In this report, 216 vulnerabilities have been publicly disclosed. Security patches for 187 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Currently, 29 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.
WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.
WordPress Plugins — 159 Patched / 28 Unpatched
Pz-LinkCard
- Plugin:
- Pz-LinkCard
- Plugin Slug:
- pz-linkcard
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-2434
WCFM Marketplace – Multivendor Marketplace for WooCommerce
- Plugin Slug:
- wc-multivendor-marketplace
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-63029
Smart Online Order for Clover
- Plugin:
- Smart Online Order for Clover
- Plugin Slug:
- clover-online-orders
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-15635
Accept Cryptocurrencies with Plisio
- Plugin Slug:
- plisio-payment-gateway-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-6372
Quick Interest Slider
- Plugin:
- Quick Interest Slider
- Plugin Slug:
- quick-interest-slider
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-5694
Livemesh Addons for Elementor
- Plugin:
- Livemesh Addons for Elementor
- Plugin Slug:
- addons-for-elementor
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-1620
Livemesh Addons for Elementor
- Plugin:
- Livemesh Addons for Elementor
- Plugin Slug:
- addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-1572
Canto
- Plugin:
- Canto
- Plugin Slug:
- canto
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-6441
CMS für Motorrad Werkstätten
- Plugin:
- CMS für Motorrad Werkstätten
- Plugin Slug:
- cms-fuer-motorrad-werkstaetten
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-6451
Coachific Shortcode
- Plugin:
- Coachific Shortcode
- Plugin Slug:
- coachific-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4005
Custom New User Notification
- Plugin:
- Custom New User Notification
- Plugin Slug:
- custom-new-user-notification
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3551
e-shot
- Plugin:
- e-shot
- Plugin Slug:
- e-shot-form-builder
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3642
Inquiry form to posts or pages
- Plugin:
- Inquiry form to posts or pages
- Plugin Slug:
- inquiry-form-to-posts-or-pages
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-6293
Katalogportal-pdf-sync Widget
- Plugin:
- Katalogportal-pdf-sync Widget
- Plugin Slug:
- katalogportal-pdf-sync
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3649
Login as User
- Plugin:
- Login as User
- Plugin Slug:
- one-click-login-as-user
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-5617
Accessibility Suite
- Plugin:
- Accessibility Suite
- Plugin Slug:
- online-accessibility
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-3773
OPEN-BRAIN
- Plugin:
- OPEN-BRAIN
- Plugin Slug:
- open-brain
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3995
OPEN-BRAIN
- Plugin:
- OPEN-BRAIN
- Plugin Slug:
- open-brain
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4091
Accessibly – WordPress Website Accessibility
- Plugin:
- Accessibly – WordPress Website Accessibility
- Plugin Slug:
- otm-accessibly
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2026-3643
Petje.af
- Plugin:
- Petje.af
- Plugin Slug:
- petje-af
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4002
Riaxe Product Customizer
- Plugin:
- Riaxe Product Customizer
- Plugin Slug:
- riaxe-product-customizer
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-3599
Riaxe Product Customizer
- Plugin:
- Riaxe Product Customizer
- Plugin Slug:
- riaxe-product-customizer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3595
Riaxe Product Customizer
- Plugin:
- Riaxe Product Customizer
- Plugin Slug:
- riaxe-product-customizer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-3596
VI: Include Post By
- Plugin:
- VI: Include Post By
- Plugin Slug:
- vi-include-post-by
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-5717
Visa Acceptance Solutions
- Plugin:
- Visa Acceptance Solutions
- Plugin Slug:
- visa-acceptance-solutions
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-3461
WM JqMath
- Plugin:
- WM JqMath
- Plugin Slug:
- wm-jqmath
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3998
WP Circliful
- Plugin:
- WP Circliful
- Plugin Slug:
- wp-circliful
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-3659
Power Charts
- Plugin:
- Power Charts
- Plugin Slug:
- wpgo-power-charts-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2026-4011
Advanced Custom Fields (ACF®)
- Plugin:
- Advanced Custom Fields (ACF®)
- Plugin Slug:
- advanced-custom-fields
- Installations
- 2,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 6.7.1
- Severity Score:
- Medium
- CVE:
- 2026-4812
ManageWP Worker
- Plugin:
- ManageWP Worker
- Plugin Slug:
- worker
- Installations
- 1,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.9.32
- Severity Score:
- High
- CVE:
- 2026-39463
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
- Plugin Slug:
- fluentform
- Installations
- 700,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 6.2.0
- Severity Score:
- Medium
- CVE:
- 2026-4160
Royal Addons for Elementor – Addons and Templates Kit for Elementor
- Plugin Slug:
- royal-elementor-addons
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1057
- Severity Score:
- Medium
- CVE:
- 2026-5162
WP Statistics – Simple, privacy-friendly Google Analytics alternative
- Plugin Slug:
- wp-statistics
- Installations
- 600,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 14.16.5
- Severity Score:
- Medium
- CVE:
- 2026-3488
WP Statistics – Simple, privacy-friendly Google Analytics alternative
- Plugin Slug:
- wp-statistics
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 14.16.5
- Severity Score:
- High
- CVE:
- 2026-5231
BackWPup – WordPress Backup & Restore Plugin
- Plugin Slug:
- backwpup
- Installations
- 500,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 5.6.7
- Severity Score:
- High
- CVE:
- 2026-6227
Meta Box
- Plugin:
- Meta Box
- Plugin Slug:
- meta-box
- Installations
- 500,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 5.11.2
- Severity Score:
- Medium
- CVE:
- 2026-39468
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
- Plugin Slug:
- ml-slider
- Installations
- 500,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.107.0
- Severity Score:
- High
- CVE:
- 2026-39467
Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider
- Plugin Slug:
- ml-slider
- Installations
- 500,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 3.107.0
- Severity Score:
- Critical
- CVE:
- 2026-39465
WP Shortcodes Plugin — Shortcodes Ultimate
- Plugin Slug:
- shortcodes-ultimate
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.5.0
- Severity Score:
- Medium
- CVE:
- 2026-3885
Page Builder Gutenberg Blocks – CoBlocks
- Plugin Slug:
- coblocks
- Installations
- 300,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.1.17
- Severity Score:
- Medium
- CVE:
- 2026-4801
ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF
- Plugin Slug:
- shortpixel-image-optimiser
- Installations
- 300,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 6.4.4
- Severity Score:
- High
- CVE:
- 2026-39471
Unlimited Elements For Elementor
- Plugin:
- Unlimited Elements For Elementor
- Plugin Slug:
- unlimited-elements-for-elementor
- Installations
- 300,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 2.0.7
- Severity Score:
- High
- CVE:
- 2026-4659
PDF Invoices & Packing Slips for WooCommerce
- Plugin Slug:
- woocommerce-pdf-invoices-packing-slips
- Installations
- 300,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 5.9.0
- Severity Score:
- High
- CVE:
- 2026-39472
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
- Plugin Slug:
- cmp-coming-soon-maintenance
- Installations
- 200,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.1.17
- Severity Score:
- High
- CVE:
- 2026-6518
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
- Plugin Slug:
- optimole-wp
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.3
- Severity Score:
- High
- CVE:
- 2026-5217
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
- Plugin Slug:
- optimole-wp
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.4
- Severity Score:
- High
- CVE:
- 2026-5226
Post Duplicator
- Plugin:
- Post Duplicator
- Plugin Slug:
- post-duplicator
- Installations
- 200,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.0.11
- Severity Score:
- High
- CVE:
- 2026-39474
JetBackup – Backup, Restore & Migrate
- Plugin Slug:
- backup
- Installations
- 100,000+
- Vulnerability:
- Path Traversal
- Patched in Version:
- 3.1.20.3
- Severity Score:
- Medium
- CVE:
- 2026-4853
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
- Plugin Slug:
- everest-forms
- Installations
- 100,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 3.4.5
- Severity Score:
- High
- CVE:
- 2026-5478
Anti-Malware Security and Brute-Force Firewall
- Plugin Slug:
- gotmls
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 4.23.88
- Severity Score:
- High
- CVE:
- 2026-39478
Kubio AI Page Builder
- Plugin:
- Kubio AI Page Builder
- Plugin Slug:
- kubio
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.7.3
- Severity Score:
- Medium
- CVE:
- 2026-5427
LatePoint – Calendar Booking Plugin for Appointments and Events
- Plugin Slug:
- latepoint
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 5.4.0
- Severity Score:
- Medium
- CVE:
- 2026-5234
Modula Image Gallery – Photo Grid & Video Gallery
- Plugin Slug:
- modula-best-grid-gallery
- Installations
- 100,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.14.19
- Severity Score:
- High
- CVE:
- 2026-39481
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.8
- Severity Score:
- Medium
- CVE:
- 2026-40743
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.9.9
- Severity Score:
- High
- CVE:
- 2026-6080
Tutor LMS – eLearning and online course solution
- Plugin Slug:
- tutor
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.9
- Severity Score:
- Medium
- CVE:
- 2026-5502
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
- Plugin Slug:
- wp-user-avatar
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.16.13
- Severity Score:
- Medium
- CVE:
- 2026-4949
Download Monitor
- Plugin:
- Download Monitor
- Plugin Slug:
- download-monitor
- Installations
- 90,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 5.1.10
- Severity Score:
- Medium
- CVE:
- 2026-39489
Email Encoder – Protect Email Addresses and Phone Numbers
- Plugin Slug:
- email-encoder-bundle
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.4
- Severity Score:
- Medium
- CVE:
- 2024-7083
Email Encoder – Protect Email Addresses and Phone Numbers
- Plugin Slug:
- email-encoder-bundle
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.5
- Severity Score:
- Medium
- CVE:
- 2026-2840
ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
- Plugin Slug:
- woolentor-addons
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.6
- Severity Score:
- Medium
- CVE:
- 2026-4059
Customer Reviews for WooCommerce
- Plugin:
- Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.102.0
- Severity Score:
- High
- CVE:
- 2026-3355
Customer Reviews for WooCommerce
- Plugin:
- Customer Reviews for WooCommerce
- Plugin Slug:
- customer-reviews-woocommerce
- Installations
- 80,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 5.104.0
- Severity Score:
- Medium
- CVE:
- 2026-4664
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
- Plugin Slug:
- interactive-3d-flipbook-powered-physics-engine
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.16.18
- Severity Score:
- Medium
- CVE:
- 2026-1314
Jupiter X Core
- Plugin:
- Jupiter X Core
- Plugin Slug:
- jupiterx-core
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.14.2
- Severity Score:
- High
- CVE:
- 2026-39490
Jupiter X Core
- Plugin:
- Jupiter X Core
- Plugin Slug:
- jupiterx-core
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.14.2
- Severity Score:
- Medium
- CVE:
- 2026-39491
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
- Plugin Slug:
- learnpress
- Installations
- 80,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.3.3
- Severity Score:
- Critical
- CVE:
- 2026-4365
OneSignal – Web Push Notifications
- Plugin Slug:
- onesignal-free-web-push-notifications
- Installations
- 70,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.8.1
- Severity Score:
- Low
- CVE:
- 2026-3155
Germanized for WooCommerce
- Plugin:
- Germanized for WooCommerce
- Plugin Slug:
- woocommerce-germanized
- Installations
- 70,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 3.20.6
- Severity Score:
- Medium
- CVE:
- 2026-2582
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
- Plugin Slug:
- wpdatatables
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.5.0.5
- Severity Score:
- Medium
- CVE:
- 2026-5721
Contextual Related Posts
- Plugin:
- Contextual Related Posts
- Plugin Slug:
- contextual-related-posts
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.2
- Severity Score:
- Medium
- CVE:
- 2026-2986
Drag and Drop Multiple File Upload for Contact Form 7
- Plugin Slug:
- drag-and-drop-multiple-file-upload-contact-form-7
- Installations
- 60,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.3.9.7
- Severity Score:
- High
- CVE:
- 2026-5718
Drag and Drop Multiple File Upload for Contact Form 7
- Plugin Slug:
- drag-and-drop-multiple-file-upload-contact-form-7
- Installations
- 60,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 1.3.9.7
- Severity Score:
- High
- CVE:
- 2026-5710
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
- Plugin Slug:
- user-registration
- Installations
- 60,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 5.1.5
- Severity Score:
- Medium
- CVE:
- 2026-6203
Product Filter for WooCommerce by WBW
- Plugin Slug:
- woo-product-filter
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.1.3
- Severity Score:
- Critical
- CVE:
- 2026-3830
Product Filter for WooCommerce by WBW
- Plugin Slug:
- woo-product-filter
- Installations
- 60,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.1.3
- Severity Score:
- Critical
- CVE:
- 2026-39494
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
- Plugin Slug:
- wp-google-map-plugin
- Installations
- 60,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.8
- Severity Score:
- Medium
- CVE:
- 2025-13364
Advanced Product Fields (Product Addons) for WooCommerce
- Plugin Slug:
- advanced-product-fields-for-woocommerce
- Installations
- 50,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6.20
- Severity Score:
- High
- CVE:
- 2026-39499
Categories Images
- Plugin:
- Categories Images
- Plugin Slug:
- categories-images
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.2
- Severity Score:
- Medium
- CVE:
- 2026-2505
Better Find and Replace – AI-Powered Suggestions
- Plugin Slug:
- real-time-auto-find-and-replace
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.8.0
- Severity Score:
- Medium
- CVE:
- 2026-3369
YayMail – WooCommerce Email Customizer
- Plugin Slug:
- yaymail
- Installations
- 50,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 4.3.4
- Severity Score:
- High
- CVE:
- 2026-39498
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
- Plugin Slug:
- betterdocs
- Installations
- 40,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3.9
- Severity Score:
- Medium
- CVE:
- 2026-3875
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
- Plugin Slug:
- easy-digital-downloads
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.6.6
- Severity Score:
- High
- CVE:
- 2026-39503
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
- Plugin Slug:
- quiz-master-next
- Installations
- 40,000+
- Vulnerability:
- Content Injection
- Patched in Version:
- 11.1.1
- Severity Score:
- Medium
- CVE:
- 2026-5797
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
- Plugin Slug:
- ultimate-post
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.0.6
- Severity Score:
- Medium
- CVE:
- 2026-0718
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.15.41
- Severity Score:
- High
- CVE:
- 2026-3330
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.15.41
- Severity Score:
- High
- CVE:
- 2026-4388
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
- Plugin Slug:
- form-maker
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.15.38
- Severity Score:
- Critical
- CVE:
- 2025-15441
Website LLMs.txt
- Plugin:
- Website LLMs.txt
- Plugin Slug:
- website-llms-txt
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.2.7
- Severity Score:
- Medium
- CVE:
- 2026-6712
Website LLMs.txt
- Plugin:
- Website LLMs.txt
- Plugin Slug:
- website-llms-txt
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 8.2.7
- Severity Score:
- Medium
- CVE:
- 2026-6711
WP YouTube Lyte
- Plugin:
- WP YouTube Lyte
- Plugin Slug:
- wp-youtube-lyte
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.30
- Severity Score:
- Medium
- CVE:
- 2026-3299
Social Slider Feed
- Plugin:
- Social Slider Feed
- Plugin Slug:
- instagram-slider-widget
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.3
- Severity Score:
- High
- CVE:
- 2026-39507
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
- Plugin Slug:
- post-carousel
- Installations
- 20,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 3.0.13
- Severity Score:
- High
- CVE:
- 2026-3017
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin:
- UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
- Plugin Slug:
- userswp
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.61
- Severity Score:
- Medium
- CVE:
- 2026-5742
Payment Gateway for Redsys & WooCommerce Lite
- Plugin Slug:
- woo-redsys-gateway-light
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 7.0.1
- Severity Score:
- High
- CVE:
- 2026-40741
Payment Gateway for Redsys & WooCommerce Lite
- Plugin Slug:
- woo-redsys-gateway-light
- Installations
- 20,000+
- Vulnerability:
- Bypass Vulnerability
- Patched in Version:
- 7.0.1
- Severity Score:
- High
- CVE:
- 2026-5050
wpForo Forum
- Plugin:
- wpForo Forum
- Plugin Slug:
- wpforo
- Installations
- 20,000+
- Vulnerability:
- Directory Traversal
- Patched in Version:
- 3.0.6
- Severity Score:
- High
- CVE:
- 2026-6248
wpForo Forum
- Plugin:
- wpForo Forum
- Plugin Slug:
- wpforo
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.0.0
- Severity Score:
- Medium
- CVE:
- 2026-4666
wpForo Forum
- Plugin:
- wpForo Forum
- Plugin Slug:
- wpforo
- Installations
- 20,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 3.0.3
- Severity Score:
- High
- CVE:
- 2026-5809
WPZOOM Addons for Elementor – Starter Templates & Widgets
- Plugin Slug:
- wpzoom-elementor-addons
- Installations
- 20,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- High
- CVE:
- 2026-39597
Content Blocks (Custom Post Widget)
- Plugin Slug:
- custom-post-widget
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.4.1
- Severity Score:
- Medium
- CVE:
- 2026-0894
WP Customer Area
- Plugin:
- WP Customer Area
- Plugin Slug:
- customer-area
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 8.3.5
- Severity Score:
- High
- CVE:
- 2026-3464
Easy Appointments
- Plugin:
- Easy Appointments
- Plugin Slug:
- easy-appointments
- Installations
- 10,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.12.22
- Severity Score:
- High
- CVE:
- 2026-2262
Easy Appointments
- Plugin:
- Easy Appointments
- Plugin Slug:
- easy-appointments
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.12.22
- Severity Score:
- High
- CVE:
- 2026-39513
EMC – Easily Embed Calendly Scheduling
- Plugin Slug:
- embed-calendly-scheduling
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.5
- Severity Score:
- Medium
- CVE:
- 2026-0868
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
- Plugin Slug:
- geodirectory
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.8.154
- Severity Score:
- Critical
- CVE:
- 2026-39512
MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Plugin Slug:
- masterstudy-lms-learning-management-system
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.7.26
- Severity Score:
- High
- CVE:
- 2026-4817
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.0
- Severity Score:
- High
- CVE:
- 2026-39514
Royal WordPress Backup, Restore & Migration Plugin – Backup WordPress Sites Safely
- Plugin Slug:
- royal-backup-reset
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.17
- Severity Score:
- High
- CVE:
- 2026-4305
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
- Plugin Slug:
- wp-event-solution
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.1.9
- Severity Score:
- Medium
- CVE:
- 2026-4109
WP Photo Album Plus
- Plugin:
- WP Photo Album Plus
- Plugin Slug:
- wp-photo-album-plus
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 9.1.08.002
- Severity Score:
- Critical
- CVE:
- 2026-39511
YML for Yandex Market
- Plugin:
- YML for Yandex Market
- Plugin Slug:
- yml-for-yandex-market
- Installations
- 10,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 5.0.26
- Severity Score:
- High
- CVE:
- 2025-14545
WCAPF – Ajax Product Filter for WooCommerce
- Plugin Slug:
- wc-ajax-product-filter
- Installations
- 9,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.3.0
- Severity Score:
- Critical
- CVE:
- 2026-3396
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
- Plugin Slug:
- acymailing
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 10.8.2
- Severity Score:
- High
- CVE:
- 2026-3614
EventPrime – Events Calendar, Bookings and Tickets
- Plugin Slug:
- eventprime-event-calendar-management
- Installations
- 7,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 4.3.0.1
- Severity Score:
- High
- CVE:
- 2026-39518
ActivityPub
- Plugin:
- ActivityPub
- Plugin Slug:
- activitypub
- Installations
- 6,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 8.0.2
- Severity Score:
- High
- CVE:
- 2026-4338
Nexi XPay
- Plugin:
- Nexi XPay
- Plugin Slug:
- cartasi-x-pay
- Installations
- 6,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 8.3.2
- Severity Score:
- Medium
- CVE:
- 2025-15565
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
- Plugin Slug:
- fluent-boards
- Installations
- 6,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 1.91.3
- Severity Score:
- High
- CVE:
- 2026-40784
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin:
- Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin Slug:
- youzify
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.7
- Severity Score:
- Medium
- CVE:
- 2026-1559
Booking Activities
- Plugin:
- Booking Activities
- Plugin Slug:
- booking-activities
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.17.0
- Severity Score:
- Medium
- CVE:
- 2026-39525
Notification for Telegram
- Plugin:
- Notification for Telegram
- Plugin Slug:
- notification-for-telegram
- Installations
- 4,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.1
- Severity Score:
- High
- CVE:
- 2026-40732
Responsive Blocks – Page Builder for Blocks & Patterns
- Plugin Slug:
- responsive-block-editor-addons
- Installations
- 4,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- 2.2.1
- Severity Score:
- Medium
- CVE:
- 2026-6675
WpStream – Live Streaming, Video on Demand, Pay Per View
- Plugin Slug:
- wpstream
- Installations
- 4,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 4.11.2
- Severity Score:
- Medium
- CVE:
- 2026-39527
Basic Google Maps Placemarks
- Plugin:
- Basic Google Maps Placemarks
- Plugin Slug:
- basic-google-maps-placemarks
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.10.8
- Severity Score:
- Medium
- CVE:
- 2026-3581
Events Calendar for GeoDirectory
- Plugin:
- Events Calendar for GeoDirectory
- Plugin Slug:
- events-for-geodirectory
- Installations
- 3,000+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.3.26
- Severity Score:
- High
- CVE:
- 2026-39532
Image Source Control Lite – Show Image Credits and Captions
- Plugin Slug:
- image-source-control-isc
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.9.2
- Severity Score:
- Medium
- CVE:
- 2026-4852
SpeakOut! Email Petitions
- Plugin:
- SpeakOut! Email Petitions
- Plugin Slug:
- speakout
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 4.6.5.1
- Severity Score:
- Critical
- CVE:
- 2026-39530
WP Directory Kit
- Plugin:
- WP Directory Kit
- Plugin Slug:
- wpdirectorykit
- Installations
- 3,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.1
- Severity Score:
- Critical
- CVE:
- 2026-39531
Groundhogg — CRM, Newsletters, and Marketing Automation
- Plugin Slug:
- groundhogg
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 4.4.1
- Severity Score:
- High
- CVE:
- 2026-40727
Prismatic
Shipment Tracker for Woocommerce
- Plugin:
- Shipment Tracker for Woocommerce
- Plugin Slug:
- shipment-tracker-for-woocommerce
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.3.3
- Severity Score:
- Medium
- CVE:
- 2026-39540
MyRewards
- Plugin:
- MyRewards
- Plugin Slug:
- woorewards
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 5.7.4
- Severity Score:
- Medium
- CVE:
- 2026-40786
Video Gallery – YouTube Gallery & Responsive Video Playlist
- Plugin Slug:
- youtube-showcase
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.2
- Severity Score:
- Medium
- CVE:
- 2025-15636
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
- Plugin:
- Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 1,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.12.0
- Severity Score:
- Critical
- CVE:
- 2026-4880
Mini Ajax Cart for WooCommerce
- Plugin:
- Mini Ajax Cart for WooCommerce
- Plugin Slug:
- mini-ajax-woo-cart
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.5
- Severity Score:
- Medium
- CVE:
- 2026-6370
WP Docs
DirectoryPress – Business Directory And Classified Ad Listing
- Plugin Slug:
- directorypress
- Installations
- 900+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.6.27
- Severity Score:
- Critical
- CVE:
- 2026-3489
InPost Gallery
- Plugin:
- InPost Gallery
- Plugin Slug:
- inpost-gallery
- Installations
- 800+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.1.5
- Severity Score:
- Critical
- CVE:
- 2026-39574
bBlocks – Essential Gutenberg Blocks & Patterns Collection
- Plugin Slug:
- b-blocks
- Installations
- 700+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.0.32
- Severity Score:
- High
- CVE:
- 2026-39579
WP Sessions Time Monitoring Full Automatic
- Plugin Slug:
- activitytime
- Installations
- 600+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.1.5
- Severity Score:
- High
- CVE:
- 2026-39581
List View Google Calendar
- Plugin:
- List View Google Calendar
- Plugin Slug:
- list-view-google-calendar
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.4.4
- Severity Score:
- Medium
- CVE:
- 2026-2396
Webling
RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress
- Plugin Slug:
- computer-repair-shop
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.1133
- Severity Score:
- Medium
- CVE:
- 2026-39584
Flipbox Addon for Elementor
- Plugin:
- Flipbox Addon for Elementor
- Plugin Slug:
- ultimate-flipbox-addon-for-elementor
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.2
- Severity Score:
- Medium
- CVE:
- 2026-6048
BuddyPress Groupblog
- Plugin:
- BuddyPress Groupblog
- Plugin Slug:
- bp-groupblog
- Installations
- 50+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 1.9.4
- Severity Score:
- High
- CVE:
- 2026-5144
Age Verification & Identity Verification by Token of Trust
- Plugin Slug:
- token-of-trust
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.32.4
- Severity Score:
- High
- CVE:
- 2026-2834
Ultra Addons for WPForms
- Plugin:
- Ultra Addons for WPForms
- Plugin Slug:
- ultra-addons-for-wpforms
- Installations
- 40+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.12
- Severity Score:
- Medium
- CVE:
- 2026-39594
Hostel
HAPPY – Helpdesk Support Ticket System
- Plugin Slug:
- happy-helpdesk-support-ticket-system
- Installations
- 10+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.11
- Severity Score:
- Medium
- CVE:
- 2026-39593
Surbma | Booking.com Shortcode
- Plugin:
- Surbma | Booking.com Shortcode
- Plugin Slug:
- surbma-bookingcom-shortcode
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.1
- Severity Score:
- Medium
- CVE:
- 2026-1607
WholeSale Products Dynamic Pricing Management WooCommerce
- Plugin Slug:
- wholesale-products-dynamic-pricing-management-woocommerce
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2026-4479
Academy LMS Pro
- Plugin:
- Academy LMS Pro
- Plugin Slug:
- academy-pro
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.5.2
- Severity Score:
- High
- CVE:
- 2026-39598
Accordion and Accordion Slider
- Plugin:
- Accordion and Accordion Slider
- Plugin Slug:
- accordion-and-accordion-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.4.6.1
- Severity Score:
- Critical
Album and Image Gallery plus Lightbox
- Plugin:
- Album and Image Gallery plus Lightbox
- Plugin Slug:
- album-and-image-gallery-plus-lightbox
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.1.8.1
- Severity Score:
- Critical
Blog Designer – Post and Widget
- Plugin:
- Blog Designer – Post and Widget
- Plugin Slug:
- blog-designer-for-post-and-widget
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.7.7.1
- Severity Score:
- Critical
Career Section
- Plugin:
- Career Section
- Plugin Slug:
- career-section
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- 1.7
- Severity Score:
- High
- CVE:
- 2025-14868
Countdown Timer Ultimate
- Plugin:
- Countdown Timer Ultimate
- Plugin Slug:
- countdown-timer-ultimate
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.6.9.1
- Severity Score:
- Critical
Featured Post Creative
- Plugin:
- Featured Post Creative
- Plugin Slug:
- featured-post-creative
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.5.7.1
- Severity Score:
- Critical
Fusion Builder
- Plugin:
- Fusion Builder
- Plugin Slug:
- fusion-builder
- Vulnerability:
- Content Injection
- Patched in Version:
- 3.15.2
- Severity Score:
- Medium
- CVE:
- 2026-1509
Fusion Builder
- Plugin:
- Fusion Builder
- Plugin Slug:
- fusion-builder
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.15.2
- Severity Score:
- Medium
- CVE:
- 2026-1541
Gravity SMTP
- Plugin:
- Gravity SMTP
- Plugin Slug:
- gravitysmtp
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.5
- Severity Score:
- High
- CVE:
- 2026-4162
Video gallery and Player
- Plugin:
- Video gallery and Player
- Plugin Slug:
- html5-videogallery-plus-player
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.8.7.1
- Severity Score:
- Critical
JetEngine
- Plugin:
- JetEngine
- Plugin Slug:
- jet-engine
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.8.6.2
- Severity Score:
- Critical
- CVE:
- 2026-4352
Client Portal (Pro)
- Plugin:
- Client Portal (Pro)
- Plugin Slug:
- leco-client-portal
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 5.6.3
- Severity Score:
- Medium
- CVE:
- 2026-40724
Meta slider and carousel with lightbox
- Plugin:
- Meta slider and carousel with lightbox
- Plugin Slug:
- meta-slider-and-carousel-with-lightbox
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.0.8.1
- Severity Score:
- Critical
MetForm Pro
- Plugin:
- MetForm Pro
- Plugin Slug:
- metform-pro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.8
- Severity Score:
- Medium
- CVE:
- 2026-1782
Popup Anything
- Plugin:
- Popup Anything
- Plugin Slug:
- popup-anything-on-click
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.9.1.1
- Severity Score:
- Critical
Portfolio and Projects
- Plugin:
- Portfolio and Projects
- Plugin Slug:
- portfolio-and-projects
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.5.6.1
- Severity Score:
- Critical
Post grid and filter ultimate
- Plugin:
- Post grid and filter ultimate
- Plugin Slug:
- post-grid-and-filter-ultimate
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.7.4.1
- Severity Score:
- Critical
WP responsive FAQ with category
- Plugin:
- WP responsive FAQ with category
- Plugin Slug:
- sp-faq
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.9.5.1
- Severity Score:
- Critical
WP News and Scrolling Widgets
- Plugin:
- WP News and Scrolling Widgets
- Plugin Slug:
- sp-news-and-widget
- Vulnerability:
- Backdoor
- Patched in Version:
- 5.0.6.1
- Severity Score:
- Critical
WowShipping Pro
- Plugin:
- WowShipping Pro
- Plugin Slug:
- table-rate-shipping-pro
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.0.8
- Severity Score:
- Critical
Post Ticker Ultimate
- Plugin:
- Post Ticker Ultimate
- Plugin Slug:
- ticker-ultimate
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.7.6.1
- Severity Score:
- Critical
Timeline and History slider
- Plugin:
- Timeline and History slider
- Plugin Slug:
- timeline-and-history-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.4.5.1
- Severity Score:
- Critical
User Registration Stripe
- Plugin:
- User Registration Stripe
- Plugin Slug:
- user-registration-stripe
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.3.15
- Severity Score:
- High
- CVE:
- 2026-40726
Userpro
- Plugin:
- Userpro
- Plugin Slug:
- userpro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.1.11
- Severity Score:
- Medium
- CVE:
- 2025-53444
Product Pricing Table by WooBeWoo
- Plugin:
- Product Pricing Table by WooBeWoo
- Plugin Slug:
- woo-product-pricing-tables
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.1.1
- Severity Score:
- High
- CVE:
- 2026-1852
WooCommerce Product Filters
- Plugin:
- WooCommerce Product Filters
- Plugin Slug:
- woocommerce-product-filters
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.0.6
- Severity Score:
- Critical
- CVE:
- 2026-40725
WP Blog and Widget
- Plugin:
- WP Blog and Widget
- Plugin Slug:
- wp-blog-and-widgets
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.6.6.1
- Severity Score:
- Critical
WP Featured Content and Slider
- Plugin:
- WP Featured Content and Slider
- Plugin Slug:
- wp-featured-content-and-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.7.6.1
- Severity Score:
- Critical
WP Logo Showcase Responsive Slider and Carousel
- Plugin:
- WP Logo Showcase Responsive Slider and Carousel
- Plugin Slug:
- wp-logo-showcase-responsive-slider-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.8.7.1
- Severity Score:
- Critical
WP Responsive Recent Post Slider/Carousel
- Plugin:
- WP Responsive Recent Post Slider/Carousel
- Plugin Slug:
- wp-responsive-recent-post-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.7.1.1
- Severity Score:
- Critical
WP Slick Slider and Image Carousel
- Plugin:
- WP Slick Slider and Image Carousel
- Plugin Slug:
- wp-slick-slider-and-image-carousel
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.7.8.2
- Severity Score:
- Critical
Team Slider and Team Grid Showcase plus Team Carousel
- Plugin:
- Team Slider and Team Grid Showcase plus Team Carousel
- Plugin Slug:
- wp-team-showcase-and-slider
- Vulnerability:
- Backdoor
- Patched in Version:
- 2.8.6.1
- Severity Score:
- Critical
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
- Plugin:
- Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
- Plugin Slug:
- wp-testimonial-with-widget
- Vulnerability:
- Backdoor
- Patched in Version:
- 3.5.6.1
- Severity Score:
- Critical
Trending/Popular Post Slider and Widget
- Plugin:
- Trending/Popular Post Slider and Widget
- Plugin Slug:
- wp-trending-post-slider-and-widget
- Vulnerability:
- Backdoor
- Patched in Version:
- 1.8.6.1
- Severity Score:
- Critical
Royal Elementor Addons Pro
- Plugin:
- Royal Elementor Addons Pro
- Plugin Slug:
- wpr-addons-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1041
- Severity Score:
- High
- CVE:
- 2026-40720
WordPress Themes — 28 Patched / 1 Unpatched
WebStack
- Theme:
- WebStack
- Theme Slug:
- webstack
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2026-1555
Charity Zone
- Theme:
- Charity Zone
- Theme Slug:
- charity-zone
- Downloads
- 112,126
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.1.2
- Severity Score:
- Critical
- CVE:
- 2026-40749
Ecommerce Zone
- Theme:
- Ecommerce Zone
- Theme Slug:
- ecommerce-zone
- Downloads
- 89,443
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.9.8
- Severity Score:
- Critical
- CVE:
- 2026-40747
Kids Gift Shop
- Theme:
- Kids Gift Shop
- Theme Slug:
- kids-gift-shop
- Downloads
- 20,521
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.5.5
- Severity Score:
- Critical
- CVE:
- 2026-40748
Kids Online Store
- Theme:
- Kids Online Store
- Theme Slug:
- kids-online-store
- Downloads
- 53,065
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.9.0
- Severity Score:
- Critical
- CVE:
- 2026-40750
Restaurant Zone
- Theme:
- Restaurant Zone
- Theme Slug:
- restaurant-zone
- Downloads
- 80,108
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.7.9
- Severity Score:
- Critical
- CVE:
- 2026-40746
Vantage
Webenvo
- Theme:
- Webenvo
- Theme Slug:
- webenvo
- Downloads
- 10,224
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 0.0.7
- Severity Score:
- Critical
- CVE:
- 2026-39589
Ashtanga
- Theme:
- Ashtanga
- Theme Slug:
- ashtanga
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-40751
Atomlab
- Theme:
- Atomlab
- Theme Slug:
- atomlab
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 2.4.6
- Severity Score:
- High
- CVE:
- 2026-39590
Behold
- Theme:
- Behold
- Theme Slug:
- behold
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-40760
ChapterOne
- Theme:
- ChapterOne
- Theme Slug:
- chapterone
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.8
- Severity Score:
- High
- CVE:
- 2026-40731
Château
- Theme:
- Château
- Theme Slug:
- chateau
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-40757
EasyMeals
- Theme:
- EasyMeals
- Theme Slug:
- easymeals
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-40753
Eldon
- Theme:
- Eldon
- Theme Slug:
- eldon
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-40738
Eleganzo
- Theme:
- Eleganzo
- Theme Slug:
- eleganzo
- Vulnerability:
- Path Traversal
- Patched in Version:
- 1.3
- Severity Score:
- Medium
- CVE:
- 2025-15470
Elementra
- Theme:
- Elementra
- Theme Slug:
- elementra
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.1.0
- Severity Score:
- Critical
- CVE:
- 2026-39529
Esmée
- Theme:
- Esmée
- Theme Slug:
- esme
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-40759
Laurits
- Theme:
- Laurits
- Theme Slug:
- laurits
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.6
- Severity Score:
- High
- CVE:
- 2026-40736
Léonie
- Theme:
- Léonie
- Theme Slug:
- lonie
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-40758
LuxeDrive
- Theme:
- LuxeDrive
- Theme Slug:
- luxedrive
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-40739
MagOne
- Theme:
- MagOne
- Theme Slug:
- magone
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 9.1
- Severity Score:
- High
- CVE:
- 2026-39548
Manufaktur Solutions
- Theme:
- Manufaktur Solutions
- Theme Slug:
- manufaktursolutions
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.2
- Severity Score:
- High
- CVE:
- 2026-40752
Reina
- Theme:
- Reina
- Theme Slug:
- reina
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 2.2
- Severity Score:
- High
- CVE:
- 2026-40735
Roisin
- Theme:
- Roisin
- Theme Slug:
- roisin
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-40754
ShiftUp
- Theme:
- ShiftUp
- Theme Slug:
- shiftup
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.4
- Severity Score:
- High
- CVE:
- 2026-40733
TechLink
- Theme:
- TechLink
- Theme Slug:
- techlink
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.4
- Severity Score:
- High
- CVE:
- 2026-40755
Valeska
- Theme:
- Valeska
- Theme Slug:
- valeska
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.3
- Severity Score:
- High
- CVE:
- 2026-40761
Zoya
- Theme:
- Zoya
- Theme Slug:
- zoya
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.5
- Severity Score:
- High
- CVE:
- 2026-40756
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
