In this report, 486 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.
Additionally, there are 393 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.
WordPress Core
WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.
WordPress Plugins — 90 Patched / 371 Unpatched
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
- Plugin Slug:
- post-and-page-builder
- Installations
- 70,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22759
CoDesigner – All in One Elementor WooCommerce Builder
- Plugin Slug:
- woolementor
- Installations
- 9,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22788
Bold pagos en linea
- Plugin:
- Bold pagos en linea
- Plugin Slug:
- bold-pagos-en-linea
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22793
GSheetConnector for Forminator Forms
- Plugin Slug:
- gsheetconnector-forminator
- Installations
- 700+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22752
Post Carousel & Slider
- Plugin:
- Post Carousel & Slider
- Plugin Slug:
- post-types-carousel-slider
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22750
Product Carousel For WooCommerce – WoorouSell
- Plugin Slug:
- woorousell
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22724
WP Headmaster
- Plugin:
- WP Headmaster
- Plugin Slug:
- wp-headmaster
- Installations
- 200+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22755
Course Booking System
- Plugin:
- Course Booking System
- Plugin Slug:
- course-booking-system
- Installations
- 100+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-22785
Neon Product Designer
- Plugin:
- Neon Product Designer
- Plugin Slug:
- neon-product-designer-for-woocommerce
- Installations
- 100+
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22799
Partners
- Plugin:
- Partners
- Plugin Slug:
- partners
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22751
Online Payments – Get Paid with PayPal, Square & Stripe
- Plugin Slug:
- paypal-payment-button-by-vcita
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22661
WP Order By
- Plugin:
- WP Order By
- Plugin Slug:
- wp-order-by
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22765
WR Price List Manager For Woocommerce
- Plugin Slug:
- wr-price-list-for-woocommerce
- Installations
- 100+
- Vulnerability:
- Remote Code Execution (RCE)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-22782
Estatebud – Properties & Listings
- Plugin Slug:
- estatebud-properties-listings
- Installations
- 90+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23994
Amber
- Plugin:
- Amber
- Plugin Slug:
- amberlink
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22754
Multilang Contact Form
- Plugin:
- Multilang Contact Form
- Plugin Slug:
- multilang-contact-form
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22795
Responsive jQuery Slider
- Plugin:
- Responsive jQuery Slider
- Plugin Slug:
- responsive-jquery-slider
- Installations
- 80+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22798
Gallery and Lightbox
- Plugin:
- Gallery and Lightbox
- Plugin Slug:
- gallery-and-lightbox
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22797
User Management
- Plugin:
- User Management
- Plugin Slug:
- user-management
- Installations
- 70+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22736
WP Post Corrector
- Plugin:
- WP Post Corrector
- Plugin Slug:
- wp-post-corrector
- Installations
- 70+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22764
Foundation Columns
- Plugin:
- Foundation Columns
- Plugin Slug:
- foundation-columns
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22747
Navigation Du Lapin Blanc
- Plugin:
- Navigation Du Lapin Blanc
- Plugin Slug:
- navigation-du-lapin-blanc
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22745
WordPress HelpDesk & Support Ticket System Plugin – Octrace Support
- Plugin Slug:
- octrace-support
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22762
S-DEV SEO
- Plugin:
- S-DEV SEO
- Plugin Slug:
- s-dev-seo
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22744
SetMore Theme – Custom Post Types
- Plugin Slug:
- service-provider-profile-cpt
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22748
Social Media Engine
- Plugin:
- Social Media Engine
- Plugin Slug:
- social-media-engine
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22749
WP ViewSTL
- Plugin:
- WP ViewSTL
- Plugin Slug:
- wp-viewstl
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22742
HireHive Job Plugin
- Plugin:
- HireHive Job Plugin
- Plugin Slug:
- zartis-job-plugin
- Installations
- 50+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22746
Ajax Contact Form
- Plugin:
- Ajax Contact Form
- Plugin Slug:
- fws-ajax-contact-form
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22761
Related Post Shortcode
- Plugin:
- Related Post Shortcode
- Plugin Slug:
- related-post-shortcode
- Installations
- 30+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22276
CodeBard Help Desk
- Plugin:
- CodeBard Help Desk
- Plugin Slug:
- codebard-help-desk
- Installations
- 10+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22760
1003 Mortgage Application
- Plugin:
- 1003 Mortgage Application
- Plugin Slug:
- 1003-mortgage-application
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13536
a Gateway for Pasargad Bank on WooCommerce
- Plugin:
- a Gateway for Pasargad Bank on WooCommerce
- Plugin Slug:
- a-gateway-for-pasargad-bank-on-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23966
Ad Blocking Detector
- Plugin:
- Ad Blocking Detector
- Plugin Slug:
- ad-blocking-detector
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22732
add custom google tag manager
- Plugin:
- add custom google tag manager
- Plugin Slug:
- add-custom-google-tag-manager
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23537
Add RSS
- Plugin:
- Add RSS
- Plugin Slug:
- add-rss
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23895
Admin Cleanup
- Plugin:
- Admin Cleanup
- Plugin Slug:
- admin-cleanup
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23832
Admin Menu Organizer
- Plugin:
- Admin Menu Organizer
- Plugin Slug:
- admin-menu-organizer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23686
Elementor AI Addons
- Plugin:
- Elementor AI Addons
- Plugin Slug:
- ai-addons-for-elementor
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22758
AI Responsive Gallery Album
- Plugin:
- AI Responsive Gallery Album
- Plugin Slug:
- ai-responsive-gallery-album
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23785
Ajax WP Query Search Filter
- Plugin:
- Ajax WP Query Search Filter
- Plugin Slug:
- ajax-wp-query-search-filter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23926
AlT Report
- Plugin:
- AlT Report
- Plugin Slug:
- alt-report
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23432
Altima Lookbook Free for WooCommerce
- Plugin:
- Altima Lookbook Free for WooCommerce
- Plugin Slug:
- altima-lookbook-free-for-woocommerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23429
amr personalise
- Plugin:
- amr personalise
- Plugin Slug:
- amr-personalise
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23880
Annie
- Plugin:
- Annie
- Plugin Slug:
- annie
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23884
Annie
- Plugin:
- Annie
- Plugin Slug:
- annie
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23886
Anonymize Links
- Plugin:
- Anonymize Links
- Plugin Slug:
- anonymize-links
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23702
AnyRoad
- Plugin:
- AnyRoad
- Plugin Slug:
- anyguide
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23996
Apply with LinkedIn buttons
- Plugin:
- Apply with LinkedIn buttons
- Plugin Slug:
- apply-with-linkedin-buttons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23897
Apply with LinkedIn buttons
- Plugin:
- Apply with LinkedIn buttons
- Plugin Slug:
- apply-with-linkedin-buttons
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23898
Auphonic Importer
- Plugin:
- Auphonic Importer
- Plugin Slug:
- auphonic-importer
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23649
Auto FTP
- Plugin:
- Auto FTP
- Plugin Slug:
- auto-ftp
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23793
Background animation blocks
- Plugin:
- Background animation blocks
- Plugin Slug:
- background-animation-blocks
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23948
Background Control
- Plugin:
- Background Control
- Plugin Slug:
- background-control
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22784
Better Protected Pages
- Plugin:
- Better Protected Pages
- Plugin Slug:
- better-protected-pages
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23875
Bible Embed
- Plugin:
- Bible Embed
- Plugin Slug:
- bible-embed
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23513
Bit.ly linker
- Plugin:
- Bit.ly linker
- Plugin Slug:
- bitly-linker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23674
BizLibrary
- Plugin:
- BizLibrary
- Plugin Slug:
- bizlibrary
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23580
Blog Summary
- Plugin:
- Blog Summary
- Plugin Slug:
- blog-summary
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23887
Blogger Image Import
- Plugin:
- Blogger Image Import
- Plugin Slug:
- blogger-image-import
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23689
Blrt WP Embed
- Plugin:
- Blrt WP Embed
- Plugin Slug:
- blrt-wp-embed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23507
Blue Wrench Video Widget
- Plugin:
- Blue Wrench Video Widget
- Plugin Slug:
- blue-wrench-videos-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23809
Board Election
- Plugin:
- Board Election
- Plugin Slug:
- board-election
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23499
Bonjour Bar
- Plugin:
- Bonjour Bar
- Plugin Slug:
- bonjour-bar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22262
Book a Place
- Plugin:
- Book a Place
- Plugin Slug:
- book-a-place
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23690
Bookalet
- Plugin:
- Bookalet
- Plugin Slug:
- bookalet
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23899
Brizy Pro
- Plugin:
- Brizy Pro
- Plugin Slug:
- brizy-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22763
Calendi
- Plugin:
- Calendi
- Plugin Slug:
- calendi
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23606
Call me Now
- Plugin:
- Call me Now
- Plugin Slug:
- call-me-now
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23745
Call To Action Popup
- Plugin:
- Call To Action Popup
- Plugin Slug:
- call-to-action-popup
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23605
CAMOO SMS
- Plugin:
- CAMOO SMS
- Plugin Slug:
- camoo-sms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23607
Captchelfie – Captcha by Selfie
- Plugin:
- Captchelfie – Captcha by Selfie
- Plugin Slug:
- captchelfie-captcha-by-selfie
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23620
Car Demon
- Plugin:
- Car Demon
- Plugin Slug:
- car-demon
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13334
Category D3 Tree
- Plugin:
- Category D3 Tree
- Plugin Slug:
- category-d3-tree
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23873
Category Custom Fields
- Plugin:
- Category Custom Fields
- Plugin Slug:
- categorycustomfields
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23822
CC Circle Progress Bar
- Plugin:
- CC Circle Progress Bar
- Plugin Slug:
- cc-circle-progress-bar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23936
Contact Form 7 – CCAvenue Add-on
- Plugin:
- Contact Form 7 – CCAvenue Add-on
- Plugin Slug:
- cf7-cc-avenue-add-on
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23623
Charity-thermometer
- Plugin:
- Charity-thermometer
- Plugin Slug:
- charitydonation-thermometer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23860
Chatter
- Plugin:
- Chatter
- Plugin Slug:
- chatter
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23760
Chess Tempo Viewer
- Plugin:
- Chess Tempo Viewer
- Plugin Slug:
- chesstempoviewer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23868
CJ Custom Content
- Plugin:
- CJ Custom Content
- Plugin Slug:
- cj-custom-content
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23869
CMC MIGRATE
- Plugin:
- CMC MIGRATE
- Plugin Slug:
- cmc-migrate
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23746
CNZZ&51LA for WordPress
- Plugin:
- CNZZ&51LA for WordPress
- Plugin Slug:
- cnzz51la-for-wordpress
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23823
Comment-Emailer
- Plugin:
- Comment-Emailer
- Plugin Slug:
- comment-emailer
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23627
HyperComments
- Plugin:
- HyperComments
- Plugin Slug:
- comments-with-hypercommentscom
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23509
Compare Ninja
- Plugin:
- Compare Ninja
- Plugin Slug:
- compare-ninja-comparison-tables
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23909
Contact Form 7 Anti Spambot
- Plugin:
- Contact Form 7 Anti Spambot
- Plugin Slug:
- contact-form-7-anti-spambot
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23862
Contact Form 7 Round Robin Lead Distribution
- Plugin:
- Contact Form 7 Round Robin Lead Distribution
- Plugin Slug:
- contact-form-7-round-robin-lead-distribution
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23812
Contact Form 7 Round Robin Lead Distribution
- Plugin:
- Contact Form 7 Round Robin Lead Distribution
- Plugin Slug:
- contact-form-7-round-robin-lead-distribution
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23784
Contact Form Master – by Edmon
- Plugin:
- Contact Form Master – by Edmon
- Plugin Slug:
- contact-form-master
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-12587
Content Mirror
- Plugin:
- Content Mirror
- Plugin Slug:
- content-mirror
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23769
Content Planner
- Plugin:
- Content Planner
- Plugin Slug:
- content-planner
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23631
Content Security Policy Pro
- Plugin:
- Content Security Policy Pro
- Plugin Slug:
- content-security-policy-pro
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23820
ContentOptin Lite
- Plugin:
- ContentOptin Lite
- Plugin Slug:
- contentoptin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23589
Cookie Consent & Autoblock for GDPR/CCPA
- Plugin:
- Cookie Consent & Autoblock for GDPR/CCPA
- Plugin Slug:
- cookie-consent-autoblock
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23501
Copy Move Posts
- Plugin:
- Copy Move Posts
- Plugin Slug:
- copy-move-posts
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23764
Copyright Safeguard Footer Notice
- Plugin:
- Copyright Safeguard Footer Notice
- Plugin Slug:
- copyright-safeguard-footer-notice
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23870
Custom CSS Addons
- Plugin:
- Custom CSS Addons
- Plugin Slug:
- css-addons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23578
Custom List Table Example
- Plugin:
- Custom List Table Example
- Plugin Slug:
- custom-list-table-example
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23808
Custom Post
- Plugin:
- Custom Post
- Plugin Slug:
- custom-post-type-gui
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23566
Custom Post Type Lockdown
- Plugin:
- Custom Post Type Lockdown
- Plugin Slug:
- custom-post-type-lockdown
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23530
Custom Widget Classes
- Plugin:
- Custom Widget Classes
- Plugin Slug:
- custom-widget-classes
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23844
Customizable Captcha and Contact Us
- Plugin:
- Customizable Captcha and Contact Us
- Plugin Slug:
- customizable-captcha-and-contact-us-form
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23503
Cyber Slider
- Plugin:
- Cyber Slider
- Plugin Slug:
- cyber-new-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23630
Daily Proverb
- Plugin:
- Daily Proverb
- Plugin Slug:
- daily-proverb
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23859
Database Sync
- Plugin:
- Database Sync
- Plugin Slug:
- database-sync
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23486
DD Roles
- Plugin:
- DD Roles
- Plugin Slug:
- dd-roles
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23528
Debt Calculator
- Plugin:
- Debt Calculator
- Plugin Slug:
- debt-calculator
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23861
Debug Tool
- Plugin:
- Debug Tool
- Plugin Slug:
- debug-tool
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23684
DF Draggable
- Plugin:
- DF Draggable
- Plugin Slug:
- df-draggable
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23708
dForms
- Plugin:
- dForms
- Plugin Slug:
- dforms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23592
WordPress Local SEO
- Plugin:
- WordPress Local SEO
- Plugin Slug:
- dh-local-seo
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23931
REAL WordPress Sidebar
- Plugin:
- REAL WordPress Sidebar
- Plugin Slug:
- drag-and-drop-custom-sidebar
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23535
EU DSGVO Helper
- Plugin:
- EU DSGVO Helper
- Plugin Slug:
- dsgvo
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23866
Easy Automatic Newsletter Lite
- Plugin:
- Easy Automatic Newsletter Lite
- Plugin Slug:
- easy-automatic-newsletter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23879
Easy Code Snippets
- Plugin:
- Easy Code Snippets
- Plugin Slug:
- easy-code-snippets
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23780
Easy EU Cookie law
- Plugin:
- Easy EU Cookie law
- Plugin Slug:
- easy-eu-cookie-law
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23434
Easy FAQs
- Plugin:
- Easy FAQs
- Plugin Slug:
- easy-faqs
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23795
Easy Filtering
- Plugin:
- Easy Filtering
- Plugin Slug:
- easy-filtering
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23732
Easy Portfolio
- Plugin:
- Easy Portfolio
- Plugin Slug:
- easy-portfolio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23796
Post-to-Post Links
- Plugin:
- Post-to-Post Links
- Plugin Slug:
- easy-post-to-post-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23878
Easy Real Estate
- Plugin:
- Easy Real Estate
- Plugin Slug:
- easy-real-estate
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-32555
Easy Shortcode Buttons
- Plugin:
- Easy Shortcode Buttons
- Plugin Slug:
- easy-shortcode-buttons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23825
Easy Tweet Embed
- Plugin:
- Easy Tweet Embed
- Plugin Slug:
- easy-tweet-embed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23890
Easy Tynt
- Plugin:
- Easy Tynt
- Plugin Slug:
- easy-tynt
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23445
ECT Add to Cart Button
- Plugin:
- ECT Add to Cart Button
- Plugin Slug:
- ect-add-to-cart-button
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23471
EditionGuard for WooCommerce – eBook Sales with DRM
- Plugin:
- EditionGuard for WooCommerce – eBook Sales with DRM
- Plugin Slug:
- editionguard-for-woocommerce-ebook-sales-with-drm
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23452
EELV Newsletter
- Plugin:
- EELV Newsletter
- Plugin Slug:
- eelv-newsletter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23602
Email Capture & Lead Generation
- Plugin:
- Email Capture & Lead Generation
- Plugin Slug:
- email-capture-lead-generation
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23929
Email on Publish
- Plugin:
- Email on Publish
- Plugin Slug:
- email-on-publish
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23673
EmailShroud
- Plugin:
- EmailShroud
- Plugin Slug:
- emailshroud
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23456
iSpring Embedder
- Plugin:
- iSpring Embedder
- Plugin Slug:
- embed-ispring
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23922
Enhanced YouTube Shortcode
- Plugin:
- Enhanced YouTube Shortcode
- Plugin Slug:
- enhanced-youtube-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23946
Error Notification
- Plugin:
- Error Notification
- Plugin Slug:
- error-notification
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23902
Event Countdown Timer Plugin by TechMix
- Plugin:
- Event Countdown Timer Plugin by TechMix
- Plugin Slug:
- event-countdown-timer
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23699
Event Registration Calendar By vcita
- Plugin:
- Event Registration Calendar By vcita
- Plugin Slug:
- event-registration-calendar-by-vcita
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-11870
Explara Membership
- Plugin:
- Explara Membership
- Plugin Slug:
- explara-membership
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23583
Explore pages
- Plugin:
- Explore pages
- Plugin Slug:
- explore-pages
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23563
Extra Options – Favicons
- Plugin:
- Extra Options – Favicons
- Plugin Slug:
- extra-options-favicons
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23508
EZPlayer
- Plugin:
- EZPlayer
- Plugin Slug:
- ezplayer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23950
Fast Tube
- Plugin:
- Fast Tube
- Plugin Slug:
- fast-tube
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23770
FAT Event Lite
- Plugin:
- FAT Event Lite
- Plugin Slug:
- fat-event-lite
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23915
FAT Event Lite
- Plugin:
- FAT Event Lite
- Plugin Slug:
- fat-event-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22718
Feedburner Optin Form
- Plugin:
- Feedburner Optin Form
- Plugin Slug:
- feedburner-optin-form
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23925
Find Your Reps
- Plugin:
- Find Your Reps
- Plugin Slug:
- find-your-reps
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23557
Flexible Blogtitle
- Plugin:
- Flexible Blogtitle
- Plugin Slug:
- flexible-blogtitle
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23846
Floatbox Plus
- Plugin:
- Floatbox Plus
- Plugin Slug:
- floatbox-plus
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23617
Flying Twitter Birds
- Plugin:
- Flying Twitter Birds
- Plugin Slug:
- flying-twitter-birds
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23710
FontAwesome.io ShortCodes
- Plugin:
- FontAwesome.io ShortCodes
- Plugin Slug:
- fontawesomeio-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23824
Formatted post
- Plugin:
- Formatted post
- Plugin Slug:
- formatted-post
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23709
FP RSS Category Excluder
- Plugin:
- FP RSS Category Excluder
- Plugin Slug:
- fp-rss-category-excluder
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23679
FWD Slider
- Plugin:
- FWD Slider
- Plugin Slug:
- fwd-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23462
GDPR Personal Data Reports
- Plugin:
- GDPR Personal Data Reports
- Plugin Slug:
- gdpr-personal-data-reports
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23777
GDReseller
- Plugin:
- GDReseller
- Plugin Slug:
- gdreseller
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23567
Genki Announcement
- Plugin:
- Genki Announcement
- Plugin Slug:
- genki-announcement
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23900
Geotagged Media
- Plugin:
- Geotagged Media
- Plugin Slug:
- geotagged-media
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23558
Multi Uploader for Gravity Forms
- Plugin:
- Multi Uploader for Gravity Forms
- Plugin Slug:
- gf-multi-uploader
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23921
Giveaways and Contests by PromoSimple
- Plugin:
- Giveaways and Contests by PromoSimple
- Plugin Slug:
- giveaways-contests-by-promosimple
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23934
Glofox Shortcodes
- Plugin:
- Glofox Shortcodes
- Plugin Slug:
- glofox-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12508
GMap Shortcode
- Plugin:
- GMap Shortcode
- Plugin Slug:
- gmap-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23893
GMAPS for WPBakery Page Builder Free
- Plugin:
- GMAPS for WPBakery Page Builder Free
- Plugin Slug:
- gmaps-for-visual-composer-free
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23775
go Social
- Plugin:
- go Social
- Plugin Slug:
- go-social
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23426
Goldstar
- Plugin:
- Goldstar
- Plugin Slug:
- goldstar
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23962
Good Old Gallery
- Plugin:
- Good Old Gallery
- Plugin Slug:
- good-old-gallery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23959
WordPress Google Map Professional
- Plugin:
- WordPress Google Map Professional
- Plugin Slug:
- google-map-professional
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23913
Google Org Chart
- Plugin:
- Google Org Chart
- Plugin Slug:
- google-org-chart
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23928
WordPress Graphs & Charts
- Plugin:
- WordPress Graphs & Charts
- Plugin Slug:
- graph-lite
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23961
GravatarLocalCache
- Plugin:
- GravatarLocalCache
- Plugin Slug:
- gravatarlocalcache
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23901
Greek Namedays Widget From Eortologio.Net
- Plugin:
- Greek Namedays Widget From Eortologio.Net
- Plugin Slug:
- greek-namedays-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23783
Group category creator
- Plugin:
- Group category creator
- Plugin Slug:
- group-category-creator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23603
Hack me if you can
- Plugin:
- Hack me if you can
- Plugin Slug:
- hack-me-if-you-can
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23713
History timeline
- Plugin:
- History timeline
- Plugin Slug:
- history-timeline
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23475
Horizontal Line Shortcode
- Plugin:
- Horizontal Line Shortcode
- Plugin Slug:
- horizontal-line-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23791
Hotspots Analytics
- Plugin:
- Hotspots Analytics
- Plugin Slug:
- hotspots
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23848
HTTP to HTTPS link changer by Eyga.net
- Plugin:
- HTTP to HTTPS link changer by Eyga.net
- Plugin Slug:
- https-links-in-content
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23677
Gallery: Hybrid – Advanced Visual Gallery
- Plugin:
- Gallery: Hybrid – Advanced Visual Gallery
- Plugin Slug:
- hybrid-gallery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23951
CtyGrid Hyp3rL0cal Search
- Plugin:
- CtyGrid Hyp3rL0cal Search
- Plugin Slug:
- hyp3rl0cal-city-search
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23695
Image Gallery Box by CRUDLab
- Plugin:
- Image Gallery Box by CRUDLab
- Plugin Slug:
- image-gallery-box-by-crudlab
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23938
Image Switcher
- Plugin:
- Image Switcher
- Plugin Slug:
- image-switcher
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23939
Image Switcher
- Plugin:
- Image Switcher
- Plugin Slug:
- image-switcher
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23940
imaGenius
- Plugin:
- imaGenius
- Plugin Slug:
- imagenius
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23772
Import Users to MailChimp
- Plugin:
- Import Users to MailChimp
- Plugin Slug:
- import-users-to-mailchimp
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23675
Improved Sale Badges – Free Version
- Plugin:
- Improved Sale Badges – Free Version
- Plugin Slug:
- improved-sale-badges-free-version
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23949
Incredible Font Awesome
- Plugin:
- Incredible Font Awesome
- Plugin Slug:
- incredible-font-awesome
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23927
InFunding
- Plugin:
- InFunding
- Plugin Slug:
- infunding
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23768
Instant Appointment
- Plugin:
- Instant Appointment
- Plugin Slug:
- instant-appointment
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23672
Interactive Page Hierarchy
- Plugin:
- Interactive Page Hierarchy
- Plugin Slug:
- interactive-page-hierarchy
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23615
JB Horizontal Scroller News Ticker
- Plugin:
- JB Horizontal Scroller News Ticker
- Plugin Slug:
- jb-horizontal-scroller-news-ticker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23830
Jet Skinner for BuddyPress
- Plugin:
- Jet Skinner for BuddyPress
- Plugin Slug:
- jet-skinner-for-buddypress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23706
Kapost
- Plugin:
- Kapost
- Plugin Slug:
- kapost-byline
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23712
Kopa Nictitate Toolkit
- Plugin:
- Kopa Nictitate Toolkit
- Plugin Slug:
- kopa-nictitate-toolkit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23965
Len Slider
- Plugin:
- Len Slider
- Plugin Slug:
- len-slider
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23810
LH Email
- Plugin:
- LH Email
- Plugin Slug:
- lh-email
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23676
LH Login Page
- Plugin:
- LH Login Page
- Plugin Slug:
- lh-login-page
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23547
Lime Developer Login
- Plugin:
- Lime Developer Login
- Plugin Slug:
- lime-developer-login
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23701
LocalGrid
- Plugin:
- LocalGrid
- Plugin Slug:
- localgrid
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23678
Loginplus
- Plugin:
- Loginplus
- Plugin Slug:
- loginplus
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23514
LSD Google Maps Embedder
- Plugin:
- LSD Google Maps Embedder
- Plugin Slug:
- lsd-google-maps-embedder
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23871
MACME
- Plugin:
- MACME
- Plugin Slug:
- macme
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23683
Magic Google Maps
- Plugin:
- Magic Google Maps
- Plugin Slug:
- magic-google-maps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23935
Free MailClient FMC
- Plugin:
- Free MailClient FMC
- Plugin Slug:
- mailclient
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23703
Mapbox for WP Advanced
- Plugin:
- Mapbox for WP Advanced
- Plugin Slug:
- mapbox-for-wp-advanced
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22772
Mark Posts
- Plugin:
- Mark Posts
- Plugin Slug:
- mark-posts
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23963
Marmoset Viewer
- Plugin:
- Marmoset Viewer
- Plugin Slug:
- marmoset-viewer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23767
Marquee Style RSS News Ticker
- Plugin:
- Marquee Style RSS News Ticker
- Plugin Slug:
- marquee-style-rss-news-ticker
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23424
Mass Custom Fields Manager
- Plugin:
- Mass Custom Fields Manager
- Plugin Slug:
- mass-custom-fields-manager
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23430
Mass Messaging in BuddyPress
- Plugin:
- Mass Messaging in BuddyPress
- Plugin Slug:
- mass-messaging-in-buddypress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23798
MD Custom content after or before of post
- Plugin:
- MD Custom content after or before of post
- Plugin Slug:
- md-custom-content
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23463
MDC YouTube Downloader
- Plugin:
- MDC YouTube Downloader
- Plugin Slug:
- mdc-youtube-downloader
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23639
MeinTurnierplan.de Widget Viewer
- Plugin:
- MeinTurnierplan.de Widget Viewer
- Plugin Slug:
- meinturnierplande-widget-viewer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23941
MemeOne
- Plugin:
- MemeOne
- Plugin Slug:
- memeone
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23559
Menus Plus+
- Plugin:
- Menus Plus+
- Plugin Slug:
- menus-plus
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23910
MercadoLibre Integration
- Plugin:
- MercadoLibre Integration
- Plugin Slug:
- mercadolibre-integration
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23659
MFPlugin
- Plugin:
- MFPlugin
- Plugin Slug:
- mfplugin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23660
MHR-Custom-Anti-Copy
- Plugin:
- MHR-Custom-Anti-Copy
- Plugin Slug:
- mhr-custom-anti-copy
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23817
Mindmeister Shortcode
- Plugin:
- Mindmeister Shortcode
- Plugin Slug:
- mindmeister-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23896
More Link Modifier
- Plugin:
- More Link Modifier
- Plugin Slug:
- more-link-modifier
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23818
WP VTiger Synchronization
- Plugin:
- WP VTiger Synchronization
- Plugin Slug:
- msstiger
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23455
Metaphor Widgets
- Plugin:
- Metaphor Widgets
- Plugin Slug:
- mtphr-widgets
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23816
Muzaara Google Ads Report
- Plugin:
- Muzaara Google Ads Report
- Plugin Slug:
- muzaara-adwords-optimize-dashboard
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23914
my-related-posts
- Plugin:
- my-related-posts
- Plugin Slug:
- my-related-posts
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23476
MyAnime Widget
- Plugin:
- MyAnime Widget
- Plugin Slug:
- myanime-widget
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23532
mybb Last Topics
- Plugin:
- mybb Last Topics
- Plugin Slug:
- mybb-last-topics
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23749
MyBookProgress by Stormhill Media
- Plugin:
- MyBookProgress by Stormhill Media
- Plugin Slug:
- mybookprogress
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12598
Nativery
- Plugin:
- Nativery
- Plugin Slug:
- nativery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22781
Nite Shortcodes
- Plugin:
- Nite Shortcodes
- Plugin Slug:
- nite-shortcodes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23877
NV Slider
- Plugin:
- NV Slider
- Plugin Slug:
- nv-slider
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23661
OrangeBox
- Plugin:
- OrangeBox
- Plugin Slug:
- orangebox
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23800
Password Protect Plugin for WordPress
- Plugin:
- Password Protect Plugin for WordPress
- Plugin Slug:
- password-protect-plugin-for-wordpress
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23435
Pastebin
- Plugin:
- Pastebin
- Plugin Slug:
- pastebin-embed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23908
PayForm
- Plugin:
- PayForm
- Plugin Slug:
- payform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23872
PayPal Marketing Solutions
- Plugin:
- PayPal Marketing Solutions
- Plugin Slug:
- paypal-promotions-and-insights
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23930
PDF.js Shortcode
- Plugin:
- PDF.js Shortcode
- Plugin Slug:
- pdfjs-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23943
Powie’s pLinks PagePeeker
- Plugin:
- Powie’s pLinks PagePeeker
- Plugin Slug:
- plinks
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23641
Pod?lánková inzerce
- Plugin:
- Pod?lánková inzerce
- Plugin Slug:
- podclankova-inzerce
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23697
Pootle button
- Plugin:
- Pootle button
- Plugin Slug:
- pootle-button
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23758
Popliup
- Plugin:
- Popliup
- Plugin Slug:
- popliup
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23945
Post & Page Notes
- Plugin:
- Post & Page Notes
- Plugin Slug:
- post-page-notes
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23715
PPO Call To Actions
- Plugin:
- PPO Call To Actions
- Plugin Slug:
- ppo-call-to-actions
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-24001
Preloader Quotes
- Plugin:
- Preloader Quotes
- Plugin Slug:
- preloader-quotes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23682
Progress Tracker
- Plugin:
- Progress Tracker
- Plugin Slug:
- progress-tracker
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23892
QR Code Generator
- Plugin:
- QR Code Generator
- Plugin Slug:
- qrcode-wprhe
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23831
Quick Count
- Plugin:
- Quick Count
- Plugin Slug:
- quick-count
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23932
quote-posttype-plugin
- Plugin:
- quote-posttype-plugin
- Plugin Slug:
- quote-post-type-plugin
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13386
QuoteMedia Tools
- Plugin:
- QuoteMedia Tools
- Plugin Slug:
- quotemedia-tools
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23644
ReadMe Creator
- Plugin:
- ReadMe Creator
- Plugin Slug:
- readme-creator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23643
Realty Workstation
- Plugin:
- Realty Workstation
- Plugin Slug:
- realty-workstation
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23477
REDIRECTION PLUS
- Plugin:
- REDIRECTION PLUS
- Plugin Slug:
- redirection-plus
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23681
User Sync ActiveCampaign
- Plugin:
- User Sync ActiveCampaign
- Plugin Slug:
- registered-user-sync-activecampaign
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23778
Rezdy Reloaded
- Plugin:
- Rezdy Reloaded
- Plugin Slug:
- reloaded-rezdy
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23604
Rename Author Slug
- Plugin:
- Rename Author Slug
- Plugin Slug:
- rename-author-slug
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23640
Links/Problem Reporter
- Plugin:
- Links/Problem Reporter
- Plugin Slug:
- report-broken-links
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23833
ResAds
- Plugin:
- ResAds
- Plugin Slug:
- resads
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23779
Responsivity
- Plugin:
- Responsivity
- Plugin Slug:
- responsivity
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23548
Rio Photo Gallery
- Plugin:
- Rio Photo Gallery
- Plugin Slug:
- rio-photo-gallery
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23597
Rollover Tab
- Plugin:
- Rollover Tab
- Plugin Slug:
- rollover-tab
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23863
root Cookie
- Plugin:
- root Cookie
- Plugin Slug:
- root-cookie
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23815
RSS Icon Widget
- Plugin:
- RSS Icon Widget
- Plugin Slug:
- rss-icon-widget
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-12203
RSS News Scroller
- Plugin:
- RSS News Scroller
- Plugin Slug:
- rss-news-scroller
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23467
RSV GMaps
- Plugin:
- RSV GMaps
- Plugin Slug:
- rsv-google-maps
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23665
Salvador – AI Image Generator
- Plugin:
- Salvador – AI Image Generator
- Plugin Slug:
- salvador-ai-image-generator
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23954
Scroll Top Advanced
- Plugin:
- Scroll Top Advanced
- Plugin Slug:
- scroll-top-advanced
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23444
Secure CAPTCHA
- Plugin:
- Secure CAPTCHA
- Plugin Slug:
- secure-captcha
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23693
Real Seguro Viagem
- Plugin:
- Real Seguro Viagem
- Plugin Slug:
- seguro-viagem
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23664
Send to a Friend Addon
- Plugin:
- Send to a Friend Addon
- Plugin Slug:
- send-booking-invites-to-friends
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23600
Send to Twitter
- Plugin:
- Send to Twitter
- Plugin Slug:
- send-to-twitter
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23691
SOCIAL.NINJA
- Plugin:
- SOCIAL.NINJA
- Plugin Slug:
- seo-meta
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23907
SexBundle
- Plugin:
- SexBundle
- Plugin Slug:
- sexbundle
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23551
Shabbos and Yom Tov
- Plugin:
- Shabbos and Yom Tov
- Plugin Slug:
- shabbos-and-yom-tov
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23694
Shockingly Big IE6 Warning
- Plugin:
- Shockingly Big IE6 Warning
- Plugin Slug:
- shockingly-big-ie6-warning
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23442
Shortcode in Comment
- Plugin:
- Shortcode in Comment
- Plugin Slug:
- shortcode-in-comment
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23569
Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com
- Plugin:
- Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com
- Plugin Slug:
- shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23854
Sidebar-Content from Shortcode
- Plugin:
- Sidebar-Content from Shortcode
- Plugin Slug:
- sidebar-content-from-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23642
Simple Custom post type custom field
- Plugin:
- Simple Custom post type custom field
- Plugin Slug:
- simple-content-construction-kit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23500
Simple Project Manager
- Plugin:
- Simple Project Manager
- Plugin Slug:
- simple-project-managment
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23497
Simple shortcode buttons
- Plugin:
- Simple shortcode buttons
- Plugin Slug:
- simple-shortcode-buttons
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23449
Simple Vertical Timeline
- Plugin:
- Simple Vertical Timeline
- Plugin Slug:
- simple-vertical-timeline
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23856
Slides & Presentations
- Plugin:
- Slides & Presentations
- Plugin Slug:
- slide
- Vulnerability:
- Content Injection
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23919
Slider for Writers
- Plugin:
- Slider for Writers
- Plugin Slug:
- slider-for-writers
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23692
Smallerik File Browser
- Plugin:
- Smallerik File Browser
- Plugin Slug:
- smallerik-file-browser
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23918
Smooth Dynamic Slider
- Plugin:
- Smooth Dynamic Slider
- Plugin Slug:
- smooth-dynamic-slider
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23447
Cache Sniper for Nginx
- Plugin:
- Cache Sniper for Nginx
- Plugin Slug:
- snipe-nginx-cache
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23776
Snippy
- Plugin:
- Snippy
- Plugin Slug:
- snippy
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23803
Social Analytics
- Plugin:
- Social Analytics
- Plugin Slug:
- social-analytics
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23743
Social Pug: Author Box
- Plugin:
- Social Pug: Author Box
- Plugin Slug:
- social-pug-author-box
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22706
Social2Blog
- Plugin:
- Social2Blog
- Plugin Slug:
- social2blog
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23461
Solidres – Hotel booking plugin
- Plugin:
- Solidres – Hotel booking plugin
- Plugin Slug:
- solidres
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23911
Spiderpowa Embed PDF
- Plugin:
- Spiderpowa Embed PDF
- Plugin Slug:
- spiderpowa-embed-pdf
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23807
SEOReseller Partner
- Plugin:
- SEOReseller Partner
- Plugin Slug:
- sr-partner
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23805
Staging CDN
- Plugin:
- Staging CDN
- Plugin Slug:
- staging-cdn
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23696
Stars SMTP Mailer
- Plugin:
- Stars SMTP Mailer
- Plugin Slug:
- stars-smtp-mailer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23453
Strx Magic Floating Sidebar Maker
- Plugin:
- Strx Magic Floating Sidebar Maker
- Plugin Slug:
- strx-magic-floating-sidebar-maker
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23827
Style Admin
- Plugin:
- Style Admin
- Plugin Slug:
- style-admin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23801
Sur.ly
- Plugin:
- Sur.ly
- Plugin Slug:
- surly
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23957
Tab My Content
- Plugin:
- Tab My Content
- Plugin Slug:
- tab-my-content
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23601
Tagesteller
- Plugin:
- Tagesteller
- Plugin Slug:
- tagesteller
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23609
Team 118GROUP Agent
- Plugin:
- Team 118GROUP Agent
- Plugin Slug:
- team-118group-agent
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23512
Theme My Ontraport Smartform
- Plugin:
- Theme My Ontraport Smartform
- Plugin Slug:
- theme-my-ontraport-smartform
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23717
Top Flash Embed
- Plugin:
- Top Flash Embed
- Plugin Slug:
- top-flash-embed
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23841
Track Page Scroll
- Plugin:
- Track Page Scroll
- Plugin Slug:
- track-page-scroll
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23536
Translation.Pro
- Plugin:
- Translation.Pro
- Plugin Slug:
- translation-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23498
ts-tree
- Plugin:
- ts-tree
- Plugin Slug:
- ts-tree
- Vulnerability:
- Arbitrary Content Deletion
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23515
Twitter Bootstrap Collapse aka Accordian Shortcode
- Plugin:
- Twitter Bootstrap Collapse aka Accordian Shortcode
- Plugin Slug:
- twitter-bootstrap-collapse-aka-accordian-shortcode
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22743
Twitter Shortcode
- Plugin:
- Twitter Shortcode
- Plugin Slug:
- twitter-shortcode
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23618
Twitter Post
- Plugin:
- Twitter Post
- Plugin Slug:
- twitterpost
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23654
Ultimate Events
- Plugin:
- Ultimate Events
- Plugin Slug:
- ultimate-events
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23610
Ultimate Subscribe
- Plugin:
- Ultimate Subscribe
- Plugin Slug:
- ultimate-subscribe
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23806
Unique UX
- Plugin:
- Unique UX
- Plugin Slug:
- unique-ux
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23625
Universal Analytics Injector
- Plugin:
- Universal Analytics Injector
- Plugin Slug:
- universal-analytics-injector
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23483
UpDownUpDown
- Plugin:
- UpDownUpDown
- Plugin Slug:
- updownupdown-postcomment-voting
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23572
user files
- Plugin:
- user files
- Plugin Slug:
- user-files
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23953
Utilities for MTG
- Plugin:
- Utilities for MTG
- Plugin Slug:
- utilities-for-mtg
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13433
Nature FlipBook
- Plugin:
- Nature FlipBook
- Plugin Slug:
- vertical-diamond-flipbook-flash
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23454
ViewMedica 9
- Plugin:
- ViewMedica 9
- Plugin Slug:
- viewmedica
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13394
Visit Site Link enhanced
- Plugin:
- Visit Site Link enhanced
- Plugin Slug:
- visit-site-link-enhanced
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23470
W3SPEEDSTER
- Plugin:
- W3SPEEDSTER
- Plugin Slug:
- w3speedster-wp
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23765
WCS QR Code Generator
- Plugin:
- WCS QR Code Generator
- Plugin Slug:
- wcs-qr-code-generator
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23864
Weaver Themes Shortcode Compatibility
- Plugin:
- Weaver Themes Shortcode Compatibility
- Plugin Slug:
- weaver-themes-shortcode-compatibility
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22267
Web Push
- Plugin:
- Web Push
- Plugin Slug:
- web-push
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23720
Web Testimonials
- Plugin:
- Web Testimonials
- Plugin Slug:
- web-testimonials
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23560
WH Cache & Security
- Plugin:
- WH Cache & Security
- Plugin Slug:
- wh-cache-and-security
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23611
Wibstats
- Plugin:
- Wibstats
- Plugin Slug:
- wibstats-statistics-for-wordpress-mu
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23565
Winning Portfolio
- Plugin:
- Winning Portfolio
- Plugin Slug:
- winning-portfolio
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23865
WM Options Import Export
- Plugin:
- WM Options Import Export
- Plugin Slug:
- wm-options-import-export
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23781
Woo Tuner
- Plugin:
- Woo Tuner
- Plugin Slug:
- woo-tuner
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23761
WooCommerce Order Search
- Plugin:
- WooCommerce Order Search
- Plugin Slug:
- woocommerce-order-searching
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23495
WOOEXIM
- Plugin:
- WOOEXIM
- Plugin Slug:
- wooexim
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23944
Word Freshener
- Plugin:
- Word Freshener
- Plugin Slug:
- word-freshener
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23577
WordPress Custom Sidebar
- Plugin:
- WordPress Custom Sidebar
- Plugin Slug:
- wordpress-custom-sidebar
- Vulnerability:
- SQL Injection
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23912
WordPress Data Guard
- Plugin:
- WordPress Data Guard
- Plugin Slug:
- wordpress-data-guards
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23828
WordPress Gallery Plugin
- Plugin:
- WordPress Gallery Plugin
- Plugin Slug:
- wordpress-gallery-plugin
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23842
WordPress Logging Service
- Plugin:
- WordPress Logging Service
- Plugin Slug:
- wordpress-logging-service
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23510
WP All Import Pro
- Plugin:
- WP All Import Pro
- Plugin Slug:
- wp-all-import-pro
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-8722
wp_amaps
- Plugin:
- wp_amaps
- Plugin Slug:
- wp-amaps
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23794
WP-Announcements
- Plugin:
- WP-Announcements
- Plugin Slug:
- wp-announcements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23489
WP Background Tile
- Plugin:
- WP Background Tile
- Plugin Slug:
- wp-background-tile
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23573
WP-BlackCheck
- Plugin:
- WP-BlackCheck
- Plugin Slug:
- wp-blackcheck
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23511
WP Block Pack
- Plugin:
- WP Block Pack
- Plugin Slug:
- wp-block-pack
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23874
WP Bulletin Board
- Plugin:
- WP Bulletin Board
- Plugin Slug:
- wp-bulletin-board
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22776
WP Cookies Alert
- Plugin:
- WP Cookies Alert
- Plugin Slug:
- wp-cookies-alert
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23821
WP Custom Google Search
- Plugin:
- WP Custom Google Search
- Plugin Slug:
- wp-custom-google-search
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23698
WP Download Codes
- Plugin:
- WP Download Codes
- Plugin Slug:
- wp-download-codes
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23882
WP FixTag
- Plugin:
- WP FixTag
- Plugin Slug:
- wp-fixtag
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23564
WP IMAP Auth
- Plugin:
- WP IMAP Auth
- Plugin Slug:
- wp-imap-authentication
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23506
WP Intro.JS
- Plugin:
- WP Intro.JS
- Plugin Slug:
- wp-intro-js-tours
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23576
WP krpano
- Plugin:
- WP krpano
- Plugin Slug:
- wp-krpano
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23876
Lijit Search
- Plugin:
- Lijit Search
- Plugin Slug:
- wp-lijit-wijit
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22778
WP Load Gallery
- Plugin:
- WP Load Gallery
- Plugin Slug:
- wp-load-gallery
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23942
WP Meetup
- Plugin:
- WP Meetup
- Plugin Slug:
- wp-meetup
- Vulnerability:
- Settings Change
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23916
WP News Sliders
- Plugin:
- WP News Sliders
- Plugin Slug:
- wp-news-sliders
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22779
WP Options Editor
- Plugin:
- WP Options Editor
- Plugin Slug:
- wp-options-editor
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2025-23797
wp-pano
- Plugin:
- wp-pano
- Plugin Slug:
- wp-pano
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22780
WP Panoramio
- Plugin:
- WP Panoramio
- Plugin Slug:
- wp-panoramio
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23662
WP Photo Sphere
- Plugin:
- WP Photo Sphere
- Plugin Slug:
- wp-photo-sphere
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23924
WP-Player
- Plugin:
- WP-Player
- Plugin Slug:
- wp-player
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23947
WP PT-Viewer
- Plugin:
- WP PT-Viewer
- Plugin Slug:
- wp-ptviewer
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23438
WP-Revive Adserver
- Plugin:
- WP-Revive Adserver
- Plugin Slug:
- wp-revive-adserver
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23802
Wp-Scribd-List
- Plugin:
- Wp-Scribd-List
- Plugin Slug:
- wp-scribd-list
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23436
SendGrid for WordPress
- Plugin:
- SendGrid for WordPress
- Plugin Slug:
- wp-sendgrid-mailer
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23423
WP Service Payment Form With Authorize.net
- Plugin:
- WP Service Payment Form With Authorize.net
- Plugin Slug:
- wp-service-payment-form-with-authorizenet
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23804
WP2APP
- Plugin:
- WP2APP
- Plugin Slug:
- wp2appir
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23811
WPDB to Sql
- Plugin:
- WPDB to Sql
- Plugin Slug:
- wpdb-to-sql
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23774
WpF Ultimate Carousel
- Plugin:
- WpF Ultimate Carousel
- Plugin Slug:
- wpf-ultimate-carousel
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23933
WordPress File Search
- Plugin:
- WordPress File Search
- Plugin Slug:
- wpfilesearch
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23867
WP Journal
- Plugin:
- WP Journal
- Plugin Slug:
- wpjournal
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23613
WP Lyrics
- Plugin:
- WP Lyrics
- Plugin Slug:
- wplyrics
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23533
XLSXviewer
- Plugin:
- XLSXviewer
- Plugin Slug:
- xlsx-viewer
- Vulnerability:
- Arbitrary File Deletion
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23562
Xola
- Plugin:
- Xola
- Plugin Slug:
- xola-bookings-for-tours-activities
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23955
Yet Another Countdown
- Plugin:
- Yet Another Countdown
- Plugin Slug:
- yacp
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-23891
yCyclista
- Plugin:
- yCyclista
- Plugin Slug:
- ycyclista
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23700
Zarinpal Paid Download
- Plugin:
- Zarinpal Paid Download
- Plugin Slug:
- zarinpal-paid-downloads
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22766
UpdraftPlus: WP Backup & Migration Plugin
- Plugin Slug:
- updraftplus
- Installations
- 3,000,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.25.1
- Severity Score:
- High
- CVE:
- 2025-0215
W3 Total Cache
- Plugin:
- W3 Total Cache
- Plugin Slug:
- w3-total-cache
- Installations
- 1,000,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.8.2
- Severity Score:
- Medium
- CVE:
- 2024-12008
W3 Total Cache
- Plugin:
- W3 Total Cache
- Plugin Slug:
- w3-total-cache
- Installations
- 1,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.8.2
- Severity Score:
- Medium
- CVE:
- 2024-12006
W3 Total Cache
- Plugin:
- W3 Total Cache
- Plugin Slug:
- w3-total-cache
- Installations
- 1,000,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.8.2
- Severity Score:
- Medium
- CVE:
- 2024-12365
Page Builder by SiteOrigin
- Plugin:
- Page Builder by SiteOrigin
- Plugin Slug:
- siteorigin-panels
- Installations
- 600,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.31.1
- Severity Score:
- Medium
- CVE:
- 2024-12240
Royal Elementor Addons and Templates
- Plugin Slug:
- royal-elementor-addons
- Installations
- 500,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.7.1007
- Severity Score:
- High
- CVE:
- 2025-0393
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 2.9.2
- Severity Score:
- Medium
- CVE:
- 2025-0318
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
- Plugin Slug:
- ultimate-member
- Installations
- 200,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 2.9.2
- Severity Score:
- Critical
- CVE:
- 2025-0308
Elementor Addon Elements
- Plugin:
- Elementor Addon Elements
- Plugin Slug:
- addon-elements-for-elementor-page-builder
- Installations
- 100,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.14
- Severity Score:
- Medium
- CVE:
- 2024-13215
Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin
- Plugin Slug:
- file-manager-advanced
- Installations
- 100,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 5.2.14
- Severity Score:
- High
- CVE:
- 2024-13333
NitroPack – Caching & Speed Optimization for Core Web Vitals, Defer CSS & JS, Lazy load Images and CDN
- Plugin Slug:
- nitropack
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.17.6
- Severity Score:
- Medium
- CVE:
- 2024-11848
Widget Options – The #1 WordPress Widget & Block Control Plugin
- Plugin Slug:
- widget-options
- Installations
- 100,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 4.0.9
- Severity Score:
- Medium
- CVE:
- 2025-22722
List category posts
- Plugin:
- List category posts
- Plugin Slug:
- list-category-posts
- Installations
- 90,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 0.90.3
- Severity Score:
- Medium
- CVE:
- 2024-9020
Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce
- Plugin Slug:
- email-subscribers
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.7.45
- Severity Score:
- Medium
- CVE:
- 2024-11636
Kubio AI Page Builder
- Plugin:
- Kubio AI Page Builder
- Plugin Slug:
- kubio
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.4.0
- Severity Score:
- High
- CVE:
- 2024-13516
WP ULike – All-in-One Engagement Toolkit
- Plugin Slug:
- wp-ulike
- Installations
- 80,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7.7
- Severity Score:
- Medium
- CVE:
- 2025-22738
WP Booking Calendar
- Plugin:
- WP Booking Calendar
- Plugin Slug:
- booking
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 10.9.3
- Severity Score:
- Medium
- CVE:
- 2024-13323
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
- Plugin Slug:
- easy-digital-downloads
- Installations
- 50,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.3
- Severity Score:
- Medium
- CVE:
- 2024-13517
Piotnet Addons For Elementor
- Plugin:
- Piotnet Addons For Elementor
- Plugin Slug:
- piotnet-addons-for-elementor
- Installations
- 40,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.4.33
- Severity Score:
- Medium
- CVE:
- 2024-10775
Post Grid and Gutenberg Blocks – ComboBlocks
- Plugin Slug:
- post-grid
- Installations
- 40,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.3.4
- Severity Score:
- Critical
- CVE:
- 2024-9636
HTML5 Video Player – mp4 Video Player Plugin and Block
- Plugin Slug:
- html5-video-player
- Installations
- 30,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.5.36
- Severity Score:
- Medium
- CVE:
- 2024-13156
Social Share, Social Login and Social Comments Plugin – Super Socializer
- Plugin Slug:
- super-socializer
- Installations
- 30,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 7.14.1
- Severity Score:
- Medium
- CVE:
- 2024-13230
VOD Infomaniak
- Plugin:
- VOD Infomaniak
- Plugin Slug:
- vod-infomaniak
- Installations
- 30,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.10
- Severity Score:
- Medium
- CVE:
- 2025-22729
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress
- Plugin Slug:
- bookingpress-appointment-booking
- Installations
- 20,000+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.1.23
- Severity Score:
- Medium
- CVE:
- 2024-12274
Link Library
- Plugin:
- Link Library
- Plugin Slug:
- link-library
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 7.7.3
- Severity Score:
- High
- CVE:
- 2024-13404
Multi Step Form
- Plugin:
- Multi Step Form
- Plugin Slug:
- multi-step-form
- Installations
- 10,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.7.24
- Severity Score:
- Medium
- CVE:
- 2024-12427
Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin:
- Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction
- Plugin Slug:
- paid-member-subscriptions
- Installations
- 10,000+
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 2.13.8
- Severity Score:
- Critical
- CVE:
- 2024-12919
WooCommerce Advanced Bulk Edit Products, Orders, Coupons, Any WordPress Post Type – Smart Manager
- Plugin:
- WooCommerce Advanced Bulk Edit Products, Orders, Coupons, Any WordPress Post Type – Smart Manager
- Plugin Slug:
- smart-manager-for-wp-e-commerce
- Installations
- 10,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 8.53.0
- Severity Score:
- High
- CVE:
- 2025-22710
Payment Button for PayPal
- Plugin:
- Payment Button for PayPal
- Plugin Slug:
- wp-paypal
- Installations
- 10,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.3.36
- Severity Score:
- Medium
- CVE:
- 2024-13401
WP User Profile Avatar
- Plugin:
- WP User Profile Avatar
- Plugin Slug:
- wp-user-profile-avatar
- Installations
- 10,000+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.0.6
- Severity Score:
- Medium
- CVE:
- 2024-10789
Motors – Car Dealer, Classifieds & Listing
- Plugin Slug:
- motors-car-dealership-classified-listings
- Installations
- 9,000+
- Vulnerability:
- Arbitrary Code Execution
- Patched in Version:
- 1.4.44
- Severity Score:
- Medium
- CVE:
- 2024-10970
WP Hotel Booking
- Plugin:
- WP Hotel Booking
- Plugin Slug:
- wp-hotel-booking
- Installations
- 8,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.1.6
- Severity Score:
- Medium
- CVE:
- 2024-12370
Proofreading
- Plugin:
- Proofreading
- Plugin Slug:
- proofreading
- Installations
- 6,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.2.2
- Severity Score:
- High
- CVE:
- 2024-12466
ElementInvader Addons for Elementor
- Plugin Slug:
- elementinvader-addons-for-elementor
- Installations
- 5,000+
- Vulnerability:
- Local File Inclusion
- Patched in Version:
- 1.2.7
- Severity Score:
- High
- CVE:
- 2025-22786
Podlove Podcast Publisher
- Plugin:
- Podlove Podcast Publisher
- Plugin Slug:
- podlove-podcasting-plugin-for-wordpress
- Installations
- 5,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2.0
- Severity Score:
- Medium
- CVE:
- 2025-0554
Button Block – Get fully customizable & multi-functional buttons
- Plugin Slug:
- button-block
- Installations
- 4,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.1.6
- Severity Score:
- Medium
- CVE:
- 2025-22787
ApplyOnline – Application Form Builder and Manager
- Plugin Slug:
- apply-online
- Installations
- 3,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.6.7.2
- Severity Score:
- Medium
- CVE:
- 2025-22721
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder
- Plugin Slug:
- mailchimp-subscribe-sm
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.2
- Severity Score:
- Medium
- CVE:
- 2025-22727
Tag Groups is the Advanced Way to Display Your Taxonomy Terms
- Plugin Slug:
- tag-groups
- Installations
- 3,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.5
- Severity Score:
- High
- CVE:
- 2025-22735
Eventer
- Plugin:
- Eventer
- Plugin Slug:
- eventer
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Download
- Patched in Version:
- 3.9.8
- Severity Score:
- Medium
- CVE:
- 2024-10799
Flexible PDF Coupons – Gift Cards & Vouchers for WooCommerce
- Plugin Slug:
- flexible-coupons
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.10.3
- Severity Score:
- Medium
- CVE:
- 2025-22825
WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg
- Plugin Slug:
- groundhogg
- Installations
- 2,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 3.7.3.6
- Severity Score:
- Critical
- CVE:
- 2025-0394
Htaccess File Editor – Easily Edit, Backup, Restore .htaccess file
- Plugin Slug:
- htaccess-file-editor
- Installations
- 2,000+
- Vulnerability:
- Broken Authentication
- Patched in Version:
- 1.0.20
- Severity Score:
- Medium
- CVE:
- 2025-22773
Image Source Control Lite – Show Image Credits and Captions
- Plugin Slug:
- image-source-control-isc
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.29.1
- Severity Score:
- High
- CVE:
- 2025-22711
Image Source Control Lite – Show Image Credits and Captions
- Plugin Slug:
- image-source-control-isc
- Installations
- 2,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.28.1
- Severity Score:
- High
- CVE:
- 2024-13515
Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
- Plugin:
- Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)
- Plugin Slug:
- barcode-scanner-lite-pos-to-manage-products-inventory-and-orders
- Installations
- 1,000+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 1.7.0
- Severity Score:
- Critical
- CVE:
- 2025-22723
Checkout for PayPal
- Plugin:
- Checkout for PayPal
- Plugin Slug:
- checkout-for-paypal
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.0.33
- Severity Score:
- Medium
- CVE:
- 2024-13398
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution
- Plugin Slug:
- marketking-multivendor-marketplace-for-woocommerce
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.0.0
- Severity Score:
- Medium
- CVE:
- 2024-13519
Social proof testimonials and reviews by Repuso
- Plugin Slug:
- social-testimonials-and-reviews-widget
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 5.21
- Severity Score:
- Medium
- CVE:
- 2024-13351
WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly
- Plugin Slug:
- tour-booking-manager
- Installations
- 1,000+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.8.6
- Severity Score:
- Medium
- CVE:
- 2025-22737
WP Inventory Manager
- Plugin:
- WP Inventory Manager
- Plugin Slug:
- wp-inventory-manager
- Installations
- 1,000+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.3.3
- Severity Score:
- High
- CVE:
- 2024-13434
The Ultimate WordPress Toolkit – WP Extended
- Plugin Slug:
- wpextended
- Installations
- 1,000+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.0.13
- Severity Score:
- Critical
- CVE:
- 2024-13184
My Tickets – Accessible Event Ticketing
- Plugin Slug:
- my-tickets
- Installations
- 900+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.10
- Severity Score:
- High
- CVE:
- 2025-22717
Taskbuilder – WordPress Project & Task Management plugin
- Plugin Slug:
- taskbuilder
- Installations
- 800+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 3.0.7
- Severity Score:
- High
- CVE:
- 2025-22716
FireCask Like & Share Button
- Plugin:
- FireCask Like & Share Button
- Plugin Slug:
- facebook-like-send-button
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3
- Severity Score:
- Medium
- CVE:
- 2024-11226
My auctions allegro
- Plugin:
- My auctions allegro
- Plugin Slug:
- my-auctions-allegro-free-edition
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.19
- Severity Score:
- High
- CVE:
- 2025-22733
Verge3D Publishing and E-Commerce
- Plugin Slug:
- verge3d
- Installations
- 600+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.1
- Severity Score:
- High
- CVE:
- 2025-22709
PDF for WPForms + Drag and Drop Template Builder
- Plugin Slug:
- pdf-for-wpforms
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.8.0
- Severity Score:
- Medium
- CVE:
- 2024-12593
Simple:Press Forum
- Plugin:
- Simple:Press Forum
- Plugin Slug:
- simplepress
- Installations
- 500+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 6.10.11
- Severity Score:
- High
VikAppointments Services Booking Calendar
- Plugin Slug:
- vikappointments
- Installations
- 500+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.2.17
- Severity Score:
- High
- CVE:
- 2025-22719
Admin and Customer Messages After Order for WooCommerce: OrderConvo
- Plugin Slug:
- admin-and-client-message-after-order-for-woocommerce
- Installations
- 400+
- Vulnerability:
- Arbitrary File Upload
- Patched in Version:
- 13.3
- Severity Score:
- Medium
- CVE:
- 2024-13355
Chamber Dashboard Business Directory
- Plugin Slug:
- chamber-dashboard-business-directory
- Installations
- 400+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 3.3.11
- Severity Score:
- Medium
- CVE:
- 2025-23917
Chamber Dashboard Business Directory
- Plugin Slug:
- chamber-dashboard-business-directory
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.10
- Severity Score:
- Medium
- CVE:
- 2024-11452
Picture Gallery – Frontend Image Uploads, AJAX Photo List
- Plugin Slug:
- picture-gallery
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.5.23
- Severity Score:
- Medium
- CVE:
- 2024-12696
Stop Comment Spam
- Plugin:
- Stop Comment Spam
- Plugin Slug:
- stop-comment-spam
- Installations
- 400+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 0.5.4
- Severity Score:
- High
- CVE:
- 2025-23826
WP Smart TV
- Plugin:
- WP Smart TV
- Plugin Slug:
- wp-smart-tv
- Installations
- 400+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1.9
- Severity Score:
- Medium
- CVE:
- 2024-12818
ShipWorks Connector for Woocommerce
- Plugin Slug:
- shipworks-e-commerce-bridge
- Installations
- 300+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 5.2.6
- Severity Score:
- Medium
- CVE:
- 2024-13317
turboSMTP
- Plugin:
- turboSMTP
- Plugin Slug:
- turbosmtp
- Installations
- 300+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 4.7
- Severity Score:
- High
- CVE:
- 2025-22753
aDirectory – WordPress Directory Listing Plugin
- Plugin Slug:
- adirectory
- Installations
- 200+
- Vulnerability:
- PHP Object Injection
- Patched in Version:
- 1.9
- Severity Score:
- High
Build Private Store For Woocommerce
- Plugin Slug:
- build-private-store-for-woocommerce
- Installations
- 200+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 1.1
- Severity Score:
- Medium
- CVE:
- 2025-22731
Awesome Responsive Photo Gallery – Image & Video Lightbox Gallery
- Plugin Slug:
- awesome-responsive-photo-gallery
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.1
- Severity Score:
- High
- CVE:
- 2024-12403
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
- Plugin Slug:
- evergreen-content-poster
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.4.5
- Severity Score:
- High
- CVE:
- 2024-12071
Moving Users
- Plugin:
- Moving Users
- Plugin Slug:
- moving-users
- Installations
- 100+
- Vulnerability:
- Sensitive Data Exposure
- Patched in Version:
- 1.10
- Severity Score:
- Medium
- CVE:
- 2024-12637
Passwords Manager
- Plugin:
- Passwords Manager
- Plugin Slug:
- passwords-manager
- Installations
- 100+
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2024-12614
Passwords Manager
- Plugin:
- Passwords Manager
- Plugin Slug:
- passwords-manager
- Installations
- 100+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.1
- Severity Score:
- High
- CVE:
- 2024-12615
Passwords Manager
- Plugin:
- Passwords Manager
- Plugin Slug:
- passwords-manager
- Installations
- 100+
- Vulnerability:
- SQL Injection
- Patched in Version:
- 1.5.1
- Severity Score:
- Critical
- CVE:
- 2024-12613
Video Share VOD – Turnkey Video Site Builder Script
- Plugin Slug:
- video-share-vod
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.6.32
- Severity Score:
- Medium
- CVE:
- 2024-13393
WP-BibTeX
- Plugin:
- WP-BibTeX
- Plugin Slug:
- wp-bibtex
- Installations
- 100+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.2
- Severity Score:
- High
- CVE:
- 2024-12005
Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings
- Plugin Slug:
- rate-star-review
- Installations
- 90+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.4
- Severity Score:
- Medium
- CVE:
- 2024-13392
MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet
- Plugin Slug:
- paid-membership
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.30
- Severity Score:
- Medium
- CVE:
- 2024-13391
Webcamconsult
- Plugin:
- Webcamconsult
- Plugin Slug:
- webcamconsult
- Installations
- 60+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.6.0
- Severity Score:
- High
- CVE:
- 2024-13432
wp-greet
- Plugin:
- wp-greet
- Plugin Slug:
- wp-greet
- Installations
- 60+
- Vulnerability:
- Cross Site Request Forgery (CSRF)
- Patched in Version:
- 6.3
- Severity Score:
- High
- CVE:
- 2024-13444
JSM Screenshot Machine Shortcode
- Plugin:
- JSM Screenshot Machine Shortcode
- Plugin Slug:
- screenshot-machine-shortcode
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.0.0
- Severity Score:
- Medium
- CVE:
- 2024-13385
WP Responsive Tabs
- Plugin:
- WP Responsive Tabs
- Plugin Slug:
- wp-responsive-tabs
- Installations
- 40+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.3.0
- Severity Score:
- Medium
- CVE:
- 2024-13387
Posts Footer Manager
- Plugin:
- Posts Footer Manager
- Plugin Slug:
- intelly-posts-footer-manager
- Installations
- 20+
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.2.0
- Severity Score:
- Medium
- CVE:
- 2025-22734
Adifier System
- Plugin:
- Adifier System
- Plugin Slug:
- adifier-system
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- 3.1.8
- Severity Score:
- Critical
- CVE:
- 2024-13375
Gravity Forms
- Plugin:
- Gravity Forms
- Plugin Slug:
- gravityforms
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.9.2
- Severity Score:
- High
- CVE:
- 2024-13377
JetElements For Elementor
- Plugin:
- JetElements For Elementor
- Plugin Slug:
- jet-elements
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 2.7.3
- Severity Score:
- Medium
- CVE:
- 2025-0371
JetEngine
- Plugin:
- JetEngine
- Plugin Slug:
- jet-engine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.6.3
- Severity Score:
- Medium
- CVE:
- 2025-0369
Tamara Checkout
- Plugin:
- Tamara Checkout
- Plugin Slug:
- tamara-checkout
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 1.9.9.1
- Severity Score:
- Medium
- CVE:
- 2025-23997
WordPress Themes — 3 Patched / 22 Unpatched
Multifox
- Theme:
- Multifox
- Theme Slug:
- multifox
- Downloads
- 5,014
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22769
my money
- Theme:
- my money
- Theme Slug:
- my-money
- Downloads
- 20,130
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-49269
The Ultralight
- Theme:
- The Ultralight
- Theme Slug:
- the-ultralight
- Downloads
- 19,244
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23998
TIJAJI
- Theme:
- TIJAJI
- Theme Slug:
- tijaji
- Downloads
- 13,991
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23983
CarZine
- Theme:
- CarZine
- Theme Slug:
- carzine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23981
Envo Multipurpose
- Theme:
- Envo Multipurpose
- Theme Slug:
- envo-multipurpose
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2025-22770
Flashy
- Theme:
- Flashy
- Theme Slug:
- flashy
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23979
ghostwriter
- Theme:
- ghostwriter
- Theme Slug:
- ghostwriter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23988
Js O3 Lite
- Theme:
- Js O3 Lite
- Theme Slug:
- js-o3-lite
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22792
moseter
- Theme:
- moseter
- Theme Slug:
- moseter
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22790
my depressive
- Theme:
- my depressive
- Theme Slug:
- my-depressive
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-49269
my engine
- Theme:
- my engine
- Theme Slug:
- my-engine
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-49269
my white
- Theme:
- my white
- Theme Slug:
- my-white
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22678
my zebra
- Theme:
- my zebra
- Theme Slug:
- my-zebra
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-49269
offset writing
- Theme:
- offset writing
- Theme Slug:
- offset-writing
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22791
polka dots
- Theme:
- polka dots
- Theme Slug:
- polka-dots
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22789
RealHomes
- Theme:
- RealHomes
- Theme Slug:
- realhomes
- Vulnerability:
- Privilege Escalation
- Patched in Version:
- No Fix
- Severity Score:
- Critical
- CVE:
- 2024-32444
Sandbox
- Theme:
- Sandbox
- Theme Slug:
- sandbox
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2024-13366
Sandbox
- Theme:
- Sandbox
- Theme Slug:
- sandbox
- Vulnerability:
- Broken Access Control
- Patched in Version:
- No Fix
- Severity Score:
- Medium
- CVE:
- 2024-13367
Tantyyellow
- Theme:
- Tantyyellow
- Theme Slug:
- tantyyellow
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23995
Tiki Time
- Theme:
- Tiki Time
- Theme Slug:
- tiki-time
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-23986
Tuaug4
- Theme:
- Tuaug4
- Theme Slug:
- tuaug4
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- No Fix
- Severity Score:
- High
- CVE:
- 2025-22687
Betheme
- Theme:
- Betheme
- Theme Slug:
- betheme
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 27.6.2
- Severity Score:
- Medium
- CVE:
- 2025-0450
Buzz Club
- Theme:
- Buzz Club
- Theme Slug:
- buzzclub
- Vulnerability:
- Broken Access Control
- Patched in Version:
- 2.0.5
- Severity Score:
- Medium
- CVE:
- 2025-0515
DWT – Directory & Listing
- Theme:
- DWT – Directory & Listing
- Theme Slug:
- dwt-listing
- Vulnerability:
- Cross Site Scripting (XSS)
- Patched in Version:
- 3.3.4
- Severity Score:
- High
- CVE:
- 2025-0170
Solid Security is part of Solid Suite — The best foundation for WordPress websites.
Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!
Sign up now — Get SolidWP updates and valuable content straight to your inbox
Sign up
Get started with confidence — risk free, guaranteed
