WordPress Vulnerability Report

WordPress Vulnerability Report — January 14, 2026

Since last week, 282 new vulnerabilities have emerged in the WordPress ecosystem, including 233 plugins and 49 themes. Of those, 162 remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 282 vulnerabilities have been publicly disclosed. Security patches for 120 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Currently, 162 plugin and theme vulnerabilities remain unpatched. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.9 “Gene” was released on December 2, 2025, adding Notes for block-level comments, an expanded Command Palette, and the new Abilities API to standardize permissions for future automation. It also includes performance improvements and new blocks and design tools to support faster, more flexible site building.

After any major release, don’t update live sites until you’ve taken backups and tested in a non-production environment.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 106 Patched / 127 Unpatched

Cookies and Content Security Policy

Plugin Slug:
cookies-and-content-security-policy
Installations
10,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Pricing Table

Plugin Slug:
dk-pricr-responsive-pricing-table
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Yoco Payments

Plugin Slug:
yoco-payment-gateway
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Campaign Monitor for WordPress

Plugin Slug:
forms-for-campaign-monitor
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Slider Slideshow

Plugin Slug:
image-slider-slideshow
Installations
3,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
nextgen-download-gallery
Installations
3,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Speed Kit

Plugin:
Speed Kit
Plugin Slug:
baqend
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

BD Courier Order Ratio Checker

Plugin Slug:
bd-courier-order-ratio-checker
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Welcome for Beaver Builder

Plugin Slug:
dashboard-welcome-for-beaver-builder
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GA4WP – Analytics Dashboard for the Website

Plugin Slug:
ga-for-wp
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IMGspider – ????????

Plugin Slug:
imgspider
Installations
2,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

teachPress

Plugin:
teachPress
Plugin Slug:
teachpress
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

X Addons for Elementor

Plugin Slug:
x-addons-elementor
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
regallery
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HBLPAY Payment Gateway for WooCommerce

Plugin Slug:
hblpay-payment-gateway-for-woocommerce
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Page Keys

Plugin:
Page Keys
Plugin Slug:
page-keys
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Money Space

Plugin Slug:
money-space
Installations
70+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AI BotKit – AI Chatbot & Live Chat for WordPress (No-Code)

Plugin Slug:
ai-botkit-for-lead-generation
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FireStorm Professional Real Estate Plugin

Plugin Slug:
fs-real-estate-plugin
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

1180px Shortcodes

Plugin:
1180px Shortcodes
Plugin Slug:
1180px-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Virtual Assistant

Plugin:
WP Virtual Assistant
Plugin Slug:
VirtualAssistant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Attractive Donations System – Easy Stripe & Paypal donations

Plugin:
WP Attractive Donations System – Easy Stripe & Paypal donations
Plugin Slug:
WP_AttractiveDonationsSystem
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AA Block country

Plugin:
AA Block country
Plugin Slug:
aa-block-country
Vulnerability:
Bypass Vulnerability
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accordion Slider PRO

Plugin:
Accordion Slider PRO
Plugin Slug:
accordion_slider_pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACF to REST API

Plugin:
ACF to REST API
Plugin Slug:
acf-to-rest-api
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AD Sliding FAQ

Plugin:
AD Sliding FAQ
Plugin Slug:
ad-sliding-faq
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AH Shortcodes

Plugin:
AH Shortcodes
Plugin Slug:
ah-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

AS Password Field In Default Registration Form

Plugin:
AS Password Field In Default Registration Form
Plugin Slug:
as-password-field-in-default-registration-form
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Autogen Headers Menu

Plugin:
Autogen Headers Menu
Plugin Slug:
autogen-headers-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Awesome Hotel Booking

Plugin Slug:
awesome-hotel-booking
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Page Permalink Extension
Plugin Slug:
change-wp-page-permalinks
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form vCard Generator

Plugin:
Contact Form vCard Generator
Plugin Slug:
contact-form-vcard-generator
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Us Simple Form

Plugin:
Contact Us Simple Form
Plugin Slug:
contact-us-simple-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cool YT Player

Plugin:
Cool YT Player
Plugin Slug:
cool-yt-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CountDown With Image or Video Background

Plugin:
CountDown With Image or Video Background
Plugin Slug:
countdown-with-background
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Curved Text

Plugin:
Curved Text
Plugin Slug:
curved-text
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Debt.com Business in a Box

Plugin:
Debt.com Business in a Box
Plugin Slug:
debtcom-business-in-a-box
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
DZS Video Gallery
Plugin Slug:
dzs-videogallery
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Easy GitHub Gist Shortcodes

Plugin:
Easy GitHub Gist Shortcodes
Plugin Slug:
easy-github-gist-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EDD Download Info

Plugin:
EDD Download Info
Plugin Slug:
edd-download-info
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Customizer for WooCommerce

Plugin:
Email Customizer for WooCommerce
Plugin Slug:
email-customizer-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Entry Views

Plugin:
Entry Views
Plugin Slug:
entry-views
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Famous – Responsive Image And Video Grid Gallery WordPress Plugin
Plugin Slug:
famous_grid_image_and_video_gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Felan Framework

Plugin:
Felan Framework
Plugin Slug:
felan-framework
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Felan Framework

Plugin:
Felan Framework
Plugin Slug:
felan-framework
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Flashcard

Plugin:
Flashcard
Plugin Slug:
flashcard
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ShareThis Dashboard for Google Analytics

Plugin:
ShareThis Dashboard for Google Analytics
Plugin Slug:
googleanalytics
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Handmade Framework

Plugin:
Handmade Framework
Plugin Slug:
handmade-framework
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Header and Footer Scripts
Plugin Slug:
header-and-footer-scripts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

HelpDesk contact form

Plugin:
HelpDesk contact form
Plugin Slug:
helpdesk-contact-form
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

JNews – Frontend Submit

Plugin:
JNews – Frontend Submit
Plugin Slug:
jnews-frontend-submit
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Latest Tabs

Plugin:
Latest Tabs
Plugin Slug:
kento-latest-tabs
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Key Figures

Plugin:
Key Figures
Plugin Slug:
key-figures
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Latest Registered Users

Plugin:
Latest Registered Users
Plugin Slug:
latest-registered-users
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Video Player

Plugin:
HTML5 Video Player
Plugin Slug:
lbg-vp2-html5-bottom
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HTML5 Video Player with Playlist & Multiple Skins

Plugin:
HTML5 Video Player with Playlist & Multiple Skins
Plugin Slug:
lbg-vp2-html5-rightside
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image&Video FullScreen Background

Plugin:
Image&Video FullScreen Background
Plugin Slug:
lbg_fullscreen_fullwidth_slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Lesson Plan Book

Plugin:
Lesson Plan Book
Plugin Slug:
lesson-plan-book
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ListingHub

Plugin:
ListingHub
Plugin Slug:
listinghub
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Magic Responsive Slider and Carousel WordPress
Plugin Slug:
magic_carousel
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Magic Slider

Plugin:
Magic Slider
Plugin Slug:
magic_slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mamurjor Employee Info

Plugin:
Mamurjor Employee Info
Plugin Slug:
mamurjor-employee-info
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Menu Card

Plugin:
Menu Card
Plugin Slug:
menu-card
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MG AdvancedOptions

Plugin:
MG AdvancedOptions
Plugin Slug:
mg-advancedoptions
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Moosend Landing Pages

Plugin:
Moosend Landing Pages
Plugin Slug:
moosend-landing-pages
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Mstoic Shortcodes

Plugin:
Mstoic Shortcodes
Plugin Slug:
mstoic-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MTCaptcha

Plugin:
MTCaptcha
Plugin Slug:
mtcaptcha
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Plugin:
Multi-column Tag Map
Plugin Slug:
multi-column-tag-map
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
My Album Gallery
Plugin Slug:
my-album-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
My Album Gallery
Plugin Slug:
my-album-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Nearby Now Reviews

Plugin:
Nearby Now Reviews
Plugin Slug:
nearby-now-reviews
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Newsletter Email Subscribe

Plugin:
Newsletter Email Subscribe
Plugin Slug:
newsletter-email-subscribe
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Niche Hero

Plugin:
Niche Hero
Plugin Slug:
niche-hero
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

nK Themes Helper

Plugin:
nK Themes Helper
Plugin Slug:
nk-themes-helper
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NS Ie Compatibility Fixer

Plugin:
NS Ie Compatibility Fixer
Plugin Slug:
ns-ie-compatibility-fixer
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Optional Email

Plugin:
Optional Email
Plugin Slug:
optional-email
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PhotoFade

Plugin:
PhotoFade
Plugin Slug:
photofade
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Like Dislike

Plugin:
Post Like Dislike
Plugin Slug:
post-like-dislike
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PullQuote

Plugin:
PullQuote
Plugin Slug:
pullquote
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Pure WC Variation Swatches

Plugin:
Pure WC Variation Swatches
Plugin Slug:
pure-wc-variations-swatches
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

QR Code Tag for WC

Plugin:
QR Code Tag for WC
Plugin Slug:
qr-code-tag-for-wc-from-goaskle-com
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Quote Comments

Plugin:
Quote Comments
Plugin Slug:
quote-comments
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rankology SEO and Analytics Tool

Plugin:
Rankology SEO and Analytics Tool
Plugin Slug:
rankology-seo-and-analytics-tool
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Real Estate Pro

Plugin:
Real Estate Pro
Plugin Slug:
real-estate-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

REHub Framework

Plugin:
REHub Framework
Plugin Slug:
rehub-framework
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Shabat Keeper

Plugin:
Shabat Keeper
Plugin Slug:
shabat-keeper
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Simcast

Plugin:
Simcast
Plugin Slug:
simcast
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Simple User Meta Editor

Plugin:
Simple User Meta Editor
Plugin Slug:
simple-user-meta-editor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart App Banners

Plugin:
Smart App Banners
Plugin Slug:
smart-app-banners
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Snillrik Restaurant

Plugin:
Snillrik Restaurant
Plugin Slug:
snillrik-restaurant-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Starred Review

Plugin:
Starred Review
Plugin Slug:
starred-review
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Sticky Action Buttons

Plugin:
Sticky Action Buttons
Plugin Slug:
sticky-action-buttons
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
STM Gallery 1.9
Plugin Slug:
stm-gallery
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Stumble! for WordPress

Plugin:
Stumble! for WordPress
Plugin Slug:
stumble-for-wordpress
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Stylish Order Form Builder

Plugin:
Stylish Order Form Builder
Plugin Slug:
stylish-order-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Super Interactive Maps

Plugin:
Super Interactive Maps
Plugin Slug:
super-interactive-maps
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SVG Map Plugin

Plugin:
SVG Map Plugin
Plugin Slug:
svg-map-by-saedi
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Testimonial Master

Plugin:
Testimonial Master
Plugin Slug:
testimonial-master
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Tooltip

Plugin:
The Tooltip
Plugin Slug:
the-tooltip
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Top Position Google Finance

Plugin:
Top Position Google Finance
Plugin Slug:
top-position-google-finance
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

xPromoter

Plugin:
xPromoter
Plugin Slug:
top_bar_promoter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

twinklesmtp

Plugin:
twinklesmtp
Plugin Slug:
twinklesmtp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Unify

Plugin:
Unify
Plugin Slug:
unify
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

User Activity Log

Plugin:
User Activity Log
Plugin Slug:
user-activity-log
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Viitor Button Shortcodes

Plugin:
Viitor Button Shortcodes
Plugin Slug:
viitor-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Wish To Go

Plugin:
Wish To Go
Plugin Slug:
wish-to-go
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Premmerce WooCommerce Customers Manager

Plugin:
Premmerce WooCommerce Customers Manager
Plugin Slug:
woo-customers-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Piraeus Bank WooCommerce Payment Gateway

Plugin:
Piraeus Bank WooCommerce Payment Gateway
Plugin Slug:
woo-payment-gateway-for-piraeus-bank
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Orders & Customers Exporter

Plugin:
WooCommerce Orders & Customers Exporter
Plugin Slug:
woocommerce-orders-ei
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woodpecker for WordPress

Plugin:
Woodpecker for WordPress
Plugin Slug:
woodpecker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Workreap (theme’s plugin)

Plugin:
Workreap (theme’s plugin)
Plugin Slug:
workreap
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Status Notifier

Plugin:
WP Status Notifier
Plugin Slug:
wp-change-status-notifier
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Client Testimonial Slider

Plugin:
Client Testimonial Slider
Plugin Slug:
wp-client-testimonial
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Enable WebP

Plugin:
WP Enable WebP
Plugin Slug:
wp-enable-webp
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Js List Pages Shortcodes

Plugin:
WP Js List Pages Shortcodes
Plugin Slug:
wp-js-list-pages-shortcodes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:
WP Lead Capturing Pages
Plugin Slug:
wp-lead-capture
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Lead Capturing Pages

Plugin:
WP Lead Capturing Pages
Plugin Slug:
wp-lead-capture
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Recipe Manager

Plugin:
WP Recipe Manager
Plugin Slug:
wp-recipe-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Widget Changer

Plugin:
WP Widget Changer
Plugin Slug:
wp-widget-changer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Popup Magic

Plugin:
WP Popup Magic
Plugin Slug:
wppopupmagic
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

xShare

Plugin:
xShare
Plugin Slug:
xshare
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Events Calendar

Plugin Slug:
the-events-calendar
Installations
700,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.15.13
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.15.13.

Download Manager

Plugin Slug:
download-manager
Installations
100,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.41
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.41.

GiveWP – Donation Plugin and Fundraising Platform

Plugin Slug:
give
Installations
100,000+
Vulnerability:
Content Injection
Patched in Version:
4.13.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.13.2.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.4.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.4.

Tutor LMS – eLearning and online course solution

Plugin Slug:
tutor
Installations
100,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.9.4.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
90,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.11.

AMP for WP – Accelerated Mobile Pages

Plugin Slug:
accelerated-mobile-pages
Installations
90,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.1.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.10.

Depicter — Popup & Slider Builder

Plugin Slug:
depicter
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.0.

Depicter — Popup & Slider Builder

Plugin Slug:
depicter
Installations
90,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.5.

Customer Reviews for WooCommerce

Plugin Slug:
customer-reviews-woocommerce
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.94.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.94.0.

Jupiter X Core

Plugin Slug:
jupiterx-core
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
4.11.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.11.0.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
4.3.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.2.

LearnPress – WordPress LMS Plugin

Plugin Slug:
learnpress
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.2.1.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
SQL Injection
Patched in Version:
5.2.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.5.

WooCommerce Square

Plugin Slug:
woocommerce-square
Installations
80,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.1.2.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.4.

SlimStat Analytics

Plugin Slug:
wp-slimstat
Installations
80,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.5.

Drag and Drop Multiple File Upload for Contact Form 7

Plugin Slug:
drag-and-drop-multiple-file-upload-contact-form-7
Installations
60,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.3.9.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.9.3.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.4.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.4.9.

Table Field Add-on for ACF and SCF

Plugin Slug:
advanced-custom-fields-table-field
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.31.

Blog2Social: Social Media Auto Post & Scheduler

Plugin Slug:
blog2social
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
8.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.7.3.

Booking Calendar

Plugin Slug:
booking
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
10.14.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.14.11.

EmailKit – Email Customizer for WooCommerce & WP

Plugin Slug:
emailkit
Installations
50,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.6.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.2.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
50,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
3.5.4.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.5.

WP Table Builder – Drag & Drop Table Builder

Plugin Slug:
wp-table-builder
Installations
50,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.20
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.20.

BulletProof Security

Plugin Slug:
bulletproof-security
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
7.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.8.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.8.9.

Docket Cache – Object Cache Accelerator

Plugin Slug:
docket-cache
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
24.07.05
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 24.07.05.

Icegram Engage – Popups, Optins, CTAs & lot more…

Plugin Slug:
icegram
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.1.36
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.36.

Quiz Maker

Plugin:
Quiz Maker
Plugin Slug:
quiz-maker
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.7.0.89
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.0.89.

Brevo for WooCommerce

Plugin Slug:
woocommerce-sendinblue-newsletter-subscription
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.0.50
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.50.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.28.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.28.24.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.28.26
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.28.26.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Privilege Escalation
Patched in Version:
3.28.26
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.28.26.

AffiliateX – Amazon Affiliate Plugin

Plugin Slug:
affiliatex
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.0.

Demo Importer Plus

Plugin Slug:
demo-importer-plus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.9.

Easy Media Download

Plugin Slug:
easy-media-download
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.12
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.12.

Form Vibes – Database Manager for Forms

Plugin Slug:
form-vibes
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

ShopMagic – email automation

Plugin Slug:
shopmagic-for-woocommerce
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
4.7.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.7.3.

Team – Team Members Showcase Plugin

Plugin Slug:
tlp-team
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
5.0.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.11.

Japanized for WooCommerce

Plugin Slug:
woocommerce-for-japan
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

WP Photo Album Plus

Plugin Slug:
wp-photo-album-plus
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.05.009
Severity Score:
High
The vulnerability has been patched, so you should update to version 9.1.05.009.

Xagio SEO – AI Powered SEO

Plugin Slug:
xagio-seo
Installations
10,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
7.1.0.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.1.0.31.

NEX-Forms – Ultimate Forms Plugin for WordPress

Plugin Slug:
nex-forms-express-wp-form-builder
Installations
8,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
9.1.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 9.1.8.

MediaPress

Plugin:
MediaPress
Plugin Slug:
mediapress
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.3.

BuddyPress Xprofile Custom Field Types

Plugin Slug:
bp-xprofile-custom-field-types
Installations
4,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.0.

FastDup – Fastest WordPress Migration & Duplicator

Plugin Slug:
fastdup
Installations
4,000+
Vulnerability:
Path Traversal
Patched in Version:
2.7.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.7.1.

FlexTable – Data Table Sync with Google Sheets

Plugin Slug:
sheets-to-wp-table-live-sync
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.19.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.19.2.

Better Business Reviews – Trustpilot WordPress Plugin

Plugin Slug:
better-business-reviews
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.1.2.

The Events Calendar Countdown Addon

Plugin Slug:
countdown-for-the-events-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.4.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.4.16.

Bulk Page Generator – LPagery

Plugin Slug:
lpagery
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.10.

Spiffy Calendar

Plugin Slug:
spiffy-calendar
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
5.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.8.

Tickera – Sell Tickets & Manage Events

Plugin Slug:
tickera-event-ticketing-system
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.6.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.6.5.

RSS Feed Widget

Plugin Slug:
rss-feed-widget
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.0.3.

CBX Bookmark & Favorite

Plugin Slug:
cbxwpbookmark
Installations
1,000+
Vulnerability:
SQL Injection
Patched in Version:
2.0.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.5.

Proxy & VPN Blocker

Plugin Slug:
proxy-vpn-blocker
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

ForumWP – Forum & Discussion Board

Plugin Slug:
forumwp
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.7.

IndieWeb

Plugin:
IndieWeb
Plugin Slug:
indieweb
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.0.

Recras

Plugin:
Recras
Plugin Slug:
recras
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.2.

URL Image Importer

Plugin Slug:
url-image-importer
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.8.

miniOrange OTP Verification and SMS Notification for WooCommerce

Plugin Slug:
miniorange-sms-order-notification-otp-verification
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
4.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.9.

ilGhera Support System for WooCommerce

Plugin Slug:
wc-support-system
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.7.
Plugin Slug:
ehive-search
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.1.

FS Registration Password

Plugin Slug:
registration-password
Installations
40+
Vulnerability:
Privilege Escalation
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

iPaymu Payment Gateway for WooCommerce

Plugin Slug:
ipaymu-for-woocommerce
Installations
10+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.3.

Page Expire Popup/Redirection for WordPress

Plugin Slug:
page-expire-popup
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.

Automotive Listings

Plugin:
Automotive Listings
Plugin Slug:
automotive
Vulnerability:
SQL Injection
Patched in Version:
18.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 18.7.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.7.8.

Listeo Core

Plugin:
Listeo Core
Plugin Slug:
listeo-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.19.

TheGem Theme Elements (for WPBakery)

Plugin:
TheGem Theme Elements (for WPBakery)
Plugin Slug:
thegem-elements
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.11.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.1.

TheGem Theme Elements (for Elementor)

Plugin:
TheGem Theme Elements (for Elementor)
Plugin Slug:
thegem-elements-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.11.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.11.1.

TheGem Theme Elements (for Elementor)

Plugin:
TheGem Theme Elements (for Elementor)
Plugin Slug:
thegem-elements-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
5.11.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.11.1.

Woffice Core

Plugin:
Woffice Core
Plugin Slug:
woffice-core
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
5.4.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.4.31.

WordPress Themes — 14 Patched / 35 Unpatched

AeroLand

Theme:
AeroLand
Theme Slug:
aeroland
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Amuli

Theme:
Amuli
Theme Slug:
amuli
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Anarkali

Theme:
Anarkali
Theme Slug:
anarkali
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Athens

Theme:
Athens
Theme Slug:
athens
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Atlas

Theme:
Atlas
Theme Slug:
atlas
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

AutoParts

Theme:
AutoParts
Theme Slug:
autoparts
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Barberry

Theme:
Barberry
Theme Slug:
barberry
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Brook

Theme:
Brook
Theme Slug:
brook
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Consult Aid

Theme:
Consult Aid
Theme Slug:
consultaid
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

DeepDigital

Theme:
DeepDigital
Theme Slug:
deepdigital
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Depot

Theme:
Depot
Theme Slug:
depot
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Drone

Theme:
Drone
Theme Slug:
drone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Electron

Theme:
Electron
Theme Slug:
electron
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Energia

Theme:
Energia
Theme Slug:
energia
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Melania

Theme:
Melania
Theme Slug:
melania
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Mella

Theme:
Mella
Theme Slug:
mella
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Mitech

Theme:
Mitech
Theme Slug:
mitech
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Myour

Theme:
Myour
Theme Slug:
myour
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Navian

Theme:
Navian
Theme Slug:
navian
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

OchaHouse

Theme:
OchaHouse
Theme Slug:
ochahouse
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Oshine

Theme:
Oshine
Theme Slug:
oshin
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Promo

Theme:
Promo
Theme Slug:
promo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Racquet

Theme:
Racquet
Theme Slug:
racquet
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Reprizo

Theme:
Reprizo
Theme Slug:
reprizo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Right Way

Theme:
Right Way
Theme Slug:
rightway
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Rozy – Flower Shop

Theme:
Rozy – Flower Shop
Theme Slug:
rozy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Search & Go

Theme:
Search & Go
Theme Slug:
search-and-go
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

TheNa

Theme:
TheNa
Theme Slug:
thena
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Moody

Theme:
Moody
Theme Slug:
tm-moody
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Typify

Theme:
Typify
Theme Slug:
typify
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

VideoPro

Theme:
VideoPro
Theme Slug:
videopro
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

xSmart

Theme:
xSmart
Theme Slug:
xsmart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zorka

Theme:
Zorka
Theme Slug:
zorka
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Phlox

Theme:
Phlox
Theme Slug:
phlox
Downloads
1,711,142
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.17.11
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.17.11.

Corpkit

Theme:
Corpkit
Theme Slug:
corpkit
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.1.

Corpkit

Theme:
Corpkit
Theme Slug:
corpkit
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.0.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.1.

Curly

Theme:
Curly
Theme Slug:
curly
Vulnerability:
Local File Inclusion
Patched in Version:
3.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.

Grand Restaurant

Theme:
Grand Restaurant
Theme Slug:
grandrestaurant
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.0.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.0.9.

Hendon

Theme:
Hendon
Theme Slug:
hendon
Vulnerability:
Local File Inclusion
Patched in Version:
1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.

Jobify

Theme:
Jobify
Theme Slug:
jobify
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.3.1.

Lobo

Theme:
Lobo
Theme Slug:
lobo
Vulnerability:
SQL Injection
Patched in Version:
2.8.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.6.

Neo Ocular

Theme:
Neo Ocular
Theme Slug:
neoocular
Vulnerability:
Local File Inclusion
Patched in Version:
1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.

Optimize

Theme:
Optimize
Theme Slug:
optimizewp
Vulnerability:
Local File Inclusion
Patched in Version:
2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.4.

Photography

Theme:
Photography
Theme Slug:
photography
Vulnerability:
Local File Inclusion
Patched in Version:
7.7.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.7.5.

Traveler

Theme:
Traveler
Theme Slug:
traveler
Vulnerability:
Broken Access Control
Patched in Version:
3.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.7.

Wellspring

Theme:
Wellspring
Theme Slug:
wellspring
Vulnerability:
Local File Inclusion
Patched in Version:
2.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.

Woffice

Theme:
Woffice
Theme Slug:
woffice
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.4.31
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.4.31.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security