In this report, 139 vulnerabilities have been publicly disclosed. Security patches for 66 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Currently, 73 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.9 “Gene” was released on December 2, 2025. This release brings major upgrades to how teams collaborate and create. The new Notes feature adds block-level commenting for posts and pages, streamlining editorial reviews, while an expanded Command Palette helps power users navigate and operate across the dashboard even faster. The introduction of the Abilities API delivers a standardized, machine-readable permissions system that lays the groundwork for next-generation AI-powered and automated workflows. WordPress 6.9 also includes notable performance improvements for faster page loads, several new practical blocks, and more visual drag-and-drop tools to help creators build richer, more dynamic content.
Following a major release, you should not update live sites without first taking backups and testing the update in a non-production environment.
WordPress Plugins — 62 Patched / 68 Unpatched
Shortcodes and extra features for Phlox theme
- Plugin Slug:
- auxin-elements
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69016
Crowdsignal Forms
- Plugin:
- Crowdsignal Forms
- Plugin Slug:
- crowdsignal-forms
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Low
- CVE:
- 2025-69015
Comments – wpDiscuz
- Plugin:
- Comments – wpDiscuz
- Plugin Slug:
- wpdiscuz
- Installations
- 80,000+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68997
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin:
- Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers
- Plugin Slug:
- popup-builder-block
- Installations
- 40,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69026
Custom Field Template
- Plugin:
- Custom Field Template
- Plugin Slug:
- custom-field-template
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68607
Event Organiser
- Plugin:
- Event Organiser
- Plugin Slug:
- event-organiser
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69012
Accept Donations with PayPal & Stripe
- Plugin Slug:
- easy-paypal-donation
- Installations
- 10,000+
- Vulnerability:
- Open Redirection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68602
Link Library
- Plugin:
- Link Library
- Plugin Slug:
- link-library
- Installations
- 10,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68600
Five Star Restaurant Reservations – WordPress Booking Plugin
- Plugin Slug:
- restaurant-reservations
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68601
Widgets for Social Photo Feed
- Plugin:
- Widgets for Social Photo Feed
- Plugin Slug:
- social-photo-feed-widget
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68595
Themebeez Toolkit
- Plugin:
- Themebeez Toolkit
- Plugin Slug:
- themebeez-toolkit
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69010
Blog Filter Post Filtering
- Plugin:
- Blog Filter Post Filtering
- Plugin Slug:
- blog-filter
- Installations
- 8,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69033
Poll, Survey & Quiz Maker Plugin by Opinion Stage
- Plugin Slug:
- social-polls-by-opinionstage
- Installations
- 7,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68594
Project Manager – AI-Powered Project & Task Manager with Kanban Board & Gantt Chart
- Plugin Slug:
- wedevs-project-manager
- Installations
- 7,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68040
Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin:
- Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
- Plugin Slug:
- youzify
- Installations
- 6,000+
- Vulnerability:
- Server Side Request Forgery (SSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69014
Simple File List
- Plugin:
- Simple File List
- Plugin Slug:
- simple-file-list
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68591
WP Telegram Widget and Join Link
- Plugin:
- WP Telegram Widget and Join Link
- Plugin Slug:
- wptelegram-widget
- Installations
- 5,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68589
Custom Related Posts
- Plugin:
- Custom Related Posts
- Plugin Slug:
- custom-related-posts
- Installations
- 4,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68033
TS Poll – Survey, Versus Poll, Image Poll, Video Poll
- Plugin Slug:
- poll-wp
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68588
Cooked – Recipe Management
- Plugin:
- Cooked – Recipe Management
- Plugin Slug:
- cooked
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68586
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments
- Plugin Slug:
- wallet-system-for-woocommerce
- Installations
- 3,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68029
Fast User Switching
- Plugin:
- Fast User Switching
- Plugin Slug:
- fast-user-switching
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68583
FlippingBook
- Plugin:
- FlippingBook
- Plugin Slug:
- flippingbook
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69019
Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
- Plugin:
- Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free
- Plugin Slug:
- funnelforms-free
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68582
Newsletters
- Plugin:
- Newsletters
- Plugin Slug:
- newsletters-lite
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69020
Discussion Board – WordPress Forum Plugin
- Plugin Slug:
- wp-discussion-board
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69023
YITH Slider for page builders
- Plugin:
- YITH Slider for page builders
- Plugin Slug:
- yith-slider-for-page-builders
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68581
BBP Core – Advanced bbPress Forum Management with Voting, Private Replies & Elementor
- Plugin Slug:
- bbp-core
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68572
GLS Shipping for WooCommerce
- Plugin:
- GLS Shipping for WooCommerce
- Plugin Slug:
- gls-shipping-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68011
Heateor Social Login WordPress
- Plugin:
- Heateor Social Login WordPress
- Plugin Slug:
- heateor-social-login
- Installations
- 1,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68998
Netgsm
- Plugin:
- Netgsm
- Plugin Slug:
- netgsm
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68010
Product Delivery Date for WooCommerce – Lite
- Plugin Slug:
- product-delivery-date-for-woocommerce-lite
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69027
RestroPress – Online Food Ordering System
- Plugin Slug:
- restropress
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69017
Slider Templates
- Plugin:
- Slider Templates
- Plugin Slug:
- slider-templates
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68009
Booking Ultra Pro Appointments Booking Calendar Plugin
- Plugin Slug:
- booking-ultra-pro
- Installations
- 500+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68006
HR Management Lite
- Plugin:
- HR Management Lite
- Plugin Slug:
- hr-management-lite
- Installations
- 300+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69022
AM Events
- Plugin:
- AM Events
- Plugin Slug:
- am-events
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69006
File Uploader for WooCommerce
- Plugin:
- File Uploader for WooCommerce
- Plugin Slug:
- file-uploader-for-woocommerce
- Installations
- 100+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-13329
Gift Hunt
- Plugin:
- Gift Hunt
- Plugin Slug:
- gift-hunt
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-67631
Inboxify Sign Up Form
- Plugin:
- Inboxify Sign Up Form
- Plugin Slug:
- inboxify-sign-up-form
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69008
Mobile builder
- Plugin:
- Mobile builder
- Plugin Slug:
- mobile-builder
- Installations
- 100+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-68860
Popping Sidebars and Widgets Light
- Plugin Slug:
- popping-sidebars-and-widgets-light
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69007
Plugin Optimizer – Speed Up Your WordPress Like Never Before
- Plugin Slug:
- plugin-optimizer
- Installations
- 80+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68861
CookieHint WP
- Plugin:
- CookieHint WP
- Plugin Slug:
- cookiehint-wp
- Installations
- 70+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68870
Flaming Password Reset
- Plugin:
- Flaming Password Reset
- Plugin Slug:
- flaming-password-reset
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68875
Wp Text Slider Widget
- Plugin:
- Wp Text Slider Widget
- Plugin Slug:
- wp-text-slider-widget
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68868
Advanced Custom CSS
- Plugin:
- Advanced Custom CSS
- Plugin Slug:
- advanced-custom-css
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68878
CedCommerce Integration for Good Market
- Plugin Slug:
- ced-good-market-integration
- Installations
- 60+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68877
Content Grid Slider
- Plugin:
- Content Grid Slider
- Plugin Slug:
- content-grid-slider
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68879
PRIMER by chloédigital
- Plugin:
- PRIMER by chloédigital
- Plugin Slug:
- primer-by-chloedigital
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68873
Visitor Stats Widget
- Plugin:
- Visitor Stats Widget
- Plugin Slug:
- visitor-stats-widget
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68874
Invelity SPS connect
- Plugin:
- Invelity SPS connect
- Plugin Slug:
- invelity-sps-connect
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68876
Scroll rss excerpt
- Plugin:
- Scroll rss excerpt
- Plugin Slug:
- scroll-rss-excerpt
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68892
WP App Bar
- Plugin:
- WP App Bar
- Plugin Slug:
- wp-app-bar
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68891
IF AS Shortcode
- Plugin:
- IF AS Shortcode
- Plugin Slug:
- if-as-shortcode
- Installations
- 10+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-68897
Attachments Handler
- Plugin:
- Attachments Handler
- Plugin Slug:
- attachments-handler
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12581
Cool Tag Cloud
- Plugin:
- Cool Tag Cloud
- Plugin Slug:
- cool-tag-cloud
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69011
Flex Store Users
- Plugin:
- Flex Store Users
- Plugin Slug:
- flex-store-user
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-13619
Overstock Affiliate Links
- Plugin:
- Overstock Affiliate Links
- Plugin Slug:
- overstock-affiliate-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-13624
Product Loops for WooCommerce
- Plugin:
- Product Loops for WooCommerce
- Plugin Slug:
- product-loops
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68994
Responsive Posts Carousel Pro
- Plugin:
- Responsive Posts Carousel Pro
- Plugin Slug:
- responsive-posts-carousel-pro
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68996
Share, Print and PDF Products for WooCommerce
- Plugin:
- Share, Print and PDF Products for WooCommerce
- Plugin Slug:
- share-print-pdf-woocommerce
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68993
Testimonial Slider
- Plugin:
- Testimonial Slider
- Plugin Slug:
- testimonial
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-68000
Userpro
- Plugin:
- Userpro
- Plugin Slug:
- userpro
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-68608
WooMulti
- Plugin:
- WooMulti
- Plugin Slug:
- woomulti
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-12835
WP Hallo Welt
- Plugin:
- WP Hallo Welt
- Plugin Slug:
- wp-hallo-welt
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-13365
WP JobHunt
- Plugin:
- WP JobHunt
- Plugin Slug:
- wp-jobhunt
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-7733
WP JobHunt
- Plugin:
- WP JobHunt
- Plugin Slug:
- wp-jobhunt
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-7782
WooCommerce
- Plugin:
- WooCommerce
- Plugin Slug:
- woocommerce
- Installations
- 7,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 10.4.3
- Severity Score:
- Medium
- CVE:
- 2025-15033
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
- Plugin Slug:
- premium-addons-for-elementor
- Installations
- 700,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.11.54
- Severity Score:
- Medium
- CVE:
- 2025-14163
PixelYourSite – Your smart PIXEL (TAG) & API Manager
- Plugin Slug:
- pixelyoursite
- Installations
- 500,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 11.1.5.1
- Severity Score:
- Medium
- CVE:
- 2025-14280
Happy Addons for Elementor
- Plugin:
- Happy Addons for Elementor
- Plugin Slug:
- happy-elementor-addons
- Installations
- 400,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.20.4
- Severity Score:
- Medium
- CVE:
- 2025-14635
Astra Widgets
- Plugin:
- Astra Widgets
- Plugin Slug:
- astra-widgets
- Installations
- 200,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.17
- Severity Score:
- Medium
- CVE:
- 2025-68497
User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
- Plugin Slug:
- userfeedback-lite
- Installations
- 200,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.10.1
- Severity Score:
- High
- CVE:
- 2025-68496
Advanced Ads – Ad Manager & AdSense
- Plugin Slug:
- advanced-ads
- Installations
- 100,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 2.0.15
- Severity Score:
- Critical
- CVE:
- 2025-13592
Beaver Builder Page Builder – Drag and Drop Website Builder
- Plugin Slug:
- beaver-builder-lite-version
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.9.4.2
- Severity Score:
- High
- CVE:
- 2025-12934
GiveWP – Donation Plugin and Fundraising Platform
- Plugin Slug:
- give
- Installations
- 100,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 4.13.2
- Severity Score:
- Medium
- CVE:
- 2025-67467
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups
- Plugin Slug:
- ays-popup-box
- Installations
- 50,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.0.8
- Severity Score:
- Medium
- CVE:
- 2025-69021
Interactive Content – H5P
- Plugin:
- Interactive Content – H5P
- Plugin Slug:
- h5p
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.16.2
- Severity Score:
- Medium
- CVE:
- 2025-68505
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
- Plugin Slug:
- mystickyelements
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.3.4
- Severity Score:
- Medium
- CVE:
- 2025-68995
Stratum Widgets for Elementor
- Plugin:
- Stratum Widgets for Elementor
- Plugin Slug:
- stratum
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.2
- Severity Score:
- Medium
- CVE:
- 2025-69013
Print Invoice & Delivery Notes for WooCommerce
- Plugin Slug:
- woocommerce-delivery-notes
- Installations
- 30,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 5.9.0
- Severity Score:
- Critical
- CVE:
- 2025-13773
Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content
- Plugin:
- Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content
- Plugin Slug:
- brave-popup-builder
- Installations
- 20,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 0.8.4
- Severity Score:
- Medium
- CVE:
- 2025-68508
Docket Cache – Object Cache Accelerator
- Plugin Slug:
- docket-cache
- Installations
- 20,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 24.07.04
- Severity Score:
- High
- CVE:
- 2025-68506
Bold Timeline Lite
- Plugin:
- Bold Timeline Lite
- Plugin Slug:
- bold-timeline-lite
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.8
- Severity Score:
- Medium
- CVE:
- 2025-68513
Ocean Modal Window
- Plugin:
- Ocean Modal Window
- Plugin Slug:
- ocean-modal-window
- Installations
- 10,000+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- 2.3.3
- Severity Score:
- Critical
- CVE:
- 2025-13307
PhastPress
- Plugin:
- PhastPress
- Plugin Slug:
- phastpress
- Installations
- 10,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 3.8
- Severity Score:
- High
- CVE:
- 2025-14388
Plugin Organizer
- Plugin:
- Plugin Organizer
- Plugin Slug:
- plugin-organizer
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 10.2.4
- Severity Score:
- High
- CVE:
- 2025-13417
Membership Plugin – Restrict Content
- Plugin Slug:
- restrict-content
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.2.16
- Severity Score:
- Medium
- CVE:
- 2025-14000
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress
- Plugin Slug:
- url-shortify
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.11.4
- Severity Score:
- High
- CVE:
- 2025-13355
URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress
- Plugin Slug:
- url-shortify
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.11.3
- Severity Score:
- High
- CVE:
- 2025-12684
weForms – Easy Drag & Drop Contact Form Builder For WordPress
- Plugin Slug:
- weforms
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.6.26
- Severity Score:
- Medium
- CVE:
- 2025-69028
YaMaps for WordPress Plugin
- Plugin:
- YaMaps for WordPress Plugin
- Plugin Slug:
- yamaps
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.6.40
- Severity Score:
- Medium
- CVE:
- 2025-13958
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
- Plugin Slug:
- tablesome
- Installations
- 9,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.35.2
- Severity Score:
- Medium
- CVE:
- 2025-68517
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
- Plugin Slug:
- tablesome
- Installations
- 9,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.1.35.2
- Severity Score:
- Medium
- CVE:
- 2025-68516
Brands for WooCommerce
- Plugin:
- Brands for WooCommerce
- Plugin Slug:
- brands-for-woocommerce
- Installations
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.8.6.4
- Severity Score:
- High
- CVE:
- 2025-68519
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
- Plugin Slug:
- cf7-hubspot
- Installations
- 6,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.4.3
- Severity Score:
- High
- CVE:
- 2025-68590
Calendar
- Plugin:
- Calendar
- Plugin Slug:
- calendar
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.17
- Severity Score:
- Medium
- CVE:
- 2025-14548
CubeWP Framework
- Plugin:
- CubeWP Framework
- Plugin Slug:
- cubewp-framework
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.28
- Severity Score:
- High
- CVE:
- 2025-68036
WpStream – Live Streaming, Video on Demand, Pay Per View
- Plugin Slug:
- wpstream
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.9.6
- Severity Score:
- Medium
- CVE:
- 2025-68522
WpStream – Live Streaming, Video on Demand, Pay Per View
- Plugin Slug:
- wpstream
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.9.6
- Severity Score:
- Medium
- CVE:
- 2025-68521
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution
- Plugin Slug:
- academy
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.4.1
- Severity Score:
- Medium
- CVE:
- 2025-68527
Advanced Classifieds & Directory Pro
- Plugin Slug:
- advanced-classifieds-and-directory-pro
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 3.3.0
- Severity Score:
- Medium
- CVE:
- 2025-68580
Auto Listings – Car Listings & Car Dealership Plugin for WordPress
- Plugin Slug:
- auto-listings
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.2
- Severity Score:
- Medium
- CVE:
- 2025-69089
Category Icon
- Plugin:
- Category Icon
- Plugin Slug:
- category-icon
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.3
- Severity Score:
- Medium
- CVE:
- 2025-68525
Vimeotheque – Vimeo WordPress Plugin & Video Gallery
- Plugin Slug:
- codeflavors-vimeo-video-post-lite
- Installations
- 2,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 2.3.6
- Severity Score:
- Medium
- CVE:
- 2025-68584
Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin
- Plugin Slug:
- frontend-post-submission-manager-lite
- Installations
- 2,000+
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- 1.2.7
- Severity Score:
- Medium
- CVE:
- 2025-14913
FV Simpler SEO
- Plugin:
- FV Simpler SEO
- Plugin Slug:
- fv-all-in-one-seo-pack
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.9.7
- Severity Score:
- Medium
- CVE:
- 2025-68579
Combo Offers WooCommerce
- Plugin:
- Combo Offers WooCommerce
- Plugin Slug:
- woo-combo-offers
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.3
- Severity Score:
- Medium
- CVE:
- 2025-69088
WP Document Revisions
- Plugin:
- WP Document Revisions
- Plugin Slug:
- wp-document-revisions
- Installations
- 2,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.8.0
- Severity Score:
- Low
- CVE:
- 2025-68585
MapSVG – Vector maps, Image maps, Google Maps
- Plugin Slug:
- mapsvg-lite-interactive-vector-maps
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 8.7.4
- Severity Score:
- Critical
- CVE:
- 2025-68562
Poptics – Popup Builder, Email Opt-ins, Exit-Intent & WooCommerce Popups Sales
- Plugin Slug:
- poptics
- Installations
- 1,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.0.21
- Severity Score:
- Medium
- CVE:
- 2025-69025
Print Anywhere & Create PDFs of Order Receipts, Invoices, Labels & More.
- Plugin Slug:
- print-google-cloud-print-gcp-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.7.1
- Severity Score:
- Medium
- CVE:
- 2025-69024
SALESmanago & Leadoo
- Plugin:
- SALESmanago & Leadoo
- Plugin Slug:
- salesmanago
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.9.1
- Severity Score:
- Medium
- CVE:
- 2025-68571
WC Builder – WooCommerce Page Builder for WPBakery
- Plugin Slug:
- wc-builder
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.1
- Severity Score:
- Medium
- CVE:
- 2025-68533
ContentStudio
- Plugin:
- ContentStudio
- Plugin Slug:
- contentstudio
- Installations
- 900+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.4.0
- Severity Score:
- Critical
- CVE:
- 2025-67910
Membership For WooCommerce – WordPress Membership Plugin, Restrict Content, Build Online Communities, Paywall & Content Dripping
- Plugin Slug:
- membership-for-woocommerce
- Installations
- 900+
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 3.0.4
- Severity Score:
- High
- CVE:
- 2025-67909
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress
- Plugin Slug:
- subscribe-to-unlock-lite
- Installations
- 500+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.1
- Severity Score:
- High
- CVE:
- 2025-68563
Web Directory Free
- Plugin:
- Web Directory Free
- Plugin Slug:
- web-directory-free
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.13
- Severity Score:
- Medium
- CVE:
- 2025-69018
VPSUForm – Drag & Drop Contact Form Builder with Email Automation
- Plugin Slug:
- v-form
- Installations
- 300+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 3.2.25
- Severity Score:
- Medium
- CVE:
- 2025-68551
WPBulky – WordPress Bulk Edit Post Types
- Plugin Slug:
- wpbulky-wp-bulk-edit-post-types
- Installations
- 300+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.1.14
- Severity Score:
- High
- CVE:
- 2025-68550
Chakra test
- Plugin:
- Chakra test
- Plugin Slug:
- chakra-test
- Installations
- 10+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.2
- Severity Score:
- Medium
- CVE:
- 2025-68557
HAPPY – Helpdesk Support Ticket System
- Plugin Slug:
- happy-helpdesk-support-ticket-system
- Installations
- 10+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.0.10
- Severity Score:
- Medium
- CVE:
- 2025-68556
Gravity Forms
- Plugin:
- Gravity Forms
- Plugin Slug:
- gravityforms
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 2.9.23.1
- Severity Score:
- Critical
- CVE:
- 2025-13407
JetBlog
- Plugin:
- JetBlog
- Plugin Slug:
- jet-blog
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.7.1
- Severity Score:
- Medium
- CVE:
- 2025-68503
JetPopup
- Plugin:
- JetPopup
- Plugin Slug:
- jet-popup
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- 2.0.20.2
- Severity Score:
- Medium
- CVE:
- 2025-68502
JetSearch
- Plugin:
- JetSearch
- Plugin Slug:
- jet-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.5.16.1
- Severity Score:
- Medium
- CVE:
- 2025-68504
JetTabs
- Plugin:
- JetTabs
- Plugin Slug:
- jet-tabs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.12.1
- Severity Score:
- Medium
- CVE:
- 2025-68499
JetTabs
- Plugin:
- JetTabs
- Plugin Slug:
- jet-tabs
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.2.12.1
- Severity Score:
- Medium
- CVE:
- 2025-68498
Responsive Posts Carousel Pro
- Plugin:
- Responsive Posts Carousel Pro
- Plugin Slug:
- responsive-posts-carousel-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 15.3
- Severity Score:
- Medium
- CVE:
- 2025-68548
WordPress Themes — 4 Patched / 5 Unpatched
Arcane
- Theme:
- Arcane
- Theme Slug:
- arcane
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69031
Backpack Traveler
- Theme:
- Backpack Traveler
- Theme Slug:
- backpacktraveler
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69030
FiveStar
- Theme:
- FiveStar
- Theme Slug:
- fivestar
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69032
Medicalequipment
- Theme:
- Medicalequipment
- Theme Slug:
- medicalequipment
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69009
Struktur
- Theme:
- Struktur
- Theme Slug:
- struktur
- Vulnerability:
- Insecure Direct Object References (IDOR)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-69029
Diza
- Theme:
- Diza
- Theme Slug:
- diza
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.16
- Severity Score:
- High
- CVE:
- 2025-68544
Fana
- Theme:
- Fana
- Theme Slug:
- fana
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.1.36
- Severity Score:
- High
- CVE:
- 2025-68540
Nika
- Theme:
- Nika
- Theme Slug:
- nika
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.15
- Severity Score:
- High
- CVE:
- 2025-68546
Zota
- Theme:
- Zota
- Theme Slug:
- zota
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.3.15
- Severity Score:
- High
- CVE:
- 2025-68537
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
