eltd-listing
Vulnerability:
Broken Access Control
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

XStore Core

Plugin:
XStore Core
Plugin Slug:
et-core-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.5.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.15.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.15.0.

Gyan Elements

Plugin:
Gyan Elements
Plugin Slug:
gyan-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

Green Downloads

Plugin:
Green Downloads
Plugin Slug:
halfdata-paypal-green-downloads
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.09
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.09.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Broken Authentication
Patched in Version:
13.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.7.1.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

Jobica Core

Plugin:
Jobica Core
Plugin Slug:
jobica-core
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.2.

Lumise Product Designer

Plugin:
Lumise Product Designer
Plugin Slug:
lumise
Vulnerability:
SQL Injection
Patched in Version:
2.0.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.9.

Miraculous Core Plugin

Plugin:
Miraculous Core Plugin
Plugin Slug:
miraculouscore
Vulnerability:
SQL Injection
Patched in Version:
2.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.2.

Motta Addons

Plugin:
Motta Addons
Plugin Slug:
motta-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

NaturaLife Extensions

Plugin:
NaturaLife Extensions
Plugin Slug:
naturalife-extensions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

NaturaLife Extensions

Plugin:
NaturaLife Extensions
Plugin Slug:
naturalife-extensions
Vulnerability:
Local File Inclusion
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
SQL Injection
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Organici Library

Plugin:
Organici Library
Plugin Slug:
noo-organici-library
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Visionary Core

Plugin:
Visionary Core
Plugin Slug:
noo-visionary-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Visionary Core

Plugin:
Visionary Core
Plugin Slug:
noo-visionary-core
Vulnerability:
PHP Object Injection
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

Phox Hosting

Plugin:
Phox Hosting
Plugin Slug:
phox-host
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.9.

Salon Booking System Pro

Plugin:
Salon Booking System Pro
Plugin Slug:
salon-booking-plugin-pro
Vulnerability:
Broken Authentication
Patched in Version:
10.30.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.30.12.

tagDiv Opt-In Builder

Plugin:
tagDiv Opt-In Builder
Plugin Slug:
td-subscription
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

The Grid

Plugin:
The Grid
Plugin Slug:
the-grid
Vulnerability:
Broken Access Control
Patched in Version:
2.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.0.

The Grid

Plugin:
The Grid
Plugin Slug:
the-grid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

UpSolution Core

Plugin:
UpSolution Core
Plugin Slug:
us-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.42
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.42.

WooCommerce Support Ticket System

Plugin:
WooCommerce Support Ticket System
Plugin Slug:
woocommerce-support-ticket-system
Vulnerability:
Arbitrary File Deletion
Patched in Version:
18.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 18.5.

WP Configurator Pro

Plugin:
WP Configurator Pro
Plugin Slug:
wp-configurator-pro
Vulnerability:
Broken Access Control
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Themes — 49 Patched / 7 Unpatched

Apicona

Theme:
Apicona
Theme Slug:
apicona
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jannah

Theme:
Jannah
Theme Slug:
jannah
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kentha

Theme:
Kentha
Theme Slug:
kentha
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Mixtape

Theme:
Mixtape
Theme Slug:
mixtape
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Moments

Theme:
Moments
Theme Slug:
moments
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

The League

Theme:
The League
Theme Slug:
the-league
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Education Zone

Theme Slug:
education-zone
Downloads
483,880
Vulnerability:
Broken Access Control
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Ona

Theme:
Ona
Theme Slug:
ona
Downloads
243,101
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.24
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.24.

Archicon

Theme:
Archicon
Theme Slug:
archicon
Vulnerability:
PHP Object Injection
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Borgholm

Theme:
Borgholm
Theme Slug:
borgholm-marketing-agency-theme
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.

Feedy

Theme:
Feedy
Theme Slug:
feedy
Vulnerability:
Local File Inclusion
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.

Gaea

Theme:
Gaea
Theme Slug:
gaea
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

Goldish

Theme:
Goldish
Theme Slug:
goldish
Vulnerability:
PHP Object Injection
Patched in Version:
3.47
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.47.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.5.

Gracey

Theme:
Gracey
Theme Slug:
gracey
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Halstein

Theme:
Halstein
Theme Slug:
halstein
Vulnerability:
PHP Object Injection
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

IdealAuto

Theme:
IdealAuto
Theme Slug:
idealauto
Vulnerability:
Local File Inclusion
Patched in Version:
3.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.6.

Jaroti

Theme:
Jaroti
Theme Slug:
jaroti
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.

Kamperen

Theme:
Kamperen
Theme Slug:
kamperen
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Kiddy

Theme:
Kiddy
Theme Slug:
kiddy
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.9.

KIDZ

Theme:
KIDZ
Theme Slug:
kidz
Vulnerability:
PHP Object Injection
Patched in Version:
5.25
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.25.

Kunco

Theme:
Kunco
Theme Slug:
kunco
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

Boutique

Theme:
Boutique
Theme Slug:
kute-boutique
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.6.

Leroux

Theme:
Leroux
Theme Slug:
leroux
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Loobek

Theme:
Loobek
Theme Slug:
loobek
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.2.

LoveDate

Theme:
LoveDate
Theme Slug:
lovedate
Vulnerability:
Local File Inclusion
Patched in Version:
3.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.6.

Meloo

Theme:
Meloo
Theme Slug:
meloo
Vulnerability:
PHP Object Injection
Patched in Version:
2.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.2.

MetaMax

Theme:
MetaMax
Theme Slug:
metamax
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Miraculous

Theme:
Miraculous
Theme Slug:
miraculous
Vulnerability:
Broken Access Control
Patched in Version:
2.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.2.

Miti

Theme:
Miti
Theme Slug:
miti
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Molla

Theme:
Molla
Theme Slug:
molla
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.19.

MyDecor

Theme:
MyDecor
Theme Slug:
mydecor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.9.

MyMedi

Theme:
MyMedi
Theme Slug:
mymedi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.7.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
PHP Object Injection
Patched in Version:
3.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.2.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.2.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
SQL Injection
Patched in Version:
4.8.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.8.4.

Nooni

Theme:
Nooni
Theme Slug:
nooni
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.

Pelicula

Theme:
Pelicula
Theme Slug:
pelicula-video-production-and-movie-theme
Vulnerability:
PHP Object Injection
Patched in Version:
1.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.10.

Pendulum

Theme:
Pendulum
Theme Slug:
pendulum
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.5.

Reebox

Theme:
Reebox
Theme Slug:
reebox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.

Ricky

Theme:
Ricky
Theme Slug:
ricky
Vulnerability:
PHP Object Injection
Patched in Version:
2.31
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.31.

Riode

Theme:
Riode
Theme Slug:
riode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.29
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.29.

Sanzo

Theme:
Sanzo
Theme Slug:
sanzo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.3.

Scape

Theme:
Scape
Theme Slug:
scape
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.5.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.16.

Stål

Theme:
Stål
Theme Slug:
stal
Vulnerability:
PHP Object Injection
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

StreamVid

Theme:
StreamVid
Theme Slug:
streamvid
Vulnerability:
Local File Inclusion
Patched in Version:
6.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.8.6.

Tasty Daily

Theme:
Tasty Daily
Theme Slug:
tastydaily
Vulnerability:
PHP Object Injection
Patched in Version:
1.27
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.27.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
PHP Object Injection
Patched in Version:
3.2.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.8.1.

Trendustry

Theme:
Trendustry
Theme Slug:
trendustry
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Vayvo

Theme:
Vayvo
Theme Slug:
vayvo-progression
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.8.

Vex

Theme:
Vex
Theme Slug:
vex
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.9.

VintWood

Theme:
VintWood
Theme Slug:
vintwood
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.9.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
PHP Object Injection
Patched in Version:
8.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.9.

Yobazar

Theme:
Yobazar
Theme Slug:
yobazar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security