WordPress Vulnerability Report

WordPress Vulnerability Report — December 24, 2025

Since last week, 150 new vulnerabilities have emerged in the WordPress ecosystem, including 140 plugins and 10 themes. Of those, 26 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 150 vulnerabilities have been publicly disclosed. Security patches for 124 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 26 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 114 Patched / 26 Unpatched

Health Check & Troubleshooting

Plugin Slug:
health-check
Installations
300,000+
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WCFM Marketplace – Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Doubly – Cross Domain Copy Paste for WordPress

Plugin Slug:
doubly
Installations
10,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Read More & Accordion

Plugin Slug:
expand-maker
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Protect WP Admin

Plugin Slug:
protect-wp-admin
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pretty Google Calendar

Plugin Slug:
pretty-google-calendar
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meks Quick Plugin Disabler

Plugin Slug:
meks-quick-plugin-disabler
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Semrush Content Toolkit

Plugin Slug:
semrush-contentshake
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yaad Sarig Payment Gateway For WC

Plugin Slug:
yaad-sarig-payment-gateway-for-wc
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FAPI Member

Plugin Slug:
fapi-member
Installations
500+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JAY Login & Register

Plugin Slug:
jay-login-register
Installations
40+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Amazon affiliate lite

Plugin:
Amazon affiliate lite
Plugin Slug:
afiliados-de-amazon-lite
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Amazon affiliate lite

Plugin:
Amazon affiliate lite
Plugin Slug:
afiliados-de-amazon-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener

Plugin:
URL Shortener
Plugin Slug:
exact-links
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

F70 Lead Document Download

Plugin:
F70 Lead Document Download
Plugin Slug:
f70-lead-document-download
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HelloLeads CRM Form Shortcode

Plugin:
HelloLeads CRM Form Shortcode
Plugin Slug:
hls-crm-form-shortcode
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

?????? ????? ??????? ??? ???? ?? (????) payamito sms woocommerce

Plugin:
?????? ????? ??????? ??? ???? ?? (????) payamito sms woocommerce
Plugin Slug:
payamito-sms-woocommerce
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Postem Ipsum

Plugin:
Postem Ipsum
Plugin Slug:
postem-ipsum
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quran Gateway

Plugin:
Quran Gateway
Plugin Slug:
quran-gateway
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RESPONSIVE AND SWIPE SLIDER!

Plugin:
RESPONSIVE AND SWIPE SLIDER!
Plugin Slug:
responsive-and-swipe-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooMulti

Plugin:
WooMulti
Plugin Slug:
woomulti
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP DB Booster

Plugin:
WP DB Booster
Plugin Slug:
wp-db-booster
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP3D Model Import Viewer

Plugin:
WP3D Model Import Viewer
Plugin Slug:
wp3d-model-import-block
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPS Visitor Counter

Plugin:
WPS Visitor Counter
Plugin Slug:
wps-visitor-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.4.3.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.4.

Newsletter – Send awesome emails from WordPress

Plugin Slug:
newsletter
Installations
300,000+
Vulnerability:
SQL Injection
Patched in Version:
9.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.0.

Admin and Site Enhancements (ASE)

Plugin Slug:
admin-site-enhancements
Installations
200,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.1.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 8.1.0.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.14.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.4.

FiboSearch – Ajax Search for WooCommerce

Plugin Slug:
ajax-search-for-woocommerce
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.32.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.32.1.

Prime Slider – Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.4.2.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.358
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.358.

Login Lockdown & Protection

Plugin Slug:
login-lockdown
Installations
100,000+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.4.

HUSKY – Products Filter Professional for WooCommerce

Plugin Slug:
woocommerce-products-filter
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.3.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.4.

Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN

Plugin Slug:
hummingbird-performance
Installations
80,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.18.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.18.1.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
5.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.4.

OneSignal – Web Push Notifications

Plugin Slug:
onesignal-free-web-push-notifications
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.2.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.3.

Events Manager – Calendar, Bookings, Tickets, and more!

Plugin Slug:
events-manager
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.2.3.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.7.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.2.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
SQL Injection
Patched in Version:
10.14.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 10.14.9.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.4.

Download Plugins and Themes in ZIP from Dashboard

Plugin Slug:
download-plugins-dashboard
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.7.

Themify Portfolio Post

Plugin Slug:
themify-portfolio-post
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.1.

MailerLite – WooCommerce integration

Plugin Slug:
woo-mailerlite
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.
Plugin Slug:
final-tiles-grid-gallery-lite
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.8.

My Calendar – Accessible Event Manager

Plugin Slug:
my-calendar
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.17.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
SQL Injection
Patched in Version:
2.4.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.4.13.

BA Book Everything

Plugin Slug:
ba-book-everything
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.15.

CC Child Pages

Plugin Slug:
cc-child-pages
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

OpenID Connect Generic Client

Plugin Slug:
daggerhart-openid-connect-generic
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.1.

Demo Importer Plus

Plugin Slug:
demo-importer-plus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.9.

HandL UTM Grabber / Tracker

Plugin Slug:
handl-utm-grabber
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.1.

HTML Forms – Simple WordPress Forms Plugin

Plugin Slug:
html-forms
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.1.

JetWidgets For Elementor

Plugin Slug:
jetwidgets-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.21.

Lightweight Accordion

Plugin Slug:
lightweight-accordion
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

Live Composer – Free WordPress Website Builder

Plugin Slug:
live-composer-page-builder
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.16.

WP-ShowHide

Plugin Slug:
wp-showhide
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.06
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.06.

Multi-Step Checkout for WooCommerce

Plugin Slug:
wp-multi-step-checkout
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.34
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.34.

Social Media Auto Publish

Plugin Slug:
social-media-auto-publish
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.6.6.

Calendar

Plugin:
Calendar
Plugin Slug:
calendar
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.17.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.31.

Watu Quiz

Plugin:
Watu Quiz
Plugin Slug:
watu
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.1.

Filter & Grids

Plugin Slug:
ymc-smart-filter
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.1.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Document Library Lite

Plugin Slug:
document-library-lite
Installations
3,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.0.

Sitewide Notice WP

Plugin Slug:
sitewide-notice-wp
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
1.4.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.8.

UseStrict’s Calendly Embedder

Plugin Slug:
cal-embedder-lite
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.
Plugin Slug:
simple-link-directory
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.4.
Plugin Slug:
simple-link-directory
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
8.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.8.4.

VK Google Job Posting Manager

Plugin Slug:
vk-google-job-posting-manager
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.23.

CWW Companion

Plugin Slug:
cww-companion
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

WP to LinkedIn Auto Publish

Plugin Slug:
linkedin-auto-publish
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.9.

WPCOM Member

Plugin Slug:
wpcom-member
Installations
1,000+
Vulnerability:
Broken Authentication
Patched in Version:
1.7.17
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.17.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.3.204
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.204.

Highlight and Share – Social Text and Image Sharing

Plugin Slug:
highlight-and-share
Installations
900+
Vulnerability:
Broken Access Control
Patched in Version:
5.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.0.

WP eBay Product Feeds

Plugin Slug:
ebay-feeds-for-wordpress
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.4.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.10.

Appointment Booking and Scheduler Plugin – Truebooker

Plugin Slug:
truebooker-appointment-booking
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Easy Invoice – PDF Invoice Generator & Quote Builder

Plugin Slug:
easy-invoice
Installations
500+
Vulnerability:
Local File Inclusion
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

Wbcom Designs – Private Community for BuddyPress

Plugin Slug:
lock-my-bp
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.2.

Rencontre – Dating Site

Plugin Slug:
rencontre
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.13.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.8.

Sweet Energy Efficiency

Plugin Slug:
sweet-energy-efficiency
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.7.

Fox LMS – WordPress LMS Plugin

Plugin Slug:
fox-lms
Installations
40+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.5.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.5.2.

Simple Folio

Plugin Slug:
simple-folio
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

Dokan Pro

Plugin:
Dokan Pro
Plugin Slug:
dokan-pro
Vulnerability:
Broken Access Control
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.0.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.0.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Sensitive Data Exposure
Patched in Version:
6.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.0.

Image Caption Hover Pro

Plugin:
Image Caption Hover Pro
Plugin Slug:
image-caption-hover-pro
Vulnerability:
Broken Access Control
Patched in Version:
20.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20.0.

ModelTheme Addons for WPBakery and Elementor

Plugin:
ModelTheme Addons for WPBakery and Elementor
Plugin Slug:
modeltheme-addons-for-wpbakery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Broken Access Control
Patched in Version:
16.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 16.9.

WordPress Themes — 10 Patched / 0 Unpatched

Besa

Theme:
Besa
Theme Slug:
besa
Vulnerability:
Local File Inclusion
Patched in Version:
2.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.16.

ekommart

Theme:
ekommart
Theme Slug:
ekommart
Vulnerability:
Local File Inclusion
Patched in Version:
4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.1.

Fashion

Theme:
Fashion
Theme Slug:
fashion2
Vulnerability:
Local File Inclusion
Patched in Version:
5.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.0.

Hara

Theme:
Hara
Theme Slug:
hara
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.18.

Kerge

Theme:
Kerge
Theme Slug:
kerge
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.4.

Sailing

Theme:
Sailing
Theme Slug:
sailing
Vulnerability:
Broken Access Control
Patched in Version:
4.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.6.

Sailing

Theme:
Sailing
Theme Slug:
sailing
Vulnerability:
Local File Inclusion
Patched in Version:
4.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.4.6.

Sober

Theme:
Sober
Theme Slug:
sober
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.5.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.12.

Urna

Theme:
Urna
Theme Slug:
urna
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.13.

Wilmër

Theme:
Wilmër
Theme Slug:
wilmer
Vulnerability:
Local File Inclusion
Patched in Version:
3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security