WordPress Vulnerability Report

WordPress Vulnerability Report — April 1, 2026

Since last week, 225 new vulnerabilities have emerged in the WordPress ecosystem, including 203 plugins and 22 themes. Of those, 91 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 225 vulnerabilities have been publicly disclosed. Security patches for 134 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 91 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress 7.0 is scheduled for release on April 9, 2026.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 113 Patched / 90 Unpatched

WPCargo Track & Trace

Plugin Slug:
wpcargo
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
mimetypes-link-icons
Installations
8,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Coinbase Commerce – Crypto Gateway for WooCommerce

Plugin Slug:
commerce-coinbase-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Uploader for WooCommerce

Plugin Slug:
file-uploader-for-woocommerce
Installations
100+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Any Post Slider

Plugin Slug:
any-post-slider
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FuseDesk

Plugin:
FuseDesk
Plugin Slug:
fusedesk
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPFAQBlock– FAQ & Accordion Plugin For Gutenberg

Plugin Slug:
wpfaqblock
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ad Short

Plugin:
Ad Short
Plugin Slug:
ad-short
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Google Social Profiles to Knowledge Graph Box

Plugin:
Add Google Social Profiles to Knowledge Graph Box
Plugin Slug:
add-google-social-profiles-to-knowledge-graph-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Alfie

Plugin:
Alfie
Plugin Slug:
alfie-the-productfeedtool-wp-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

App Builder

Plugin:
App Builder
Plugin Slug:
app-builder
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Reward Video Ad for WordPress

Plugin:
Reward Video Ad for WordPress
Plugin Slug:
applixir
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appmax

Plugin:
Appmax
Plugin Slug:
appmax
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ARForms Form Builder

Plugin:
ARForms Form Builder
Plugin Slug:
arforms-form-builder
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin:
Build App Online
Plugin Slug:
build-app-online
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CMS Commander

Plugin:
CMS Commander
Plugin Slug:
cms-commander-client
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comment Genius

Plugin:
Comment Genius
Plugin Slug:
comment-genius
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comment SPAM Wiper

Plugin:
Comment SPAM Wiper
Plugin Slug:
comment-spam-wiper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Company Posts for LinkedIn

Plugin:
Company Posts for LinkedIn
Plugin Slug:
company-posts-for-linkedin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Syndication Toolkit

Plugin:
Content Syndication Toolkit
Plugin Slug:
content-syndication-toolkit
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:
e-shot
Plugin Slug:
e-shot-form-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Image Gallery
Plugin Slug:
easy-image-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ecover Builder For Dummies

Plugin:
Ecover Builder For Dummies
Plugin Slug:
ecover-builder-for-dummies
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Font Awesome

Plugin:
Ed’s Font Awesome
Plugin Slug:
eds-font-awesome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ed’s Social Share

Plugin:
Ed’s Social Share
Plugin Slug:
eds-social-share
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementCamp

Plugin:
ElementCamp
Plugin Slug:
element-camp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Expire Users

Plugin:
Expire Users
Plugin Slug:
expire-users
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin:
Fonts Manager | Custom Fonts
Plugin Slug:
fonts-manager-custom-fonts
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

fyyd podcast shortcodes

Plugin:
fyyd podcast shortcodes
Plugin Slug:
fyyd-podcast-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Go Night Pro

Plugin:
Go Night Pro
Plugin Slug:
go-night-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hr Press Lite

Plugin:
Hr Press Lite
Plugin Slug:
hr-press-lite
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Integration with Hubspot Forms

Plugin:
Integration with Hubspot Forms
Plugin Slug:
integration-with-hubspot-forms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Invelity Product Feeds

Plugin:
Invelity Product Feeds
Plugin Slug:
invelity-products-feeds
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

itsukaita

Plugin:
itsukaita
Plugin Slug:
itsukaita
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iVysilani Shortcode

Plugin:
iVysilani Shortcode
Plugin Slug:
ivysilani-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Linksy Search and Replace

Plugin:
Linksy Search and Replace
Plugin Slug:
linksy-search-and-replace
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lobot Slider Administrator

Plugin:
Lobot Slider Administrator
Plugin Slug:
lobot-slider-administrator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

login_register

Plugin:
login_register
Plugin Slug:
login-register
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mandatory Field

Plugin:
Mandatory Field
Plugin Slug:
mandatory-fields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
MinhNhut Link Gateway
Plugin Slug:
minhnhut-link-gateway
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Functional Flexi Lightbox

Plugin:
Multi Functional Flexi Lightbox
Plugin Slug:
multi-functional-flexi-lightbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi Post Carousel by Category

Plugin:
Multi Post Carousel by Category
Plugin Slug:
multi-post-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

myLinksDump

Plugin:
myLinksDump
Plugin Slug:
mylinksdump
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Neos Connector for Fakturama

Plugin:
Neos Connector for Fakturama
Plugin Slug:
neos-connector-for-fakturama
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Outgrow

Plugin:
Outgrow
Plugin Slug:
outgrow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Paypal Shortcodes

Plugin:
Paypal Shortcodes
Plugin Slug:
paypal-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PQ Addons – Creative Elementor Widgets

Plugin:
PQ Addons – Creative Elementor Widgets
Plugin Slug:
peacefulqode-elementzplus-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:
Performance Monitor
Plugin Slug:
performance-monitor
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Flagger

Plugin:
Post Flagger
Plugin Slug:
post-flagger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Snippits

Plugin:
Post Snippits
Plugin Slug:
post-snippits
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Affiliate Pro

Plugin:
Post Affiliate Pro
Plugin Slug:
postaffiliatepro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pre* Party Resource Hints

Plugin:
Pre* Party Resource Hints
Plugin Slug:
pre-party-browser-hints
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Punnel – Landing Page Builder

Plugin:
Punnel – Landing Page Builder
Plugin Slug:
punnel-landing-page-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quentn WP

Plugin:
Quentn WP
Plugin Slug:
quentn-wp
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Redirect countdown

Plugin:
Redirect countdown
Plugin Slug:
redirect-countdown
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

REST API TO MiniProgram

Plugin:
REST API TO MiniProgram
Plugin Slug:
rest-api-to-miniprogram
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Review Map by RevuKangaroo

Plugin:
Review Map by RevuKangaroo
Plugin Slug:
review-map-by-revukangaroo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

rexCrawler

Plugin:
rexCrawler
Plugin Slug:
rexcrawler
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Ricerca – advanced search
Plugin Slug:
ricerca-smart-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Schema Shortcode

Plugin:
Schema Shortcode
Plugin Slug:
schema-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sheets2Table

Plugin:
Sheets2Table
Plugin Slug:
sheets2table
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sherk Custom Post Type Displays

Plugin:
Sherk Custom Post Type Displays
Plugin Slug:
sherk-custom-post-type-displays
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weaver Show Posts

Plugin:
Weaver Show Posts
Plugin Slug:
show-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Show Posts list

Plugin:
Show Posts list
Plugin Slug:
show-posts-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Football Scoreboard

Plugin:
Simple Football Scoreboard
Plugin Slug:
simple-football-score-board
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smarter Analytics

Plugin:
Smarter Analytics
Plugin Slug:
smarter-analytics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Speedup Optimization

Plugin:
Speedup Optimization
Plugin Slug:
speedup-optimization
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SR WP Minify HTML

Plugin:
SR WP Minify HTML
Plugin Slug:
sr-wp-minify-html
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Survey

Plugin:
Survey
Plugin Slug:
survey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:
Task Manager
Plugin Slug:
task-manager
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Task Manager

Plugin:
Task Manager
Plugin Slug:
task-manager
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Text Toggle

Plugin:
Text Toggle
Plugin Slug:
text-toggle
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tour & Activity Operator Plugin for TourCMS

Plugin:
Tour & Activity Operator Plugin for TourCMS
Plugin Slug:
tour-operator-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS Pro

Plugin:
Tutor LMS Pro
Plugin Slug:
tutor-pro
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Feeds

Plugin:
Twitter Feeds
Plugin Slug:
twitter-feeds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Blocks Creator Ultimate

Plugin:
Shortcodes Blocks Creator Ultimate
Plugin Slug:
ultimate-shortcodes-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Blocks Creator Ultimate

Plugin:
Shortcodes Blocks Creator Ultimate
Plugin Slug:
ultimate-shortcodes-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Vagaro Booking Widget

Plugin:
Vagaro Booking Widget
Plugin Slug:
vagaro-booking-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wikilookup

Plugin:
Wikilookup
Plugin Slug:
wikilookup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress PayPal Donation

Plugin:
WordPress PayPal Donation
Plugin Slug:
wordpress-paypal-donation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Games Embed

Plugin:
WP Games Embed
Plugin Slug:
wp-games-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP NG Weather

Plugin:
WP NG Weather
Plugin Slug:
wp-ng-weather
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Posts Re-order

Plugin:
WP Posts Re-order
Plugin Slug:
wp-posts-re-order
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Random Button

Plugin:
WP Random Button
Plugin Slug:
wp-random-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-WebAuthn

Plugin:
WP-WebAuthn
Plugin Slug:
wp-webauthn
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:
WPBookit Pro
Plugin Slug:
wpbookit-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit Pro

Plugin:
WPBookit Pro
Plugin Slug:
wpbookit-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Xhanch – My Advanced Settings

Plugin:
Xhanch – My Advanced Settings
Plugin Slug:
xhanch-my-advanced-settings
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.5.

Smart Slider 3

Plugin Slug:
smart-slider-3
Installations
800,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.5.1.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.34.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
90,000+
Vulnerability:
Broken Authentication
Patched in Version:
9.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.2.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.8.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
90,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.5.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.6.3.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
90,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.5.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.6.2.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.14.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.14.2.

Conditional Menus

Plugin Slug:
conditional-menus
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.5.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Privilege Escalation
Patched in Version:
5.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.3.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

Smart Custom Fields

Plugin Slug:
smart-custom-fields
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.7.
Plugin Slug:
simply-gallery-block
Installations
40,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
3.3.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.2.1.

Blackhole for Bad Bots

Plugin Slug:
blackhole-bad-bots
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

LeadConnector

Plugin Slug:
leadconnector
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.22.

PPWP – Password Protect Pages

Plugin Slug:
password-protect-page
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.16.

WPGraphQL

Plugin:
WPGraphQL
Plugin Slug:
wp-graphql
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

Ibtana – WordPress Website Builder

Plugin Slug:
ibtana-visual-editor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.8.

Quads Ads Manager for Google AdSense

Plugin Slug:
quick-adsense-reloaded
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.99
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.99.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.28.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.28.32.

Kali Forms — Contact Form & Drag-and-Drop Builder

Plugin Slug:
kali-forms
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.4.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.10.

Lead Form Builder & Contact Form

Plugin Slug:
lead-form-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.2.

Responsive Plus – Elementor Templates & Starter Sites

Plugin Slug:
responsive-add-ons
Installations
10,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

Review Schema – Review & Structure Data Schema Plugin

Plugin Slug:
review-schema
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.7.

WP DSGVO Tools (GDPR)

Plugin Slug:
shapepress-dsgvo
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.39
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.39.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.12.

WP REST Cache

Plugin Slug:
wp-rest-cache
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2026.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2026.1.1.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

Contact Form Email

Plugin Slug:
contact-form-to-email
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.64
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.64.

WP TripAdvisor Review Slider

Plugin Slug:
wp-tripadvisor-review-slider
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.2.

JS Help Desk – AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
3.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.5.

JS Help Desk – AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.4.

WP Review Slider

Plugin Slug:
wp-facebook-reviews
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.0.

PeproDev Ultimate Invoice

Plugin Slug:
pepro-ultimate-invoice
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.6.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.9.8.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.8.2.

User Verification by PickPlugins

Plugin Slug:
user-verification
Installations
5,000+
Vulnerability:
Broken Authentication
Patched in Version:
2.0.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.46.

RSFirewall!

Plugin Slug:
rsfirewall
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.46
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.46.
Plugin Slug:
wptelegram-widget
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.14.

ElementInvader Addons for Elementor

Plugin Slug:
elementinvader-addons-for-elementor
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.3.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.0.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.0.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Injection Guard

Plugin Slug:
injection-guard
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

The Ultimate WordPress Toolkit – WP Extended

Plugin Slug:
wpextended
Installations
700+
Vulnerability:
Privilege Escalation
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Truebooker – Appointment Booking and Scheduler System

Plugin Slug:
truebooker-appointment-booking
Installations
600+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

Vertex Addons for Elementor

Plugin Slug:
addons-for-elementor-builder
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

FormLift for Infusionsoft Web Forms

Plugin Slug:
formlift
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
7.5.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.22.

Helpdesk Support Ticket System for WooCommerce

Plugin Slug:
support-ticket-system-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Contact Manager

Plugin Slug:
contact-manager
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.1.

DSGVO snippet for Leaflet Map and its Extensions

Plugin Slug:
dsgvo-leaflet-map
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.
Plugin Slug:
gallery-for-ultimate-member
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Product File Upload for WooCommerce

Plugin Slug:
products-file-upload-for-woocommerce
Installations
100+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

Filestack WP Upload

Plugin Slug:
filestack-upload
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.0.

Debugger & Troubleshooter

Plugin Slug:
debugger-troubleshooter
Installations
40+
Vulnerability:
Privilege Escalation
Patched in Version:
1.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.0.

BWL Advanced FAQ Manager Lite

Plugin Slug:
bwl-advanced-faq-manager-lite
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

WP Cost Estimation & Payment Forms Builder

Plugin:
WP Cost Estimation & Payment Forms Builder
Plugin Slug:
WP_Estimation_Form
Vulnerability:
Broken Access Control
Patched in Version:
10.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.3.0.

Addon Jobsearch Chat

Plugin:
Addon Jobsearch Chat
Plugin Slug:
addon-jobsearch-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Addon Jobsearch Chat

Plugin:
Addon Jobsearch Chat
Plugin Slug:
addon-jobsearch-chat
Vulnerability:
SQL Injection
Patched in Version:
3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.

Gyan Elements

Plugin:
Gyan Elements
Plugin Slug:
gyan-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

Ultimate Membership Pro

Plugin:
Ultimate Membership Pro
Plugin Slug:
indeed-membership-pro
Vulnerability:
Broken Authentication
Patched in Version:
13.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.7.1.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
SQL Injection
Patched in Version:
3.8.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.6.2.

NaturaLife Extensions

Plugin:
NaturaLife Extensions
Plugin Slug:
naturalife-extensions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

NaturaLife Extensions

Plugin:
NaturaLife Extensions
Plugin Slug:
naturalife-extensions
Vulnerability:
Local File Inclusion
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Salon Booking System Pro

Plugin:
Salon Booking System Pro
Plugin Slug:
salon-booking-plugin-pro
Vulnerability:
Broken Authentication
Patched in Version:
10.30.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.30.12.

LearnDash LMS

Plugin:
LearnDash LMS
Plugin Slug:
sfwd-lms
Vulnerability:
SQL Injection
Patched in Version:
5.0.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.3.1.

The Grid

Plugin:
The Grid
Plugin Slug:
the-grid
Vulnerability:
Broken Access Control
Patched in Version:
2.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.0.

The Grid

Plugin:
The Grid
Plugin Slug:
the-grid
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.38.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.38.5.

Woocommerce Custom Product Addons Pro

Plugin:
Woocommerce Custom Product Addons Pro
Plugin Slug:
woo-custom-product-addons-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
5.4.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.2.

WP Configurator Pro

Plugin:
WP Configurator Pro
Plugin Slug:
wp-configurator-pro
Vulnerability:
Broken Access Control
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.

WordPress Themes — 21 Patched / 1 Unpatched

Apicona

Theme:
Apicona
Theme Slug:
apicona
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Ona

Theme:
Ona
Theme Slug:
ona
Downloads
244,053
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.24
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.24.

Archicon

Theme:
Archicon
Theme Slug:
archicon
Vulnerability:
PHP Object Injection
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Borgholm

Theme:
Borgholm
Theme Slug:
borgholm-marketing-agency-theme
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.

Car Dealer

Theme:
Car Dealer
Theme Slug:
cardealer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.

Gaea

Theme:
Gaea
Theme Slug:
gaea
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

Goldish

Theme:
Goldish
Theme Slug:
goldish
Vulnerability:
PHP Object Injection
Patched in Version:
3.47
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.47.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.5.

Gracey

Theme:
Gracey
Theme Slug:
gracey
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Halstein

Theme:
Halstein
Theme Slug:
halstein
Vulnerability:
PHP Object Injection
Patched in Version:
1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.

Kamperen

Theme:
Kamperen
Theme Slug:
kamperen
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

KIDZ

Theme:
KIDZ
Theme Slug:
kidz
Vulnerability:
PHP Object Injection
Patched in Version:
5.25
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.25.

Boutique

Theme:
Boutique
Theme Slug:
kute-boutique
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.6.

Leroux

Theme:
Leroux
Theme Slug:
leroux
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Meloo

Theme:
Meloo
Theme Slug:
meloo
Vulnerability:
PHP Object Injection
Patched in Version:
2.8.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.2.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
SQL Injection
Patched in Version:
4.8.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.8.4.

Ricky

Theme:
Ricky
Theme Slug:
ricky
Vulnerability:
PHP Object Injection
Patched in Version:
2.31
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.31.

Sanzo

Theme:
Sanzo
Theme Slug:
sanzo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.3.

Stål

Theme:
Stål
Theme Slug:
stal
Vulnerability:
PHP Object Injection
Patched in Version:
1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.

Tasty Daily

Theme:
Tasty Daily
Theme Slug:
tastydaily
Vulnerability:
PHP Object Injection
Patched in Version:
1.27
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.27.

Vayvo

Theme:
Vayvo
Theme Slug:
vayvo-progression
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.8.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
PHP Object Injection
Patched in Version:
8.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security