WordPress Vulnerability Report

WordPress Vulnerability Report — February 4, 2026

Since last week, 661 new vulnerabilities have emerged in the WordPress ecosystem, including 638 plugins and 23 themes. Of those, 164 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 661 vulnerabilities have been publicly disclosed. Security patches for 497 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 164 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9.1 was released on February 3, 2026, as a short-cycle maintenance update, addressing 49 bugs across WordPress Core and the Block Editor, including fixes affecting the editor, mail functionality, and classic themes. Sites with automatic background updates may already be updated. We recommend reviewing the details and updating as part of your regular maintenance cycle.

The next major WordPress release, version 7.0, is scheduled for April 9, 2026, during WordCamp Asia.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 488 Patched / 150 Unpatched

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kama Thumbnail

Plugin Slug:
kama-thumbnail
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leadpages

Plugin:
Leadpages
Plugin Slug:
leadpages
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Shiprocket

Plugin:
Shiprocket
Plugin Slug:
shiprocket
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

NextMove Lite – Thank You Page for WooCommerce

Plugin Slug:
woo-thank-you-page-nextmove-lite
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CLP Varnish Cache

Plugin Slug:
clp-varnish-cache
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar
Installations
9,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Subscribe

Plugin Slug:
wp-subscribe
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Travelpayouts

Plugin Slug:
travelpayouts
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

?????? ????? ???? ?? ???? ?? ?? ??

Plugin Slug:
farazsms
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nova Blocks by Pixelgrade

Plugin Slug:
nova-blocks
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Inquiry & Cart Options for WooCommerce

Plugin Slug:
woocommerce-email-inquiry-cart-options
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Generic Elements

Plugin Slug:
generic-elements-for-elementor
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quick Restaurant Reservations

Plugin Slug:
quick-restaurant-reservations
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Hotel Booking – Powerful Hotel Booking

Plugin Slug:
easy-hotel
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sendy

Plugin:
Sendy
Plugin Slug:
sendy
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Asynchronous Javascript

Plugin Slug:
asynchronous-javascript
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

eDS Responsive Menu

Plugin Slug:
eds-responsive-menu
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FeedWordPress Advanced Filters

Plugin Slug:
faf
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Membee Login

Plugin Slug:
membees-member-login-widget
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widget Logic Visual

Plugin Slug:
widget-logic-visual
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ID Arrays

Plugin:
ID Arrays
Plugin Slug:
id-arrays
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iSape

Plugin:
iSape
Plugin Slug:
isape
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JobBoard Job listing plugin

Plugin Slug:
job-board-light
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mopinion Feedback Form

Plugin Slug:
mopinion-feedback-form
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JavaScript Notifier

Plugin Slug:
javascript-notifier
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple Archive Generator

Plugin Slug:
simple-archive-generator
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Aardvark Plugin

Plugin:
Aardvark Plugin
Plugin Slug:
aardvark-plugin
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:
ABC Notation
Plugin Slug:
abc-notation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AhaChat Messenger Marketing

Plugin:
AhaChat Messenger Marketing
Plugin Slug:
ahachat-messenger-marketing
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AhaChat Messenger Marketing

Plugin:
AhaChat Messenger Marketing
Plugin Slug:
ahachat-messenger-marketing
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:
AHAthat
Plugin Slug:
ahathat
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Allmart

Plugin:
Allmart
Plugin Slug:
allmart-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Anber Elementor Addon

Plugin:
Anber Elementor Addon
Plugin Slug:
anber-elementor-addon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aoa Downloadable

Plugin:
Aoa Downloadable
Plugin Slug:
aoa-downloadable
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Aoa Downloadable

Plugin:
Aoa Downloadable
Plugin Slug:
aoa-downloadable
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:
Ads Pro
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:
Ads Pro
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro

Plugin:
Ads Pro
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ArielBrailovsky-ViralAd

Plugin:
ArielBrailovsky-ViralAd
Plugin Slug:
arielbrailovsky-viralad
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Auto Thickbox

Plugin:
Auto Thickbox
Plugin Slug:
auto-thickbox
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bitcoin Donate Button

Plugin:
Bitcoin Donate Button
Plugin Slug:
bitcoin-donate-button
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlockArt Blocks

Plugin:
BlockArt Blocks
Plugin Slug:
blockart-blocks
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BlossomThemes Social Feed

Plugin:
BlossomThemes Social Feed
Plugin Slug:
blossomthemes-instagram-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Booked

Plugin:
Booked
Plugin Slug:
booked
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:
Business Card
Plugin Slug:
business-card-by-esterox-100
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:
Business Card
Plugin Slug:
business-card-by-esterox-100
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Business Card

Plugin:
Business Card
Plugin Slug:
business-card-by-esterox-100
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Buttons Shortcode and Widget

Plugin:
Buttons Shortcode and Widget
Plugin Slug:
buttons-shortcode-and-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Change WP URL

Plugin:
Change WP URL
Plugin Slug:
change-wp-url
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

cits-support-svg-webp-media-upload

Plugin:
cits-support-svg-webp-media-upload
Plugin Slug:
cits-support-svg-webp-media-upload
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Crete Core

Plugin:
Crete Core
Plugin Slug:
crete-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

CRM Memberships

Plugin:
CRM Memberships
Plugin Slug:
crm-memberships
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CRM Memberships

Plugin:
CRM Memberships
Plugin Slug:
crm-memberships
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

DesignThemes Core Features

Plugin:
DesignThemes Core Features
Plugin Slug:
designthemes-core-features
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pixter Right Click Protect Images for WordPress

Plugin:
Pixter Right Click Protect Images for WordPress
Plugin Slug:
disable-right-click-powered-by-pixterme
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:
Dyn Business Panel
Plugin Slug:
dyn-business-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Jump Links Menus
Plugin Slug:
easy-jump-links-menus
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Electio Core

Plugin:
Electio Core
Plugin Slug:
electio-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Elegant Addons for elementor

Plugin:
Elegant Addons for elementor
Plugin Slug:
elegant-addons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Emerce Core

Plugin:
Emerce Core
Plugin Slug:
emerce-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Eyewear prescription form

Plugin:
Eyewear prescription form
Plugin Slug:
eyewear-prescription-form
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Feedback Modal for Website

Plugin:
Feedback Modal for Website
Plugin Slug:
feedback-modal-for-website
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fintelligence Calculator

Plugin:
Fintelligence Calculator
Plugin Slug:
fintelligence-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Font Farsi

Plugin:
Font Farsi
Plugin Slug:
font-farsi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontend Checklist

Plugin:
Frontend Checklist
Plugin Slug:
frontend-checklist
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GoZen Forms

Plugin:
GoZen Forms
Plugin Slug:
gozen-forms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Hide Categories Or Products On Shop Page

Plugin:
Hide Categories Or Products On Shop Page
Plugin Slug:
hide-categories-or-products-on-shop-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HL Twitter

Plugin:
HL Twitter
Plugin Slug:
hl-twitter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Image Hover Effects – Caption Hover with Carousel
Plugin Slug:
image-hover-effects-with-carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Optimizer by wps.sk

Plugin:
Image Optimizer by wps.sk
Plugin Slug:
image-optimizer-wpssk
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

imwptip

Plugin:
imwptip
Plugin Slug:
imwptip
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Likes and Dislikes

Plugin:
Likes and Dislikes
Plugin Slug:
inprosysmedia-likes-dislikes-post
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Internal Link Builder
Plugin Slug:
internal-link-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Joy Of Text Lite

Plugin:
Joy Of Text Lite
Plugin Slug:
joy-of-text
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JustClick registration plugin

Plugin:
JustClick registration plugin
Plugin Slug:
justclick-subscriber
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Kalrav AI Agent

Plugin:
Kalrav AI Agent
Plugin Slug:
kalrav-ai-agent
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

KiotViet Sync

Plugin:
KiotViet Sync
Plugin Slug:
kiotvietsync
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Kona Gallery Block
Plugin Slug:
kona-instagram-feed-for-gutenberg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Light Poll

Plugin:
Light Poll
Plugin Slug:
light-poll
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Login Logout Register Menu

Plugin:
Login Logout Register Menu
Plugin Slug:
login-logout-register-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketplace Items

Plugin:
Marketplace Items
Plugin Slug:
marketplace-items
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Medinik Core

Plugin:
Medinik Core
Plugin Slug:
medinik-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Meta-box GalleryMeta

Plugin Slug:
meta-box-gallerymeta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Search Atlas SEO

Plugin:
Search Atlas SEO
Plugin Slug:
metasync
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ModelTheme Framework

Plugin:
ModelTheme Framework
Plugin Slug:
modeltheme-framework
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Takeads

Plugin:
Takeads
Plugin Slug:
monetize-link
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nestbyte Core

Plugin:
Nestbyte Core
Plugin Slug:
nestbyte-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:
Newsletter Popup
Plugin Slug:
newsletter-popup
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:
Newsletter Popup
Plugin Slug:
newsletter-popup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Popup

Plugin:
Newsletter Popup
Plugin Slug:
newsletter-popup
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Norby AI

Plugin:
Norby AI
Plugin Slug:
norby-ai
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode

Plugin:
PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode
Plugin Slug:
paypal-pay-buy-donation-and-cart-buttons-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pet Manager

Plugin:
Pet Manager
Plugin Slug:
pet-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image License and Protection

Plugin:
Image License and Protection
Plugin Slug:
pixter-image-digital-license
Vulnerability:
Backdoor
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Postalicious

Plugin:
Postalicious
Plugin Slug:
postalicious
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premmerce Brands for WooCommerce

Plugin:
Premmerce Brands for WooCommerce
Plugin Slug:
premmerce-woocommerce-brands
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Recooty

Plugin:
Recooty
Plugin Slug:
recooty
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Header

Plugin:
Responsive Header
Plugin Slug:
responsive-header
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rupantorpay

Plugin:
Rupantorpay
Plugin Slug:
rupantorpay
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Saasplate Core

Plugin:
Saasplate Core
Plugin Slug:
saasplate-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin:
SendPress Newsletters
Plugin Slug:
sendpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Plugin:
SendPress Newsletters
Plugin Slug:
sendpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
SEO Links Interlinking
Plugin Slug:
seo-links-interlinking
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sermon Manager

Plugin:
Sermon Manager
Plugin Slug:
sermon-manager-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart PopUp Blaster

Plugin:
Smart PopUp Blaster
Plugin Slug:
smart-popup-blaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Solidres – Hotel booking plugin

Plugin:
Solidres – Hotel booking plugin
Plugin Slug:
solidres
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

Plugin:
SP Project & Document Manager
Plugin Slug:
sp-client-document-manager
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SSP Debug

Plugin:
SSP Debug
Plugin Slug:
ssp-debugging
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SVS Pricing Tables

Plugin:
SVS Pricing Tables
Plugin Slug:
svs-pricing-tables
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Testimonials Widget

Plugin:
Testimonials Widget
Plugin Slug:
testimonials-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Comments

Plugin:
Top Comments
Plugin Slug:
top-comments
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Translate This gTranslate Shortcode

Plugin:
Translate This gTranslate Shortcode
Plugin Slug:
translate-this-google-translate-web-element-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quantic Social Image Hover

Plugin:
Quantic Social Image Hover
Plugin Slug:
tw-image-hover-share
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Twitter Bootstrap Collapse aka Accordian Shortcode

Plugin:
Twitter Bootstrap Collapse aka Accordian Shortcode
Plugin Slug:
twitter-bootstrap-collapse-aka-accordian-shortcode
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Uroan Core

Plugin:
Uroan Core
Plugin Slug:
uroan-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Vzaar Media Management

Plugin:
Vzaar Media Management
Plugin Slug:
vzaar-media-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Widget4Call

Plugin:
Widget4Call
Plugin Slug:
widget4call
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woodly Core

Plugin:
Woodly Core
Plugin Slug:
woodly-core
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WoWPth

Plugin:
WoWPth
Plugin Slug:
wowpth
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:
WordPress Auction Plugin
Plugin Slug:
wp-auctions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Easy FAQs

Plugin:
WP Easy FAQs
Plugin Slug:
wp-easy-faqs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Featherlight

Plugin:
WP Featherlight
Plugin Slug:
wp-featherlight
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Google Ad Manager

Plugin:
WP Google Ad Manager
Plugin Slug:
wp-google-ad-manager-plugin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Logs Book

Plugin:
WP Logs Book
Plugin Slug:
wp-logs-book
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP MultiTasking

Plugin:
WP MultiTasking
Plugin Slug:
wp-multitasking
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Online Users Stats

Plugin:
WP Online Users Stats
Plugin Slug:
wp-online-users-stats
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:
WP Prayer
Plugin Slug:
wp-prayer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Prayer

Plugin:
WP Prayer
Plugin Slug:
wp-prayer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Revive Adserver

Plugin:
WP-Revive Adserver
Plugin Slug:
wp-revive-adserver
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Survey & Poll

Plugin:
WordPress Survey & Poll
Plugin Slug:
wp-survey-and-poll
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YouTube Embed, Playlist and Popup by WpDevArt

Plugin:
YouTube Embed, Playlist and Popup by WpDevArt
Plugin Slug:
youtube-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ElementsKit Elementor Addons and Templates

Plugin Slug:
elementskit-lite
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.

Spectra Gutenberg Blocks – Website Builder for the Block Editor

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
1,000,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.19.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.19.18.

Spectra Gutenberg Blocks – Website Builder for the Block Editor

Plugin Slug:
ultimate-addons-for-gutenberg
Installations
1,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.12.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.9.
Plugin Slug:
cookie-notice
Installations
900,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.9.

Migration, Backup, Staging – WPvivid Backup & Migration

Plugin Slug:
wpvivid-backuprestore
Installations
800,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.9.121
Severity Score:
Low
The vulnerability has been patched, so you should update to version 0.9.121.

Ocean Extra

Plugin Slug:
ocean-extra
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.4.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.12.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.12.3.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.5.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.8.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.11.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.11.0.

Happy Addons for Elementor

Plugin Slug:
happy-elementor-addons
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.9.

Page Builder: Pagelayer – Drag and Drop website builder

Plugin Slug:
pagelayer
Installations
400,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.8.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
400,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.6.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.136
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.136.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Unlimited Elements For Elementor

Plugin Slug:
unlimited-elements-for-elementor
Installations
300,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.113
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.113.

WP Go Maps (formerly WP Google Maps)

Plugin Slug:
wp-google-maps
Installations
300,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.0.05
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.0.05.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha
Installations
200,000+
Vulnerability:
SQL Injection
Patched in Version:
1.30
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.30.

FileOrganizer – WordPress File Manager

Plugin Slug:
fileorganizer
Installations
200,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Jetpack Boost – Website Speed, Performance and Critical CSS

Plugin Slug:
jetpack-boost
Installations
200,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.7.
Plugin Slug:
photo-gallery
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.31.

Redirection for Contact Form 7

Plugin Slug:
wpcf7-redirect
Installations
200,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
3.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.8.

Ivory Search – WordPress Search Plugin

Plugin Slug:
add-search-to-menu
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.14.

AI Engine – The Chatbot and AI Framework for WordPress

Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.3.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.1.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.6.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.6.12.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.3.

Element Pack Addons for Elementor

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.10.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.10.3.

Prime Slider – Addons for Elementor

Plugin Slug:
bdthemes-prime-slider-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.2.

Lightbox & Modal Popup WordPress Plugin – FooBox

Plugin Slug:
foobox-image-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.35
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.35.
Plugin Slug:
foogallery
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.15.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.14.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.14.2.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.1.

WP Ghost (Hide My WP Ghost) – Security & Firewall

Plugin Slug:
hide-my-wp
Installations
100,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
5.4.02
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.02.
Plugin Slug:
modula-best-grid-gallery
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.13.4.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.22.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.22.1.
Plugin Slug:
relevanssi
Installations
100,000+
Vulnerability:
SQL Injection
Patched in Version:
4.26.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.26.0.
Plugin Slug:
responsive-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.8.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.9.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.6.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.4.

VK All in One Expansion Unit

Plugin Slug:
vk-all-in-one-expansion-unit
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.112.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.112.2.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.3.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.4.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.6.

Addon Elements for Elementor (formerly Elementor Addon Elements)

Plugin Slug:
addon-elements-for-elementor-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.13.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.13.7.

Booking for Appointments and Events Calendar – Amelia

Plugin Slug:
ameliabooking
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.3.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.15.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.15.8.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.1.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.14.

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
90,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.17.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.14.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.274
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.274.

Colibri Page Builder

Plugin Slug:
colibri-page-builder
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.277
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.277.

JetFormBuilder — Dynamic Blocks Form Builder

Plugin Slug:
jetformbuilder
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Custom Login Page Customizer

Plugin Slug:
login-customizer
Installations
90,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.5.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.5.4.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.6.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.26.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.26.7.

MaxButtons – Create buttons

Plugin Slug:
maxbuttons
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.8.1.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.3.

Advanced Contact form 7 DB

Plugin Slug:
advanced-cf7-db
Installations
70,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.41
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.41.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.42
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.42.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Database for Contact Form 7, WPforms, Elementor forms

Plugin Slug:
contact-form-entries
Installations
70,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.6.
Plugin Slug:
featured-image-from-url
Installations
70,000+
Vulnerability:
SQL Injection
Patched in Version:
5.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.8.
Plugin Slug:
featured-image-from-url
Installations
70,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.2.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.3.

Exclusive Addons for Elementor

Plugin Slug:
exclusive-addons-for-elementor
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.9.5.

Master Slider – Responsive Touch Slider

Plugin Slug:
master-slider
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.10.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.0.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Qi Blocks

Plugin:
Qi Blocks
Plugin Slug:
qi-blocks
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

Ultimate Dashboard – Custom WordPress Dashboard

Plugin Slug:
ultimate-dashboard
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.6.

Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme

Plugin Slug:
addons-for-divi
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.6.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.9.

Bold Page Builder

Plugin Slug:
bold-page-builder
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.3.6.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.14.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.7.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.14.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.14.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.6.5.

Getwid – Gutenberg Blocks

Plugin Slug:
getwid
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.11.

Search Exclude

Plugin Slug:
search-exclude
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.0.

Sina Extension for Elementor

Plugin Slug:
sina-extension-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.8.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.8.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.4.

Ultimate Blocks – 25+ Gutenberg Blocks for Block Editor

Plugin Slug:
ultimate-blocks
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

WP Recipe Maker

Plugin Slug:
wp-recipe-maker
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
10.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.3.0.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.3.6.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.

Livemesh Addons by Elementor

Plugin Slug:
addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.4.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2025.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2025.0.

Calculated Fields Form

Plugin Slug:
calculated-fields-form
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.62
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.2.62.
Plugin Slug:
carousel-slider
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.15.

FunnelKit – Funnel Builder for WooCommerce Checkout

Plugin Slug:
funnel-builder
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.13.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.13.1.3.

Genesis Blocks

Plugin Slug:
genesis-blocks
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.3.

Genesis Blocks

Plugin Slug:
genesis-blocks
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.
Plugin Slug:
robo-gallery
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.23.
Plugin Slug:
yith-woocommerce-ajax-search
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

Ditty – Responsive News Tickers, Sliders, and Lists

Plugin Slug:
ditty-news-ticker
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.46
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.46.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.29
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.29.

Post Grid

Plugin:
Post Grid
Plugin Slug:
post-grid
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.81.

Post Grid

Plugin:
Post Grid
Plugin Slug:
post-grid
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.81
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.81.

SEO Plugin by Squirrly SEO

Plugin Slug:
squirrly-seo
Installations
30,000+
Vulnerability:
SQL Injection
Patched in Version:
12.3.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.3.20.

Stop Spammers Classic

Plugin Slug:
stop-spammer-registrations-plugin
Installations
30,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2026.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2026.2.

Stratum Widgets for Elementor

Plugin Slug:
stratum
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.1.

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.5.

WP Video Lightbox

Plugin Slug:
wp-video-lightbox
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.12.

Xpro Addons — 140+ Widgets for Elementor

Plugin Slug:
xpro-elementor-addons
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.8.
Plugin Slug:
final-tiles-grid-gallery-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.9.

Icegram Engage – Popups, Optins, CTAs & lot more…

Plugin Slug:
icegram
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.32.

New User Approve

Plugin Slug:
new-user-approve
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.3.

Secure Copy Content Protection and Content Locking

Plugin Slug:
secure-copy-content-protection
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.7.

Snow Monkey Forms

Plugin Slug:
snow-monkey-forms
Installations
20,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
12.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.0.4.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Ultimate Addons for Beaver Builder – Lite

Plugin Slug:
ultimate-addons-for-beaver-builder-lite
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.8.

Welcart e-Commerce

Plugin Slug:
usc-e-shop
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.11.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.11.21.

Appointment Hour Booking – Booking Calendar

Plugin Slug:
appointment-hour-booking
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.61
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.61.

Bold Timeline Lite

Plugin Slug:
bold-timeline-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.8.

Passster – Password Protect Pages and Content

Plugin Slug:
content-protector
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.25.

Crelly Slider

Plugin Slug:
crelly-slider
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.7.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.1.

Content Blocks (Custom Post Widget)

Plugin Slug:
custom-post-widget
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.5.

Document Embedder – Embed PDFs, Word, Excel, and Other Files

Plugin Slug:
document-emberdder
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.9.

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

Motors – Car Dealership & Classified Listings Plugin

Plugin Slug:
motors-car-dealership-classified-listings
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.58
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.58.

Child Theme Creator by Orbisius

Plugin Slug:
orbisius-child-theme-creator
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.6.

Order Minimum/Maximum Amount Limits for WooCommerce

Plugin Slug:
order-minimum-amount-for-woocommerce
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.9.

OSM – OpenStreetMap

Plugin Slug:
osm
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.0.4.

Recipe Card Blocks Lite

Plugin Slug:
recipe-card-blocks-by-wpzoom
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.4.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.13.

SupportCandy – Helpdesk & Customer Support Ticket System

Plugin Slug:
supportcandy
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
3.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.5.
Plugin Slug:
testimonials-carousel-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.2.0.

Countdown Timer – Widget Countdown

Plugin Slug:
widget-countdown
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.8.

Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart
Installations
10,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.4.

Backup, Restore and Migrate your sites with XCloner

Plugin Slug:
xcloner-backup-and-restore
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.8.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.3.

Prisna GWT – Google Website Translator

Plugin Slug:
google-website-translator
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.14.

Qubely – Advanced Gutenberg Blocks

Plugin Slug:
qubely
Installations
9,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.13.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

Ultimate Coming Soon & Maintenance

Plugin Slug:
ultimate-coming-soon
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.0.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
9,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.8.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
9.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.9.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.4.3.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.0.

EventPrime – Events Calendar, Bookings and Tickets

Plugin Slug:
eventprime-event-calendar-management
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.1.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.8.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.9.

EventON – Events Calendar

Plugin Slug:
eventon-lite
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

Hunk Companion

Plugin Slug:
hunk-companion
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.0.

Pearl – Header Builder

Plugin Slug:
pearl-header-builder
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
PHP Object Injection
Patched in Version:
5.9.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.4.6.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.9.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.9.4.5.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.9.5.

Booking Calendar | Appointment Booking | Bookit

Plugin Slug:
bookit
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.1.
Plugin Slug:
easy-image-gallery
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.3.

Return Refund and Exchange For WooCommerce

Plugin Slug:
woo-refund-and-exchange-lite
Installations
5,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.5.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.6.

CubeWP Framework

Plugin Slug:
cubewp-framework
Installations
4,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.1.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.28.

CubeWP Framework

Plugin Slug:
cubewp-framework
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.28
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.28.

CubeWP Framework

Plugin Slug:
cubewp-framework
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.27.

ELEX WooCommerce Bulk Edit Products, Prices & Attributes (Basic)

Plugin Slug:
elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.0.

HelloAsso

Plugin:
HelloAsso
Plugin Slug:
helloasso
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

MediaPress

Plugin:
MediaPress
Plugin Slug:
mediapress
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

WPZOOM Addons for Beaver Builder

Plugin Slug:
wpzoom-addons-for-beaver-builder
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.5.

AVIF Uploader

Plugin Slug:
avif-support
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

MultiVendorX – WooCommerce Multivendor Marketplace Solutions

Plugin Slug:
dc-woocommerce-multi-vendor
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.2.23
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.23.
Plugin Slug:
photoblocks-grid-gallery
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.3.

Tickera – Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.5.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.9.

WP-DownloadManager

Plugin Slug:
wp-downloadmanager
Installations
3,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.68.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.68.11.

WP-WebAuthn

Plugin Slug:
wp-webauthn
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.4.

WP Directory Kit

Plugin Slug:
wpdirectorykit
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
4.0.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.0.

Markup Markdown

Plugin Slug:
markup-markdown
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.20.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.20.10.

Melapress Login Security

Plugin Slug:
melapress-login-security
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

RSS Feed Widget

Plugin Slug:
rss-feed-widget
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.1.

Geo Controller

Plugin Slug:
cf-geoplugin
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
8.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.0.

Smart Online Order for Clover

Plugin Slug:
clover-online-orders
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.5.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.7.

Web3 Crypto Payments by DePay for WooCommerce

Plugin Slug:
depay-payments-for-woocommerce
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.12.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.18.

Double the Donation – A workplace giving tool

Plugin Slug:
double-the-donation
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.0.

Educare – Students & Result Management System

Plugin Slug:
educare
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.2.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.3.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.9.

EPROLO-Dropshipping

Plugin Slug:
eprolo-dropshipping
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

Flamix: Bitrix24 and Contact Form 7 integrations

Plugin Slug:
flamix-bitrix24-and-contact-forms-7-integrations
Installations
1,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.0.

Friendly Functions for Welcart

Plugin Slug:
friendly-functions-for-welcart
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Mizan Demo Importer

Plugin Slug:
mizan-demo-importer
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.4.

Nelio Popups

Plugin Slug:
nelio-popups
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.6.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
23.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 23.5.

PDF Generator Addon for Elementor Page Builder

Plugin Slug:
pdf-generator-addon-for-elementor-page-builder
Installations
1,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Private Google Calendars

Plugin Slug:
private-google-calendars
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
20251128
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 20251128.

Save as PDF Plugin by PDFCrowd

Plugin Slug:
save-as-pdf-by-pdfcrowd
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.6.

Simple Popup Plugin

Plugin Slug:
simple-popup-plugin
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.6.

Squelch Tabs and Accordions Shortcodes

Plugin Slug:
squelch-tabs-and-accordions-shortcodes
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.4.4.

Subscriptions & Memberships for PayPal

Plugin Slug:
subscriptions-memberships-for-paypal
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.8.

Tainacan

Plugin:
Tainacan
Plugin Slug:
tainacan
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Tutor LMS – Migration Tool

Plugin Slug:
tutor-lms-migration-tool
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

WC Builder – WooCommerce Page Builder for WPBakery

Plugin Slug:
wc-builder
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

WishSuite – Wishlist for WooCommerce

Plugin Slug:
wishsuite
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.2.

Easy 3D Viewer

Plugin Slug:
woo-3d-viewer
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.6.7.

WP Sync for Notion – Notion to WordPress

Plugin Slug:
wp-sync-for-notion
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1.

Zephyr Project Manager

Plugin Slug:
zephyr-project-manager
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.102
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.102.

CBX Map for Google Map & OpenStreetMap

Plugin Slug:
cbxgooglemap
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

ContentStudio

Plugin Slug:
contentstudio
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Ebook Store

Plugin Slug:
ebook-store
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8015
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8015.

Omnipress

Plugin:
Omnipress
Plugin Slug:
omnipress
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

3DPrint Lite

Plugin Slug:
3dprint-lite
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
2.1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.7.

3DPrint Lite

Plugin Slug:
3dprint-lite
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
2.1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.7.

3DPrint Lite

Plugin Slug:
3dprint-lite
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
2.1.3.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.7.

Frontis Blocks — Block Library for the Block Editor

Plugin Slug:
frontis-blocks
Installations
800+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.7.

RapidLoad AI – Optimize Web Vitals Automatically

Plugin Slug:
unusedcss
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Confetti Fall Animation

Plugin Slug:
confetti-fall-animation
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.2.

Frontend Dashboard

Plugin Slug:
frontend-dashboard
Installations
600+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.8.

Simplebooklet PDF Viewer and Embedder

Plugin Slug:
simplebooklet
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

eMagicOne Store Manager for WooCommerce

Plugin Slug:
store-manager-connector
Installations
600+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.0.

Polls CP

Plugin:
Polls CP
Plugin Slug:
cp-polls
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.77
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.77.

Dynamic AJAX Product Filters for WooCommerce

Plugin Slug:
dynamic-ajax-product-filters-for-woocommerce
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.

Easy Replace Image

Plugin Slug:
easy-replace-image
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.3.

EZ SQL Reports Shortcode Widget and DB Backup

Plugin Slug:
elisqlreports
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.25.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.25.25.

g-FFL Cockpit

Plugin Slug:
g-ffl-cockpit
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.0.

Simple calendar for Elementor

Plugin Slug:
simple-calendar-for-elementor
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
1.6.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.7.

SurveyJS: Drag & Drop Form Builder

Plugin Slug:
surveyjs
Installations
500+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.20.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.20.27.

VidShop – Shoppable Videos for WooCommerce

Plugin Slug:
vidshop-for-woocommerce
Installations
400+
Vulnerability:
SQL Injection
Patched in Version:
1.1.5
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.5.

CYAN Backup

Plugin Slug:
cyan-backup
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.3.

DeBounce Email Validator

Plugin Slug:
debounce-io-email-validator
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.8.1.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.2.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
3.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.6.

TableOn – WordPress Posts Table Filterable 

Plugin Slug:
posts-table-filterable
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.2.

Photo Contest | Competition | Video Contest

Plugin Slug:
totalcontest-lite
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.0.

Webcake – Landing Page Builder

Plugin Slug:
webcake
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.

Autoship Cloud for WooCommerce Subscription Products

Plugin Slug:
autoship-cloud
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.1.

Site.pro for WooCommerce

Plugin Slug:
b1-accounting
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
2.2.57
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.57.
Plugin Slug:
header-footer-code
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.
Plugin Slug:
invoice-payment-for-woocommerce
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.1.

Premmerce Wishlist for WooCommerce

Plugin Slug:
premmerce-woocommerce-wishlist
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

Simple User Registration

Plugin Slug:
wp-registration
Installations
200+
Vulnerability:
Privilege Escalation
Patched in Version:
6.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 6.4.

Zigaform – Price Calculator & Cost Estimation Form Builder Lite

Plugin Slug:
zigaform-calculator-cost-estimation-form-builder-lite
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.8.

Run Contests, Raffles, and Giveaways with ContestsWP

Plugin Slug:
contest-code-checker
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Course Booking System

Plugin Slug:
course-booking-system
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
6.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.1.6.

Feedify – Web Push Notifications

Plugin Slug:
push-notification-by-feedify
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.6.

Chatbot with ChatGPT WordPress

Plugin Slug:
smartsearchwp
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

Uptodown APK Download Widget

Plugin Slug:
uptodown-apk-download-widget
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.11.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

WP To Do

Plugin:
WP To Do
Plugin Slug:
wp-todo
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.1.

Pdf & Print to Post – Custom Post Type and Pages

Plugin Slug:
post-to-pdf
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

Ganohrs Toggle Shortcode

Plugin Slug:
ganohrs-toggle-shortcode
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.5.

Linear

Plugin:
Linear
Plugin Slug:
linear
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

GeoDataSource Country Region DropDown

Plugin Slug:
geodatasource-country-region-dropdown
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Zigaform – Form Builder Lite

Plugin Slug:
zigaform-form-builder-lite
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.8.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.9.

IRM Newsroom

Plugin Slug:
irm-newsroom
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.20.

IRM Newsroom

Plugin Slug:
irm-newsroom
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.20.

Sertifier Certificate & Badge Maker for WordPress – Tutor LMS

Plugin Slug:
sertifier-certificates-open-badges
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.20.

Binary MLM Plan

Plugin Slug:
binary-mlm-plan
Installations
50+
Vulnerability:
Privilege Escalation
Patched in Version:
5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.

ConvertForce Popup Builder

Plugin Slug:
convertforce-popup-builder
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.0.8.

Bread & Butter: Content Gating for Verified Leads

Plugin Slug:
bread-butter
Installations
30+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.0.1398
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 8.0.1398.

Community Events

Plugin Slug:
community-events
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
1.5.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.5.2.

Forms Bridge – Infinite integrations

Plugin Slug:
forms-bridge
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.0.

Magic Buttons for Elementor

Plugin Slug:
magic-buttons-for-elementor
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

EKC Tournament Manager

Plugin Slug:
ekc-tournament-manager
Installations
20+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Ultimate Classified Listings

Plugin Slug:
ultimate-classified-listings
Installations
20+
Vulnerability:
Local File Inclusion
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

Buy Now Plus — Payments with Stripe

Plugin Slug:
buy-now-plus
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

coreActivity: Activity Logging for WordPress

Plugin Slug:
coreactivity
Installations
10+
Vulnerability:
Content Spoofing
Patched in Version:
2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.

HAPPY – Helpdesk Support Ticket System

Plugin Slug:
happy-helpdesk-support-ticket-system
Installations
10+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.9.

Simple Folio

Plugin Slug:
simple-folio
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
10+
Vulnerability:
Privilege Escalation
Patched in Version:
1.0.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.3.

ARMember Premium

Plugin:
ARMember Premium
Plugin Slug:
armember
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
6.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.1.

Beaver Builder Plugin (Starter Version)

Plugin:
Beaver Builder Plugin (Starter Version)
Plugin Slug:
bb-plugin
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.9.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.1.1.

BM Content Builder

Plugin:
BM Content Builder
Plugin Slug:
bm-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.16.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.16.3.

bodi0’s Easy Cache

Plugin:
bodi0’s Easy Cache
Plugin Slug:
bodi0s-easy-cache
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.

Bridge Core

Plugin:
Bridge Core
Plugin Slug:
bridge-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.

Buddyboss Platform

Plugin:
Buddyboss Platform
Plugin Slug:
buddyboss-platform
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.0.

Divi Builder

Plugin:
Divi Builder
Plugin Slug:
divi-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.27.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.27.2.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.29.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.29.1.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Sensitive Data Exposure
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Broken Access Control
Patched in Version:
4.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.5.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Broken Access Control
Patched in Version:
4.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.5.9.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Broken Access Control
Patched in Version:
4.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.5.6.

Favicon Generator

Plugin:
Favicon Generator
Plugin Slug:
favicon-generator
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.

Gyan Elements

Plugin:
Gyan Elements
Plugin Slug:
gyan-elements
Vulnerability:
Local File Inclusion
Patched in Version:
2.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.2.

WPGYM

Plugin:
WPGYM
Plugin Slug:
gym-management
Vulnerability:
SQL Injection
Patched in Version:
67.8.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 67.8.0.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.6.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.7.

MelaPress Login Security Premium

Plugin:
MelaPress Login Security Premium
Plugin Slug:
melapress-login-security-premium
Vulnerability:
Broken Access Control
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Memberlite Shortcodes

Plugin:
Memberlite Shortcodes
Plugin Slug:
memberlite-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.1.

ModelTheme Addons for WPBakery and Elementor

Plugin:
ModelTheme Addons for WPBakery and Elementor
Plugin Slug:
modeltheme-addons-for-wpbakery
Vulnerability:
PHP Object Injection
Patched in Version:
1.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.6.

Paid Memberships Pro

Plugin:
Paid Memberships Pro
Plugin Slug:
paid-memberships-pro
Vulnerability:
Broken Access Control
Patched in Version:
2.12.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.12.9.

Community by PeepSo

Plugin:
Community by PeepSo
Plugin Slug:
peepso-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.6.0.

Community by PeepSo

Plugin:
Community by PeepSo
Plugin Slug:
peepso-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.3.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.3.1.2.

Porto Theme – Functionality

Plugin:
Porto Theme – Functionality
Plugin Slug:
porto-functionality
Vulnerability:
Local File Inclusion
Patched in Version:
3.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.0.

Prague

Plugin:
Prague
Plugin Slug:
prague-plugins
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.2.9.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Premium Addons PRO

Plugin:
Premium Addons PRO
Plugin Slug:
premium-addons-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.13.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
Broken Access Control
Patched in Version:
2.25.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.25.1.

Relevanssi Premium

Plugin:
Relevanssi Premium
Plugin Slug:
relevanssi-premium
Vulnerability:
SQL Injection
Patched in Version:
2.29.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.29.0.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.11.

Slider Revolution

Plugin:
Slider Revolution
Plugin Slug:
revslider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.11.

Salient Core

Plugin:
Salient Core
Plugin Slug:
salient-core
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.8.

Salient Shortcodes

Plugin:
Salient Shortcodes
Plugin Slug:
salient-shortcodes
Vulnerability:
Local File Inclusion
Patched in Version:
1.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.4.

Salient Shortcodes

Plugin:
Salient Shortcodes
Plugin Slug:
salient-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.4.

Schedula – Smart Appointment Booking

Plugin Slug:
schedula-smart-appointment-booking
Vulnerability:
Broken Access Control
Patched in Version:
1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Privilege Escalation
Patched in Version:
6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Privilege Escalation
Patched in Version:
6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.

Simple Locator

Plugin:
Simple Locator
Plugin Slug:
simple-locator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

The Grid

Plugin:
The Grid
Plugin Slug:
the-grid
Vulnerability:
Broken Access Control
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Ultimate Addons for WPBakery Page Builder

Plugin:
Ultimate Addons for WPBakery Page Builder
Plugin Slug:
ultimate_vc_addons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.20.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.20.1.

Web to SugarCRM Lead

Plugin Slug:
web-to-sugarcrm-lead
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Broken Authentication
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Social Login

Plugin:
WooCommerce Social Login
Plugin Slug:
woo-social-login
Vulnerability:
Privilege Escalation
Patched in Version:
2.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.4.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
30.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 30.1.

WooCommerce PDF Vouchers

Plugin:
WooCommerce PDF Vouchers
Plugin Slug:
woocommerce-pdf-vouchers
Vulnerability:
Broken Authentication
Patched in Version:
4.9.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.4.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

Affiliate Manager

Plugin:
Affiliate Manager
Plugin Slug:
wp-affiliate-platform
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.5.1.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.5.

WP eStore

Plugin:
WP eStore
Plugin Slug:
wp-cart-for-digital-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.5.6.

WP eMember

Plugin:
WP eMember
Plugin Slug:
wp-eMember
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.6.6.

WordPress Themes — 9 Patched / 14 Unpatched

Oxygen

Theme:
Oxygen
Theme Slug:
oxygen
Downloads
403,132
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Aardvark

Theme:
Aardvark
Theme Slug:
aardvark
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Capella

Theme:
Capella
Theme Slug:
capella
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Cas

Theme:
Cas
Theme Slug:
cas
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Cas

Theme:
Cas
Theme Slug:
cas
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gauge

Theme:
Gauge
Theme Slug:
gauge
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

KindlyCare

Theme:
KindlyCare
Theme Slug:
kindlycare
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Outdoor

Theme:
Outdoor
Theme Slug:
outdoor
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Oyster – Photography WordPress Theme

Theme:
Oyster – Photography WordPress Theme
Theme Slug:
oyster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PhotoMe

Theme:
PhotoMe
Theme Slug:
photome
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

SOHO – Photography WordPress Theme

Theme:
SOHO – Photography WordPress Theme
Theme Slug:
soho
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

The Wound

Theme:
The Wound
Theme Slug:
the-wound
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

WPJobster

Theme:
WPJobster
Theme Slug:
wpjobster
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

WPJobster

Theme:
WPJobster
Theme Slug:
wpjobster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OceanWP

Theme:
OceanWP
Theme Slug:
oceanwp
Downloads
9,187,846
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.6.1.

Divi

Theme:
Divi
Theme Slug:
divi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.27.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.27.2.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Himer

Theme:
Himer
Theme Slug:
himer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Jobify

Theme:
Jobify
Theme Slug:
jobify
Vulnerability:
Broken Access Control
Patched in Version:
4.2.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.8.

Konte

Theme:
Konte
Theme Slug:
konte
Vulnerability:
Broken Access Control
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

Travel Tour

Theme:
Travel Tour
Theme Slug:
traveltour
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security