WordPress Vulnerability Report

WordPress Vulnerability Report — February 18, 2026

Since last week, 190 new vulnerabilities have emerged in the WordPress ecosystem, including 158 plugins and 32 themes. Of those, 94 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 190 vulnerabilities have been publicly disclosed. Security patches for 96 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 94 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 83 Patched / 75 Unpatched

Persian WooCommerce SMS

Plugin Slug:
persian-woocommerce-sms
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Chatbot for WordPress by Collect.chat ??

Plugin Slug:
collectchat
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
new-image-gallery
Installations
4,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cliengo – Chatbot

Plugin Slug:
cliengo
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Slideshow

Plugin Slug:
slider-responsive-slideshow
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OpenPix for WooCommerce

Plugin Slug:
openpix-for-woocommerce
Installations
700+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iMoney

Plugin:
iMoney
Plugin Slug:
imoney
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Magic Login Mail or QR Code

Plugin Slug:
magic-login-mail
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RVCFDI para Woocommerce

Plugin Slug:
rvcfdi-para-woocommerce
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Visitor Maps Extended Referer Field

Plugin Slug:
visitor-maps-extended-referer-field
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Retail Menus

Plugin Slug:
simple-retail-menus
Installations
90+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPshop 2 – E-Commerce

Plugin Slug:
wpshop
Installations
70+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OpenPOS Lite – Point of Sale for WooCommerce

Plugin Slug:
wpos-lite-version
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Microtango

Plugin:
Microtango
Plugin Slug:
microtango
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Press3D

Plugin:
Press3D
Plugin Slug:
press3d
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Allow HTML in Category Descriptions

Plugin:
Allow HTML in Category Descriptions
Plugin Slug:
allow-html-in-category-descriptions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AMP Enhancer – Compatibility Layer for Official AMP Plugin

Plugin:
AMP Enhancer – Compatibility Layer for Official AMP Plugin
Plugin Slug:
amp-enhancer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Best-wp-google-map

Plugin:
Best-wp-google-map
Plugin Slug:
best-wp-google-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlueSnap Payment Gateway for WooCommerce

Plugin:
BlueSnap Payment Gateway for WooCommerce
Plugin Slug:
bluesnap-payment-gateway-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bookr

Plugin:
Bookr
Plugin Slug:
bookr
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bravis Addons

Plugin:
Bravis Addons
Plugin Slug:
bravis-addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CallbackKiller service widget

Plugin:
CallbackKiller service widget
Plugin Slug:
callbackkiller-service-widget
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Category Image

Plugin:
Category Image
Plugin Slug:
category-image
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Citations tools

Plugin:
Citations tools
Plugin Slug:
citations-tools
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cnvrse

Plugin:
Cnvrse
Plugin Slug:
cnvrse
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Voice Mail

Plugin:
Easy Voice Mail
Plugin Slug:
easy-voice-mail
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IDE Micro code-editor

Plugin:
IDE Micro code-editor
Plugin Slug:
flask-micro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flexi Product Slider and Grid for WooCommerce

Plugin:
Flexi Product Slider and Grid for WooCommerce
Plugin Slug:
flexi-product-slider-grid
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HTML Shortcodes

Plugin:
HTML Shortcodes
Plugin Slug:
html-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Invoct – PDF Invoices & Billing for WooCommerce

Plugin Slug:
kirilkirkov-pdf-invoice-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link Hopper
Plugin Slug:
link-hopper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BuddyHolis ListSearch

Plugin:
BuddyHolis ListSearch
Plugin Slug:
listsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MDirector Newsletter

Plugin:
MDirector Newsletter
Plugin Slug:
mdirector-newsletter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

midi-Synth

Plugin:
midi-Synth
Plugin Slug:
midi-synth
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

MMA Call Tracking

Plugin:
MMA Call Tracking
Plugin Slug:
mma-call-tracking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Campaigns

Plugin:
MailChimp Campaigns
Plugin Slug:
olalaweb-mailchimp-campaign-manager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payment Page

Plugin:
Payment Page
Plugin Slug:
payment-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Percent to Infograph

Plugin:
Percent to Infograph
Plugin Slug:
percent-to-infograph
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

personal-authors-category

Plugin:
personal-authors-category
Plugin Slug:
personal-authors-category
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
PhotoStack Gallery
Plugin Slug:
photostack-gallery
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Post Slides

Plugin:
Post Slides
Plugin Slug:
post-slides
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Prime Listing Manager

Plugin:
Prime Listing Manager
Plugin Slug:
prime-listing-manager
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

QuestionPro Surveys

Plugin:
QuestionPro Surveys
Plugin Slug:
questionpro-surveys
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ravelry Designs Widget

Plugin:
Ravelry Designs Widget
Plugin Slug:
ravelry-designs-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scheduler Widget

Plugin:
Scheduler Widget
Plugin Slug:
scheduler-widget
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEATT: Simple Event Attendance

Plugin:
SEATT: Simple Event Attendance
Plugin Slug:
simple-event-attendance
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Plyr

Plugin:
Simple Plyr
Plugin Slug:
simple-plyr
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Wp colorfull Accordion

Plugin:
Simple Wp colorfull Accordion
Plugin Slug:
simple-wp-colorfull-accordion
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slideshow Wp

Plugin:
Slideshow Wp
Plugin Slug:
slideshow-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Forms

Plugin:
Smart Forms
Plugin Slug:
smart-forms
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sphere Manager

Plugin:
Sphere Manager
Plugin Slug:
sphere-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sudoku Shortcode

Plugin:
Sudoku Shortcode
Plugin Slug:
sudoku-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Themesflat Elementor

Plugin:
Themesflat Elementor
Plugin Slug:
themesflat-elementor
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Timeline Event History

Plugin:
Timeline Event History
Plugin Slug:
timeline-event-history
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Twitter posts to Blog

Plugin:
Twitter posts to Blog
Plugin Slug:
twitter-posts-to-blog
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ZoomifyWP Free

Plugin:
ZoomifyWP Free
Plugin Slug:
tz-zoomifywp-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

UpMenu

Plugin:
UpMenu
Plugin Slug:
upmenu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin:
User Language Switch
Plugin Slug:
user-language-switch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Language Switch

Plugin:
User Language Switch
Plugin Slug:
user-language-switch
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Videospirecore Theme

Plugin:
Videospirecore Theme
Plugin Slug:
videospirecore
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WaMate Confirm

Plugin:
WaMate Confirm
Plugin Slug:
wamate-confirm
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WDES Responsive Popup

Plugin:
WDES Responsive Popup
Plugin Slug:
wdes-responsive-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Bulk Product Editor

Plugin:
WooCommerce Bulk Product Editor
Plugin Slug:
woocommerce-quick-product-editor
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP eCommerce

Plugin:
WP eCommerce
Plugin Slug:
wp-e-commerce
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Contact Us

Plugin:
WP Quick Contact Us
Plugin Slug:
wp-quick-contact-us
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Server Log Viewer

Plugin:
WP Server Log Viewer
Plugin Slug:
wp-server-log-viewer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:
Upload Files Anywhere
Plugin Slug:
wp-upload-files-anywhere
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Upload Files Anywhere

Plugin:
Upload Files Anywhere
Plugin Slug:
wp-upload-files-anywhere
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPlyr Media Block

Plugin:
WPlyr Media Block
Plugin Slug:
wplyr-media-block
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoast Duplicate Post

Plugin Slug:
duplicate-post
Installations
4,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.4.

Migration, Backup, Staging – WPvivid Backup & Migration

Plugin Slug:
wpvivid-backuprestore
Installations
900,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.9.124
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.9.124.

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

Plugin Slug:
kadence-blocks
Installations
600,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.0.

Converter for Media – Optimize images | Convert WebP & AVIF

Plugin Slug:
webp-converter-for-media
Installations
500,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.2.

SureForms – Contact Form, Payment Form & Other Custom Form Builder

Plugin Slug:
sureforms
Installations
400,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

Backup Migration

Plugin Slug:
backup-backup
Installations
100,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.4.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.0.

Beaver Builder Page Builder – Drag and Drop Website Builder

Plugin Slug:
beaver-builder-lite-version
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.0.6.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.10.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.7.

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.1.2.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.98.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.98.0.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
5.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.2.

Auto Featured Image (Auto Post Thumbnail)

Plugin Slug:
auto-post-thumbnail
Installations
50,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.9.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.4.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.4.2.

WP Last Modified Info

Plugin Slug:
wp-last-modified-info
Installations
30,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.6.

Custom Block Builder – Lazy Blocks

Plugin Slug:
lazy-blocks
Installations
20,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
4.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.1.

New User Approve

Plugin Slug:
new-user-approve
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.1.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.9.

The Events Calendar Shortcode & Block

Plugin Slug:
the-events-calendar-shortcode
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

WCFM Marketplace – Multivendor Marketplace for WooCommerce

Plugin Slug:
wc-multivendor-marketplace
Installations
20,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.

wpForo Forum

Plugin Slug:
wpforo
Installations
20,000+
Vulnerability:
PHP Object Injection
Patched in Version:
2.4.14
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.14.

WPZOOM Addons for Elementor – Starter Templates & Widgets

Plugin Slug:
wpzoom-elementor-addons
Installations
20,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Passster – Password Protect Pages and Content

Plugin Slug:
content-protector
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.26
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.26.

MasterStudy LMS WordPress Plugin – for Online Courses and Education

Plugin Slug:
masterstudy-lms-learning-management-system
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.12.

Media Library Folders

Plugin Slug:
media-library-plus
Installations
10,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
8.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.7.

Open User Map

Plugin Slug:
open-user-map
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.4.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.17.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.8.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.5.

Download Manager Addons for Elementor

Plugin Slug:
wpdm-elementor
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
2.0.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.0.

YayCurrency – WooCommerce Multi-Currency Switcher

Plugin Slug:
yaycurrency
Installations
7,000+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
3.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.1.

FastDup – Fastest WordPress Migration & Duplicator

Plugin Slug:
fastdup
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.2.

Simple File List

Plugin Slug:
simple-file-list
Installations
5,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
6.1.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.16.

Name Directory

Plugin Slug:
name-directory
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.32.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.32.1.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Paytium: Mollie payment forms & donations

Plugin Slug:
paytium
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.

Accordion and Accordion Slider

Plugin Slug:
accordion-and-accordion-slider
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.

Modal Popup Box: A Flexible Pop Up Box Builder

Plugin Slug:
modal-popup-box
Installations
2,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

PDF for Elementor Forms + Drag And Drop Template Builder

Plugin Slug:
pdf-for-elementor-forms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.5.0.

PDF for WPForms + Drag and Drop Template Builder

Plugin Slug:
pdf-for-wpforms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.3.1.

Lucky Wheel Giveaway

Plugin Slug:
wp-lucky-wheel
Installations
600+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.0.23
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.23.

Primer MyData for Woocommerce

Plugin Slug:
primer-mydata
Installations
100+
Vulnerability:
Path Traversal
Patched in Version:
4.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.9.

Activity Log for WordPress

Plugin Slug:
winterlock
Installations
70+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.9.

Orbisius Random Name Generator

Plugin Slug:
orbisius-random-name-generator
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

Tune Library

Plugin Slug:
tune-library
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.4.

BFG Tools – Extension Zipper

Plugin Slug:
bfg-tools-extension-zipper
Vulnerability:
Path Traversal
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

Fluent Forms Pro Add On Pack

Plugin:
Fluent Forms Pro Add On Pack
Plugin Slug:
fluentformpro
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
6.1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.13.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

Miraculous Elementor

Plugin:
Miraculous Elementor
Plugin Slug:
miraculous-el
Vulnerability:
Broken Authentication
Patched in Version:
2.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.8.

StickEasy Protected Contact Form

Plugin Slug:
stickeasy-protected-contact-form
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Truelysell Core

Plugin:
Truelysell Core
Plugin Slug:
truelysell-core
Vulnerability:
Privilege Escalation
Patched in Version:
1.8.8
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.8.8.

Uni CPO (Premium)

Plugin:
Uni CPO (Premium)
Plugin Slug:
uni-woo-custom-product-options-premium
Vulnerability:
Broken Access Control
Patched in Version:
4.9.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.61.

Whizz Plugins

Plugin:
Whizz Plugins
Plugin Slug:
whizz-plugins
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.0.

WooCommerce Coming Soon Product with Countdown

Plugin:
WooCommerce Coming Soon Product with Countdown
Plugin Slug:
woo-coming-soon-product
Vulnerability:
Local File Inclusion
Patched in Version:
5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.

User Extra Fields

Plugin:
User Extra Fields
Plugin Slug:
wp-user-extra-fields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
16.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 16.9.

WordPress Themes — 13 Patched / 19 Unpatched

Diamond

Theme:
Diamond
Theme Slug:
diamond
Downloads
37,609
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

WordPress Dating Theme

Theme:
WordPress Dating Theme
Theme Slug:
DA10
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Belletrist

Theme:
Belletrist
Theme Slug:
belletrist
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cartify – WooCommerce Gutenberg WordPress Theme

Theme:
Cartify – WooCommerce Gutenberg WordPress Theme
Theme Slug:
cartify
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Cobble

Theme:
Cobble
Theme Slug:
cobble
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Extreme Store

Theme:
Extreme Store
Theme Slug:
extremestore
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Exzo

Theme:
Exzo
Theme Slug:
exzo
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FiveStar

Theme:
FiveStar
Theme Slug:
fivestar
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

FreightCo

Theme:
FreightCo
Theme Slug:
freightco
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gable

Theme:
Gable
Theme Slug:
gable
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

HealthFirst

Theme:
HealthFirst
Theme Slug:
healthfirst
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lorem Ipsum | Books & Media Store

Theme:
Lorem Ipsum | Books & Media Store
Theme Slug:
lorem-ipsum-books-media-store
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

PJ | Life & Business Coaching

Theme:
PJ | Life & Business Coaching
Theme Slug:
pj
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Plank

Theme:
Plank
Theme Slug:
plank
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

R&F

Theme:
R&F
Theme Slug:
rf
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Splendour

Theme:
Splendour
Theme Slug:
splendour
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Struktur

Theme:
Struktur
Theme Slug:
struktur
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tint

Theme:
Tint
Theme Slug:
tint
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Yokoo

Theme:
Yokoo
Theme Slug:
yokoo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AdForest

Theme:
AdForest
Theme Slug:
adforest
Vulnerability:
Broken Authentication
Patched in Version:
6.0.13
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.0.13.

Diza

Theme:
Diza
Theme Slug:
diza
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.16
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.16.

Fana

Theme:
Fana
Theme Slug:
fana
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.36
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.36.

Ippsum

Theme:
Ippsum
Theme Slug:
ippsum
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.1.

Nestin

Theme:
Nestin
Theme Slug:
nestin
Vulnerability:
PHP Object Injection
Patched in Version:
1.2.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.6.

Nika

Theme:
Nika
Theme Slug:
nika
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.15.

CitiLights

Theme:
CitiLights
Theme Slug:
noo-citilights
Vulnerability:
Broken Access Control
Patched in Version:
3.7.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.2.

PatioTime

Theme:
PatioTime
Theme Slug:
patiotime
Vulnerability:
PHP Object Injection
Patched in Version:
2.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.1.

PatioTime

Theme:
PatioTime
Theme Slug:
patiotime
Vulnerability:
Local File Inclusion
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

Prestige

Theme:
Prestige
Theme Slug:
prestige
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.1.

Prestige

Theme:
Prestige
Theme Slug:
prestige
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.1.

Travelicious

Theme:
Travelicious
Theme Slug:
travelicious
Vulnerability:
PHP Object Injection
Patched in Version:
1.6.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.7.

Zota

Theme:
Zota
Theme Slug:
zota
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.15.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security