WordPress Vulnerability Report

WordPress Vulnerability Report — December 10, 2025

Since last week, 170 new vulnerabilities have emerged in the WordPress ecosystem, including 168 plugins and 2 themes. Of those, 91 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 170 vulnerabilities have been publicly disclosed. Security patches for 79 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 91 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 77 Patched / 91 Unpatched

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yandex.Metrica

Plugin Slug:
wp-yandex-metrika
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Ultimate Review

Plugin Slug:
wp-ultimate-review
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xpro Addons — 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Page View Count

Plugin Slug:
page-views-count
Installations
20,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Make Section & Column Clickable For Elementor

Plugin Slug:
make-section-column-clickable-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Order Delivery Date for WooCommerce

Plugin Slug:
order-delivery-date-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Xagio SEO – AI Powered SEO

Plugin Slug:
xagio-seo
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Paysera Payment Gateway for WooCommerce

Plugin Slug:
woo-payment-gateway-paysera
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Layouts – Post + Product grids made easy

Plugin Slug:
custom-layouts
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Plugin Slug:
multiparcels-shipping-for-woocommerce
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shopping Cart & eCommerce Store

Plugin Slug:
wp-easycart
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ergonet Cache

Plugin Slug:
ergonet-varnish-cache
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eupago Gateway For Woocommerce

Plugin Slug:
eupago-gateway-for-woocommerce
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Photo Fetcher

Plugin Slug:
facebook-photo-fetcher
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Gravitec.net – Web Push Notifications

Plugin Slug:
gravitec-net-web-push-notifications
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Just TinyMCE Custom Styles

Plugin Slug:
just-tinymce-styles
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Media Library Downloader

Plugin Slug:
media-library-downloader
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Cloner

Plugin Slug:
post-cloner
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Flashy Marketing Automation

Plugin Slug:
wp-flashy-marketing-automation
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Sidebars by ProteusThemes

Plugin Slug:
custom-sidebars-by-proteusthemes
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Formstack Online Forms

Plugin Slug:
formstack
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMTP Mail

Plugin:
SMTP Mail
Plugin Slug:
smtp-mail
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Spam Remover

Plugin Slug:
user-spam-remover
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-CRM System – Manage Clients and Projects

Plugin Slug:
wp-crm-system
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

g-FFL Cockpit

Plugin Slug:
g-ffl-cockpit
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Search, Filters & Merchandising for WooCommerce

Plugin Slug:
instantsearch-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Actionwear products sync

Plugin Slug:
actionwear-products-sync
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flex QR Code Generator

Plugin Slug:
flex-qr-code-generator
Installations
50+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hype

Plugin:
Hype
Plugin Slug:
pico
Installations
50+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Application Passwords

Plugin:
Application Passwords
Plugin Slug:
application-passwords
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
ARK Related Posts
Plugin Slug:
ark-relatedpost
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Broken Link Manager
Plugin Slug:
broken-link-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Canadian Nutrition Facts Label

Plugin:
Canadian Nutrition Facts Label
Plugin Slug:
canadian-nutrition-facts-label
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Clikstats

Plugin:
Clikstats
Plugin Slug:
clikstats
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CryptX

Plugin:
CryptX
Plugin Slug:
cryptx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSS3 Buttons

Plugin:
CSS3 Buttons
Plugin Slug:
css3-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CSV Sumotto

Plugin:
CSV Sumotto
Plugin Slug:
csv-sumotto
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cute News Ticker

Plugin:
Cute News Ticker
Plugin Slug:
cute-news-ticker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DB Access

Plugin:
DB Access
Plugin Slug:
db-access
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
dream gallery
Plugin Slug:
dream-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Extra Post Images

Plugin:
Extra Post Images
Plugin Slug:
extra-post-images
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FitVids for WordPress

Plugin:
FitVids for WordPress
Plugin Slug:
fitvids-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Helloprint

Plugin:
Helloprint
Plugin Slug:
helloprint
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Jabbernotification

Plugin:
Jabbernotification
Plugin Slug:
jabberbenachrichtigung
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

List Attachments Shortcode

Plugin:
List Attachments Shortcode
Plugin Slug:
list-attachments-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Listar – Directory Listing & Classifieds

Plugin:
Listar – Directory Listing & Classifieds
Plugin Slug:
listar-directory-listing
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Listar – Directory Listing & Classifieds

Plugin:
Listar – Directory Listing & Classifieds
Plugin Slug:
listar-directory-listing
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live CSS Preview

Plugin:
Live CSS Preview
Plugin Slug:
live-css-preview
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

myLCO

Plugin:
myLCO
Plugin Slug:
mylco
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Nouri.sh Newsletter

Plugin:
Nouri.sh Newsletter
Plugin Slug:
newsletters-from-rss-to-email-newsletters-using-nourish
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Payaza

Plugin:
Payaza
Plugin Slug:
payaza
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Grid and Gutenberg Blocks

Plugin:
Post Grid and Gutenberg Blocks
Plugin Slug:
post-grid
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PostGallery

Plugin:
PostGallery
Plugin Slug:
postgallery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Projectopia

Plugin:
Projectopia
Plugin Slug:
projectopia-core
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Projectopia

Plugin:
Projectopia
Plugin Slug:
projectopia-core
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RevInsite

Plugin:
RevInsite
Plugin Slug:
revinsite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Feed Gallery Portfolio
Plugin Slug:
social-feed-gallery-portfolio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress eCommerce Plugin – Studiocart

Plugin:
WordPress eCommerce Plugin – Studiocart
Plugin Slug:
studiocart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Thai Lottery Widget

Plugin:
Thai Lottery Widget
Plugin Slug:
thai-lottery-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin:
Time Sheets
Plugin Slug:
time-sheets
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Time Sheets

Plugin:
Time Sheets
Plugin Slug:
time-sheets
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TR Timthumb

Plugin:
TR Timthumb
Plugin Slug:
tr-timthumb
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Trail Manager

Plugin:
Trail Manager
Plugin Slug:
trail-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Twitscription

Plugin:
Twitscription
Plugin Slug:
twitscription
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultra Skype Button

Plugin:
Ultra Skype Button
Plugin Slug:
ultra-skype-button
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Generator and Importer

Plugin:
User Generator and Importer
Plugin Slug:
user-importer-and-generator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Verification

Plugin:
User Verification
Plugin Slug:
user-verification
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Voidek Employee Portal

Plugin:
Voidek Employee Portal
Plugin Slug:
voidek-employee-portal
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WebP Express

Plugin:
WebP Express
Plugin Slug:
webp-express
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Weekly Planner

Plugin:
Weekly Planner
Plugin Slug:
weekly-planner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:
Live Sales Notification for Woocommerce – Woomotiv
Plugin Slug:
woomotiv
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Landing Page

Plugin:
WP Landing Page
Plugin Slug:
wp-landing-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-SOS-Donate

Plugin:
WP-SOS-Donate
Plugin Slug:
wp-sos-donate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Yet Another WebClap for WordPress

Plugin:
Yet Another WebClap for WordPress
Plugin Slug:
yet-another-webclap-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Post Type UI

Plugin Slug:
custom-post-type-ui
Installations
1,000,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.18.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.18.1.

Autoptimize

Plugin Slug:
autoptimize
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.14.

Widgets for Google Reviews

Plugin Slug:
wp-reviews-plugin-for-google
Installations
800,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
13.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 13.2.5.

PDF Invoices & Packing Slips for WooCommerce

Plugin Slug:
woocommerce-pdf-invoices-packing-slips
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Advanced Custom Fields: Extended

Plugin Slug:
acf-extended
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
0.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.9.2.

Backup Migration

Plugin Slug:
backup-backup
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.1.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.1.

Kadence WooCommerce Email Designer

Plugin Slug:
kadence-woocommerce-email-designer
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.18.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.3.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.3.

Rich Shortcodes for Google Reviews

Plugin Slug:
widget-google-reviews
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.8.1.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.3.

WP 2FA – Two-factor authentication for WordPress

Plugin Slug:
wp-2fa
Installations
90,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Wp Social Login and Register Social Counter

Plugin Slug:
wp-social
Installations
60,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.13.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.1.3.

Cost Calculator Builder

Plugin Slug:
cost-calculator-builder
Installations
30,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.4.

Envo Extra

Plugin:
Envo Extra
Plugin Slug:
envo-extra
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.12.

Timetable and Event Schedule by MotoPress

Plugin Slug:
mp-timetable
Installations
30,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.4.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.16.
Plugin Slug:
all-in-one-video-gallery
Installations
20,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.6.4.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.7.0.83
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.83.

Visualizer: Tables and Charts Manager for WordPress

Plugin Slug:
visualizer
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
3.11.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.11.13.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.28.21
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.28.21.

Nexter Extension – Site Enhancements Toolkit

Plugin Slug:
nexter-extension
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.2.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.20.

GSheetConnector For WPForms

Plugin Slug:
gsheetconnector-wpforms
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.1.

Event Booking Manager for WooCommerce

Plugin Slug:
mage-eventpress
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.5.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.

Chartify – WordPress Chart Plugin

Plugin Slug:
chart-builder
Installations
4,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.4.

SMS Alert Order Notifications – WooCommerce

Plugin Slug:
sms-alert
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.9.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.5.

Salon Booking System – Free Version

Plugin Slug:
salon-booking-system
Installations
3,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.30.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.30.4.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.4.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.5.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.7.

Advanced FAQ Manager

Plugin Slug:
advanced-faq-manager
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Auto Alt Text

Plugin Slug:
auto-alt-text
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

CSSIgniter Shortcodes

Plugin Slug:
cssigniter-shortcodes
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.
Plugin Slug:
gallery-photo-gallery
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.9.

PDF Thumbnail Generator

Plugin Slug:
pdf-thumbnail-generator
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

Portfolio and Projects

Plugin Slug:
portfolio-and-projects
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Tableberg – Simple Gutenberg Table Block

Plugin Slug:
tableberg
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.6.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.10.

Email Marketing Plugin – WP Email Capture

Plugin Slug:
wp-email-capture
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.12.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.5.

Constant Contact + WooCommerce

Plugin Slug:
constant-contact-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

MxChat – AI Chatbot for WordPress

Plugin Slug:
mxchat-basic
Installations
900+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

My Tickets – Accessible Event Ticketing

Plugin Slug:
my-tickets
Installations
700+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
600+
Vulnerability:
Local File Inclusion
Patched in Version:
3.6.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.33.

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
3.6.33
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.33.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.3.

Zigaform – Price Calculator & Cost Estimation Form Builder Lite

Plugin Slug:
zigaform-calculator-cost-estimation-form-builder-lite
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.7.

TAX SERVICE Electronic HDM

Plugin Slug:
virtual-hdm-for-taxservice-am
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.1.

DesignThemes LMS

Plugin:
DesignThemes LMS
Plugin Slug:
designthemes-lms
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.

FindAll Listing

Plugin:
FindAll Listing
Plugin Slug:
findall-listing
Vulnerability:
Privilege Escalation
Patched in Version:
1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.
Plugin:
JNews Gallery
Plugin Slug:
jnews-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
12.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.0.1.

JNews Paywall

Plugin:
JNews Paywall
Plugin Slug:
jnews-paywall
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
12.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 12.0.1.

StreamTube Core

Plugin:
StreamTube Core
Plugin Slug:
streamtube-core
Vulnerability:
Broken Authentication
Patched in Version:
4.79
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.79.

Upload.am – File Hosting & VPN

Plugin Slug:
upload-am-file-hosting-vpn
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

WordPress Themes — 2 Patched / 0 Unpatched

AdForest

Theme:
AdForest
Theme Slug:
adforest
Vulnerability:
Broken Access Control
Patched in Version:
6.0.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.12.

Rehub

Theme:
Rehub
Theme Slug:
rehub-theme
Vulnerability:
Sensitive Data Exposure
Patched in Version:
19.9.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 19.9.9.2.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security