WordPress Vulnerability Report

WordPress Vulnerability Report — April 8, 2026

Since last week, 68 new vulnerabilities have emerged in the WordPress ecosystem, including 67 plugins and 1 theme. Of those, 4 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 68 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 4 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.4 is available, addressing 10 security issues and a template loading bug. Immediate updates are recommended for all production sites.

WordPress 7.0 Release Candidate 2 (RC2) is now ready for testing via the Beta Tester plugin, direct download, WP-CLI, or WordPress Playground. As a pre-release version, it should only be evaluated in staging or local environments.

WordPress 7.0 is scheduled for release on April 9, 2026.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 63 Patched / 4 Unpatched

MSTW League Manager

Plugin Slug:
mstw-league-manager
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Post Scheduler

Plugin:
Auto Post Scheduler
Plugin Slug:
auto-post-scheduler
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Performance Monitor

Plugin:
Performance Monitor
Plugin Slug:
performance-monitor
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IDPay Payment Gateway for Woocommerce

Plugin:
IDPay Payment Gateway for Woocommerce
Plugin Slug:
woo-idpay-gateway
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
complianz-gdpr
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.5.

Loco Translate

Plugin Slug:
loco-translate
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.3.

W3 Total Cache

Plugin Slug:
w3-total-cache
Installations
900,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.4.

WooPayments: Integrated WooCommerce Payments

Plugin Slug:
woocommerce-payments
Installations
900,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.6.0.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.9.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.8.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.5.0.

MW WP Form

Plugin:
MW WP Form
Plugin Slug:
mw-wp-form
Installations
200,000+
Vulnerability:
Directory Traversal
Patched in Version:
5.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.1.

Query Monitor

Plugin Slug:
query-monitor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.20.4.

Kubio AI Page Builder

Plugin Slug:
kubio
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.

Download Monitor

Plugin Slug:
download-monitor
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.8.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.35.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
SQL Injection
Patched in Version:
3.35
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.35.

Conditional Menus

Plugin Slug:
conditional-menus
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.

Export All URLs

Plugin Slug:
export-all-urls
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.

Simple Membership

Plugin Slug:
simple-membership
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.2.

Blackhole for Bad Bots

Plugin Slug:
blackhole-bad-bots
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

WP Lightbox 2

Plugin Slug:
wp-lightbox-2
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.7.

Xpro Addons — 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.21.

Xpro Addons — 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.25.

WCFM – Frontend Manager for WooCommerce

Plugin Slug:
wc-frontend-manager
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
6.7.26
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.7.26.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.28.32
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.28.32.

Ibtana – WordPress Website Builder

Plugin Slug:
ibtana-visual-editor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.8.

Minify HTML

Plugin Slug:
minify-html-markup
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.13.

Responsive Plus – Elementor Templates & Starter Sites

Plugin Slug:
responsive-add-ons
Installations
10,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.5.

Spam Protect for Contact Form 7

Plugin Slug:
wp-contact-form-7-spam-blocker
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.2.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.10.

JS Help Desk – AI-Powered Support & Ticketing System

Plugin Slug:
js-support-ticket
Installations
8,000+
Vulnerability:
SQL Injection
Patched in Version:
3.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.0.5.

Contact Form by Supsystic

Plugin Slug:
contact-form-by-supsystic
Installations
7,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.0.

Webmention

Plugin:
Webmention
Plugin Slug:
webmention
Installations
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.0.

Webmention

Plugin:
Webmention
Plugin Slug:
webmention
Installations
900+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.7.0.

TrueBooker – Appointment Booking and Scheduler System

Plugin Slug:
truebooker-appointment-booking
Installations
600+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Debugger & Troubleshooter

Plugin Slug:
debugger-troubleshooter
Installations
50+
Vulnerability:
Privilege Escalation
Patched in Version:
1.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.0.

Bricksforge

Plugin:
Bricksforge
Plugin Slug:
bricksforge
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.1.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.8.5.

Everest Forms Pro

Plugin:
Everest Forms Pro
Plugin Slug:
everest-forms-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.13.

Gravity SMTP

Plugin:
Gravity SMTP
Plugin Slug:
gravitysmtp
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.

LeadConnector

Plugin:
LeadConnector
Plugin Slug:
leadconnector
Vulnerability:
Broken Access Control
Patched in Version:
3.0.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.22.

Perfmatters

Plugin:
Perfmatters
Plugin Slug:
perfmatters
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.6.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.0.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.38.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.38.5.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.21.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.21.4.

WordPress Themes — 1 Patched / 0 Unpatched

Oxygen

Theme:
Oxygen
Theme Slug:
oxygen
Downloads
403,225
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.0.9.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security