WordPress Vulnerability Report

WordPress Vulnerability Report — April 15, 2026

Since last week, 185 new vulnerabilities have emerged in the WordPress ecosystem, including 161 plugins and 24 themes. Of those, 16 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 185 vulnerabilities have been publicly disclosed. Security patches for 169 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 16 plugin vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 145 Patched / 16 Unpatched

AM LottiePlayer

Plugin:
AM LottiePlayer
Plugin Slug:
am-lottieplayer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Attendance Manager

Plugin:
Attendance Manager
Plugin Slug:
attendance-manager
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Columns by BestWebSoft

Plugin:
Columns by BestWebSoft
Plugin Slug:
columns-bws
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DSGVO Google Web Fonts GDPR

Plugin:
DSGVO Google Web Fonts GDPR
Plugin Slug:
dsgvo-google-web-fonts-gdpr
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gerador de Certificados – DevApps

Plugin:
Gerador de Certificados – DevApps
Plugin Slug:
gerador-de-certificados-devapps
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Inquiry form to posts or pages

Plugin:
Inquiry form to posts or pages
Plugin Slug:
inquiry-form-to-posts-or-pages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pinterest Site Verification plugin using Meta Tag

Plugin:
Pinterest Site Verification plugin using Meta Tag
Plugin Slug:
pinterest-site-verification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

pz-frontend-manager

Plugin:
pz-frontend-manager
Plugin Slug:
pz-frontend-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quran Translations

Plugin:
Quran Translations
Plugin Slug:
quran-translations-by-edc
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:
Riaxe Product Customizer
Plugin Slug:
riaxe-product-customizer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sports Club Management

Plugin:
Sports Club Management
Plugin Slug:
sports-club-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wavr

Plugin:
Wavr
Plugin Slug:
wavr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Whole Enquiry Cart for WooCommerce

Plugin:
Whole Enquiry Cart for WooCommerce
Plugin Slug:
whole-cart-enquiry
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IDPay Payment Gateway for Woocommerce

Plugin:
IDPay Payment Gateway for Woocommerce
Plugin Slug:
woo-idpay-gateway
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WowPress

Plugin:
WowPress
Plugin Slug:
wowpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Blockade

Plugin:
WP Blockade
Plugin Slug:
wp-blockade
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ManageWP Worker

Plugin Slug:
worker
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.32.

Smart Slider 3

Plugin Slug:
smart-slider-3
Installations
800,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.1.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.1.34.

BackWPup – WordPress Backup & Restore Plugin

Plugin Slug:
backwpup
Installations
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.7.

Meta Box

Plugin:
Meta Box
Plugin Slug:
meta-box
Installations
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.2.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
500,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.4.

YITH WooCommerce Wishlist

Plugin Slug:
yith-woocommerce-wishlist
Installations
500,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.13.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.13.0.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

MW WP Form

Plugin:
MW WP Form
Plugin Slug:
mw-wp-form
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

Post Duplicator

Plugin Slug:
post-duplicator
Installations
200,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.0.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.11.

Aruba HiSpeed Cache

Plugin Slug:
aruba-hispeed-cache
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.5.

Element Pack – Widgets, Templates & Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.0.

Prime Slider – Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.11.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.1.2.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.52
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.52.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.53.

MainWP Child Reports

Plugin Slug:
mainwp-child-reports
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.8.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.8.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.8.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.11.

Strong Testimonials

Plugin Slug:
strong-testimonials
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.22.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Broken Authentication
Patched in Version:
5.104.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.104.0.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.14.2.

List category posts

Plugin Slug:
list-category-posts
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.95.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.95.0.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db
Installations
70,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Online Scheduling and Appointment Booking System – Bookly

Plugin Slug:
bookly-responsive-appointment-booking-tool
Installations
70,000+
Vulnerability:
Content Injection
Patched in Version:
27.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 27.1.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.9.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.9.0.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.35.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
SQL Injection
Patched in Version:
3.35
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.35.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Open Redirection
Patched in Version:
5.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.5.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
5.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.3.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Broken Authentication
Patched in Version:
8.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.4.
Plugin Slug:
robo-gallery
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

LightPress Lightbox

Plugin Slug:
wp-jquery-lightbox
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.5.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Settings Change
Patched in Version:
0.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.1.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.15.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.15.16.

Ultimate FAQ Accordion Plugin

Plugin Slug:
ultimate-faqs
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Visitor Traffic Real Time Statistics

Plugin Slug:
visitors-traffic-real-time-statistics
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.
Plugin Slug:
addfunc-head-footer-code
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.3.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.4.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.17.

Easy Appointments

Plugin Slug:
easy-appointments
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.12.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.22.

OSM – OpenStreetMap

Plugin Slug:
osm
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.16.

Widgets for Social Photo Feed

Plugin Slug:
social-photo-feed-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Under Construction, Coming Soon & Maintenance Mode

Plugin Slug:
under-construction-maintenance-mode
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.2.

Product Table and List Builder for WooCommerce Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.4.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.08.002
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.1.08.002.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
5.0.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.26.

WCAPF – Ajax Product Filter for WooCommerce

Plugin Slug:
wc-ajax-product-filter
Installations
9,000+
Vulnerability:
SQL Injection
Patched in Version:
4.3.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3.0.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
7,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.8.

ActivityPub

Plugin Slug:
activitypub
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
8.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.0.2.

Booking Activities

Plugin Slug:
booking-activities
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.17.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.17.0.

AWP Classifieds

Plugin Slug:
another-wordpress-classifieds-plugin
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.5.

MStore API – Create Native Android & iOS Apps On The Cloud

Plugin Slug:
mstore-api
Installations
3,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.18.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.18.4.

SpeakOut! Email Petitions

Plugin Slug:
speakout
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.1.

Extensions for Leaflet Map

Plugin Slug:
extensions-leaflet-map
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.15.

Timetics – Appointment Booking & Scheduling

Plugin Slug:
timetics
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.54
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.54.

Event Tickets Manager for WooCommerce

Plugin Slug:
event-tickets-manager-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

iControlWP

Plugin:
iControlWP
Plugin Slug:
worpit-admin-dashboard-plugin
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
5.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.5.4.

SQL Chart Builder

Plugin Slug:
sql-chart-builder
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
2.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.8.

Webling

Plugin:
Webling
Plugin Slug:
webling
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.1.

Datalogics Ecommerce Delivery – Datalogics

Plugin Slug:
datalogics
Installations
400+
Vulnerability:
Privilege Escalation
Patched in Version:
2.6.63
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.63.

Post Blocks & Tools

Plugin Slug:
bnm-blocks
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.1.

TableOn – WordPress Posts Table Filterable 

Plugin Slug:
posts-table-filterable
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events
Installations
200+
Vulnerability:
Privilege Escalation
Patched in Version:
6.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.0.0.

Text to Speech – TTSWP

Plugin Slug:
text-to-speech-tts
Installations
100+
Vulnerability:
Bypass Vulnerability
Patched in Version:
1.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.9.

LTL Freight Quotes – Worldwide Express Edition

Plugin Slug:
ltl-freight-quotes-worldwide-express-edition
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
5.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.2.

Ziggeo

Plugin:
Ziggeo
Plugin Slug:
ziggeo
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.2.

BuddyPress Groupblog

Plugin Slug:
bp-groupblog
Installations
50+
Vulnerability:
Privilege Escalation
Patched in Version:
1.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.4.

Advanced Members for ACF

Plugin Slug:
advanced-members
Installations
30+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.2.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.6.

PrivateContent Free

Plugin Slug:
privatecontent-free
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

ProSolution WP Client

Plugin Slug:
prosolution-wp-client
Installations
20+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.0.

Experto Dashboard for WooCommerce

Plugin Slug:
experto-custom-dashboard
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.5.

Investi

Plugin:
Investi
Plugin Slug:
investi
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.27.

LTL Freight Quotes – R+L Carriers Edition

Plugin Slug:
ltl-freight-quotes-rl-edition
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.14.

Magic Conversation For Gravity Forms

Plugin Slug:
magic-conversation-for-gravity-forms
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.98
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.98.

Surbma | Booking.com Shortcode

Plugin Slug:
surbma-bookingcom-shortcode
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

WholeSale Products Dynamic Pricing Management WooCommerce

Plugin Slug:
wholesale-products-dynamic-pricing-management-woocommerce
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

WPAMS

Plugin:
WPAMS
Plugin Slug:
apartment-management
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
49.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 49.5.3.

Blocksy Companion Pro

Plugin:
Blocksy Companion Pro
Plugin Slug:
blocksy-companion-pro
Vulnerability:
SQL Injection
Patched in Version:
2.1.29
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.29.

Bricksforge

Plugin:
Bricksforge
Plugin Slug:
bricksforge
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.8.5.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.31.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.31.

Gravity SMTP

Plugin:
Gravity SMTP
Plugin Slug:
gravitysmtp
Vulnerability:
Broken Access Control
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.

Integrio Core

Plugin:
Integrio Core
Plugin Slug:
integrio-core
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.8.

Listeo Core

Plugin:
Listeo Core
Plugin Slug:
listeo-core
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.28.

Mikado Core

Plugin:
Mikado Core
Plugin Slug:
mikado-core
Vulnerability:
Local File Inclusion
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

Smart Slider 3 PRO

Plugin:
Smart Slider 3 PRO
Plugin Slug:
nextend-smart-slider3-pro
Vulnerability:
Backdoor
Patched in Version:
3.5.1.36
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.1.36.

Ninja Forms File Uploads Extension

Plugin:
Ninja Forms File Uploads Extension
Plugin Slug:
ninja-forms-uploads
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.27
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.27.

pdfl.io

Plugin:
pdfl.io
Plugin Slug:
pdfl-io
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.6.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Directory Traversal
Patched in Version:
2.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.0.

Quick Playground

Plugin Slug:
quick-playground
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.2.

Softlab Core

Plugin:
Softlab Core
Plugin Slug:
softlab-core
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.11.

Solene Core

Plugin:
Solene Core
Plugin Slug:
solene-core
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.4.

Thegov Core

Plugin:
Thegov Core
Plugin Slug:
thegov-core
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.23
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.23.

Users manager – PN

Plugin Slug:
userspn
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.20
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.20.

MultiLoca

Plugin:
MultiLoca
Plugin Slug:
woocommerce-multi-locations-inventory-management
Vulnerability:
Privilege Escalation
Patched in Version:
4.2.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.16.

WordPress Themes — 24 Patched / 0 Unpatched

Alloggio – Hotel Booking

Theme:
Alloggio – Hotel Booking
Theme Slug:
alloggio
Vulnerability:
PHP Object Injection
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Aperitif

Theme:
Aperitif
Theme Slug:
aperitif
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

Aperitif

Theme:
Aperitif
Theme Slug:
aperitif
Vulnerability:
Local File Inclusion
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Askka

Theme:
Askka
Theme Slug:
askka
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Blueprint

Theme:
Blueprint
Theme Slug:
blueprint
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

Fidalgo

Theme:
Fidalgo
Theme Slug:
fidalgo
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Getaway

Theme:
Getaway
Theme Slug:
getaway
Vulnerability:
Local File Inclusion
Patched in Version:
1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.

Hiroshi

Theme:
Hiroshi
Theme Slug:
hiroshi
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Konsept

Theme:
Konsept
Theme Slug:
konsept
Vulnerability:
PHP Object Injection
Patched in Version:
2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.

Malmö

Theme:
Malmö
Theme Slug:
malmo
Vulnerability:
Local File Inclusion
Patched in Version:
2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.

Micdrop

Theme:
Micdrop
Theme Slug:
micdrop
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Mildhill

Theme:
Mildhill
Theme Slug:
mildhill
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Mr. SEO

Theme:
Mr. SEO
Theme Slug:
mrseo
Vulnerability:
Local File Inclusion
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

NeoBeat

Theme:
NeoBeat
Theme Slug:
neobeat
Vulnerability:
PHP Object Injection
Patched in Version:
1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.

Playroom

Theme:
Playroom
Theme Slug:
playroom
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Santé

Theme:
Santé
Theme Slug:
sante
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

SingleMalt

Theme:
SingleMalt
Theme Slug:
singlemalt
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Solene

Theme:
Solene
Theme Slug:
solene
Vulnerability:
Local File Inclusion
Patched in Version:
3.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.1.

Töbel

Theme:
Töbel
Theme Slug:
tobel
Vulnerability:
PHP Object Injection
Patched in Version:
1.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.

Uppercase

Theme:
Uppercase
Theme Slug:
uppercase
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

Valiance

Theme:
Valiance
Theme Slug:
valiance
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

WaveRide

Theme:
WaveRide
Theme Slug:
waveride
Vulnerability:
Local File Inclusion
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Hitek

Theme:
Hitek
Theme Slug:
xts-hitek
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.3.

Zermatt

Theme:
Zermatt
Theme Slug:
zermatt
Vulnerability:
PHP Object Injection
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security