WordPress Vulnerability Report

WordPress Vulnerability Report — December 31, 2025

Since last week, 139 new vulnerabilities have emerged in the WordPress ecosystem, including 130 plugins and 9 themes. Of those, 73 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 139 vulnerabilities have been publicly disclosed. Security patches for 66 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 73 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.

Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 62 Patched / 68 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crowdsignal Forms

Plugin Slug:
crowdsignal-forms
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Comments – wpDiscuz

Plugin Slug:
wpdiscuz
Installations
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field Template

Plugin Slug:
custom-field-template
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Event Organiser

Plugin Slug:
event-organiser
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accept Donations with PayPal & Stripe

Plugin Slug:
easy-paypal-donation
Installations
10,000+
Vulnerability:
Open Redirection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-library
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Five Star Restaurant Reservations – WordPress Booking Plugin

Plugin Slug:
restaurant-reservations
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Widgets for Social Photo Feed

Plugin Slug:
social-photo-feed-widget
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themebeez Toolkit

Plugin Slug:
themebeez-toolkit
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog Filter Post Filtering

Plugin Slug:
blog-filter
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Poll, Survey & Quiz Maker Plugin by Opinion Stage

Plugin Slug:
social-polls-by-opinionstage
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple File List

Plugin Slug:
simple-file-list
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wptelegram-widget
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
custom-related-posts
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cooked – Recipe Management

Plugin Slug:
cooked
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Plugin Slug:
wallet-system-for-woocommerce
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fast User Switching

Plugin Slug:
fast-user-switching
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FlippingBook

Plugin Slug:
flippingbook
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletters

Plugin Slug:
newsletters-lite
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Discussion Board – WordPress Forum Plugin

Plugin Slug:
wp-discussion-board
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YITH Slider for page builders

Plugin Slug:
yith-slider-for-page-builders
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GLS Shipping for WooCommerce

Plugin Slug:
gls-shipping-for-woocommerce
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Heateor Social Login WordPress

Plugin Slug:
heateor-social-login
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Netgsm

Plugin:
Netgsm
Plugin Slug:
netgsm
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Delivery Date for WooCommerce – Lite

Plugin Slug:
product-delivery-date-for-woocommerce-lite
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RestroPress – Online Food Ordering System

Plugin Slug:
restropress
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slider Templates

Plugin Slug:
slider-templates
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booking Ultra Pro Appointments Booking Calendar Plugin

Plugin Slug:
booking-ultra-pro
Installations
500+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HR Management Lite

Plugin Slug:
hr-management-lite
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AM Events

Plugin:
AM Events
Plugin Slug:
am-events
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

File Uploader for WooCommerce

Plugin Slug:
file-uploader-for-woocommerce
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Gift Hunt

Plugin:
Gift Hunt
Plugin Slug:
gift-hunt
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Inboxify Sign Up Form

Plugin Slug:
inboxify-sign-up-form
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mobile builder

Plugin Slug:
mobile-builder
Installations
100+
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Popping Sidebars and Widgets Light

Plugin Slug:
popping-sidebars-and-widgets-light
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CookieHint WP

Plugin Slug:
cookiehint-wp
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Flaming Password Reset

Plugin Slug:
flaming-password-reset
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wp Text Slider Widget

Plugin Slug:
wp-text-slider-widget
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Custom CSS

Plugin Slug:
advanced-custom-css
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CedCommerce Integration for Good Market

Plugin Slug:
ced-good-market-integration
Installations
60+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Content Grid Slider

Plugin Slug:
content-grid-slider
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PRIMER by chloédigital

Plugin Slug:
primer-by-chloedigital
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Visitor Stats Widget

Plugin Slug:
visitor-stats-widget
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Invelity SPS connect

Plugin Slug:
invelity-sps-connect
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Scroll rss excerpt

Plugin Slug:
scroll-rss-excerpt
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP App Bar

Plugin:
WP App Bar
Plugin Slug:
wp-app-bar
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

IF AS Shortcode

Plugin Slug:
if-as-shortcode
Installations
10+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Attachments Handler

Plugin:
Attachments Handler
Plugin Slug:
attachments-handler
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cool Tag Cloud

Plugin:
Cool Tag Cloud
Plugin Slug:
cool-tag-cloud
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flex Store Users

Plugin:
Flex Store Users
Plugin Slug:
flex-store-user
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Overstock Affiliate Links
Plugin Slug:
overstock-affiliate-links
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Product Loops for WooCommerce

Plugin:
Product Loops for WooCommerce
Plugin Slug:
product-loops
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Responsive Posts Carousel Pro
Plugin Slug:
responsive-posts-carousel-pro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Share, Print and PDF Products for WooCommerce

Plugin:
Share, Print and PDF Products for WooCommerce
Plugin Slug:
share-print-pdf-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Slider

Plugin:
Testimonial Slider
Plugin Slug:
testimonial
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Userpro

Plugin:
Userpro
Plugin Slug:
userpro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooMulti

Plugin:
WooMulti
Plugin Slug:
woomulti
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Hallo Welt

Plugin:
WP Hallo Welt
Plugin Slug:
wp-hallo-welt
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin Slug:
woocommerce
Installations
7,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.4.3.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
11.1.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 11.1.5.1.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.4.

Astra Widgets

Plugin Slug:
astra-widgets
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.17.

Advanced Ads – Ad Manager & AdSense

Plugin Slug:
advanced-ads
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.0.15
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.15.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.9.4.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.4.2.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.13.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.13.2.

Interactive Content – H5P

Plugin Slug:
h5p
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.16.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.16.2.

Stratum Widgets for Elementor

Plugin Slug:
stratum
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes
Installations
30,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
5.9.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.9.0.

Docket Cache – Object Cache Accelerator

Plugin Slug:
docket-cache
Installations
20,000+
Vulnerability:
Local File Inclusion
Patched in Version:
24.07.04
Severity Score:
High
The vulnerability has been patched, so you should update to version 24.07.04.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Ocean Modal Window

Plugin Slug:
ocean-modal-window
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.3.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.3.

PhastPress

Plugin:
PhastPress
Plugin Slug:
phastpress
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

Plugin Organizer

Plugin Slug:
plugin-organizer
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
10.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.2.4.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.16.

YaMaps for WordPress Plugin

Plugin Slug:
yamaps
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.6.40
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.6.40.

Brands for WooCommerce

Plugin Slug:
brands-for-woocommerce
Installations
6,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.6.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.6.4.

Calendar

Plugin:
Calendar
Plugin Slug:
calendar
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.17.

CubeWP Framework

Plugin Slug:
cubewp-framework
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.28
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.28.

Advanced Classifieds & Directory Pro

Plugin Slug:
advanced-classifieds-and-directory-pro
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.0.

Category Icon

Plugin Slug:
category-icon
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.
Plugin Slug:
codeflavors-vimeo-video-post-lite
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.6.

FV Simpler SEO

Plugin Slug:
fv-all-in-one-seo-pack
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.7.

Combo Offers WooCommerce

Plugin Slug:
woo-combo-offers
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.

WP Document Revisions

Plugin Slug:
wp-document-revisions
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.8.0
Severity Score:
Low
The vulnerability has been patched, so you should update to version 3.8.0.

MapSVG – Vector maps, Image maps, Google Maps

Plugin Slug:
mapsvg-lite-interactive-vector-maps
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
8.7.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.7.4.

SALESmanago & Leadoo

Plugin Slug:
salesmanago
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.1.

WC Builder – WooCommerce Page Builder for WPBakery

Plugin Slug:
wc-builder
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

ContentStudio

Plugin Slug:
contentstudio
Installations
900+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.4.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.0.

Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Dripping

Plugin Slug:
membership-for-woocommerce
Installations
900+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.0.4.

Web Directory Free

Plugin Slug:
web-directory-free
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.13.

WPBulky – WordPress Bulk Edit Post Types

Plugin Slug:
wpbulky-wp-bulk-edit-post-types
Installations
300+
Vulnerability:
SQL Injection
Patched in Version:
1.1.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.14.

Chakra test

Plugin Slug:
chakra-test
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

HAPPY – Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.10.

Gravity Forms

Plugin:
Gravity Forms
Plugin Slug:
gravityforms
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.23.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.23.1.

JetBlog

Plugin:
JetBlog
Plugin Slug:
jet-blog
Vulnerability:
Broken Access Control
Patched in Version:
2.4.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.1.

JetPopup

Plugin:
JetPopup
Plugin Slug:
jet-popup
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.0.20.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.20.2.

JetSearch

Plugin:
JetSearch
Plugin Slug:
jet-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.16.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.16.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.1.

JetTabs

Plugin:
JetTabs
Plugin Slug:
jet-tabs
Vulnerability:
Broken Access Control
Patched in Version:
2.2.12.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.12.1.
Plugin:
Responsive Posts Carousel Pro
Plugin Slug:
responsive-posts-carousel-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
15.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 15.3.

WordPress Themes — 4 Patched / 5 Unpatched

Arcane

Theme:
Arcane
Theme Slug:
arcane
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Backpack Traveler

Theme:
Backpack Traveler
Theme Slug:
backpacktraveler
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

FiveStar

Theme:
FiveStar
Theme Slug:
fivestar
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Medicalequipment

Theme:
Medicalequipment
Theme Slug:
medicalequipment
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Struktur

Theme:
Struktur
Theme Slug:
struktur
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Diza

Theme:
Diza
Theme Slug:
diza
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.16.

Fana

Theme:
Fana
Theme Slug:
fana
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.36
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.36.

Nika

Theme:
Nika
Theme Slug:
nika
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.15.

Zota

Theme:
Zota
Theme Slug:
zota
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.15.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security