WordPress Vulnerability Report

WordPress Vulnerability Report — April 22, 2026

Since last week, 216 new vulnerabilities have emerged in the WordPress ecosystem, including 187 plugins and 29 themes. Of those, 29 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 216 vulnerabilities have been publicly disclosed. Security patches for 187 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 29 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 159 Patched / 28 Unpatched

Pz-LinkCard

Plugin Slug:
pz-linkcard
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accept Cryptocurrencies with Plisio

Plugin Slug:
plisio-payment-gateway-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quick Interest Slider

Plugin Slug:
quick-interest-slider
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:
Livemesh Addons for Elementor
Plugin Slug:
addons-for-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Livemesh Addons for Elementor

Plugin:
Livemesh Addons for Elementor
Plugin Slug:
addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Canto

Plugin:
Canto
Plugin Slug:
canto
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CMS für Motorrad Werkstätten

Plugin:
CMS für Motorrad Werkstätten
Plugin Slug:
cms-fuer-motorrad-werkstaetten
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Coachific Shortcode

Plugin:
Coachific Shortcode
Plugin Slug:
coachific-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom New User Notification

Plugin:
Custom New User Notification
Plugin Slug:
custom-new-user-notification
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

e-shot

Plugin:
e-shot
Plugin Slug:
e-shot-form-builder
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inquiry form to posts or pages

Plugin:
Inquiry form to posts or pages
Plugin Slug:
inquiry-form-to-posts-or-pages
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Katalogportal-pdf-sync Widget

Plugin:
Katalogportal-pdf-sync Widget
Plugin Slug:
katalogportal-pdf-sync
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login as User

Plugin:
Login as User
Plugin Slug:
one-click-login-as-user
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite

Plugin:
Accessibility Suite
Plugin Slug:
online-accessibility
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OPEN-BRAIN

Plugin:
OPEN-BRAIN
Plugin Slug:
open-brain
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OPEN-BRAIN

Plugin:
OPEN-BRAIN
Plugin Slug:
open-brain
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibly – WordPress Website Accessibility

Plugin:
Accessibly – WordPress Website Accessibility
Plugin Slug:
otm-accessibly
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Petje.af

Plugin:
Petje.af
Plugin Slug:
petje-af
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:
Riaxe Product Customizer
Plugin Slug:
riaxe-product-customizer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:
Riaxe Product Customizer
Plugin Slug:
riaxe-product-customizer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Riaxe Product Customizer

Plugin:
Riaxe Product Customizer
Plugin Slug:
riaxe-product-customizer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

VI: Include Post By

Plugin:
VI: Include Post By
Plugin Slug:
vi-include-post-by
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Visa Acceptance Solutions

Plugin:
Visa Acceptance Solutions
Plugin Slug:
visa-acceptance-solutions
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WM JqMath

Plugin:
WM JqMath
Plugin Slug:
wm-jqmath
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Circliful

Plugin:
WP Circliful
Plugin Slug:
wp-circliful
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Power Charts

Plugin:
Power Charts
Plugin Slug:
wpgo-power-charts-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom Fields (ACF®)

Plugin Slug:
advanced-custom-fields
Installations
2,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.1.

ManageWP Worker

Plugin Slug:
worker
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.32.

BackWPup – WordPress Backup & Restore Plugin

Plugin Slug:
backwpup
Installations
500,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.6.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.6.7.

Meta Box

Plugin:
Meta Box
Plugin Slug:
meta-box
Installations
500,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
5.11.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.0.

Page Builder Gutenberg Blocks – CoBlocks

Plugin Slug:
coblocks
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.17.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.7.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.0.

CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance
Installations
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.1.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.17.

Post Duplicator

Plugin Slug:
post-duplicator
Installations
200,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.0.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.11.

JetBackup – Backup, Restore & Migrate

Plugin Slug:
backup
Installations
100,000+
Vulnerability:
Path Traversal
Patched in Version:
3.1.20.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.20.3.

Anti-Malware Security and Brute-Force Firewall

Plugin Slug:
gotmls
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.23.88
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.23.88.

Kubio AI Page Builder

Plugin Slug:
kubio
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.3.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.14.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.14.19.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.8.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.9.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.9.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
5.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.10.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.4.

Email Encoder – Protect Email Addresses and Phone Numbers

Plugin Slug:
email-encoder-bundle
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.102.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.102.0.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Broken Authentication
Patched in Version:
5.104.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.104.0.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.14.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.14.2.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.14.2.

OneSignal – Web Push Notifications

Plugin Slug:
onesignal-free-web-push-notifications
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.1
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.8.1.

Germanized for WooCommerce

Plugin Slug:
woocommerce-germanized
Installations
70,000+
Vulnerability:
Content Injection
Patched in Version:
3.20.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.6.
Plugin Slug:
contextual-related-posts
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.7.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.3.9.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.7.

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Open Redirection
Patched in Version:
5.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.5.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.3.

Product Filter for WooCommerce by WBW

Plugin Slug:
woo-product-filter
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
3.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.3.

Advanced Product Fields (Product Addons) for WooCommerce

Plugin Slug:
advanced-product-fields-for-woocommerce
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.20.

Categories Images

Plugin Slug:
categories-images
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

Better Find and Replace – AI-Powered Suggestions

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

YayMail – WooCommerce Email Customizer

Plugin Slug:
yaymail
Installations
50,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.4.

Website LLMs.txt

Plugin Slug:
website-llms-txt
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.7.

Website LLMs.txt

Plugin Slug:
website-llms-txt
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.7.

WP YouTube Lyte

Plugin Slug:
wp-youtube-lyte
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.30.

Social Slider Feed

Plugin Slug:
instagram-slider-widget
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.3.

Payment Gateway for Redsys & WooCommerce Lite

Plugin Slug:
woo-redsys-gateway-light
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.1.

Payment Gateway for Redsys & WooCommerce Lite

Plugin Slug:
woo-redsys-gateway-light
Installations
20,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
7.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.1.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Directory Traversal
Patched in Version:
3.0.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.6.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.3.

WPZOOM Addons for Elementor – Starter Templates & Widgets

Plugin Slug:
wpzoom-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.1.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
8.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.3.5.

Easy Appointments

Plugin Slug:
easy-appointments
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.12.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.22.

Easy Appointments

Plugin Slug:
easy-appointments
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.12.22
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.22.

EMC – Easily Embed Calendly Scheduling

Plugin Slug:
embed-calendly-scheduling
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.08.002
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 9.1.08.002.

YML for Yandex Market

Plugin Slug:
yml-for-yandex-market
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
5.0.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.26.

WCAPF – Ajax Product Filter for WooCommerce

Plugin Slug:
wc-ajax-product-filter
Installations
9,000+
Vulnerability:
SQL Injection
Patched in Version:
4.3.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3.0.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.3.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.0.1.

ActivityPub

Plugin Slug:
activitypub
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
8.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.0.2.

Nexi XPay

Plugin:
Nexi XPay
Plugin Slug:
cartasi-x-pay
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.2.

Booking Activities

Plugin Slug:
booking-activities
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.17.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.17.0.

Notification for Telegram

Plugin Slug:
notification-for-telegram
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.1.

Responsive Blocks – Page Builder for Blocks & Patterns

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Open Redirection
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Basic Google Maps Placemarks

Plugin Slug:
basic-google-maps-placemarks
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.8.

Events Calendar for GeoDirectory

Plugin Slug:
events-for-geodirectory
Installations
3,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.3.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.26.

Image Source Control Lite – Show Image Credits and Captions

Plugin Slug:
image-source-control-isc
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.2.

SpeakOut! Email Petitions

Plugin Slug:
speakout
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
4.6.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.5.1.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.1.

Prismatic

Plugin:
Prismatic
Plugin Slug:
prismatic
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.4.

Shipment Tracker for Woocommerce

Plugin Slug:
shipment-tracker-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.3.

MyRewards

Plugin:
MyRewards
Plugin Slug:
woorewards
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.4.

Mini Ajax Cart for WooCommerce

Plugin Slug:
mini-ajax-woo-cart
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WP Docs

Plugin:
WP Docs
Plugin Slug:
wp-docs
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.0.
Plugin Slug:
inpost-gallery
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
2.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.5.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
1.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.5.

List View Google Calendar

Plugin Slug:
list-view-google-calendar
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.4.

Webling

Plugin:
Webling
Plugin Slug:
webling
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.1.

Flipbox Addon for Elementor

Plugin Slug:
ultimate-flipbox-addon-for-elementor
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

BuddyPress Groupblog

Plugin Slug:
bp-groupblog
Installations
50+
Vulnerability:
Privilege Escalation
Patched in Version:
1.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.4.

Ultra Addons for WPForms

Plugin Slug:
ultra-addons-for-wpforms
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.12.

Hostel

Plugin:
Hostel
Plugin Slug:
hostel
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.7.

HAPPY – Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.11.

Surbma | Booking.com Shortcode

Plugin Slug:
surbma-bookingcom-shortcode
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

WholeSale Products Dynamic Pricing Management WooCommerce

Plugin Slug:
wholesale-products-dynamic-pricing-management-woocommerce
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

Academy LMS Pro

Plugin:
Academy LMS Pro
Plugin Slug:
academy-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.2.

Accordion and Accordion Slider

Plugin:
Accordion and Accordion Slider
Plugin Slug:
accordion-and-accordion-slider
Vulnerability:
Backdoor
Patched in Version:
1.4.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.6.1.
Plugin:
Album and Image Gallery plus Lightbox
Plugin Slug:
album-and-image-gallery-plus-lightbox
Vulnerability:
Backdoor
Patched in Version:
2.1.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.8.1.

Blog Designer – Post and Widget

Plugin:
Blog Designer – Post and Widget
Plugin Slug:
blog-designer-for-post-and-widget
Vulnerability:
Backdoor
Patched in Version:
2.7.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.7.1.

Career Section

Plugin Slug:
career-section
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

Countdown Timer Ultimate

Plugin:
Countdown Timer Ultimate
Plugin Slug:
countdown-timer-ultimate
Vulnerability:
Backdoor
Patched in Version:
2.6.9.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.9.1.

Featured Post Creative

Plugin:
Featured Post Creative
Plugin Slug:
featured-post-creative
Vulnerability:
Backdoor
Patched in Version:
1.5.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.7.1.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Content Injection
Patched in Version:
3.15.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.15.2.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.15.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.15.2.

Gravity SMTP

Plugin:
Gravity SMTP
Plugin Slug:
gravitysmtp
Vulnerability:
Broken Access Control
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.
Plugin:
Video gallery and Player
Plugin Slug:
html5-videogallery-plus-player
Vulnerability:
Backdoor
Patched in Version:
2.8.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.7.1.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
SQL Injection
Patched in Version:
3.8.6.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.6.2.

Client Portal (Pro)

Plugin:
Client Portal (Pro)
Plugin Slug:
leco-client-portal
Vulnerability:
Arbitrary File Download
Patched in Version:
5.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.3.
Plugin:
Meta slider and carousel with lightbox
Plugin Slug:
meta-slider-and-carousel-with-lightbox
Vulnerability:
Backdoor
Patched in Version:
2.0.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.8.1.

MetForm Pro

Plugin:
MetForm Pro
Plugin Slug:
metform-pro
Vulnerability:
Broken Access Control
Patched in Version:
3.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.8.

Popup Anything

Plugin:
Popup Anything
Plugin Slug:
popup-anything-on-click
Vulnerability:
Backdoor
Patched in Version:
2.9.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.1.1.

Portfolio and Projects

Plugin:
Portfolio and Projects
Plugin Slug:
portfolio-and-projects
Vulnerability:
Backdoor
Patched in Version:
1.5.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.6.1.

Post grid and filter ultimate

Plugin:
Post grid and filter ultimate
Plugin Slug:
post-grid-and-filter-ultimate
Vulnerability:
Backdoor
Patched in Version:
1.7.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.4.1.

WP responsive FAQ with category

Plugin:
WP responsive FAQ with category
Plugin Slug:
sp-faq
Vulnerability:
Backdoor
Patched in Version:
3.9.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.5.1.

WP News and Scrolling Widgets

Plugin:
WP News and Scrolling Widgets
Plugin Slug:
sp-news-and-widget
Vulnerability:
Backdoor
Patched in Version:
5.0.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.6.1.

WowShipping Pro

Plugin:
WowShipping Pro
Plugin Slug:
table-rate-shipping-pro
Vulnerability:
Backdoor
Patched in Version:
1.0.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.8.

Post Ticker Ultimate

Plugin:
Post Ticker Ultimate
Plugin Slug:
ticker-ultimate
Vulnerability:
Backdoor
Patched in Version:
1.7.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.6.1.

Timeline and History slider

Plugin:
Timeline and History slider
Plugin Slug:
timeline-and-history-slider
Vulnerability:
Backdoor
Patched in Version:
2.4.5.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.5.1.

User Registration Stripe

Plugin:
User Registration Stripe
Plugin Slug:
user-registration-stripe
Vulnerability:
Broken Access Control
Patched in Version:
1.3.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.15.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.11.

Product Pricing Table by WooBeWoo

Plugin:
Product Pricing Table by WooBeWoo
Plugin Slug:
woo-product-pricing-tables
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

WooCommerce Product Filters

Plugin:
WooCommerce Product Filters
Plugin Slug:
woocommerce-product-filters
Vulnerability:
PHP Object Injection
Patched in Version:
2.0.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.6.

WP Blog and Widget

Plugin:
WP Blog and Widget
Plugin Slug:
wp-blog-and-widgets
Vulnerability:
Backdoor
Patched in Version:
2.6.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.6.6.1.
Plugin:
WP Featured Content and Slider
Plugin Slug:
wp-featured-content-and-slider
Vulnerability:
Backdoor
Patched in Version:
1.7.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.6.1.
Plugin:
WP Logo Showcase Responsive Slider and Carousel
Plugin Slug:
wp-logo-showcase-responsive-slider-slider
Vulnerability:
Backdoor
Patched in Version:
3.8.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.7.1.

WP Responsive Recent Post Slider/Carousel

Plugin:
WP Responsive Recent Post Slider/Carousel
Plugin Slug:
wp-responsive-recent-post-slider
Vulnerability:
Backdoor
Patched in Version:
3.7.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.7.1.1.
Plugin:
WP Slick Slider and Image Carousel
Plugin Slug:
wp-slick-slider-and-image-carousel
Vulnerability:
Backdoor
Patched in Version:
3.7.8.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.7.8.2.
Plugin:
Team Slider and Team Grid Showcase plus Team Carousel
Plugin Slug:
wp-team-showcase-and-slider
Vulnerability:
Backdoor
Patched in Version:
2.8.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.6.1.
Plugin:
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
Plugin Slug:
wp-testimonial-with-widget
Vulnerability:
Backdoor
Patched in Version:
3.5.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.5.6.1.

Trending/Popular Post Slider and Widget

Plugin:
Trending/Popular Post Slider and Widget
Plugin Slug:
wp-trending-post-slider-and-widget
Vulnerability:
Backdoor
Patched in Version:
1.8.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.6.1.

Royal Elementor Addons Pro

Plugin:
Royal Elementor Addons Pro
Plugin Slug:
wpr-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1041
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1041.

WordPress Themes — 28 Patched / 1 Unpatched

WebStack

Theme:
WebStack
Theme Slug:
webstack
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Charity Zone

Theme Slug:
charity-zone
Downloads
112,126
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.2.

Ecommerce Zone

Theme Slug:
ecommerce-zone
Downloads
89,443
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.9.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.9.8.

Kids Gift Shop

Theme Slug:
kids-gift-shop
Downloads
20,521
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.5.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.5.5.

Kids Online Store

Theme Slug:
kids-online-store
Downloads
53,065
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.9.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.9.0.

Restaurant Zone

Theme Slug:
restaurant-zone
Downloads
80,108
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.7.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.7.9.

Vantage

Theme:
Vantage
Theme Slug:
vantage
Downloads
3,232,270
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.20.33
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.20.33.

Webenvo

Theme:
Webenvo
Theme Slug:
webenvo
Downloads
10,224
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.0.7.

Ashtanga

Theme:
Ashtanga
Theme Slug:
ashtanga
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Atomlab

Theme:
Atomlab
Theme Slug:
atomlab
Vulnerability:
Local File Inclusion
Patched in Version:
2.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.6.

Behold

Theme:
Behold
Theme Slug:
behold
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

ChapterOne

Theme:
ChapterOne
Theme Slug:
chapterone
Vulnerability:
Local File Inclusion
Patched in Version:
1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.

Château

Theme:
Château
Theme Slug:
chateau
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

EasyMeals

Theme:
EasyMeals
Theme Slug:
easymeals
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Eldon

Theme:
Eldon
Theme Slug:
eldon
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Eleganzo

Theme:
Eleganzo
Theme Slug:
eleganzo
Vulnerability:
Path Traversal
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Elementra

Theme:
Elementra
Theme Slug:
elementra
Vulnerability:
PHP Object Injection
Patched in Version:
1.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.0.

Esmée

Theme:
Esmée
Theme Slug:
esme
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Laurits

Theme:
Laurits
Theme Slug:
laurits
Vulnerability:
PHP Object Injection
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Léonie

Theme:
Léonie
Theme Slug:
lonie
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

LuxeDrive

Theme:
LuxeDrive
Theme Slug:
luxedrive
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

MagOne

Theme:
MagOne
Theme Slug:
magone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.

Manufaktur Solutions

Theme:
Manufaktur Solutions
Theme Slug:
manufaktursolutions
Vulnerability:
PHP Object Injection
Patched in Version:
1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.

Reina

Theme:
Reina
Theme Slug:
reina
Vulnerability:
PHP Object Injection
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Roisin

Theme:
Roisin
Theme Slug:
roisin
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

ShiftUp

Theme:
ShiftUp
Theme Slug:
shiftup
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.
Theme:
TechLink
Theme Slug:
techlink
Vulnerability:
PHP Object Injection
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Valeska

Theme:
Valeska
Theme Slug:
valeska
Vulnerability:
PHP Object Injection
Patched in Version:
1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.

Zoya

Theme:
Zoya
Theme Slug:
zoya
Vulnerability:
PHP Object Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security