In this report, 185 vulnerabilities have been publicly disclosed. Security patches for 169 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Currently, 16 plugin vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.
WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.
WordPress Plugins — 145 Patched / 16 Unpatched
AM LottiePlayer
- Plugin:
- AM LottiePlayer
- Plugin Slug:
- am-lottieplayer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-1794
Attendance Manager
- Plugin:
- Attendance Manager
- Plugin Slug:
- attendance-manager
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-3781
Columns by BestWebSoft
- Plugin:
- Columns by BestWebSoft
- Plugin Slug:
- columns-bws
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3618
DSGVO Google Web Fonts GDPR
- Plugin:
- DSGVO Google Web Fonts GDPR
- Plugin Slug:
- dsgvo-google-web-fonts-gdpr
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-3535
Gerador de Certificados – DevApps
- Plugin:
- Gerador de Certificados – DevApps
- Plugin Slug:
- gerador-de-certificados-devapps
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-4808
Inquiry form to posts or pages
- Plugin:
- Inquiry form to posts or pages
- Plugin Slug:
- inquiry-form-to-posts-or-pages
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-5169
Pinterest Site Verification plugin using Meta Tag
- Plugin:
- Pinterest Site Verification plugin using Meta Tag
- Plugin Slug:
- pinterest-site-verification
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3142
pz-frontend-manager
- Plugin:
- pz-frontend-manager
- Plugin Slug:
- pz-frontend-manager
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3477
Quran Translations
- Plugin:
- Quran Translations
- Plugin Slug:
- quran-translations-by-edc
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4141
Riaxe Product Customizer
- Plugin:
- Riaxe Product Customizer
- Plugin Slug:
- riaxe-product-customizer
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3594
Sports Club Management
- Plugin:
- Sports Club Management
- Plugin Slug:
- sports-club-management
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4871
Wavr
- Plugin:
- Wavr
- Plugin Slug:
- wavr
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-5506
Whole Enquiry Cart for WooCommerce
- Plugin:
- Whole Enquiry Cart for WooCommerce
- Plugin Slug:
- whole-cart-enquiry
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-2838
IDPay Payment Gateway for Woocommerce
- Plugin:
- IDPay Payment Gateway for Woocommerce
- Plugin Slug:
- woo-idpay-gateway
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-34891
WowPress
- Plugin:
- WowPress
- Plugin Slug:
- wowpress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-5508
WP Blockade
- Plugin:
- WP Blockade
- Plugin Slug:
- wp-blockade
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3480
Elementor Website Builder – more than just a page builder
- Plugin Slug:
- elementor
- Installations
- 10,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.35.6
- Severity Score:
- Medium
- CVE:
- 2025-14732
ManageWP Worker
- Plugin:
- ManageWP Worker
- Plugin Slug:
- worker
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.32
- Severity Score:
- High
- CVE:
- 2026-39463
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
- Plugin:
- WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
- Plugin Slug:
- wp-optimize
- Installations
- 1,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.5.1
- Severity Score:
- Medium
- CVE:
- 2026-2712
Smart Slider 3
- Plugin:
- Smart Slider 3
- Plugin Slug:
- smart-slider-3
- Installations
- 800,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.5.1.34
- Severity Score:
- Medium
- CVE:
- 2026-4065
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Plugin Slug:
- kadence-blocks
- Installations
- 600,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.4
- Severity Score:
- High
- CVE:
- 2026-2826
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
- Plugin Slug:
- kadence-blocks
- Installations
- 600,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.4
- Severity Score:
- Medium
- CVE:
- 2026-2826
BackWPup – WordPress Backup & Restore Plugin
- Plugin Slug:
- backwpup
- Installations
- 500,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 5.6.7
- Severity Score:
- High
- CVE:
- 2026-6227
Meta Box
- Plugin:
- Meta Box
- Plugin Slug:
- meta-box
- Installations
- 500,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 5.11.2
- Severity Score:
- Medium
- CVE:
- 2026-39468
Ocean Extra
- Plugin:
- Ocean Extra
- Plugin Slug:
- ocean-extra
- Installations
- 500,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.5.4
- Severity Score:
- Medium
- CVE:
- 2026-34903
YITH WooCommerce Wishlist
- Plugin:
- YITH WooCommerce Wishlist
- Plugin Slug:
- yith-woocommerce-wishlist
- Installations
- 500,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 4.13.0
- Severity Score:
- Medium
- CVE:
- 2026-4432
Page Builder: Pagelayer – Drag and Drop website builder
- Plugin Slug:
- pagelayer
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.9
- Severity Score:
- Medium
- CVE:
- 2026-2509
Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails
- Plugin Slug:
- woo-cart-abandonment-recovery
- Installations
- 300,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.1.0
- Severity Score:
- High
- CVE:
- 2026-39470
MW WP Form
- Plugin:
- MW WP Form
- Plugin Slug:
- mw-wp-form
- Installations
- 200,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 5.1.2
- Severity Score:
- High
- CVE:
- 2026-5436
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
- Plugin Slug:
- optimole-wp
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.3
- Severity Score:
- High
- CVE:
- 2026-5217
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
- Plugin Slug:
- optimole-wp
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.4
- Severity Score:
- High
- CVE:
- 2026-5226
Post Duplicator
- Plugin:
- Post Duplicator
- Plugin Slug:
- post-duplicator
- Installations
- 200,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.0.11
- Severity Score:
- High
- CVE:
- 2026-39474
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.11.2
- Severity Score:
- Medium
- CVE:
- 2025-15064
Aruba HiSpeed Cache
- Plugin:
- Aruba HiSpeed Cache
- Plugin Slug:
- aruba-hispeed-cache
- Installations
- 100,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.0.5
- Severity Score:
- Medium
- CVE:
- 2026-1924
Element Pack – Widgets, Templates & Addons for Elementor
- Plugin Slug:
- bdthemes-element-pack-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5.0
- Severity Score:
- Medium
- CVE:
- 2026-4655
Prime Slider – Addons for Elementor
- Plugin Slug:
- bdthemes-prime-slider-lite
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.1.11
- Severity Score:
- Medium
- CVE:
- 2026-4341
Beaver Builder Page Builder – Drag and Drop Website Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.10.1.2
- Severity Score:
- Medium
- CVE:
- 2026-2481
Download Manager
- Plugin:
- Download Manager
- Plugin Slug:
- download-manager
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.3.52
- Severity Score:
- Medium
- CVE:
- 2026-4057
Download Manager
- Plugin:
- Download Manager
- Plugin Slug:
- download-manager
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.53
- Severity Score:
- Medium
- CVE:
- 2026-5357
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
- Plugin Slug:
- everest-forms
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.4.4
- Severity Score:
- Critical
- CVE:
- 2026-3296
LatePoint – Calendar Booking Plugin for Appointments and Events
- Plugin Slug:
- latepoint
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.3.1
- Severity Score:
- Medium
- CVE:
- 2026-4785
MainWP Child Reports
- Plugin:
- MainWP Child Reports
- Plugin Slug:
- mainwp-child-reports
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3
- Severity Score:
- Medium
- CVE:
- 2026-4299
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce
- Plugin Slug:
- the-plus-addons-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.4.10
- Severity Score:
- Medium
- CVE:
- 2026-3311
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.9.8
- Severity Score:
- Medium
- CVE:
- 2026-3371
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.8
- Severity Score:
- Medium
- CVE:
- 2026-3358
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.8
- Severity Score:
- High
- CVE:
- 2026-3360
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
- Plugin Slug:
- wp-user-avatar
- Installations
- 100,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 4.16.12
- Severity Score:
- Medium
- CVE:
- 2026-3309
Booking for Appointments and Events Calendar – Amelia
- Plugin Slug:
- ameliabooking
- Installations
- 90,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.2
- Severity Score:
- High
- CVE:
- 2026-5465
BackupBliss – Backup & Migration with Free Cloud Storage
- Plugin Slug:
- backup-backup
- Installations
- 90,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.1.2
- Severity Score:
- High
- CVE:
- 2026-39480
BackupBliss – Backup & Migration with Free Cloud Storage
- Plugin Slug:
- backup-backup
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.0
- Severity Score:
- Medium
- CVE:
- 2025-14944
Download Monitor
- Plugin:
- Download Monitor
- Plugin Slug:
- download-monitor
- Installations
- 90,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.1.11
- Severity Score:
- Medium
- CVE:
- 2026-4401
Strong Testimonials
- Plugin:
- Strong Testimonials
- Plugin Slug:
- strong-testimonials
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.22
- Severity Score:
- Medium
- CVE:
- 2026-3239
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
- Plugin Slug:
- woolentor-addons
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.6
- Severity Score:
- Medium
- CVE:
- 2026-4059
Hustle – Email Marketing, Lead Generation, Optins, Popups
- Plugin Slug:
- wordpress-popup
- Installations
- 90,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.8.11
- Severity Score:
- Medium
- CVE:
- 2026-2263
Customer Reviews for WooCommerce
- Plugin:
- Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations
- 80,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 5.104.0
- Severity Score:
- Medium
- CVE:
- 2026-4664
Jupiter X Core
- Plugin:
- Jupiter X Core
- Plugin Slug:
- jupiterx-core
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.14.2
- Severity Score:
- Medium
- CVE:
- 2026-39491
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
- Plugin Slug:
- learnpress
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3.4
- Severity Score:
- Medium
- CVE:
- 2026-4333
List category posts
- Plugin:
- List category posts
- Plugin Slug:
- list-category-posts
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.95.0
- Severity Score:
- Medium
- CVE:
- 2026-3005
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce
- Plugin Slug:
- woo-product-feed-pro
- Installations
- 80,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 13.5.2.2
- Severity Score:
- High
- CVE:
- 2026-3499
Advanced Contact form 7 DB
- Plugin:
- Advanced Contact form 7 DB
- Plugin Slug:
- advanced-cf7-db
- Installations
- 70,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.1.0
- Severity Score:
- Medium
- CVE:
- 2026-0811
Advanced Contact form 7 DB
- Plugin:
- Advanced Contact form 7 DB
- Plugin Slug:
- advanced-cf7-db
- Installations
- 70,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.0
- Severity Score:
- Medium
- CVE:
- 2026-0814
Online Scheduling and Appointment Booking System – Bookly
- Plugin Slug:
- bookly-responsive-appointment-booking-tool
- Installations
- 70,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 27.1
- Severity Score:
- Medium
- CVE:
- 2026-2519
Greenshift – animation and page builder blocks
- Plugin Slug:
- greenshift-animation-and-page-builder-blocks
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 12.9.0
- Severity Score:
- Medium
- CVE:
- 2026-4895
Media Library Assistant
- Plugin:
- Media Library Assistant
- Plugin Slug:
- media-library-assistant
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.35
- Severity Score:
- Medium
- CVE:
- 2026-34897
Media Library Assistant
- Plugin:
- Media Library Assistant
- Plugin Slug:
- media-library-assistant
- Installations
- 70,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.35
- Severity Score:
- High
- CVE:
- 2026-34885
Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels
- Plugin Slug:
- webappick-product-feed-for-woocommerce
- Installations
- 70,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 6.6.27
- Severity Score:
- High
- CVE:
- 2026-39434
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
- Plugin Slug:
- simply-schedule-appointments
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.6.9.29
- Severity Score:
- Critical
- CVE:
- 2026-39493
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
- Plugin Slug:
- user-registration
- Installations
- 60,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 5.1.5
- Severity Score:
- Medium
- CVE:
- 2026-6203
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
- Plugin Slug:
- user-registration
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 5.1.3
- Severity Score:
- High
- CVE:
- 2026-1865
Product Filter for WooCommerce by WBW
- Plugin Slug:
- woo-product-filter
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.1.3
- Severity Score:
- Critical
- CVE:
- 2026-39494
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
- Plugin Slug:
- wp-google-map-plugin
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.9.2
- Severity Score:
- Critical
- CVE:
- 2026-39492
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
- Plugin Slug:
- ays-popup-box
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.5.0
- Severity Score:
- High
- CVE:
- 2025-15611
Blog2Social: Social Media Auto Post & Scheduler
- Plugin Slug:
- blog2social
- Installations
- 50,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 8.8.4
- Severity Score:
- Medium
- CVE:
- 2026-4330
Robo Gallery – Photo & Image Slider
- Plugin Slug:
- robo-gallery
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.1.4
- Severity Score:
- Medium
- CVE:
- 2026-4300
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
- Plugin Slug:
- woo-bulk-editor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2026-1673
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
- Plugin Slug:
- woo-bulk-editor
- Installations
- 40,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2026-1672
LightPress Lightbox
- Plugin:
- LightPress Lightbox
- Plugin Slug:
- wp-jquery-lightbox
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.5
- Severity Score:
- Medium
- CVE:
- 2026-4379
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.15.39
- Severity Score:
- Critical
- CVE:
- 2026-39502
Link Whisper Free
- Plugin:
- Link Whisper Free
- Plugin Slug:
- link-whisper
- Installations
- 30,000+
- Vulnerability:
- Settings Change
- Patched in Version:
- 0.9.1
- Severity Score:
- Medium
- CVE:
- 2026-1900
PowerPress Podcasting plugin by Blubrry
- Plugin Slug:
- powerpress
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 11.15.16
- Severity Score:
- Medium
- CVE:
- 2026-2988
Ultimate FAQ Accordion Plugin
- Plugin:
- Ultimate FAQ Accordion Plugin
- Plugin Slug:
- ultimate-faqs
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.8
- Severity Score:
- Medium
- CVE:
- 2026-4336
Visitor Traffic Real Time Statistics
- Plugin Slug:
- visitors-traffic-real-time-statistics
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5
- Severity Score:
- High
- CVE:
- 2026-2936
AddFunc Head & Footer Code
- Plugin:
- AddFunc Head & Footer Code
- Plugin Slug:
- addfunc-head-footer-code
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4
- Severity Score:
- Medium
- CVE:
- 2026-2305
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
- Plugin Slug:
- post-carousel
- Installations
- 20,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.0.13
- Severity Score:
- High
- CVE:
- 2026-3017
Simple Social Media Share Buttons – Social Sharing for Everyone
- Plugin Slug:
- simple-social-buttons
- Installations
- 20,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.2.1
- Severity Score:
- High
- CVE:
- 2026-34904
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin:
- UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin Slug:
- userswp
- Installations
- 20,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- 1.2.59
- Severity Score:
- Medium
- CVE:
- 2026-4979
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin:
- UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin Slug:
- userswp
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.2.59
- Severity Score:
- Medium
- CVE:
- 2026-4977
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin:
- UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin Slug:
- userswp
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.61
- Severity Score:
- Medium
- CVE:
- 2026-5742
WP Visitor Statistics (Real Time Traffic)
- Plugin Slug:
- wp-stats-manager
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.5
- Severity Score:
- Medium
- CVE:
- 2026-4303
wpForo Forum
- Plugin:
- wpForo Forum
- Plugin Slug:
- wpforo
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 3.0.3
- Severity Score:
- High
- CVE:
- 2026-5809
wpForo Forum
- Plugin:
- wpForo Forum
- Plugin Slug:
- wpforo
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 2.4.17
- Severity Score:
- High
- CVE:
- 2026-3666
BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library
- Plugin Slug:
- blockart-blocks
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.0
- Severity Score:
- Medium
- CVE:
- 2026-3498
Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
- Plugin Slug:
- charitable
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.10
- Severity Score:
- Medium
- CVE:
- 2026-3177
Easy Appointments
- Plugin:
- Easy Appointments
- Plugin Slug:
- easy-appointments
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.12.22
- Severity Score:
- High
- CVE:
- 2026-39513
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
- Plugin Slug:
- geodirectory
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.8.154
- Severity Score:
- Critical
- CVE:
- 2026-39512
LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes
- Plugin Slug:
- lifterlms
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 9.2.2
- Severity Score:
- Medium
- CVE:
- 2026-5207
OSM – OpenStreetMap
- Plugin:
- OSM – OpenStreetMap
- Plugin Slug:
- osm
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.1.16
- Severity Score:
- Medium
- CVE:
- 2026-4429
Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely
- Plugin Slug:
- royal-backup-reset
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.17
- Severity Score:
- High
- CVE:
- 2026-4305
Widgets for Social Photo Feed
- Plugin:
- Widgets for Social Photo Feed
- Plugin Slug:
- social-photo-feed-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.0
- Severity Score:
- High
- CVE:
- 2026-5425
Under Construction, Coming Soon & Maintenance Mode
- Plugin Slug:
- under-construction-maintenance-mode
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.1.2
- Severity Score:
- High
- CVE:
- 2026-34896
Product Table and List Builder for WooCommerce Lite
- Plugin Slug:
- wc-product-table-lite
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.6.4
- Severity Score:
- High
- CVE:
- 2026-34902
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
- Plugin Slug:
- wp-event-solution
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.1.9
- Severity Score:
- Medium
- CVE:
- 2026-4109
WP Photo Album Plus
- Plugin:
- WP Photo Album Plus
- Plugin Slug:
- wp-photo-album-plus
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 9.1.08.002
- Severity Score:
- Critical
- CVE:
- 2026-39511
YML for Yandex Market
- Plugin:
- YML for Yandex Market
- Plugin Slug:
- yml-for-yandex-market
- Installations
- 10,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 5.0.26
- Severity Score:
- High
- CVE:
- 2025-14545
WCAPF – Ajax Product Filter for WooCommerce
- Plugin Slug:
- wc-ajax-product-filter
- Installations
- 9,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.3.0
- Severity Score:
- Critical
- CVE:
- 2026-3396
Awesome Support – WordPress HelpDesk & Support Plugin
- Plugin Slug:
- awesome-support
- Installations
- 7,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 6.3.8
- Severity Score:
- Medium
- CVE:
- 2026-4654
ActivityPub
- Plugin:
- ActivityPub
- Plugin Slug:
- activitypub
- Installations
- 6,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 8.0.2
- Severity Score:
- High
- CVE:
- 2026-4338
GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content
- Plugin Slug:
- geeky-bot
- Installations
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.2.1
- Severity Score:
- Critical
- CVE:
- 2026-39519
WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
- Plugin Slug:
- wpfunnels
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.8.0
- Severity Score:
- Medium
- CVE:
- 2026-0626
Booking Activities
- Plugin:
- Booking Activities
- Plugin Slug:
- booking-activities
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.17.0
- Severity Score:
- Medium
- CVE:
- 2026-39525
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
- Plugin Slug:
- learning-management-system
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.6
- Severity Score:
- High
- CVE:
- 2026-39524
Masteriyo LMS – Online Course Builder for eLearning, LMS & Education
- Plugin Slug:
- learning-management-system
- Installations
- 4,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 2.1.8
- Severity Score:
- Medium
- CVE:
- 2026-5167
AWP Classifieds
- Plugin:
- AWP Classifieds
- Plugin Slug:
- another-wordpress-classifieds-plugin
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.4.5
- Severity Score:
- High
- CVE:
- 2026-39533
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin
- Plugin Slug:
- majestic-support
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.3
- Severity Score:
- Medium
- CVE:
- 2026-40778
MStore API – Create Native Android & iOS Apps On The Cloud
- Plugin Slug:
- mstore-api
- Installations
- 3,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 4.18.4
- Severity Score:
- Medium
- CVE:
- 2026-3568
SpeakOut! Email Petitions
- Plugin:
- SpeakOut! Email Petitions
- Plugin Slug:
- speakout
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.6.5.1
- Severity Score:
- Critical
- CVE:
- 2026-39530
WP Directory Kit
- Plugin:
- WP Directory Kit
- Plugin Slug:
- wpdirectorykit
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.1
- Severity Score:
- Critical
- CVE:
- 2026-39531
WP Directory Kit
- Plugin:
- WP Directory Kit
- Plugin Slug:
- wpdirectorykit
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2026-39534
Extensions for Leaflet Map
- Plugin:
- Extensions for Leaflet Map
- Plugin Slug:
- extensions-leaflet-map
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.15
- Severity Score:
- Medium
- CVE:
- 2026-5451
Timetics – Appointment Booking & Scheduling
- Plugin Slug:
- timetics
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.54
- Severity Score:
- High
- CVE:
- 2026-39432
Event Tickets Manager for WooCommerce
- Plugin Slug:
- event-tickets-manager-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.4
- Severity Score:
- High
- CVE:
- 2026-34898
iControlWP
- Plugin:
- iControlWP
- Plugin Slug:
- worpit-admin-dashboard-plugin
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 5.5.4
- Severity Score:
- Critical
- CVE:
- 2026-34901
SQL Chart Builder
- Plugin:
- SQL Chart Builder
- Plugin Slug:
- sql-chart-builder
- Installations
- 600+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.3.8
- Severity Score:
- Critical
- CVE:
- 2026-4079
Webling
Datalogics Ecommerce Delivery – Datalogics
- Plugin Slug:
- datalogics
- Installations
- 400+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.6.63
- Severity Score:
- Critical
- CVE:
- 2026-39583
Post Blocks & Tools
- Plugin:
- Post Blocks & Tools
- Plugin Slug:
- bnm-blocks
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.1
- Severity Score:
- Medium
- CVE:
- 2026-5711
TableOn – WordPress Posts Table Filterable
- Plugin Slug:
- posts-table-filterable
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.5
- Severity Score:
- Medium
- CVE:
- 2026-3513
WP BASE Booking of Appointments, Services and Events
- Plugin Slug:
- wp-base-booking-of-appointments-services-and-events
- Installations
- 200+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 6.0.0
- Severity Score:
- High
- CVE:
- 2026-39587
Text to Speech – TTSWP
- Plugin:
- Text to Speech – TTSWP
- Plugin Slug:
- text-to-speech-tts
- Installations
- 100+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 1.9.9
- Severity Score:
- High
- CVE:
- 2026-1233
LTL Freight Quotes – Worldwide Express Edition
- Plugin Slug:
- ltl-freight-quotes-worldwide-express-edition
- Installations
- 90+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.2.2
- Severity Score:
- Medium
- CVE:
- 2026-34899
Ziggeo
BuddyPress Groupblog
- Plugin:
- BuddyPress Groupblog
- Plugin Slug:
- bp-groupblog
- Installations
- 50+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.9.4
- Severity Score:
- High
- CVE:
- 2026-5144
WP-BusinessDirectory – Business directory plugin for WordPress
- Plugin Slug:
- wp-businessdirectory
- Installations
- 40+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.0.1
- Severity Score:
- Critical
- CVE:
- 2026-39591
Advanced Members for ACF
- Plugin:
- Advanced Members for ACF
- Plugin Slug:
- advanced-members
- Installations
- 30+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 1.2.6
- Severity Score:
- High
- CVE:
- 2026-3243
PrivateContent Free
- Plugin:
- PrivateContent Free
- Plugin Slug:
- privatecontent-free
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2026-4025
ProSolution WP Client
- Plugin:
- ProSolution WP Client
- Plugin Slug:
- prosolution-wp-client
- Installations
- 20+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.0.0
- Severity Score:
- Critical
- CVE:
- 2026-2942
Experto Dashboard for WooCommerce
- Plugin Slug:
- experto-custom-dashboard
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.5
- Severity Score:
- Medium
- CVE:
- 2026-3574
Investi
LTL Freight Quotes – R+L Carriers Edition
- Plugin Slug:
- ltl-freight-quotes-rl-edition
- Installations
- 10+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.3.14
- Severity Score:
- Medium
- CVE:
- 2026-3646
Magic Conversation For Gravity Forms
- Plugin Slug:
- magic-conversation-for-gravity-forms
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.98
- Severity Score:
- Medium
- CVE:
- 2026-1396
Surbma | Booking.com Shortcode
- Plugin:
- Surbma | Booking.com Shortcode
- Plugin Slug:
- surbma-bookingcom-shortcode
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.1
- Severity Score:
- Medium
- CVE:
- 2026-1607
WholeSale Products Dynamic Pricing Management WooCommerce
- Plugin Slug:
- wholesale-products-dynamic-pricing-management-woocommerce
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2026-4479
WPAMS
- Plugin:
- WPAMS
- Plugin Slug:
- apartment-management
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 49.5.3
- Severity Score:
- Medium
- CVE:
- 2026-39433
Blocksy Companion Pro
- Plugin:
- Blocksy Companion Pro
- Plugin Slug:
- blocksy-companion-pro
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.1.29
- Severity Score:
- Critical
- CVE:
- 2026-39596
Bricksforge
- Plugin:
- Bricksforge
- Plugin Slug:
- bricksforge
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.1.8.5
- Severity Score:
- High
- CVE:
- 2026-34888
Gravity Forms
- Plugin:
- Gravity Forms
- Plugin Slug:
- gravityforms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.31
- Severity Score:
- High
- CVE:
- 2026-4394
Gravity Forms
- Plugin:
- Gravity Forms
- Plugin Slug:
- gravityforms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.31
- Severity Score:
- High
- CVE:
- 2026-4406
Gravity SMTP
- Plugin:
- Gravity SMTP
- Plugin Slug:
- gravitysmtp
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.5
- Severity Score:
- High
- CVE:
- 2026-4162
Integrio Core
- Plugin:
- Integrio Core
- Plugin Slug:
- integrio-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.8
- Severity Score:
- High
- CVE:
- 2026-34894
Listeo Core
- Plugin:
- Listeo Core
- Plugin Slug:
- listeo-core
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.0.28
- Severity Score:
- Medium
- CVE:
- 2025-14938
Mikado Core
- Plugin:
- Mikado Core
- Plugin Slug:
- mikado-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.7.2
- Severity Score:
- High
- CVE:
- 2026-39537
Smart Slider 3 PRO
- Plugin:
- Smart Slider 3 PRO
- Plugin Slug:
- nextend-smart-slider3-pro
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.5.1.36
- Severity Score:
- Critical
Ninja Forms File Uploads Extension
- Plugin:
- Ninja Forms File Uploads Extension
- Plugin Slug:
- ninja-forms-uploads
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.3.27
- Severity Score:
- Critical
- CVE:
- 2026-0740
pdfl.io
Perfmatters
- Plugin:
- Perfmatters
- Plugin Slug:
- perfmatters
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 2.6.0
- Severity Score:
- High
- CVE:
- 2026-4351
Quick Playground
- Plugin:
- Quick Playground
- Plugin Slug:
- quick-playground
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.3.2
- Severity Score:
- Critical
- CVE:
- 2026-1830
Softlab Core
- Plugin:
- Softlab Core
- Plugin Slug:
- softlab-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.11
- Severity Score:
- High
- CVE:
- 2026-34895
Solene Core
- Plugin:
- Solene Core
- Plugin Slug:
- solene-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.3.4
- Severity Score:
- High
- CVE:
- 2026-39523
Thegov Core
- Plugin:
- Thegov Core
- Plugin Slug:
- thegov-core
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.0.23
- Severity Score:
- High
- CVE:
- 2026-34893
Users manager – PN
- Plugin:
- Users manager – PN
- Plugin Slug:
- userspn
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.1.20
- Severity Score:
- Critical
- CVE:
- 2026-4003
MultiLoca
- Plugin:
- MultiLoca
- Plugin Slug:
- woocommerce-multi-locations-inventory-management
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 4.2.16
- Severity Score:
- High
- CVE:
- 2026-39546
WordPress Themes — 24 Patched / 0 Unpatched
Alloggio – Hotel Booking
- Theme:
- Alloggio – Hotel Booking
- Theme Slug:
- alloggio
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.1.3
- Severity Score:
- High
- CVE:
- 2026-39539
Aperitif
- Theme:
- Aperitif
- Theme Slug:
- aperitif
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6.1
- Severity Score:
- High
- CVE:
- 2026-39550
Aperitif
- Theme:
- Aperitif
- Theme Slug:
- aperitif
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-39549
Askka
- Theme:
- Askka
- Theme Slug:
- askka
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.4
- Severity Score:
- High
- CVE:
- 2026-39555
Blueprint
- Theme:
- Blueprint
- Theme Slug:
- blueprint
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.5
- Severity Score:
- High
- CVE:
- 2026-39552
Fidalgo
- Theme:
- Fidalgo
- Theme Slug:
- fidalgo
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-39554
Getaway
- Theme:
- Getaway
- Theme Slug:
- getaway
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.8
- Severity Score:
- High
- CVE:
- 2026-39547
Hiroshi
- Theme:
- Hiroshi
- Theme Slug:
- hiroshi
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-39560
Konsept
- Theme:
- Konsept
- Theme Slug:
- konsept
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.0
- Severity Score:
- High
- CVE:
- 2026-39556
Malmö
- Theme:
- Malmö
- Theme Slug:
- malmo
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.3
- Severity Score:
- High
- CVE:
- 2026-39558
Micdrop
- Theme:
- Micdrop
- Theme Slug:
- micdrop
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.4
- Severity Score:
- High
- CVE:
- 2026-39580
Mildhill
- Theme:
- Mildhill
- Theme Slug:
- mildhill
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-39573
Mr. SEO
- Theme:
- Mr. SEO
- Theme Slug:
- mrseo
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.1
- Severity Score:
- High
- CVE:
- 2026-39568
NeoBeat
- Theme:
- NeoBeat
- Theme Slug:
- neobeat
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.8
- Severity Score:
- High
- CVE:
- 2026-39557
Playroom
- Theme:
- Playroom
- Theme Slug:
- playroom
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-39577
Santé
- Theme:
- Santé
- Theme Slug:
- sante
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-39567
SingleMalt
- Theme:
- SingleMalt
- Theme Slug:
- singlemalt
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-39576
Solene
- Theme:
- Solene
- Theme Slug:
- solene
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 3.4.1
- Severity Score:
- High
- CVE:
- 2026-39522
Töbel
- Theme:
- Töbel
- Theme Slug:
- tobel
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.9
- Severity Score:
- High
- CVE:
- 2026-39551
Uppercase
- Theme:
- Uppercase
- Theme Slug:
- uppercase
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.2
- Severity Score:
- High
- CVE:
- 2026-39559
Valiance
- Theme:
- Valiance
- Theme Slug:
- valiance
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-39578
WaveRide
- Theme:
- WaveRide
- Theme Slug:
- waveride
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-39553
Hitek
- Theme:
- Hitek
- Theme Slug:
- xts-hitek
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.8.3
- Severity Score:
- High
- CVE:
- 2026-39582
Zermatt
- Theme:
- Zermatt
- Theme Slug:
- zermatt
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.7
- Severity Score:
- High
- CVE:
- 2026-39545
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
