WordPress Vulnerability Report

WordPress Vulnerability Report — August 27, 2025

Since last week, 169 new vulnerabilities have emerged in the WordPress ecosystem, including 145 plugins and 24 themes. Of those, 98 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 169 vulnerabilities have been publicly disclosed. Security patches for 71 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 98 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 58 Patched / 87 Unpatched

Site Offline Or Coming Soon Or Maintenance Mode

Plugin Slug:
site-offline
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
smart-grid-gallery
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Statify Widget

Plugin Slug:
statify-widget
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Add Code To Head

Plugin Slug:
add-code-to-head
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Popup for CF7 with Sweet Alert

Plugin Slug:
cf7-sweet-alert-popup
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AutoWP – AI Content Writer & Rewriter

Plugin Slug:
autowp-ai-content-writer-rewriter
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backup Bolt

Plugin Slug:
backup-bolt
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Century ToolKit

Plugin Slug:
century-toolkit
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Type Converter

Plugin Slug:
post-type-converter
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Varnish/Nginx Proxy Caching

Plugin Slug:
vcaching
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Mailgun SMTP

Plugin Slug:
wp-mailgun-smtp
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

??????.??? ?????? / Yandex Site search pinger

Plugin Slug:
yandex-pinger
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Admin Menu Groups

Plugin Slug:
admin-menu-groups
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-warning
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cookie-warning
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link View
Plugin Slug:
link-view
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link View
Plugin Slug:
link-view
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page Transition

Plugin Slug:
page-transition
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress HTML

Plugin Slug:
custom-html-bodyhead
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Mobile-Friendly Tooltip

Plugin Slug:
responsive-mobile-friendly-tooltip
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Terms of Service & Privacy Policy Generator

Plugin Slug:
terms-of-service-and-privacy-policy
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPAvatar

Plugin:
WPAvatar
Plugin Slug:
wpavatar
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bxSlider integration for WordPress

Plugin Slug:
bxslider-integration
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iFrame Block

Plugin Slug:
iframe-block
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iframe Wrapper

Plugin Slug:
iframe-wrapper
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Risk Free Cash On Delivery (COD) – WooCommerce

Plugin Slug:
risk-free-cash-on-delivery-cod-woocommerce
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Essential Doo Components for Visual Composer

Plugin Slug:
animated-icon-banner-for-visual-composer
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Better Post & Filter Widgets for Elementor

Plugin Slug:
better-post-filter-widgets-for-elementor
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TC Testimonials

Plugin Slug:
tc-testimonial
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

LifePress

Plugin:
LifePress
Plugin Slug:
lifepress
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tripadvisor Shortcode

Plugin Slug:
tripadvisor-shortcode
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

??????

Plugin:
??????
Plugin Slug:
baidushare-wp
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BetPress

Plugin:
BetPress
Plugin Slug:
betpress
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Comments Capcha Box

Plugin Slug:
comments-capcha-box
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

e-Boekhouden.nl

Plugin Slug:
e-boekhoudennl-connector
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Invisible Optin

Plugin Slug:
invisible-optin
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
nextgen-gallery-search-galleries
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Page Manager for Elementor

Plugin Slug:
page-manager-for-elementor
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Switcher Reloaded

Plugin Slug:
theme-switcher-reloaded
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate twitter profile widget

Plugin Slug:
ultimate-twitter-profile-widget
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Table Editor

Plugin Slug:
wp-table-editor
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ATT YouTube Widget

Plugin Slug:
att-youtube
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google XML News Sitemap plugin

Plugin Slug:
gn-xml-sitemap
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kento Splash Screen

Plugin Slug:
kento-splash-screen
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SEO For Images

Plugin Slug:
seo-for-images
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

????????

Plugin:
????????
Plugin Slug:
duoshuo
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter subscription optin module

Plugin Slug:
newsletter-subscription-widget-for-sendblaster
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Theme

Plugin Slug:
wp-admin-theme
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

XM-Backup

Plugin:
XM-Backup
Plugin Slug:
xm-backup
Installations
70+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Clickbank WordPress Plugin (Niche Storefront)

Plugin Slug:
clickbank-niche-storefronts
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPMU Ldap Authentication

Plugin Slug:
wpmuldap
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bidorbuy Store Integrator

Plugin Slug:
bidorbuystoreintegrator
Installations
50+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

rajce

Plugin:
rajce
Plugin Slug:
rajce
Installations
50+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Savyour Affiliate Partner

Plugin Slug:
savyour-affiliate-partner
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SensorPress

Plugin Slug:
sensorpress-uptime-monitoring
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment

Plugin Slug:
customcomment
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simpler Checkout

Plugin Slug:
simpler-checkout
Installations
40+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Kanpress

Plugin:
Kanpress
Plugin Slug:
kanpress
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Goal Tracker for Patreon

Plugin Slug:
goal-tracker-for-patreon
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Support Ticket

Plugin Slug:
support-ticket
Installations
10+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

tli.tl auto Twitter poster

Plugin Slug:
tlitl-auto-twitter-poster
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Funnel Manager

Plugin Slug:
wp-funnel-manager
Installations
10+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Advance Food Menu

Plugin Slug:
advance-food-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premium Age Verification / Restriction for WordPress

Plugin:
Premium Age Verification / Restriction for WordPress
Plugin Slug:
age-restriction
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Bravis User

Plugin:
Bravis User
Plugin Slug:
bravis-user
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Exertio Framework

Plugin:
Exertio Framework
Plugin Slug:
exertio-framework
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Silencesoft RSS Reader

Plugin:
Silencesoft RSS Reader
Plugin Slug:
external-rss-reader
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Listeo-Core

Plugin:
Listeo-Core
Plugin Slug:
listeo-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mesa Mesa Reservation Widget

Plugin Slug:
mesa-mesa-reservation-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Customer Product Report

Plugin:
Ni WooCommerce Customer Product Report
Plugin Slug:
ni-woocommerce-customer-product-report
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ogulo – 360° Tour

Plugin:
Ogulo – 360° Tour
Plugin Slug:
ogulo-360-tour
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Manager Pro

Plugin:
Portfolio Manager Pro
Plugin Slug:
otw-portfolio-manager
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Portfolio Manager Pro

Plugin:
Portfolio Manager Pro
Plugin Slug:
otw-portfolio-manager
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PressApps Knowledge Base Contextual Sidebar Addon

Plugin:
PressApps Knowledge Base Contextual Sidebar Addon
Plugin Slug:
pressapps-knowledge-base
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ProveSource Social Proof

Plugin:
ProveSource Social Proof
Plugin Slug:
provesource
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Restore Permanently delete Post or Page Data

Plugin:
Restore Permanently delete Post or Page Data
Plugin Slug:
restore-permanently-delete-post-or-page-data
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShortcodeHub – MultiPurpose Shortcode Builder

Plugin:
ShortcodeHub – MultiPurpose Shortcode Builder
Plugin Slug:
shortcodehub
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ThemeMakers Visual Content Composer

Plugin:
ThemeMakers Visual Content Composer
Plugin Slug:
tmm_content_composer
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WC Plus

Plugin:
WC Plus
Plugin Slug:
wc-plus
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Filter & Combine RSS Feeds

Plugin:
WP Filter & Combine RSS Feeds
Plugin Slug:
wp-filter-combine-rss-feeds
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Talroo

Plugin:
WP Talroo
Plugin Slug:
wp-jobs2careers
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wptobe-memberships

Plugin:
Wptobe-memberships
Plugin Slug:
wptobe-memberships
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WS Theme Addons

Plugin:
WS Theme Addons
Plugin Slug:
ws-theme-addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Crontrol

Plugin Slug:
wp-crontrol
Installations
300,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.19.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.19.2.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations
300,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations
300,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations
300,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.5.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.1.

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

WPC Smart Compare for WooCommerce

Plugin Slug:
woo-smart-compare
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.8.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.28.

Greenshift – animation and page builder blocks

Plugin Slug:
greenshift-animation-and-page-builder-blocks
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
12.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.1.2.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
30,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.12.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.12.0.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
30,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.1.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.

Fluent Support – Helpdesk & Customer Support Ticket System

Plugin Slug:
fluent-support
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
9,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
9.1.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.4.

Flexible Map

Plugin Slug:
wp-flexible-map
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.19.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.19.0.

WP Colorbox

Plugin Slug:
wp-colorbox
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.6.

Raptive Ads

Plugin Slug:
adthrive-ads
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.0.

Themify Builder

Plugin Slug:
themify-builder
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.8.

CubeWP – All-in-One Dynamic Content Framework

Plugin Slug:
cubewp-framework
Installations
5,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.25.

Themify Icons

Plugin Slug:
themify-icons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

E-cab Taxi Booking Manager for Woocommerce

Plugin Slug:
ecab-taxi-booking-manager
Installations
1,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.3.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.1.
Plugin Slug:
fulltext-search
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.79.274
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.79.274.

Markup Markdown

Plugin Slug:
markup-markdown
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.7.

Recurring PayPal Donations

Plugin Slug:
recurring-donation
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.

Sign-up Sheets

Plugin Slug:
sign-up-sheets
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.3.1.

Simple Statistics for Feeds

Plugin Slug:
simple-feed-stats
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
20250820
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20250820.

Themify Audio Dock

Plugin Slug:
themify-audio-dock
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

MDTF – Meta Data and Taxonomies Filter

Plugin Slug:
wp-meta-data-filter-and-taxonomy-filter
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
1.3.3.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.3.8.

WPPizza – A Restaurant Plugin

Plugin Slug:
wppizza
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.19.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.8.1.

Sessions

Plugin:
Sessions
Plugin Slug:
sessions
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

Notice Bar

Plugin:
Notice Bar
Plugin Slug:
notice-bar
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Church Admin

Plugin Slug:
church-admin
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.27.

UPC/EAN/GTIN Code Generator

Plugin Slug:
upc-ean-barcode-generator
Installations
500+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.3.

Bible SuperSearch

Plugin Slug:
biblesupersearch
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.0.

Contact Manager

Plugin Slug:
contact-manager
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.6.6.

Vibes

Plugin:
Vibes
Plugin Slug:
vibes
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
2.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.1.

ads.txt Guru Connect

Plugin Slug:
adstxt-guru-connect
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.2.

Custom Query Shortcode

Plugin Slug:
custom-query-shortcode
Installations
30+
Vulnerability:
Directory Traversal
Patched in Version:
0.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.5.0.

Case Theme User

Plugin:
Case Theme User
Plugin Slug:
case-theme-user
Vulnerability:
Broken Authentication
Patched in Version:
1.0.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.4.

eventlist

Plugin:
eventlist
Plugin Slug:
eventlist
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.5.

Global DNS

Plugin:
Global DNS
Plugin Slug:
global-dns
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.1.

Miraculous Core Plugin

Plugin:
Miraculous Core Plugin
Plugin Slug:
miraculouscore
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.8.

Ovatheme Events

Plugin:
Ovatheme Events
Plugin Slug:
ova-events
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.7.

Simple Business Directory Pro

Plugin:
Simple Business Directory Pro
Plugin Slug:
simple-business-directory-pro
Vulnerability:
Privilege Escalation
Patched in Version:
15.6.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 15.6.9.

Tourfic

Plugin:
Tourfic
Plugin Slug:
tourfic
Vulnerability:
Broken Access Control
Patched in Version:
2.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.0.

Automatic

Plugin:
Automatic
Plugin Slug:
wp-automatic
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.119.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.119.0.

WordPress Themes — 13 Patched / 11 Unpatched

BlogMarks

Theme Slug:
blogmarks
Downloads
2,998
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Eximious Magazine

Theme Slug:
eximious-magazine
Downloads
89,583
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Glamer

Theme:
Glamer
Theme Slug:
glamer
Downloads
1,229
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Magazine Elite

Theme Slug:
magazine-elite
Downloads
23,250
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Magazine Saga

Theme Slug:
magazine-saga
Downloads
39,647
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Jannah

Theme:
Jannah
Theme Slug:
jannah
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kalium

Theme:
Kalium
Theme Slug:
kalium
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Kitring

Theme:
Kitring
Theme Slug:
kitring
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nuss

Theme:
Nuss
Theme Slug:
nuss
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Organic Beauty

Theme:
Organic Beauty
Theme Slug:
organic-beauty
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Pro Bulk Watermark Plugin for WordPress

Theme:
Pro Bulk Watermark Plugin for WordPress
Theme Slug:
pro-watermark
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

ColorMag

Theme:
ColorMag
Theme Slug:
colormag
Downloads
4,262,710
Vulnerability:
Broken Access Control
Patched in Version:
4.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.20.

Inspiro

Theme:
Inspiro
Theme Slug:
inspiro
Downloads
1,177,489
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

Spacious

Theme:
Spacious
Theme Slug:
spacious
Downloads
2,634,166
Vulnerability:
Broken Access Control
Patched in Version:
1.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.12.

Golo

Theme:
Golo
Theme Slug:
golo
Vulnerability:
Broken Authentication
Patched in Version:
1.7.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.1.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Broken Access Control
Patched in Version:
4.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.4.

JobZilla – Job Board WordPress Theme

Theme:
JobZilla – Job Board WordPress Theme
Theme Slug:
jobzilla
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Kipso

Theme:
Kipso
Theme Slug:
kipso
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.1.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Broken Authentication
Patched in Version:
4.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.8.0.

Real Spaces

Theme:
Real Spaces
Theme Slug:
real-spaces
Vulnerability:
Privilege Escalation
Patched in Version:
3.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.1.

Real Spaces

Theme:
Real Spaces
Theme Slug:
real-spaces
Vulnerability:
Privilege Escalation
Patched in Version:
3.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.

Sala

Theme:
Sala
Theme Slug:
sala
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security