WordPress Security

WordPress Vulnerability Report — April 9, 2025

Since last week, 612 new vulnerabilities emerged in the WordPress ecosystem, including 583 plugins and 29 themes. 504 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 612 vulnerabilities have been publicly disclosed. Security patches for 108 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 504 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

The third release candidate (“RC3”) for WordPress 6.8 is ready for download and testing. This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you evaluate RC3 on a test server and site.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 103 Patched / 480 Unpatched

CMP – Coming Soon & Maintenance Plugin by NiteoThemes

Plugin Slug:
cmp-coming-soon-maintenance
Installations
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShareThis Dashboard for Google Analytics

Plugin Slug:
googleanalytics
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP ULike – All-in-One Engagement Toolkit

Plugin Slug:
wp-ulike
Installations
80,000+
Vulnerability:
Content Spoofing
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ActiveCampaign – Forms, Site Tracking, Live Chat

Plugin Slug:
activecampaign-subscription-forms
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DethemeKit for Elementor

Plugin Slug:
dethemekit-for-elementor
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced WordPress Backgrounds

Plugin Slug:
advanced-backgrounds
Installations
30,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ecwid by Lightspeed Ecommerce Shopping Cart

Plugin Slug:
ecwid-shopping-cart
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Read More & Accordion

Plugin Slug:
expand-maker
Installations
20,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Google Maps

Plugin Slug:
google-maps-easy
Installations
20,000+
Vulnerability:
XML External Entity (XXE)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Woo Labels – Product Labels for WooCommerce

Plugin Slug:
advanced-woo-labels
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Asgaros Forum

Plugin Slug:
asgaros-forum
Installations
10,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flo Forms – Easy Drag & Drop Form Builder

Plugin Slug:
flo-forms
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OSM – OpenStreetMap

Plugin Slug:
osm
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-LESS

Plugin:
WP-LESS
Plugin Slug:
wp-less
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPCargo Track & Trace

Plugin Slug:
wpcargo
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xpro Theme Builder For Elementor – FREE

Plugin Slug:
xpro-theme-builder
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Mobile Bottom Menu

Plugin Slug:
mobile-bottom-menu-for-wp
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IMPress for IDX Broker

Plugin Slug:
idx-broker-platinum
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Header Builder Plugin – Pearl

Plugin Slug:
pearl-header-builder
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Header Builder Plugin – Pearl

Plugin Slug:
pearl-header-builder
Installations
7,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sliced Invoices – WordPress Invoice Plugin

Plugin Slug:
sliced-invoices
Installations
6,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Specia Companion

Plugin Slug:
specia-companion
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
vk-filter-search
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Directorist AddonsKit for Elementor

Plugin Slug:
addonskit-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fusion Page Builder

Plugin Slug:
fusion
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
hyperlink-group-block
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flag Icons

Plugin:
Flag Icons
Plugin Slug:
language-icons-flags-switcher
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Privyr CRM – Instant Lead Alerts for Contact Forms

Plugin Slug:
privy-crm-integration
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-icons
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Split Test For Elementor

Plugin Slug:
split-test-for-elementor
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Split Test For Elementor

Plugin Slug:
split-test-for-elementor
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widgetize Pages Light

Plugin Slug:
widgetize-pages-light
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fonto – Custom Web Fonts Manager

Plugin Slug:
fonto
Installations
3,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Libro de Reclamaciones y Quejas

Plugin Slug:
libro-de-reclamaciones-y-quejas
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms
Installations
3,000+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Forms

Plugin Slug:
piotnetforms
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons & Analytics Plugin – GetSocial.io

Plugin Slug:
wp-share-buttons-analytics-by-getsocial
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
add-to-all
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beam me up Scotty – Back to Top Button

Plugin Slug:
beam-me-up-scotty
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bulk NoIndex & NoFollow Toolkit

Plugin Slug:
bulk-noindex-nofollow-toolkit-by-mad-fish
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Category Icon

Plugin Slug:
category-icon
Installations
2,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Docxpresso

Plugin:
Docxpresso
Plugin Slug:
docxpresso
Installations
2,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
easy-media-gallery
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ELEX WooCommerce Request a Quote

Plugin Slug:
elex-request-a-quote
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MX Time Zone Clocks

Plugin Slug:
mx-time-zone-clocks
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Safe Ai Malware Protection for WP

Plugin Slug:
safe-ai-malware-protection-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SrbTransLatin – Serbian Latinisation

Plugin Slug:
srbtranslatin
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin Slug:
timeline-event-history
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tockify Events Calendar

Plugin Slug:
tockify-events-calendar
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Directory Listings WordPress plugin – uListing

Plugin Slug:
ulisting
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-modal-popup-with-cookie-integration
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Simple HTML Sitemap

Plugin Slug:
wp-simple-html-sitemap
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPoperation Elementor Addons

Plugin Slug:
wpop-elementor-addons
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Black Widgets For Elementor

Plugin Slug:
black-widgets
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyPress Members Only

Plugin Slug:
buddypress-members-only
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cal.com

Plugin:
Cal.com
Plugin Slug:
cal-com
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CLP – Custom Login Page by NiteoThemes

Plugin Slug:
clp-custom-login-page
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Builder by vcita

Plugin Slug:
contact-form-with-a-meeting-scheduler-by-vcita
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cryptocurrency Widgets Pack

Plugin Slug:
cryptocurrency-widgets-pack
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Astra Security Suite – Firewall & Malware Scan

Plugin Slug:
getastra
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gutena Kit – Gutenberg Blocks and Templates

Plugin Slug:
gutena-kit
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

onOffice for WP-Websites

Plugin Slug:
onoffice-for-wp-websites
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RestroPress – Online Food Ordering System

Plugin Slug:
restropress
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sequential Order Numbers for WooCommerce

Plugin Slug:
sequential-order-numbers-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sidebar Manager Light

Plugin Slug:
sidebar-manager-light
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Sticky Add To Cart For WooCommerce

Plugin Slug:
sticky-add-to-cart-woo
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Swiss Toolkit For WP

Plugin Slug:
swiss-toolkit-for-wp
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Swiss Toolkit For WP

Plugin Slug:
swiss-toolkit-for-wp
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video Playlist For YouTube

Plugin Slug:
video-playlist-for-youtube
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Price by Quantity & Bulk Quantity Discounts for WooCommerce

Plugin Slug:
wholesale-pricing-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Webinar Plugin – WebinarPress

Plugin Slug:
wp-webinarsystem
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP AdCenter – Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

mb.YTPlayer for background videos

Plugin Slug:
wpmbytplayer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Follow Us Badges

Plugin Slug:
wpsite-follow-us-badges
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

B Blocks – The ultimate block collection

Plugin Slug:
b-blocks
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ContentBot AI Writer (ChatGPT, GPT4)

Plugin Slug:
content-bot
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Custom Templates Lite

Plugin Slug:
post-custom-templates-lite
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rollbar

Plugin:
Rollbar
Plugin Slug:
rollbar
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
ultraaddons-elementor-lite
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

404 Image Redirection (Replace Broken Images)

Plugin Slug:
broken-images-redirection
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Doppler Forms

Plugin Slug:
doppler-form
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs
Installations
800+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JS Job Manager

Plugin Slug:
js-jobs
Installations
800+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Product Notices for WooCommerce

Plugin Slug:
product-notices-for-woocommerce
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Query Wrangler

Plugin Slug:
query-wrangler
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Revive.so – Bulk Rewrite and Republish Blog Posts

Plugin Slug:
revive-so
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SheetDB – get your Google Spreadsheet data

Plugin Slug:
sheetdb
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TailPress – Tailwind for WordPress

Plugin Slug:
tailpress
Installations
800+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TuriTop Booking System

Plugin Slug:
turitop-booking-system
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widget Manager Light

Plugin Slug:
widget-manager-light
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Group Chat & Video Chat by AtomChat

Plugin Slug:
atomchat
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Group Chat & Video Chat by AtomChat

Plugin Slug:
atomchat
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Plugin Slug:
easyappointments
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magical Blocks – Premium Gutenberg Blocks

Plugin Slug:
magical-blocks
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accessibility Suite by Ability, Inc

Plugin Slug:
online-accessibility
Installations
700+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QR Code Tag for WC order emails, POS receipt emails, PDF invoices, PDF packing slips, Blog posts, Custom post types and Pages (from goaskle.com)

Plugin Slug:
qr-code-tag-for-wc-from-goaskle-com
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SCSS WP Editor

Plugin Slug:
scss-wp-editor
Installations
700+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-owl-carousel
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slider Path for Elementor

Plugin Slug:
slider-path
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SnapWidget Social Photo Feed Widget

Plugin Slug:
snapwidget-wp-instagram-widget
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StaticPress

Plugin Slug:
staticpress
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Plugin Info Card

Plugin Slug:
wp-plugin-info-card
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMS Abandoned Cart Recovery ? CartBoss

Plugin Slug:
cartboss
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Database Applications by Caspio

Plugin Slug:
custom-database-applications-by-caspio
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Daisycon prijsvergelijkers

Plugin Slug:
daisycon
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Embed Chessboard

Plugin Slug:
embed-chessboard
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FPW Category Thumbnails

Plugin Slug:
fpw-category-thumbnails
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google SEO Pressor for Rich snippets

Plugin Slug:
google-seo-author-snippets
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Google SEO Pressor for Rich snippets

Plugin Slug:
google-seo-author-snippets
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

History Log by click5

Plugin Slug:
history-log-by-click5
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Integration of Zoho CRM and Contact Form 7

Plugin Slug:
integration-of-zoho-crm-and-contact-form-7
Installations
600+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OwnerRez

Plugin:
OwnerRez
Plugin Slug:
ownerrez
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Behance Portfolio Manager

Plugin Slug:
portfolio-manager-powered-by-behance
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:
Publitio
Plugin Slug:
publitio
Installations
600+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:
Publitio
Plugin Slug:
publitio
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Publitio

Plugin:
Publitio
Plugin Slug:
publitio
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Question Answer

Plugin Slug:
question-answer
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sheet2Site

Plugin:
Sheet2Site
Plugin Slug:
sheet2site
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Showeblogin Social Plugin

Plugin Slug:
showeblogin-facebook-page-like-box
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Post Expiration

Plugin Slug:
simple-post-expiration
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TextMe SMS

Plugin:
TextMe SMS
Plugin Slug:
textme-sms-integration
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UPC/EAN/GTIN Code Generator

Plugin Slug:
upc-ean-barcode-generator
Installations
600+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uptime Robot Plugin for WordPress

Plugin Slug:
uptime-robot-monitor
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Role Pricing

Plugin Slug:
woocommerce-role-pricing
Installations
600+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-link-preview
Installations
600+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Proposals

Plugin Slug:
wp-proposals
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACME Divi Modules

Plugin Slug:
acme-divi-modules
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Speed Increaser

Plugin Slug:
advanced-speed-increaser
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cache control by Cacholong

Plugin Slug:
cache-control-by-cacholong
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cache control by Cacholong

Plugin Slug:
cache-control-by-cacholong
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CF7 Spreadsheets

Plugin Slug:
cf7-spreadsheets
Installations
500+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Checklist

Plugin:
Checklist
Plugin Slug:
checklist
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Official CleverReach® Plugin for WooCommerce

Plugin Slug:
cleverreach-wc
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Display product variations dropdown on shop page

Plugin Slug:
display-product-variations-dropdown-on-shop-page
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Twice Commerce – Easy Rental Booking System

Plugin Slug:
embed-rentle
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Freetobook Responsive Widget

Plugin Slug:
freetobook-responsive-widget
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FunnelCockpit

Plugin Slug:
funnelcockpit
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leartes TRY Exchange Rates

Plugin Slug:
leartes-try-exchange-rates
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Intents – Live Chat and ChatGPT Chatbots

Plugin Slug:
live-chat-support-by-social-intents
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

m1.DownloadList

Plugin Slug:
m1downloadlist
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Cost Of Goods

Plugin Slug:
ni-woocommerce-cost-of-goods
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Cost Of Goods

Plugin Slug:
ni-woocommerce-cost-of-goods
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RDP Wiki Embed

Plugin Slug:
rdp-wiki-embed
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Duplicator

Plugin Slug:
theme-duplicator
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VG WooCarousel

Plugin Slug:
vg-woocarousel
Installations
500+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Webling

Plugin:
Webling
Plugin Slug:
webling
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wishlist

Plugin:
Wishlist
Plugin Slug:
wishlist
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Clone any post type

Plugin Slug:
wp-clone-any-post-type
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Clone any post type

Plugin Slug:
wp-clone-any-post-type
Installations
500+
Vulnerability:
Unvalidated Redirects and Forwards
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Administrator Z

Plugin Slug:
administrator-z
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Administrator Z

Plugin Slug:
administrator-z
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointify

Plugin:
Appointify
Plugin Slug:
appointify
Installations
400+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto scroll for reading

Plugin Slug:
auto-scroll-for-reading
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Breaking News WP

Plugin Slug:
breaking-news-wp
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Breaking News WP

Plugin Slug:
breaking-news-wp
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chamber Dashboard Business Directory

Plugin Slug:
chamber-dashboard-business-directory
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CRM WordPress Plugin – RepairBuddy

Plugin Slug:
computer-repair-shop
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dima Take Action

Plugin Slug:
dima-take-action
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pin Generator

Plugin Slug:
pin-generator
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Planyo online reservation system

Plugin Slug:
planyo-online-reservation-system
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RSVPMaker

Plugin:
RSVPMaker
Plugin Slug:
rsvpmaker
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Spider Elements – Crafted UX First Addons for Elementor

Plugin Slug:
spider-elements
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
tz-plus-gallery
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP AutoKeyword

Plugin Slug:
wp-autokeyword
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP w3all phpBB

Plugin Slug:
wp-w3all-phpbb-integration
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BWD Elementor Addons (2500+ presets, Meet The Team, Lottie, Lord Icon, Masking, Woocommerce, Theme Builder, Products, Blogs, CV, Contact Form 7 Styler, Header, Slider, Hero Section)

Plugin Slug:
bwd-elementor-addons
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form vCard Generator

Plugin Slug:
contact-form-vcard-generator
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Labinator Content Types Duplicator

Plugin Slug:
labinator-content-types-duplicator
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PhotoShelter for Photographers Blog Feed Plugin

Plugin Slug:
photoshelter-official-plugin
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TableOn – WordPress Posts Table Filterable 

Plugin Slug:
posts-table-filterable
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Silvasoft boekhouden

Plugin Slug:
silvasoft-boekhouden
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SimplyRETS Real Estate IDX

Plugin Slug:
simply-rets
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Viral Loops WP Integration

Plugin Slug:
viral-loops-wp-integration
Installations
300+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ACF City Selector

Plugin Slug:
acf-city-selector
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto Post After Image Upload

Plugin Slug:
auto-post-after-image-upload
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Connector to CiviCRM with CiviMcRestFace

Plugin Slug:
connector-civicrm-mcrestface
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
dn-footer-contacts
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Export All Post Meta

Plugin Slug:
export-all-post-meta
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fonts Manager | Custom Fonts

Plugin Slug:
fonts-manager-custom-fonts
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Leadfox for WordPress

Plugin Slug:
leadfox
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

News Element Elementor Blog Magazine

Plugin Slug:
news-element
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Product Enquiry

Plugin Slug:
ni-woocommerce-product-enquiry
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PeproDev CF7 Database

Plugin Slug:
pepro-cf7-database
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Send E-mail

Plugin Slug:
send-e-mail
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shiptimize for WooCommerce

Plugin Slug:
shiptimize-for-woocommerce
Installations
200+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMM API

Plugin:
SMM API
Plugin Slug:
smm-api
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SwiftXR (3D/AR/VR) Viewer

Plugin Slug:
swiftxr-3darvr-viewer
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Variable Inspector

Plugin Slug:
variable-inspector
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Welcome Popup

Plugin Slug:
welcome-popup
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gift Cards for WooCommerce

Plugin Slug:
woo-giftcards
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Copy Media URL

Plugin Slug:
wp-copy-media-url
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

5sterrenspecialist

Plugin Slug:
5-sterrenspecialist
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
advanced-css3-related-posts-widget
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Agency Toolkit

Plugin Slug:
agency-toolkit
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Apimo Connector

Plugin Slug:
apimo
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Author Bio Shortcode

Plugin Slug:
author-bio-shortcode
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CBX Poll

Plugin:
CBX Poll
Plugin Slug:
cbxpoll
Installations
100+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Clockinator Lite

Plugin Slug:
clockify-lite
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Manager Light

Plugin Slug:
content-manager-light
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ContentMX Content Publisher

Plugin Slug:
contentmx-content-publisher
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Course Booking System

Plugin Slug:
course-booking-system
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Content Scrollbar

Plugin Slug:
custom-content-scrollbar
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DobsonDev Shortcodes

Plugin Slug:
dobsondev-shortcodes
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Testimonials Slider

Plugin Slug:
elfsight-testimonials-slider
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Footnotes for WordPress

Plugin Slug:
footnotes-for-wordpress
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Free Woocommerce Product Table View – Woo Table Pro

Plugin Slug:
free-product-table-for-woocommerce
Installations
100+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Free Woocommerce Product Table View – Woo Table Pro

Plugin Slug:
free-product-table-for-woocommerce
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-for-ultimate-member
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gb-gallery-slideshow
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gdpr-cookie-notice
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light
Installations
100+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Local Magic

Plugin Slug:
local-magic
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opal Portfolio

Plugin Slug:
opal-portfolios
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OpenAI Tools for WordPress & WooCommerce

Plugin Slug:
openai-tools-for-wp-wc
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Payday

Plugin:
Payday
Plugin Slug:
payday
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popping Content Light

Plugin Slug:
popping-content-light
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

QR Master

Plugin:
QR Master
Plugin Slug:
qr-master
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Review Manager

Plugin Slug:
review-manager
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
rio-video-gallery
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ship Per Product

Plugin Slug:
ship-per-product
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple-Audioplayer

Plugin Slug:
simple-audioplayer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
simple-website-logo
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SP Blog Designer

Plugin Slug:
sp-blog-designer
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StaffList

Plugin:
StaffList
Plugin Slug:
stafflist
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

StaffList

Plugin:
StaffList
Plugin Slug:
stafflist
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Team Members for Elementor Page Builder

Plugin Slug:
team-members-for-elementor
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Logo Slider

Plugin Slug:
the-logo-slider
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Live Cricket WordPress Lite

Plugin Slug:
ultimate-live-cricket-lite
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LeadLab by wiredminds

Plugin Slug:
wiredminds-leadlab
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooTumblog

Plugin:
WooTumblog
Plugin Slug:
woo-tumblog
Installations
100+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Video Playlist

Plugin Slug:
wp-video-playlist
Installations
100+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Sitemap

Plugin:
WP Sitemap
Plugin Slug:
wpsitemap
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AB Google Map Travel (AB-MAP)

Plugin Slug:
ab-google-map-travel
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Adverts Plugin – Adverts Click Tracker

Plugin Slug:
adverts-click-tracker
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Clients

Plugin:
Clients
Plugin Slug:
clients
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CookieHint WP

Plugin Slug:
cookiehint-wp
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CoverManager

Plugin Slug:
covermanager
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Minimalistic Event Manager

Plugin Slug:
minimalistic-event-manager
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
open-ai-search-bar
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WR Price List Manager For Woocommerce

Plugin Slug:
wr-price-list-for-woocommerce
Installations
90+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Typekit

Plugin Slug:
advanced-typekit
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

byBrick Accordion

Plugin Slug:
bybrick-accordion
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Subscription Form for Feedblitz

Plugin Slug:
feedblitz-email-subscription
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LeadQuizzes

Plugin Slug:
leadquizzes
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SWM – Shopify to WooCommerce Migration

Plugin Slug:
migrate-shopify-to-woocommerce
Installations
80+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

News, Magazine and Blog Elements

Plugin Slug:
news-magazine-and-blog-elements
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OpenMenu – The official plugin for OpenMenu

Plugin Slug:
open-menu
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
related-posts-list-grid-and-slider-all-in-one
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Terms Before Download

Plugin Slug:
terms-before-download
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More

Plugin Slug:
ultimate-push-notifications
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More

Plugin Slug:
ultimate-push-notifications
Installations
80+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Varnish WordPress

Plugin Slug:
varnish-wp
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

6Storage Rentals

Plugin Slug:
6storage-rentals
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Append Content

Plugin Slug:
append-content
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hypotext

Plugin:
Hypotext
Plugin Slug:
hypotext
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketer Addons

Plugin Slug:
marketer-addons
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PostmarkApp Email Integrator

Plugin Slug:
postmarkapp-email-integrator
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PostmarkApp Email Integrator

Plugin Slug:
postmarkapp-email-integrator
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Radius Blocks – WordPress Gutenberg Blocks

Plugin Slug:
radius-blocks
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Rich Text Editor

Plugin Slug:
richtexteditor
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rich Text Editor

Plugin Slug:
richtexteditor
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Contact Forms

Plugin Slug:
simple-contact-forms
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync
Installations
60+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Boo Recipes

Plugin Slug:
boo-recipes
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Catch Dark Mode

Plugin Slug:
catch-dark-mode
Installations
60+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Magazine

Plugin Slug:
filtr8-magazine
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infusionsoft Web Form JavaScript

Plugin Slug:
infusionsoft-web-form-javascript
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

pCloud Backup

Plugin Slug:
pcloud-backup
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Processing Projects

Plugin Slug:
processing-projects
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sprout Clients – CRM and Lead Management

Plugin Slug:
sprout-clients
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Turbo Addons Elementor

Plugin Slug:
turbo-addons-elementor
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Useinfluence

Plugin Slug:
useinfluence
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Genealogy – Your Family History Website

Plugin Slug:
wpgenealogy
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Fields Editor

Plugin Slug:
bulk-user-editor
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chat by Chatwee

Plugin Slug:
chatwee
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Optimizer – Optimize DB & WordPress

Plugin Slug:
easy-wp-optimizer
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lightweight and Responsive Youtube Embed

Plugin Slug:
lightweight-and-responsive-youtube-embed
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Lightweight and Responsive Youtube Embed

Plugin Slug:
lightweight-and-responsive-youtube-embed
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shopper Approved Reviews

Plugin Slug:
shopperapproved-reviews
Installations
50+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Chrono

Plugin:
WP Chrono
Plugin Slug:
wp-chrono
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlockWheels

Plugin Slug:
blockwheels
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Client Showcase

Plugin Slug:
client-showcase
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DesignO

Plugin:
DesignO
Plugin Slug:
designo
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
intelly-posts-footer-manager
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Welcome Bar

Plugin Slug:
intelly-welcome-bar
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sparkle Elementor Kit

Plugin Slug:
sparkle-elementor-kit
Installations
30+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Fixed Notice

Plugin Slug:
dn-cookie-notice
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Donate Me

Plugin:
Donate Me
Plugin Slug:
donate-me
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Design Blocks – Gutenberg Blocks collection

Plugin Slug:
exclusive-blocks
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShipDepot for WooCommerce

Plugin Slug:
ship-depot
Installations
20+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smartarget Popup

Plugin Slug:
smartarget-popup
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Turisbook Booking System

Plugin Slug:
turisbook-booking-system
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AIO Performance Profiler, Monitor, Optimize, Compress & Debug

Plugin Slug:
all-in-one-performance-accelerator
Installations
10+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ethiopian Calendar

Plugin Slug:
ethiopian-calendar
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventbee RSVP Widget

Plugin Slug:
eventbee-rsvp-widget
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
hmh-footer-builder-for-elementor
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just Post Preview Widget

Plugin Slug:
just-post-preview
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Nearby Locations

Plugin Slug:
nearby-locations
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Support Helpdesk Ticket System Lite

Plugin Slug:
ticket-help-desk-system-lite
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPSHARE247 Elementor Addons

Plugin Slug:
wpshare247-elementor-addons
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

1-Click Backup & Restore Database

Plugin:
1-Click Backup & Restore Database
Plugin Slug:
1-click-backup-restore-database-by-sunbytes
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AAWP Obfuscator

Plugin:
AAWP Obfuscator
Plugin Slug:
aawp-obfuscator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:
ABC Notation
Plugin Slug:
abc-notation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Advertising System

Plugin:
Advanced Advertising System
Plugin Slug:
advanced-advertising-system
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Search by My Solr Server

Plugin:
Advanced Search by My Solr Server
Plugin Slug:
advanced-search-by-my-solr-server
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AI Content Pipelines

Plugin:
AI Content Pipelines
Plugin Slug:
ai-content-pipelines
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Apptivo Business Site CRM

Plugin:
Apptivo Business Site CRM
Plugin Slug:
apptivo-business-site
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Arkhe Blocks

Plugin:
Arkhe Blocks
Plugin Slug:
arkhe-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Arrow Custom Feed for Twitter

Plugin:
Arrow Custom Feed for Twitter
Plugin Slug:
arrow-twitter-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Logos

Plugin:
Awesome Logos
Plugin Slug:
awesome-logos
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Booking Calendar and Notification

Plugin:
Booking Calendar and Notification
Plugin Slug:
booking-calendar-and-notification
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booking Calendar and Notification

Plugin:
Booking Calendar and Notification
Plugin Slug:
booking-calendar-and-notification
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

BookingPress

Plugin:
BookingPress
Plugin Slug:
bookingpress-appointment-booking
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Botnet Attack Blocker

Plugin:
Botnet Attack Blocker
Plugin Slug:
botnet-attack-blocker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CGM Event Calendar

Plugin:
CGM Event Calendar
Plugin Slug:
cgm-event-calendar
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clearbit Reveal

Plugin:
Clearbit Reveal
Plugin Slug:
clearbit
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Delete Post Revision

Plugin:
Delete Post Revision
Plugin Slug:
delete-post-revision
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Demo Awesome

Plugin:
Demo Awesome
Plugin Slug:
demo-awesome
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DigiWidgets Image Editor

Plugin:
DigiWidgets Image Editor
Plugin Slug:
digiwidgets-image-editor
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Multi Days Events and Multi Events in One Day Calendar

Plugin Slug:
dragon-calendar-free-version
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DyaPress ERP/CRM

Plugin:
DyaPress ERP/CRM
Plugin Slug:
dyapress
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:
ZoomSounds
Plugin Slug:
dzs-zoomsounds
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:
ZoomSounds
Plugin Slug:
dzs-zoomsounds
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ZoomSounds

Plugin:
ZoomSounds
Plugin Slug:
dzs-zoomsounds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Contact

Plugin:
Easy Contact
Plugin Slug:
easy-contact
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Query – WP Query Builder

Plugin:
Easy Query – WP Query Builder
Plugin Slug:
easy-query
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:
Ebook Downloader
Plugin Slug:
ebook-downloader
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ebook Downloader

Plugin:
Ebook Downloader
Plugin Slug:
ebook-downloader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Emma for WordPress

Plugin:
Emma for WordPress
Plugin Slug:
emma-emarketing-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Exit Popup Free

Plugin Slug:
exit-popup-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Extensions for Elementor

Plugin:
Extensions for Elementor
Plugin Slug:
extensions-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ez Form Calculator – WordPress plugin

Plugin:
ez Form Calculator – WordPress plugin
Plugin Slug:
ez-form-calculator-premium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fami WooCommerce Compare

Plugin:
Fami WooCommerce Compare
Plugin Slug:
fami-woocommerce-compare
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flickr Photostream

Plugin:
Flickr Photostream
Plugin Slug:
flickr-photostream
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frizzly

Plugin:
Frizzly
Plugin Slug:
frizzly
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:
Front End Users
Plugin Slug:
front-end-only-users
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Front End Users

Plugin:
Front End Users
Plugin Slug:
front-end-only-users
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GetBookingsWP

Plugin:
GetBookingsWP
Plugin Slug:
get-bookings-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Salesmate Add-On for Gravity Forms

Plugin:
Salesmate Add-On for Gravity Forms
Plugin Slug:
gf-salesmate-add-on
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Salesmate Add-On for Gravity Forms

Plugin:
Salesmate Add-On for Gravity Forms
Plugin Slug:
gf-salesmate-add-on
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gift Certificate Creator

Plugin:
Gift Certificate Creator
Plugin Slug:
gift-certificate-creator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Global Gallery
Plugin Slug:
global-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GNUCommerce

Plugin:
GNUCommerce
Plugin Slug:
gnucommerce
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gosign – Posts Slider Block

Plugin:
Gosign – Posts Slider Block
Plugin Slug:
gosign-posts-slider-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

include-file

Plugin:
include-file
Plugin Slug:
include-file
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jetpack Feedback Exporter

Plugin:
Jetpack Feedback Exporter
Plugin Slug:
jetpack-feedback-exporter
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JSON Structuring Markup

Plugin:
JSON Structuring Markup
Plugin Slug:
json-structuring-markup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

KB Support

Plugin:
KB Support
Plugin Slug:
kb-support
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Search engine keywords highlighter

Plugin:
Search engine keywords highlighter
Plugin Slug:
keywords-highlight-tool
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lafka Plugin

Plugin:
Lafka Plugin
Plugin Slug:
lafka-plugin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Latest Custom Post Type Updates

Plugin:
Latest Custom Post Type Updates
Plugin Slug:
latest-custom-post-type-updates
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lexicata

Plugin:
Lexicata
Plugin Slug:
lexicata
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Limit Max IPs Per User

Plugin:
Limit Max IPs Per User
Plugin Slug:
limit-max-ips-per-user
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MediaView

Plugin:
MediaView
Plugin Slug:
mediaview
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Melhor Envio

Plugin:
Melhor Envio
Plugin Slug:
melhor-envio-cotacao
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

mFolio Lite

Plugin Slug:
mfolio-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookProgress by Stormhill Media

Plugin:
MyBookProgress by Stormhill Media
Plugin Slug:
mybookprogress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MyBookProgress by Stormhill Media

Plugin:
MyBookProgress by Stormhill Media
Plugin Slug:
mybookprogress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NanoSupport

Plugin:
NanoSupport
Plugin Slug:
nanosupport
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NanoSupport

Plugin:
NanoSupport
Plugin Slug:
nanosupport
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pages Order

Plugin:
Pages Order
Plugin Slug:
pages-order
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Posten – Gutenberg Post Block

Plugin Slug:
posten-post-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blubrry PowerPress Podcasting plugin MultiSite add-on

Plugin:
Blubrry PowerPress Podcasting plugin MultiSite add-on
Plugin Slug:
powerpress-multisite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RJ Quickcharts

Plugin:
RJ Quickcharts
Plugin Slug:
rj-quickcharts
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Maps

Plugin:
Maps
Plugin Slug:
robo-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO Tools

Plugin:
SEO Tools
Plugin Slug:
seo-automatic-seo-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sequel

Plugin:
Sequel
Plugin Slug:
sequel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Map No Api

Plugin:
Simple Map No Api
Plugin Slug:
simple-map-no-api
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple WP Events

Plugin:
Simple WP Events
Plugin Slug:
simple-wp-events
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple:Press

Plugin:
Simple:Press
Plugin Slug:
simplepress
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Icons For WordPress

Plugin:
Smart Icons For WordPress
Plugin Slug:
smartifw
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Share And Social Locker

Plugin:
Social Share And Social Locker
Plugin Slug:
social-share-and-social-locker-arsocial
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Social Share And Social Locker

Plugin:
Social Share And Social Locker
Plugin Slug:
social-share-and-social-locker-arsocial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Team Builder

Plugin:
Team Builder
Plugin Slug:
team-display
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Team Rosters

Plugin:
Team Rosters
Plugin Slug:
team-rosters
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Trackserver

Plugin:
Trackserver
Plugin Slug:
trackserver
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Video Url

Plugin:
Video Url
Plugin Slug:
video-sidebar-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Videos

Plugin:
Videos
Plugin Slug:
videos
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Digihood HTML Sitemap

Plugin:
Digihood HTML Sitemap
Plugin Slug:
wedesin-html-sitemap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Bookmarks

Plugin:
WP Bookmarks
Plugin Slug:
wp-bookmarks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Church Donation

Plugin:
WP Church Donation
Plugin Slug:
wp-church-donation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Crowdfunding

Plugin:
WP Crowdfunding
Plugin Slug:
wp-crowdfunding
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Galleria

Plugin:
WordPress Galleria
Plugin Slug:
wp-galleria
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP_Identicon

Plugin:
WP_Identicon
Plugin Slug:
wp-identicon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Profitshare

Plugin:
WP Profitshare
Plugin Slug:
wp-profitshare
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced All in One Admin Search by WP Spotlight

Plugin:
Advanced All in One Admin Search by WP Spotlight
Plugin Slug:
wp-spotlight-search
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wp Time Machine

Plugin:
wp Time Machine
Plugin Slug:
wp-time-machine
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP User Profiles

Plugin:
WP User Profiles
Plugin Slug:
wp-users-profiles
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Cleaner

Plugin:
WP Cleaner
Plugin Slug:
wpcleaner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wptobe-signinup

Plugin:
Wptobe-signinup
Plugin Slug:
wptobe-signinup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:
XV Random Quotes
Plugin Slug:
xv-random-quotes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XV Random Quotes

Plugin:
XV Random Quotes
Plugin Slug:
xv-random-quotes
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Enable Media Replace

Plugin Slug:
enable-media-replace
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.6.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.143
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.143.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.34.

Lightbox & Modal Popup WordPress Plugin – FooBox

Plugin Slug:
foobox-image-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.34.

LuckyWP Table of Contents

Plugin Slug:
luckywp-table-of-contents
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.11.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.2.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.25.

Product Filter by WBW

Plugin Slug:
woo-product-filter
Installations
60,000+
Vulnerability:
SQL Injection
Patched in Version:
2.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.64
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.64.

MapPress Maps for WordPress

Plugin Slug:
mappress-google-maps-for-wordpress
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.94.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.94.9.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.5.

Booster for WooCommerce

Plugin Slug:
woocommerce-jetpack
Installations
40,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.5.

WPFront User Role Editor

Plugin Slug:
wpfront-user-role-editor
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.2.

Blog Grid & Post Grid – Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry, Category Post Grid By News & Blog Designer Pack

Plugin Slug:
blog-designer-pack
Installations
30,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.1.

GTM Kit – Google Tag Manager & GA4 integration

Plugin Slug:
gtm-kit
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.5.

Import Export Suite for CSV and XML Datafeed

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
7.19.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.19.1.

Import Export Suite for CSV and XML Datafeed

Plugin Slug:
wp-ultimate-csv-importer
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
7.19.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.19.1.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.4.

Countdown, Coming Soon, Maintenance – Countdown & Clock

Plugin Slug:
countdown-builder
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.0.

Countdown, Coming Soon, Maintenance – Countdown & Clock

Plugin Slug:
countdown-builder
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.8.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.8.9.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.2.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.8.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.67
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.67.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.65
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.65.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.64
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.64.

WP Date and Time Shortcode

Plugin Slug:
wp-date-and-time-shortcode
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.8.
Plugin Slug:
automatic-featured-images-from-videos
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Awesome Support – WordPress HelpDesk & Support Plugin

Plugin Slug:
awesome-support
Installations
8,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.2.

Cue by AudioTheme.com

Plugin Slug:
cue
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Insert Headers and Footers Code – HT Script

Plugin Slug:
insert-headers-and-footers-script
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Drag and Drop Multiple File Upload for WooCommerce

Plugin Slug:
drag-and-drop-multiple-file-upload-for-woocommerce
Installations
6,000+
Vulnerability:
Directory Traversal
Patched in Version:
1.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.5.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.8.0.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.3.

Lana Downloads Manager

Plugin Slug:
lana-downloads-manager
Installations
3,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.0.

Beds24 Online Booking

Plugin Slug:
beds24-online-booking
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.28.

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
9.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.0.12.

Product Table by WBW

Plugin Slug:
woo-product-tables
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.5.

Social proof testimonials and reviews by Repuso

Plugin Slug:
social-testimonials-and-reviews-widget
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.22.

YayExtra – WooCommerce Extra Product Options

Plugin Slug:
yayextra
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.3.

3DPrint Lite

Plugin Slug:
3dprint-lite
Installations
900+
Vulnerability:
SQL Injection
Patched in Version:
2.1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.7.

Ultra Addons Lite for Elementor

Plugin Slug:
ut-elementor-addons-lite
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.9.

xili-language

Plugin Slug:
xili-language
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.21.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.21.3.

Feedbucket – Website Feedback Tool

Plugin Slug:
feedbucket
Installations
800+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Maps for WP

Plugin Slug:
maps-for-wp
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.5.

Theater for WordPress

Plugin Slug:
theatre
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
0.18.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.18.8.

Snow Storm

Plugin:
Snow Storm
Plugin Slug:
snow-storm
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.7.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.8.

WordPress Access Areas

Plugin Slug:
wp-access-areas
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.20.

Post to Social Media – WordPress to Hootsuite

Plugin Slug:
wp-to-hootsuite
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

Team Circle Image Slider With Lightbox

Plugin Slug:
circle-image-slider-with-lightbox
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
1.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.5.

DeBounce Email Validator

Plugin Slug:
debounce-io-email-validator
Installations
400+
Vulnerability:
Local File Inclusion
Patched in Version:
5.71
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.71.

Plugin Oficial – Getnet para WooCommerce

Plugin Slug:
wc-checkout-getnet
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.0.

Order Splitter for WooCommerce

Plugin Slug:
woo-order-splitter
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
5.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.1.

CardGate Payments for WooCommerce

Plugin Slug:
cardgate
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
3.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.

Falling Things

Plugin Slug:
falling-things
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
1.09
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.09.

Search, Filters & Merchandising for WooCommerce

Plugin Slug:
instantsearch-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.59.

Next-Cart Store to WooCommerce Migration

Plugin Slug:
nextcart-woocommerce-migration
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
3.9.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.5.

Oracle Cards Lite

Plugin Slug:
oracle-cards
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

Perfect Font Awesome Integration

Plugin Slug:
perfect-font-awesome-integration
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.1.

Residential Address Detection

Plugin Slug:
residential-address-detection
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.5.

Total processing card payments for WooCommerce

Plugin Slug:
totalprocessing-card-payments
Installations
200+
Vulnerability:
Arbitrary File Download
Patched in Version:
7.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.6.

Big Boom Directory

Plugin Slug:
big-boom-directory
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

GreenPay(tm) by Green.Money

Plugin Slug:
green-money-payment-gateway
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.10.
Plugin Slug:
internal-link-finder
Installations
100+
Vulnerability:
Settings Change
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

Material Dashboard

Plugin Slug:
material-dashboard
Installations
80+
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.6.

Norse Rune Oracle Plugin

Plugin Slug:
norse-runes-oracle
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.4.

Small Package Quotes – Worldwide Express Edition

Plugin Slug:
small-package-quotes-wwe-edition
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
5.2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.20.

Small Package Quotes – Worldwide Express Edition

Plugin Slug:
small-package-quotes-wwe-edition
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.19.

Awesome Event Booking

Plugin Slug:
awesome-event-booking
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.5.

Accept SagePay Payments Using Contact Form 7

Plugin Slug:
accept-sagepay-payments-using-contact-form-7
Installations
10+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

coreActivity: Activity Logging for WordPress

Plugin Slug:
coreactivity
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
2.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.1.

Bridge Core

Plugin:
Bridge Core
Plugin Slug:
bridge-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Contempo Real Estate Core

Plugin:
Contempo Real Estate Core
Plugin Slug:
ct-real-estate-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.

Fusion Builder

Plugin:
Fusion Builder
Plugin Slug:
fusion-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.15.

tagDiv Composer

Plugin:
tagDiv Composer
Plugin Slug:
td-composer
Vulnerability:
PHP Object Injection
Patched in Version:
5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.

User Registration & Membership Pro

Plugin:
User Registration & Membership Pro
Plugin Slug:
user-registration-pro
Vulnerability:
Broken Authentication
Patched in Version:
5.1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.1.3.

Vehica Core

Plugin:
Vehica Core
Plugin Slug:
vehica-core
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.98
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.98.

Vitepos

Plugin:
Vitepos
Plugin Slug:
vitepos-lite
Vulnerability:
Broken Authentication
Patched in Version:
3.1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.5.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.4.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.22.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.4.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.22.

WP RealEstate

Plugin:
WP RealEstate
Plugin Slug:
wp-realestate
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.27
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.27.

WordPress Themes — 5 Patched / 24 Unpatched

Glossy Blog

Theme Slug:
glossy-blog
Downloads
5,059
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Home Services

Theme Slug:
home-services
Downloads
19,959
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Simplish

Theme:
Simplish
Theme Slug:
simplish
Downloads
28,664
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Tainá

Theme:
Tainá
Theme Slug:
taina
Downloads
1,311
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Bloggie

Theme:
Bloggie
Theme Slug:
bloggie
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:
Themify Edmin
Theme Slug:
edmin
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Themify Edmin

Theme:
Themify Edmin
Theme Slug:
edmin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Themify Folo

Theme:
Themify Folo
Theme Slug:
folo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Themify Folo

Theme:
Themify Folo
Theme Slug:
folo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gravel

Theme:
Gravel
Theme Slug:
gravel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Themify Newsy

Theme:
Themify Newsy
Theme Slug:
newsy
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Themify Newsy

Theme:
Themify Newsy
Theme Slug:
newsy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Photobox

Theme:
Photobox
Theme Slug:
photobox
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Photobox

Theme:
Photobox
Theme Slug:
photobox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rezo

Theme:
Rezo
Theme Slug:
rezo
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Rezo

Theme:
Rezo
Theme Slug:
rezo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Shopo

Theme:
Shopo
Theme Slug:
shopo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Themify Sidepane WordPress Theme

Theme:
Themify Sidepane WordPress Theme
Theme Slug:
sidepane
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Themify Sidepane WordPress Theme

Theme:
Themify Sidepane WordPress Theme
Theme Slug:
sidepane
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Slide

Theme:
Slide
Theme Slug:
slide
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Slide

Theme:
Slide
Theme Slug:
slide
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tiger

Theme:
Tiger
Theme Slug:
tiger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Tiger

Theme:
Tiger
Theme Slug:
tiger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Wigi

Theme:
Wigi
Theme Slug:
wigi
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Real Estate 7

Theme:
Real Estate 7
Theme Slug:
realestate-7
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.5.

Streamit

Theme:
Streamit
Theme Slug:
streamit
Vulnerability:
Arbitrary File Download
Patched in Version:
4.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:
Streamit
Theme Slug:
streamit
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.0.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.2.

Streamit

Theme:
Streamit
Theme Slug:
streamit
Vulnerability:
Privilege Escalation
Patched in Version:
4.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.3.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Privilege Escalation
Patched in Version:
5.4.22
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.4.22.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security