WordPress Vulnerability Report

WordPress Vulnerability Report — April 30, 2025

Since last week, 241 new vulnerabilities emerged in the WordPress ecosystem, including 222 plugins and 19 themes. 150 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 241 vulnerabilities have been publicly disclosed. Security patches for 91 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 150 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

SolidWP Patches Multiple Plugin Vulnerabilities

On April 29, SolidWP released important security updates across several plugins, including Solid Mail, Solid Performance, Solid Security, and Solid Backups Legacy. These address an unauthenticated XSS (CVE-2025-1123), a serialized injection risk, and a telemetry privilege issue. Users are strongly urged to update immediately.

Read the full advisory and update instructions.

WordPress Core

WordPress 6.8 “Cecil” is here! Launched April 15, 2025, it honors jazz legend Cecil Taylor, whose pioneering piano fused chaos and harmony. Explore its bold features with the same experimental spirit.

Plus, WordCamp Europe 2025 lands in Basel, Switzerland, June 5-7! Connect with WordPress enthusiasts, developers, and pros for three days of learning, networking, and collaboration with the global community.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 85 Patched / 137 Unpatched

Advanced Accordion Gutenberg Block

Plugin Slug:
advanced-accordion-block
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lottie Player- Great Lottie Player Solution

Plugin Slug:
embed-lottie-player
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACF: Google Font Selector

Plugin Slug:
acf-google-font-selector-field
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Anything Popup

Plugin Slug:
anything-popup
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Pack Elementor addon

Plugin Slug:
the-pack-addon
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPMasterToolKit (WPMTK) – All in one plugin

Plugin Slug:
wpmastertoolkit
Installations
2,000+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light

Plugin Slug:
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Installations
700+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Capturly

Plugin:
Capturly
Plugin Slug:
capturly-optimize-your-website
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Checkout Field Visibility for WooCommerce

Plugin Slug:
checkout-field-visibility-for-woocommerce
Installations
80+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Lister for eBay

Plugin Slug:
product-lister-ebay
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FuseDesk

Plugin:
FuseDesk
Plugin Slug:
fusedesk
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appsero Helper

Plugin Slug:
appsero-helper
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

1 Decembrie 1918

Plugin:
1 Decembrie 1918
Plugin Slug:
1-decembrie-1918
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

360 View

Plugin:
360 View
Plugin Slug:
360-view
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Form Builder

Plugin:
Form Builder
Plugin Slug:
abcsubmit
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Absolute Links
Plugin Slug:
absolute-links
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add custom page template

Plugin:
Add custom page template
Plugin Slug:
add-custom-page-template
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Add Google +1 (Plus one) social share Button

Plugin:
Add Google +1 (Plus one) social share Button
Plugin Slug:
add-google-plus-one-social-share-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Admin-Bar Favorites

Plugin:
Custom Admin-Bar Favorites
Plugin Slug:
admin-bookmarks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced lazy load

Plugin:
Advanced lazy load
Plugin Slug:
advanced-lazy-load
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All in One Time Clock Lite

Plugin:
All in One Time Clock Lite
Plugin Slug:
aio-time-clock-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ajax Comment Form CST

Plugin:
Ajax Comment Form CST
Plugin Slug:
ajax-comment-form-cst
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Configurator Theme Core

Plugin:
Configurator Theme Core
Plugin Slug:
amz-configurator-core
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Animate

Plugin:
Animate
Plugin Slug:
animate
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Author Box After Posts

Plugin:
Author Box After Posts
Plugin Slug:
author-box-after-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Author Box Plugin With Different Description

Plugin:
Author Box Plugin With Different Description
Plugin Slug:
author-box-with-different-description
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Availability Calendar

Plugin:
Availability Calendar
Plugin Slug:
availability
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Awesome Wp Image Gallery
Plugin Slug:
awesome-wp-image-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BBCode Deluxe

Plugin:
BBCode Deluxe
Plugin Slug:
bbcode-deluxe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Best Posts Summary

Plugin:
Best Posts Summary
Plugin Slug:
best-posts-summary
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Blog Manager WP

Plugin:
Blog Manager WP
Plugin Slug:
blog-manager-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buddypress Force Password Change

Plugin:
Buddypress Force Password Change
Plugin Slug:
buddy-press-force-password-change
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Business Contact Widget

Plugin:
Business Contact Widget
Plugin Slug:
business-contact-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Call Now PHT Blog

Plugin:
Call Now PHT Blog
Plugin Slug:
call-now-coccoc-pht-blog
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Car Park Booking System for WordPress

Plugin:
Car Park Booking System for WordPress
Plugin Slug:
car-park-booking-system-for-wordpress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Carousel-of-post-images

Plugin:
Carousel-of-post-images
Plugin Slug:
carousel-of-post-images
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Calendar

Plugin:
Contact Form 7 Calendar
Plugin Slug:
cf7-calendar
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CheckBot

Plugin:
CheckBot
Plugin Slug:
checkbot
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Confirm User Registration

Plugin:
Confirm User Registration
Plugin Slug:
confirm-user-registration
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

COVID-19 (Coronavirus) Update Your Customers

Plugin:
COVID-19 (Coronavirus) Update Your Customers
Plugin Slug:
covid-19-alert
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Functions Plugin

Plugin:
Custom Functions Plugin
Plugin Slug:
custom-functions
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post Popup

Plugin:
WP Custom Post Popup
Plugin Slug:
custom-post-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LSD Custom taxonomy and category meta

Plugin:
LSD Custom taxonomy and category meta
Plugin Slug:
custom-taxonomy-category-and-term-fields
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Document Management System

Plugin:
Document Management System
Plugin Slug:
dms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Drop Caps

Plugin:
Drop Caps
Plugin Slug:
drop-caps
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dropdown Content

Plugin:
Dropdown Content
Plugin Slug:
dropdown-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Child Theme Creator

Plugin:
Easy Child Theme Creator
Plugin Slug:
easy-child-theme-creator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enhanced Paypal Shortcodes

Plugin:
Enhanced Paypal Shortcodes
Plugin Slug:
enhanced-paypal-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

External Markdown

Plugin:
External Markdown
Plugin Slug:
external-markdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:
FAT Services Booking
Plugin Slug:
fat-services-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flickr Shortcode Importer

Plugin:
Flickr Shortcode Importer
Plugin Slug:
flickr-shortcode-importer
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Floating Social Bar

Plugin:
Floating Social Bar
Plugin Slug:
floating-social-bar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:
Flynax Bridge
Plugin Slug:
flynax-bridge
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Flynax Bridge

Plugin:
Flynax Bridge
Plugin Slug:
flynax-bridge
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Foodbakery Sticky Cart

Plugin:
Foodbakery Sticky Cart
Plugin Slug:
foodbakery-sticky-cart
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:
Front End Users
Plugin Slug:
front-end-only-users
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Login and Registration Blocks

Plugin:
Frontend Login and Registration Blocks
Plugin Slug:
frontend-login-and-registration-blocks
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GNA Search Shortcode

Plugin:
GNA Search Shortcode
Plugin Slug:
gna-search-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Peadig’s Google +1 Button

Plugin:
Peadig’s Google +1 Button
Plugin Slug:
google-1
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google News

Plugin:
Google News
Plugin Slug:
google-news
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Grand Conference

Plugin:
Grand Conference
Plugin Slug:
grandconference
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Tabs

Plugin:
Tabs
Plugin Slug:
gt-tabs
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GTDB Guitar Tuners

Plugin:
GTDB Guitar Tuners
Plugin Slug:
guitar-tuner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hacklog Remote Attachment

Plugin:
Hacklog Remote Attachment
Plugin Slug:
hacklog-remote-attachment
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Hashtags [#hashtagger]

Plugin:
Smart Hashtags [#hashtagger]
Plugin Slug:
hashtagger
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hospital Management System

Plugin:
Hospital Management System
Plugin Slug:
hospital-management
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iCafe Library

Plugin:
iCafe Library
Plugin Slug:
icafe-library
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image Style Hover

Plugin:
Image Style Hover
Plugin Slug:
image-content-show-hover
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects For WPBakery Page Builder

Plugin:
Image Hover Effects For WPBakery Page Builder
Plugin Slug:
image-hover-effects-for-visual-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inline Text Popup

Plugin:
Inline Text Popup
Plugin Slug:
inline-text-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Integração entre Eduzz e Woocommerce

Plugin:
Integração entre Eduzz e Woocommerce
Plugin Slug:
integracao-entre-eduzz-e-wc-powers
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Landing pages and Domain aliases for WordPress

Plugin:
Landing pages and Domain aliases for WordPress
Plugin Slug:
landing-pages-and-domain-aliases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Libro de Reclamaciones

Plugin:
Libro de Reclamaciones
Plugin Slug:
libro-de-reclamaciones
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

License For Envato

Plugin:
License For Envato
Plugin Slug:
license-envato
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mad Mimi for WordPress

Plugin:
Mad Mimi for WordPress
Plugin Slug:
mad-mimi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Milat jQuery Automatic Popup

Plugin:
Milat jQuery Automatic Popup
Plugin Slug:
milat-jquery-automatic-popup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mini twitter feed

Plugin:
Mini twitter feed
Plugin Slug:
mini-twitter-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mixcloud Embed

Plugin:
Mixcloud Embed
Plugin Slug:
mixcloud-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Modern Polls

Plugin:
Modern Polls
Plugin Slug:
modern-polls
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Login and Registration

Plugin:
Custom Login and Registration
Plugin Slug:
ms-registration
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi-Column Taxonomy List

Plugin:
Multi-Column Taxonomy List
Plugin Slug:
multi-column-taxonomy-list
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Custom Widgets

Plugin:
My Custom Widgets
Plugin Slug:
mycustomwidget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Navegg Analytics

Plugin:
Navegg Analytics
Plugin Slug:
navegg
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Nepali Post Date

Plugin:
Nepali Post Date
Plugin Slug:
nepali-post-date
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

occupancyplan

Plugin:
occupancyplan
Plugin Slug:
occupancyplan
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PayPal Express Checkout

Plugin:
PayPal Express Checkout
Plugin Slug:
paypal-express-checkout
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Peekaboo

Plugin:
Peekaboo
Plugin Slug:
peekaboo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin Central

Plugin:
Plugin Central
Plugin Slug:
plugin-central
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Posts for Page

Plugin:
Posts for Page
Plugin Slug:
posts-for-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Print Science Designer

Plugin:
Print Science Designer
Plugin Slug:
print-science-designer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RAphicon

Plugin:
RAphicon
Plugin Slug:
raphicon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Related Posts via Taxonomies
Plugin Slug:
related-posts-via-taxonomies
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Loan Calculator

Plugin:
Loan Calculator
Plugin Slug:
repayment-calculator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:
Revy
Plugin Slug:
revy
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SUMO Reward Points

Plugin:
SUMO Reward Points
Plugin Slug:
rewardsystem
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RRSSB

Plugin:
RRSSB
Plugin Slug:
rrssb
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SCSS-Library

Plugin:
SCSS-Library
Plugin Slug:
scss-library
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Send From

Plugin:
Send From
Plugin Slug:
send-from
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEUR Oficial

Plugin:
SEUR Oficial
Plugin Slug:
seur
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Google Photos Grid

Plugin:
Simple Google Photos Grid
Plugin Slug:
simple-google-photos-grid
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Counter

Plugin:
Social Counter
Plugin Slug:
social-counter
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tayori Form

Plugin:
Tayori Form
Plugin Slug:
tayori
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Time Based Greeting

Plugin:
Time Based Greeting
Plugin Slug:
time-based-greeting
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Card Generator

Plugin:
Twitter Card Generator
Plugin Slug:
twitter-card-generator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Unsafe Mimetypes

Plugin:
Unsafe Mimetypes
Plugin Slug:
unsafe-mimetypes
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Vasaio QR Code

Plugin:
Vasaio QR Code
Plugin Slug:
vasaio-qr-code
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Vegas

Plugin:
WP Vegas
Plugin Slug:
vegas-fullscreen-background-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Verification SMS with TargetSMS

Plugin:
Verification SMS with TargetSMS
Plugin Slug:
verification-sms-targetsms
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Assign Linked Products For WooCommerce

Plugin:
Bulk Assign Linked Products For WooCommerce
Plugin Slug:
wc-bulk-assign-linked-products
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP AVCL Automation Helper (formerly WPFlyLeads)

Plugin:
WP AVCL Automation Helper (formerly WPFlyLeads)
Plugin Slug:
woozap
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin Upgrade Time Out

Plugin:
Plugin Upgrade Time Out
Plugin Slug:
wordpressplugin-upgrade-time-out-plugin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WoWHead Tooltips

Plugin:
WoWHead Tooltips
Plugin Slug:
wowhead-tooltips
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Cookie Consent
Plugin Slug:
wp-cookie-consent
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wp Custom CMS Block

Plugin:
Wp Custom CMS Block
Plugin Slug:
wp-custom-cms-block
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Customize Login Page

Plugin:
WP Customize Login Page
Plugin Slug:
wp-customize-login-page
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Customize Login Page

Plugin:
WP Customize Login Page
Plugin Slug:
wp-customize-login-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wp-cyr-cho

Plugin:
wp-cyr-cho
Plugin Slug:
wp-cyr-cho
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Guide

Plugin:
Easy Guide
Plugin Slug:
wp-easy-guide
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Filter Post Category

Plugin:
WP Filter Post Category
Plugin Slug:
wp-filter-post-categories
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FoodBakery

Plugin:
FoodBakery
Plugin Slug:
wp-foodbakery
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP HRM LITE

Plugin:
WP HRM LITE
Plugin Slug:
wp-hrm-lite-human-resource-management-system
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Meta Keywords & Description

Plugin:
Meta Keywords & Description
Plugin Slug:
wp-meta-keywords-meta-description
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Quiz

Plugin:
WP Quiz
Plugin Slug:
wp-quiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-reCAPTCHA-bp

Plugin:
WP-reCAPTCHA-bp
Plugin Slug:
wp-recaptcha-bp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tooltip

Plugin:
Tooltip
Plugin Slug:
wp-tooltip
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Events Calendar Registration & Tickets

Plugin:
WordPress Events Calendar Registration & Tickets
Plugin Slug:
wpeventplus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPVN

Plugin:
WPVN
Plugin Slug:
wpvn-username-changer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WpZon – Amazon Affiliate Plugin

Plugin:
WpZon – Amazon Affiliate Plugin
Plugin Slug:
wpzon
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WS Force Login Page

Plugin:
WS Force Login Page
Plugin Slug:
ws-force-login-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Automatic Order Printing

Plugin:
Woocommerce Automatic Order Printing
Plugin Slug:
xc-woo-google-cloud-print
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xpert Tab

Plugin:
Xpert Tab
Plugin Slug:
xpert-tab
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zalo Official Live Chat

Plugin:
Zalo Official Live Chat
Plugin Slug:
zalo-official-live-chat
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zoho Creator Forms

Plugin:
Zoho Creator Forms
Plugin Slug:
zohocreator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Content Injection
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
7.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.10.

Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.30
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.30.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
90,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.8.12
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.8.12.

Category Posts Widget

Plugin Slug:
category-posts
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.20.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
50,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
11.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.4.6.

Visual Composer Website Builder

Plugin Slug:
visualcomposer
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
45.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 45.11.0.

WP Import Export Lite

Plugin Slug:
wp-import-export-lite
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.28.

Contact Form & SMTP Plugin for WordPress by PirateForms

Plugin Slug:
pirate-forms
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

SecuPress Free — WordPress Security

Plugin Slug:
secupress
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.3.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.10.

Social Slider Feed

Plugin Slug:
instagram-slider-widget
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

PowerPress Podcasting plugin by Blubrry

Plugin Slug:
powerpress
Installations
30,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
11.12.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 11.12.6.

UiCore Elements – Free Elementor widgets and templates

Plugin Slug:
uicore-elements
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Seriously Simple Podcasting

Plugin Slug:
seriously-simple-podcasting
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.0.

AFI – The Easiest Integration Plugin

Plugin Slug:
advanced-form-integration
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.100.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.100.0.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.1.

Mang Board WP

Plugin Slug:
mangboard
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.7.

Prevent Direct Access – Protect WordPress Files

Plugin Slug:
prevent-direct-access
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.8.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.1.

Prevent Direct Access – Protect WordPress Files

Plugin Slug:
prevent-direct-access
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.3.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.
Plugin Slug:
custom-related-posts
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.5.

Upsell Funnel Builder for WooCommerce

Plugin Slug:
upsell-order-bump-offer-for-woocommerce
Installations
4,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
3.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.1.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
3.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.4.

affiliate-toolkit – WP Affiliate Plugin with Amazon

Plugin Slug:
affiliate-toolkit-starter
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.4.

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
1.6.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.33.

SKT Blocks – Gutenberg based Page Builder

Plugin Slug:
skt-blocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery)

Plugin Slug:
sky-elementor-addons
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

WP-Recall – Registration, Profile, Commerce & More

Plugin Slug:
wp-recall
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.26.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.26.12.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.93
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.93.

Appointment Booking Calendar

Plugin Slug:
appointment-booking-calendar
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.93
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.93.

Event post

Plugin:
Event post
Plugin Slug:
event-post
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.0.

Fable Extra

Plugin Slug:
fable-extra
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.7.

Fable Extra

Plugin Slug:
fable-extra
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.7.

Fable Extra

Plugin Slug:
fable-extra
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

List Last Changes

Plugin Slug:
list-last-changes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Simple Download Counter

Plugin Slug:
simple-download-counter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Image Optimizer, Resizer and CDN – Sirv

Plugin Slug:
sirv
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.4.

Smart Maintenance Mode

Plugin Slug:
smart-maintenance-mode
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

My Tickets – Accessible Event Ticketing

Plugin Slug:
my-tickets
Installations
900+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.17.

MPL-Publisher — Ebook & Audiobook Creator

Plugin Slug:
mpl-publisher
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.18.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.18.1.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
700+
Vulnerability:
SQL Injection
Patched in Version:
2.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.6.

Media Library Downloader

Plugin Slug:
media-library-downloader
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Popup Builder

Plugin Slug:
easy-notify-lite
Installations
600+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.37
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.37.

VikRestaurants Table Reservations and Take-Away

Plugin Slug:
vikrestaurants
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.

Textmetrics

Plugin Slug:
webtexttool
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.3.

Crossword Compiler Puzzles

Plugin Slug:
crossword-compiler-puzzles
Installations
400+
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.3.

Advanced Linked Variations for Woocommerce

Plugin Slug:
linked-variation
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Simple calendar for Elementor

Plugin Slug:
simple-calendar-for-elementor
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.5.

Tax Switch for WooCommerce

Plugin Slug:
tax-switch-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.3.

Mailing Group Listserv

Plugin Slug:
wp-mailing-group
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
3.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.5.

Able Player, accessible HTML5 media player

Plugin Slug:
ableplayer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.2.

Recover abandoned cart for WooCommerce

Plugin Slug:
recover-wc-abandoned-cart
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

Breeze Display

Plugin Slug:
wt-display-breeze
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Aeropage Sync for Airtable

Plugin Slug:
aeropage-sync-for-airtable
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

Aeropage Sync for Airtable

Plugin Slug:
aeropage-sync-for-airtable
Installations
70+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.0.

AnalyticsWP

Plugin:
AnalyticsWP
Plugin Slug:
analyticswp
Vulnerability:
SQL Injection
Patched in Version:
2.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.5.

Anps Theme

Plugin:
Anps Theme
Plugin Slug:
anps_theme_plugin
Vulnerability:
Content Injection
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

BeerXML Shortcode

Plugin:
BeerXML Shortcode
Plugin Slug:
beerxml-shortcode
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.8.

BM Content Builder

Plugin:
BM Content Builder
Plugin Slug:
bm-builder
Vulnerability:
Broken Access Control
Patched in Version:
3.16.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.16.3.

cookieBAR

Plugin:
cookieBAR
Plugin Slug:
cookiebar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.1.

Mayosis Core

Plugin:
Mayosis Core
Plugin Slug:
mayosis-core
Vulnerability:
Arbitrary File Download
Patched in Version:
5.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.2.

Memberpress

Plugin:
Memberpress
Plugin Slug:
memberpress
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.12.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.12.0.

Order Delivery Date for WP e-Commerce

Plugin:
Order Delivery Date for WP e-Commerce
Plugin Slug:
order-delivery-date
Vulnerability:
Privilege Escalation
Patched in Version:
12.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 12.3.1.

Post in page for Elementor

Plugin Slug:
post-in-page-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Privilege Escalation
Patched in Version:
6.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.0.

eForm – WordPress Form Builder

Plugin:
eForm – WordPress Form Builder
Plugin Slug:
wp-fsqm-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.19.

Xpro Elementor Addons – Pro

Plugin:
Xpro Elementor Addons – Pro
Plugin Slug:
xpro-elementor-addons-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.4.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.10.

WordPress Themes — 6 Patched / 13 Unpatched

Arrival

Theme:
Arrival
Theme Slug:
arrival
Downloads
126,548
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CWW Portfolio

Theme Slug:
cww-portfolio
Downloads
85,776
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grace Mag

Theme Slug:
grace-mag
Downloads
70,110
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Opstore

Theme:
Opstore
Theme Slug:
opstore
Downloads
82,188
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Xews Lite

Theme Slug:
xews-lite
Downloads
14,655
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Altair

Theme:
Altair
Theme Slug:
altair
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue

Theme:
Hotel + Bed and Breakfast Booking Calendar Theme | Bellevue
Theme Slug:
bellevuex
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

CiyaShop

Theme:
CiyaShop
Theme Slug:
ciyashop
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Grand Restaurant WordPress

Theme:
Grand Restaurant WordPress
Theme Slug:
grandrestaurant
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

JNews

Theme:
JNews
Theme Slug:
jnews
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Reales WP

Theme:
Reales WP
Theme Slug:
reales-wp-real-estate-wordpress-theme
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

EduMall

Theme:
EduMall
Theme Slug:
edumall
Vulnerability:
Local File Inclusion
Patched in Version:
4.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.0.

Kleo

Theme:
Kleo
Theme Slug:
kleo
Vulnerability:
Broken Access Control
Patched in Version:
5.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.4.

Vikinger

Theme:
Vikinger
Theme Slug:
vikinger
Vulnerability:
Privilege Escalation
Patched in Version:
1.9.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.31.

wProject

Theme:
wProject
Theme Slug:
wproject
Vulnerability:
Privilege Escalation
Patched in Version:
5.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.0.

wProject

Theme:
wProject
Theme Slug:
wproject
Vulnerability:
Settings Change
Patched in Version:
5.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.0.

wProject

Theme:
wProject
Theme Slug:
wproject
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security