WordPress Vulnerability Report

WordPress Vulnerability Report — February 5, 2025

This last week, 345 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 197 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 345 vulnerabilities have been publicly disclosed. Security patches for 148 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 197 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 146 Patched / 195 Unpatched

Shortcodes and extra features for Phlox theme

Plugin Slug:
auxin-elements
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meta Tag Manager

Plugin Slug:
meta-tag-manager
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Conditions

Plugin Slug:
dynamicconditions
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide Shipping Method For WooCommerce

Plugin Slug:
hide-shipping-method-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Payment Forms for Paystack

Plugin Slug:
payment-forms-for-paystack
Installations
3,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Blog, Posts and Category Filter for Elementor

Plugin Slug:
blog-posts-and-category-for-elementor
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nirweb support

Plugin Slug:
nirweb-support
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Scroll Styler

Plugin Slug:
scroll-styler
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Broadstreet

Plugin Slug:
broadstreet
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Job Board Manager

Plugin Slug:
job-board-manager
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Paytm Payment Donation

Plugin Slug:
paytm-donation
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Designer – Elementor Addons

Plugin Slug:
designer
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
internal-link-builder
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Press Pro

Plugin Slug:
music-press-pro
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Rotator

Plugin Slug:
appten-image-rotator
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

All push notification for WP

Plugin Slug:
all-push-notification
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Linear

Plugin:
Linear
Plugin Slug:
linear
Installations
60+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cwd-stealth-links
Installations
50+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Print PDF Generator and Publisher

Plugin Slug:
nopeamedia
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AIO Performance Profiler, Monitor, Optimize, Compress & Debug

Plugin Slug:
all-in-one-performance-accelerator
Installations
20+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Appointment Buddy Widget By Accrete

Plugin Slug:
appointment-buddy-online-appointment-booking-by-accrete
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ABC Notation

Plugin:
ABC Notation
Plugin Slug:
abc-notation
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:
Altra Side Menu
Plugin Slug:
altra-side-menu
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Altra Side Menu

Plugin:
Altra Side Menu
Plugin Slug:
altra-side-menu
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AnimateGL – Advanced Animation Plugin for WordPress

Plugin:
AnimateGL – Advanced Animation Plugin for WordPress
Plugin Slug:
animategl
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ask Me Anything (Anonymously)

Plugin:
Ask Me Anything (Anonymously)
Plugin Slug:
ask-me-anything-anonymously
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Auto SEO

Plugin:
Auto SEO
Plugin Slug:
auto-seo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BookPress – For Book Authors

Plugin:
BookPress – For Book Authors
Plugin Slug:
book-press
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BookPress – For Book Authors

Plugin:
BookPress – For Book Authors
Plugin Slug:
book-press
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Breaking News Ticker

Plugin:
Breaking News Ticker
Plugin Slug:
breaking-news-ticker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

brodos.net Onlineshop Plugin

Plugin:
brodos.net Onlineshop Plugin
Plugin Slug:
brodos-net-onlineshop
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:
Bulk Me Now!
Plugin Slug:
bulk-me-now
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:
Bulk Me Now!
Plugin Slug:
bulk-me-now
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Bulk Me Now!

Plugin:
Bulk Me Now!
Plugin Slug:
bulk-me-now
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CanvasFlow

Plugin:
CanvasFlow
Plugin Slug:
canvasflow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Child Themes Helper

Plugin:
Child Themes Helper
Plugin Slug:
child-themes-helper
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Competition Form

Plugin:
Competition Form
Plugin Slug:
competition-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Connections

Plugin:
Connections
Plugin Slug:
connections1
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Comment Notifications

Plugin:
Custom Comment Notifications
Plugin Slug:
custom-comment-notifications
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

A5 Custom Login Page

Plugin:
A5 Custom Login Page
Plugin Slug:
custom-login-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Custom Links On Admin Dashboard Toolbar
Plugin Slug:
customize-wpadmin
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Delete Comments By Status

Plugin:
Delete Comments By Status
Plugin Slug:
delete-comments-by-status
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dental Optimizer Patient Generator App

Plugin:
Dental Optimizer Patient Generator App
Plugin Slug:
dental-optimizer-patient-generator-app
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:
Dyn Business Panel
Plugin Slug:
dyn-business-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Dyn Business Panel

Plugin:
Dyn Business Panel
Plugin Slug:
dyn-business-panel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy Chart Builder for WordPress

Plugin:
Easy Chart Builder for WordPress
Plugin Slug:
easy-chart-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Easy Related Posts
Plugin Slug:
easy-related-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy WP Tiles

Plugin:
Easy WP Tiles
Plugin Slug:
easy-wp-tiles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ECPay Ecommerce for WooCommerce

Plugin:
ECPay Ecommerce for WooCommerce
Plugin Slug:
ecpay-ecommerce-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ECT Home Page Products

Plugin:
ECT Home Page Products
Plugin Slug:
ect-homepage-products
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Embed RSS

Plugin:
Embed RSS
Plugin Slug:
embed-rss
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Embed Swagger UI

Plugin:
Embed Swagger UI
Plugin Slug:
embed-swagger-ui
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Etsy Importer

Plugin:
Etsy Importer
Plugin Slug:
etsy-importer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

External Video For Everybody

Plugin:
External Video For Everybody
Plugin Slug:
external-video-for-everybody
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Facilita Form Tracker

Plugin:
Facilita Form Tracker
Plugin Slug:
facilita-form-tracker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fami Sales Popup

Plugin:
Fami Sales Popup
Plugin Slug:
fami-sales-popup
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fantastic Elasticsearch

Plugin:
Fantastic Elasticsearch
Plugin Slug:
fantastic-elasticsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fare Calculator

Plugin:
Fare Calculator
Plugin Slug:
fare-calculator
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Status Updater

Plugin:
Status Updater
Plugin Slug:
fb-status-updater
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

FlashCounter

Plugin:
FlashCounter
Plugin Slug:
flashcounter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Title (TypeWriter)

Plugin:
Post Title (TypeWriter)
Plugin Slug:
flashnews-typewriter-pearlbells
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FlexIDX Home Search
Plugin Slug:
flexidx-home-search
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Forge – Front-End Page Builder

Plugin:
Forge – Front-End Page Builder
Plugin Slug:
forge
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Frictionless

Plugin:
Frictionless
Plugin Slug:
frictionless
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Full Circle

Plugin:
Full Circle
Plugin Slug:
full-circle
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fyrebox Quizzes

Plugin:
Fyrebox Quizzes
Plugin Slug:
fyrebox-shortcode
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GlobalQuran

Plugin:
GlobalQuran
Plugin Slug:
globalquran
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

URL-Preview-Box

Plugin:
URL-Preview-Box
Plugin Slug:
good-url-preview-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Google Earth Embed

Plugin:
Google Earth Embed
Plugin Slug:
google-earth-tours
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Google Map Professional

Plugin:
WordPress Google Map Professional
Plugin Slug:
google-map-professional
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Graceful Email Obfuscation

Plugin:
Graceful Email Obfuscation
Plugin Slug:
graceful-email-obfuscation
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 chat

Plugin:
HTML5 chat
Plugin Slug:
html5-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Plugin A/B Image Optimizer

Plugin:
Plugin A/B Image Optimizer
Plugin Slug:
images-optimizer
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Implied Cookie Consent
Plugin Slug:
implied-cookie-consent
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Indeed API

Plugin:
Indeed API
Plugin Slug:
indeed-api
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Infusionsoft Analytics

Plugin:
Infusionsoft Analytics
Plugin Slug:
infusionsoft-web-tracker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

InLocation

Plugin:
InLocation
Plugin Slug:
inlocation
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Issuu Panel

Plugin:
Issuu Panel
Plugin Slug:
issuu-panel
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Vehicle Manager

Plugin:
WP Vehicle Manager
Plugin Slug:
js-vehicle-manager
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Event Kikfyre

Plugin:
Event Kikfyre
Plugin Slug:
kikfyre-events-calendar-tickets
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Kona Gallery Block
Plugin Slug:
kona-instagram-feed-for-gutenberg
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form and Calls To Action by vcita

Plugin:
Contact Form and Calls To Action by vcita
Plugin Slug:
lead-capturing-call-to-actions-by-vcita
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Like dislike plus counter

Plugin:
Like dislike plus counter
Plugin Slug:
like-dislike-plus-counter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Link to URL / Post

Plugin:
Link to URL / Post
Plugin Slug:
link-to-url-post
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Links in Captions
Plugin Slug:
links-in-captions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Live2DWebCanvas

Plugin:
Live2DWebCanvas
Plugin Slug:
live-2d
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Login-box

Plugin:
Login-box
Plugin Slug:
login-box
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MagicForm

Plugin:
MagicForm
Plugin Slug:
magicform
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Masy Gallery
Plugin Slug:
masy-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Munk Sites

Plugin:
Munk Sites
Plugin Slug:
munk-sites
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Music Sheet Viewer

Plugin:
Music Sheet Viewer
Plugin Slug:
music-sheet-viewer
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Music Sheet Viewer

Plugin:
Music Sheet Viewer
Plugin Slug:
music-sheet-viewer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
NextGen Cooliris Gallery
Plugin Slug:
nextgen-cooliris-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ni Sales Commission For WooCommerce

Plugin:
Ni Sales Commission For WooCommerce
Plugin Slug:
ni-woo-sales-commission
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NOTICE BOARD BY TOWKIR

Plugin:
NOTICE BOARD BY TOWKIR
Plugin Slug:
notice-board-by-towkir
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress SEO Friendly Accordion FAQ

Plugin:
WordPress SEO Friendly Accordion FAQ
Plugin Slug:
notice-faq
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

OneStore Sites

Plugin:
OneStore Sites
Plugin Slug:
onestore-sites
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

On Page SEO + Whatsapp Chat Button

Plugin:
On Page SEO + Whatsapp Chat Button
Plugin Slug:
ops-robots-txt
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Optimate Ads

Plugin:
Optimate Ads
Plugin Slug:
optimate-ads
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Link Fixer
Plugin Slug:
permalink-finder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Policy Genius

Plugin:
Policy Genius
Plugin Slug:
policy-genius
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pop Up

Plugin:
Pop Up
Plugin Slug:
popup-seo-optimized
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Carousel Slider

Plugin:
Post Carousel Slider
Plugin Slug:
post-carousel-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Power Ups for Elementor

Plugin:
Power Ups for Elementor
Plugin Slug:
power-ups-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quote Comments

Plugin:
Quote Comments
Plugin Slug:
quote-comments
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Read More Copy Link
Plugin Slug:
read-more-copy-link
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive iframe

Plugin:
Responsive iframe
Plugin Slug:
responsive-iframe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ReverbNation Widgets

Plugin:
ReverbNation Widgets
Plugin Slug:
reverbnation-widgets
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Royal Core

Plugin:
Royal Core
Plugin Slug:
royal-core
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RSS in Page

Plugin:
RSS in Page
Plugin Slug:
rss-in-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Safe Ai Malware Protection for WP

Plugin:
Safe Ai Malware Protection for WP
Plugin Slug:
safe-ai-malware-protection-for-wp
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons for WordPress

Plugin:
Social Share Buttons for WordPress
Plugin Slug:
share-buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Share Buttons for WordPress

Plugin:
Social Share Buttons for WordPress
Plugin Slug:
share-buttons
Vulnerability:
Path Traversal
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Show notice or message on admin area

Plugin:
Show notice or message on admin area
Plugin Slug:
show-notice-or-message-on-admin-area
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Auto Tag

Plugin:
Simple Auto Tag
Plugin Slug:
simple-auto-tag
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simple Select All Text Box

Plugin:
Simple Select All Text Box
Plugin Slug:
simple-select-all-text-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Profile

Plugin:
Simple User Profile
Plugin Slug:
simple-user-profile
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Single-user-chat

Plugin:
Single-user-chat
Plugin Slug:
single-user-chat
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slide Banners

Plugin:
Slide Banners
Plugin Slug:
slide-banners
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SlideDeck 1 Lite Content Slider

Plugin:
SlideDeck 1 Lite Content Slider
Plugin Slug:
slidedeck-lite-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Smart Countdown FX

Plugin:
Smart Countdown FX
Plugin Slug:
smart-countdown-fx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart DoFollow

Plugin:
Smart DoFollow
Plugin Slug:
smart-dofollow
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Links
Plugin Slug:
social-links
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Social Links
Plugin Slug:
social-links
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Songkick Concerts and Festivals

Plugin:
Songkick Concerts and Festivals
Plugin Slug:
songkick-concerts-and-festivals
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sports Rankings and Lists

Plugin:
Sports Rankings and Lists
Plugin Slug:
sports-rankings-lists
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

StageShow

Plugin:
StageShow
Plugin Slug:
stageshow
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Starter Templates by FancyWP

Plugin:
Starter Templates by FancyWP
Plugin Slug:
starter-templates
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Starter Templates by FancyWP

Plugin:
Starter Templates by FancyWP
Plugin Slug:
starter-templates
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stockdio Historical Chart

Plugin:
Stockdio Historical Chart
Plugin Slug:
stockdio-historical-chart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Style Tweaker

Plugin:
Style Tweaker
Plugin Slug:
style-tweaker
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

System Dashboard

Plugin:
System Dashboard
Plugin Slug:
system-dashboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tabulate

Plugin:
Tabulate
Plugin Slug:
tabulate
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theasys

Plugin:
Theasys
Plugin Slug:
theasys
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Theme Options Z

Plugin:
Theme Options Z
Plugin Slug:
theme-options-z
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Traveler Code

Plugin:
Traveler Code
Plugin Slug:
traveler-code
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Traveler Code

Plugin:
Traveler Code
Plugin Slug:
traveler-code
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Traveler Layout Essential For Elementor

Plugin:
Traveler Layout Essential For Elementor
Plugin Slug:
traveler-layout-essential-for-elementor
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Typer Core

Plugin:
Typer Core
Plugin Slug:
typer-core
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

uListing

Plugin:
uListing
Plugin Slug:
ulisting
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

uListing

Plugin:
uListing
Plugin Slug:
ulisting
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Messages

Plugin:
User Messages
Plugin Slug:
user-messages
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

User Role

Plugin:
User Role
Plugin Slug:
user-roles
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Manager for UserPro

Plugin:
Media Manager for UserPro
Plugin Slug:
userpro-mediamanager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Manager for UserPro

Plugin:
Media Manager for UserPro
Plugin Slug:
userpro-mediamanager
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Vignette Ads

Plugin:
Vignette Ads
Plugin Slug:
vignete-ads
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:
VR-Frases
Plugin Slug:
vr-frases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:
VR-Frases
Plugin Slug:
vr-frases
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VR-Frases

Plugin:
VR-Frases
Plugin Slug:
vr-frases
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WE – Testimonial Slider

Plugin:
WE – Testimonial Slider
Plugin Slug:
we-testimonial-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WizShop

Plugin:
WizShop
Plugin Slug:
wizshop
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wonder FontAwesome

Plugin:
Wonder FontAwesome
Plugin Slug:
wonder-fontawesome
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce osCommerce Sync

Plugin:
Woocommerce osCommerce Sync
Plugin Slug:
woo-oscommerce-sync
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Signature

Plugin:
WordPress Signature
Plugin Slug:
wordpress-signature
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Admin Custom Page

Plugin:
WP Admin Custom Page
Plugin Slug:
wp-admin-custom-page
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Contact Form7 Email Spam Blocker

Plugin:
WP Contact Form7 Email Spam Blocker
Plugin Slug:
wp-contact-form7-email-spam-blocker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Custom Post RSS Feed

Plugin:
WP Custom Post RSS Feed
Plugin Slug:
wp-custom-post-rss-feed
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Dispensary

Plugin:
WP Dispensary
Plugin Slug:
wp-dispensary
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Email Newsletter

Plugin:
WP Email Newsletter
Plugin Slug:
wp-email-newsletter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:
WP Finance
Plugin Slug:
wp-finance
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Finance

Plugin:
WP Finance
Plugin Slug:
wp-finance
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Find Your Nearest

Plugin:
WP Find Your Nearest
Plugin Slug:
wp-find-your-nearest
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Frontend Submit

Plugin:
WP Frontend Submit
Plugin Slug:
wp-frontend-submit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:
WP Image Uploader
Plugin Slug:
wp-image-uploader
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:
WP Image Uploader
Plugin Slug:
wp-image-uploader
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Image Uploader

Plugin:
WP Image Uploader
Plugin Slug:
wp-image-uploader
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Keyword Monitor

Plugin:
WP Keyword Monitor
Plugin Slug:
wp-keyword-monitor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP MediaTagger

Plugin:
WP MediaTagger
Plugin Slug:
wp-mediatagger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP MediaTagger

Plugin:
WP MediaTagger
Plugin Slug:
wp-mediatagger
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP SimpleWeather

Plugin:
WP SimpleWeather
Plugin Slug:
wp-simpleweather
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Social Stream

Plugin:
WP Social Stream
Plugin Slug:
wp-social-stream
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Spell Check

Plugin:
WP Spell Check
Plugin Slug:
wp-spell-check
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Survey & Poll

Plugin:
WordPress Survey & Poll
Plugin Slug:
wp-survey-and-poll
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:
WP Triggers Lite
Plugin Slug:
wp-triggers-lite
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Triggers Lite

Plugin:
WP Triggers Lite
Plugin Slug:
wp-triggers-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP doodlez

Plugin:
WP doodlez
Plugin Slug:
wpdoodlez
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Top Bar – PopUps – by WPOptin

Plugin:
Top Bar – PopUps – by WPOptin
Plugin Slug:
wpoptin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPRadio

Plugin:
WPRadio
Plugin Slug:
wpradio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Zalomení

Plugin:
Zalomení
Plugin Slug:
zalomeni
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ZMSEO

Plugin:
ZMSEO
Plugin Slug:
zmseo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

zStore Manager Basic

Plugin:
zStore Manager Basic
Plugin Slug:
zstore-manager-basic
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Orbit Fox by ThemeIsle

Plugin Slug:
themeisle-companion
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.10.45
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.10.45.

Tracking Code Manager

Plugin Slug:
tracking-code-manager
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.0.

Import any XML, CSV or Excel File to WordPress

Plugin Slug:
wp-all-import
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.8.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.0.

Event Tickets and Registration

Plugin Slug:
event-tickets
Installations
90,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.18.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.18.1.1.

HT Mega – Absolute Addons For Elementor

Plugin Slug:
ht-mega-for-elementor
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.7.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
90,000+
Vulnerability:
Local File Inclusion
Patched in Version:
4.8.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.8.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
90,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
4.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.8.8.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.2.7.5.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.2.7.5.1.

Import and export users and customers

Plugin Slug:
import-users-from-csv-with-meta
Installations
80,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.27.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.27.13.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.17
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.17.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.3.8.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.8.6.

Divi Torque Lite

Plugin Slug:
addons-for-divi
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.1.

Better Find and Replace

Plugin Slug:
real-time-auto-find-and-replace
Installations
50,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.6.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.8.

CF7 Google Sheets Connector

Plugin Slug:
cf7-google-sheets-connector
Installations
40,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.18
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.18.

NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar

Plugin Slug:
notificationx
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.0.

Contact Form & SMTP Plugin for WordPress by PirateForms

Plugin Slug:
pirate-forms
Installations
40,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
2.6.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.1.

Gwolle Guestbook

Plugin Slug:
gwolle-gb
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.2.

Stratum – Elementor Widgets

Plugin Slug:
stratum
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.5.0.
Plugin Slug:
wow-carousel-for-divi-lite
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

DSGVO All in one for WP

Plugin Slug:
dsgvo-all-in-one-for-wp
Installations
20,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.
Plugin Slug:
gt3-photo-video-gallery
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.7.7.25
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.7.7.25.

WP Customer Area

Plugin Slug:
customer-area
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
8.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.5.

Membership Plugin – Restrict Content

Plugin Slug:
restrict-content
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.2.14
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.14.

WooCommerce Product Table Lite

Plugin Slug:
wc-product-table-lite
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
3.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.5.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.3.

VikBooking Hotel Booking Engine & PMS

Plugin Slug:
vikbooking
Installations
8,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.7.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.3.

JS Help Desk – The Ultimate Help Desk & Support Plugin

Plugin Slug:
js-support-ticket
Installations
6,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
2.8.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.9.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.3.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.6.

Survey Maker

Plugin Slug:
survey-maker
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.3.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.1.3.4.

B Slider- Gutenberg Slider Block for WP

Plugin Slug:
b-slider
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.1.24
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.24.

Product Blocks for WooCommerce

Plugin Slug:
product-blocks-for-woocommerce
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

Custom Product Tabs Lite for WooCommerce

Plugin Slug:
woocommerce-custom-product-tabs-lite
Installations
5,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.1.

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.27.
Plugin Slug:
custom-related-posts
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.4.

Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out

Plugin Slug:
login-page-styler
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
7.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.2.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.0.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

aThemes Addons for Elementor

Plugin Slug:
athemes-addons-for-elementor-lite
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.13.

Automatically Hierarchic Categories in Menu

Plugin Slug:
automatically-hierarchic-categories-in-menu
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Multiple Page Generator Plugin – MPG

Plugin Slug:
multiple-pages-generator-by-porthas
Installations
3,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
4.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.6.

Eventer

Plugin:
Eventer
Plugin Slug:
eventer
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
3.9.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.9.9.

Medical Addon for Elementor

Plugin Slug:
medical-addon-for-elementor
Installations
2,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

Order Export for WooCommerce

Plugin Slug:
order-export-and-more-for-woocommerce
Installations
2,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.25
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.25.

Plethora Plugins Tabs + Accordions

Plugin Slug:
plethora-tabs-accordions
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

SendPulse Email Marketing Newsletter

Plugin Slug:
sendpulse-email-marketing-newsletter
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.6.

Ai Image Alt Text Generator for WP

Plugin Slug:
ai-image-alt-text-generator-for-wp
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

WordPress Contact Forms by Cimatti

Plugin Slug:
contact-forms
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.5.

CP Contact Form with PayPal

Plugin Slug:
cp-contact-form-with-paypal
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.53
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.53.

Flexmls® IDX Plugin

Plugin Slug:
flexmls-idx
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.14.27
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.14.27.

GoHero Store Customizer for WooCommerce

Plugin Slug:
personalize-woocommerce-cart-page
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.

RapidLoad – Optimize Web Vitals Automatically

Plugin Slug:
unusedcss
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.5.

W2S – Migrate WooCommerce to Shopify

Plugin Slug:
w2s-migrate-woo-to-shopify
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.0.

iControlWP

Plugin:
iControlWP
Plugin Slug:
worpit-admin-dashboard-plugin
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.5.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.5.0.

AI Infographic Maker

Plugin Slug:
infographic-and-list-builder-ilist
Installations
900+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Include Mastodon Feed

Plugin Slug:
include-mastodon-feed
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.10.

WP Sessions Time Monitoring Full Automatic

Plugin Slug:
activitytime
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Product Table For WooCommerce

Plugin Slug:
product-table-for-woocommerce
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.4.

Simple:Press Forum

Plugin Slug:
simplepress
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.10.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.10.12.

WP DataTable

Plugin Slug:
wp-datatable
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.2.7.

ELEX WordPress HelpDesk & Customer Ticketing System

Plugin Slug:
elex-helpdesk-customer-support-ticket-system
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.7.

Hesabfa Accounting

Plugin Slug:
hesabfa-accounting
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.1.3.

SeatReg

Plugin:
SeatReg
Plugin Slug:
seatreg
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.56.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.56.1.

Site Search 360

Plugin Slug:
site-search-360
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

Uix Shortcodes

Plugin Slug:
uix-shortcodes
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.4.

Disable Elementor Editor Translation

Plugin Slug:
disable-elementor-editor-translation
Installations
300+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.3.

OPSI Israel Domestic Shipments

Plugin Slug:
woo-ups-pickup
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.6.

Alex Reservations: Smart Restaurant Booking

Plugin Slug:
alex-reservations
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

Listings for Appfolio

Plugin Slug:
listings-for-appfolio
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.1.

Tags to Keywords

Plugin Slug:
tags-to-meta-keywords
Installations
200+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.2.

WP BASE Booking of Appointments, Services and Events

Plugin Slug:
wp-base-booking-of-appointments-services-and-events
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.0.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.8.4.

Target Video Easy Publish

Plugin Slug:
brid-video-easy-publish
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.4.

Clinked Client Portal

Plugin Slug:
clinked-client-portal
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.

DigiTimber cPanel Integration

Plugin Slug:
digitimber-cpanel-integration
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.8.
Plugin Slug:
gallery-for-ultimate-member
Installations
100+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.3.

Media Downloader

Plugin Slug:
media-downloader
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.4.7.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.4.7.6.

Morkva UA Shipping

Plugin Slug:
morkva-ua-shipping
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.20.

Content Cloner

Plugin Slug:
super-seo-content-cloner
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.2.

Unlimited Page Sidebars

Plugin Slug:
unlimited-page-sidebars
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
0.2.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.2.7.

WP Post List Table

Plugin Slug:
wp-post-list-table
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.4.

Table Editor

Plugin Slug:
wp-table-editor
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.0.

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.

Dynamic URL SEO

Plugin Slug:
dynamic-url-seo
Installations
80+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.

EthereumICO

Plugin Slug:
ethereumico
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.7.

MailUp Auto Subscription

Plugin Slug:
mailup-auto-subscribtion
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.0.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
80+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.6.10
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.6.10.

Infility Global

Plugin Slug:
infility-global
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.9.9.

Philantro – Donations and Donor Management

Plugin Slug:
philantro
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.

Bilingual Linker

Plugin Slug:
bilingual-linker
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Ticketmeo – Sell Tickets – Event Ticketing

Plugin Slug:
ploxel
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.0.

ShopSite

Plugin:
ShopSite
Plugin Slug:
shopsite-plugin
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.5.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.11.

eHive Objects Image Grid

Plugin Slug:
ehive-objects-image-grid
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.2.

Awesome Event Booking

Plugin Slug:
awesome-event-booking
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
2.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.5.

Awesome Event Booking

Plugin Slug:
awesome-event-booking
Installations
40+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

Boom Fest

Plugin:
Boom Fest
Plugin Slug:
boom-fest
Installations
40+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.

Admin and Site Enhancements (ASE) Pro

Plugin:
Admin and Site Enhancements (ASE) Pro
Plugin Slug:
admin-site-enhancements-pro
Vulnerability:
Privilege Escalation
Patched in Version:
7.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.6.3.

BoomBox Theme Extensions

Plugin:
BoomBox Theme Extensions
Plugin Slug:
boombox-theme-extensions
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.1.

Elementor Pro

Plugin:
Elementor Pro
Plugin Slug:
elementor-pro
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.25.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.25.11.

ElementsKit Pro

Plugin:
ElementsKit Pro
Plugin Slug:
elementskit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.9.

Goodlayers Core

Plugin:
Goodlayers Core
Plugin Slug:
goodlayers-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.3.

Oshine Modules

Plugin:
Oshine Modules
Plugin Slug:
oshine-modules
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
3.3.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.3.8.

Tourmaster

Plugin:
Tourmaster
Plugin Slug:
tourmaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.5.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.34.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.34.0.

ThemeREX Addons

Plugin:
ThemeREX Addons
Plugin Slug:
trx_addons
Vulnerability:
Local File Inclusion
Patched in Version:
2.34.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.34.0.

WooCommerce Customers Manager

Plugin:
WooCommerce Customers Manager
Plugin Slug:
woocommerce-customers-manager
Vulnerability:
Broken Access Control
Patched in Version:
31.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 31.4.

MultiLoca – WooCommerce Multi Locations Inventory Management

Plugin:
MultiLoca – WooCommerce Multi Locations Inventory Management
Plugin Slug:
woocommerce-multi-locations-inventory-management
Vulnerability:
SQL Injection
Patched in Version:
4.1.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.1.12.

WooCommerce Support Ticket System

Plugin:
WooCommerce Support Ticket System
Plugin Slug:
woocommerce-support-ticket-system
Vulnerability:
Broken Access Control
Patched in Version:
17.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 17.9.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.2.

WP ALL Export Pro

Plugin:
WP ALL Export Pro
Plugin Slug:
wp-all-export-pro
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.9.2.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.9.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.9.8.

WP All Import Pro

Plugin:
WP All Import Pro
Plugin Slug:
wp-all-import-pro
Vulnerability:
PHP Object Injection
Patched in Version:
4.9.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.9.8.

WPJobBoard

Plugin:
WPJobBoard
Plugin Slug:
wpjobboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.11.1.

WordPress Themes — 2 Patched / 2 Unpatched

OnePress

Theme:
OnePress
Theme Slug:
onepress
Downloads
2,352,920
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Storely

Theme:
Storely
Theme Slug:
storely
Downloads
470,680
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

SocialV

Theme:
SocialV
Theme Slug:
socialv
Vulnerability:
Broken Access Control
Patched in Version:
2.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.16.

Zox News

Theme:
Zox News
Theme Slug:
zox-news
Vulnerability:
Broken Access Control
Patched in Version:
3.17.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.17.0.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security