WordPress Vulnerability Report

WordPress Vulnerability Report — January 8, 2025

This last week, 228 new plugin and theme vulnerabilities emerged in the WordPress ecosystem. 131 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Sarah

In this report, 228 vulnerabilities have been publicly disclosed. Security patches for 97 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 131 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 95 Patched / 110 Unpatched

Smart Custom Fields

Plugin Slug:
smart-custom-fields
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
link-whisper
Installations
30,000+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Thim Elementor Kit

Plugin Slug:
thim-elementor-kit
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TemplatesNext ToolKit

Plugin Slug:
templatesnext-toolkit
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP FullCalendar

Plugin Slug:
wp-fullcalendar
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hash Elements

Plugin Slug:
hash-elements
Installations
6,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CubeWP Forms – All-in-One Form Builder

Plugin Slug:
cubewp-forms
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes

Plugin Slug:
elex-bulk-edit-products-prices-attributes-for-woocommerce-basic
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SpeakOut! Email Petitions

Plugin Slug:
speakout
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DynamicTags

Plugin Slug:
dynamictags
Installations
2,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

BSK Forms Blacklist

Plugin Slug:
bsk-gravityforms-blacklist
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hero Banner Ultimate

Plugin Slug:
hero-banner-ultimate
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Typing Text

Plugin Slug:
typing-text
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Field For WP Job Manager

Plugin Slug:
custom-field-for-wp-job-manager
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Build App Online

Plugin Slug:
build-app-online
Installations
700+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordLift – AI powered SEO – Schema

Plugin Slug:
wordlift
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SMSA Shipping (official)

Plugin Slug:
smsa-shipping-official
Installations
500+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-youtube-gallery
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

NAVER Analytics

Plugin Slug:
naver-analytics
Installations
400+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ThePerfectWedding.nl Widget

Plugin Slug:
theperfectweddingnl-widget
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hide Category by User Role for WooCommerce

Plugin Slug:
hide-category-by-user-role-for-woocommerce
Installations
200+
Vulnerability:
Arbitrary Content Deletion
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rezgo Online Booking

Plugin Slug:
rezgo
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Standard Box Sizes – for WooCommerce

Plugin Slug:
standard-box-sizes
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ARS Affiliate Page Plugin

Plugin Slug:
ars-affiliate-page
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ProductDyno

Plugin Slug:
productdyno
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SSL Wireless SMS Notification

Plugin Slug:
ssl-wireless-sms-notification
Installations
70+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Image Hover Effects for Elementor

Plugin Slug:
image-hover-effects-elementor-addon
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP SecureSubmit

Plugin Slug:
securesubmit
Installations
60+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP SecureSubmit

Plugin Slug:
securesubmit
Installations
60+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chative Live chat and Chatbot

Plugin Slug:
chative-live-chat-and-chatbot
Installations
50+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EO4WP: EmailOctopus for WordPress

Plugin Slug:
fw-integration-for-emailoctopus
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

5centsCDN – WordPress CDN Plugin

Plugin Slug:
5centscdn
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ACH Invoicing Plugin

Plugin Slug:
ach-invoice-app
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Database – CFDB7

Plugin:
Contact Form 7 Database – CFDB7
Plugin Slug:
advanced-cf7-database
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wp advertising management

Plugin:
Wp advertising management
Plugin Slug:
advertising-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

AHAthat

Plugin:
AHAthat
Plugin Slug:
ahathat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Allada T-shirt Designer for Woocommerce

Plugin:
Allada T-shirt Designer for Woocommerce
Plugin Slug:
allada-tshirt-designer-for-woocommerce
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:
ARPrice
Plugin Slug:
arprice
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:
ARPrice
Plugin Slug:
arprice
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:
ARPrice
Plugin Slug:
arprice
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ARPrice

Plugin:
ARPrice
Plugin Slug:
arprice
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Autocompleter

Plugin:
Autocompleter
Plugin Slug:
autocompleter
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Bizapp for WooCommerce

Plugin:
Bizapp for WooCommerce
Plugin Slug:
bizapp-for-woocommerce
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
BVD Easy Gallery Manager
Plugin Slug:
bvd-easy-gallery-manager
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Candifly

Plugin:
Candifly
Plugin Slug:
candifly
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chatroll Live Chat

Plugin:
Chatroll Live Chat
Plugin Slug:
chatroll-live-chat
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ClickDesigns

Plugin:
ClickDesigns
Plugin Slug:
clickdesigns
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Common Ninja

Plugin:
Common Ninja
Plugin Slug:
common-ninja
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Duplicate Post, Page and Any Custom Post

Plugin:
Duplicate Post, Page and Any Custom Post
Plugin Slug:
duplicate-pp
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elevio

Plugin:
Elevio
Plugin Slug:
elevio
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

EMC2 Alert Boxes

Plugin:
EMC2 Alert Boxes
Plugin Slug:
emc2-alert-boxes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Enable Accessibility

Plugin:
Enable Accessibility
Plugin Slug:
enable-accessibility
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Fancy Product Designer

Plugin:
Fancy Product Designer
Plugin Slug:
fancy-product-designer
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Formaloo Form Maker

Plugin:
Formaloo Form Maker
Plugin Slug:
formaloo-form-builder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GDY Modular Content

Plugin:
GDY Modular Content
Plugin Slug:
gdy-modular-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Geo Content

Plugin:
Geo Content
Plugin Slug:
geo-targetly-geo-content
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin:
Hero Mega Menu – Responsive WordPress Menu Plugin
Plugin Slug:
hmenu
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hero Mega Menu – Responsive WordPress Menu Plugin

Plugin:
Hero Mega Menu – Responsive WordPress Menu Plugin
Plugin Slug:
hmenu
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Host PHP Info

Plugin:
Host PHP Info
Plugin Slug:
host-php-info
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Learning Pro

Plugin:
Ultimate Learning Pro
Plugin Slug:
indeed-learning-pro
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LazyLoad Background Images

Plugin:
LazyLoad Background Images
Plugin Slug:
lazyload-background-images
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Marketplace Items

Plugin:
Marketplace Items
Plugin Slug:
marketplace-items
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Meteor Slides

Plugin:
Meteor Slides
Plugin Slug:
meteor-slides
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MG Parallax Slider

Plugin:
MG Parallax Slider
Plugin Slug:
mg-parallax-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Opencart Product in WP

Plugin:
Opencart Product in WP
Plugin Slug:
opencart-product-in-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OZ Canonical

Plugin:
OZ Canonical
Plugin Slug:
oz-canonical
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

PayGreen Payment Gateway

Plugin:
PayGreen Payment Gateway
Plugin Slug:
paygreen-payment-gateway
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RightMessage WP

Plugin:
RightMessage WP
Plugin Slug:
rightmessage
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Kikx Simple Post Author Filter

Plugin:
Kikx Simple Post Author Filter
Plugin Slug:
sa-post-author-filter
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

School Management System – SakolaWP

Plugin:
School Management System – SakolaWP
Plugin Slug:
sakolawp-lite
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Sell Media

Plugin:
Sell Media
Plugin Slug:
sell-media
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Sellsy

Plugin:
Sellsy
Plugin Slug:
sellsy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SEO LAT Auto Post

Plugin:
SEO LAT Auto Post
Plugin Slug:
seo-beginner-auto-post
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Simple Add Pages or Posts

Plugin:
Simple Add Pages or Posts
Plugin Slug:
simple-add-pages-or-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Slider Pro Lite

Plugin:
Slider Pro Lite
Plugin Slug:
slider-pro-lite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Rocket

Plugin:
Social Rocket
Plugin Slug:
social-rocket
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Social Rocket

Plugin:
Social Rocket
Plugin Slug:
social-rocket
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spacer

Plugin:
Spacer
Plugin Slug:
spacer
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

SweepWidget Contests, Giveaways, Photo Contests, Competitions

Plugin:
SweepWidget Contests, Giveaways, Photo Contests, Competitions
Plugin Slug:
sweepwidget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

SyncFields

Plugin:
SyncFields
Plugin Slug:
syncfields
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP-tagMaker

Plugin:
WP-tagMaker
Plugin Slug:
tagmaker
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Target Notifications

Plugin:
Target Notifications
Plugin Slug:
target-notifications
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Themes Coder

Plugin:
Themes Coder
Plugin Slug:
tc-ecommerce
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Timeline Designer

Plugin:
Timeline Designer
Plugin Slug:
timeline-designer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Transporters.io

Plugin:
Transporters.io
Plugin Slug:
transportersio
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Private Messages for UserPro

Plugin:
Private Messages for UserPro
Plugin Slug:
userpro-messaging
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ViewMedica 9

Plugin:
ViewMedica 9
Plugin Slug:
viewmedica
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ViewMedica 9

Plugin:
ViewMedica 9
Plugin Slug:
viewmedica
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WC1C

Plugin:
WC1C
Plugin Slug:
wc1c-main
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Wizhi Multi Filters by Wenprise

Plugin:
Wizhi Multi Filters by Wenprise
Plugin Slug:
wizhi-multi-filters
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Binary MLM Woocommerce

Plugin:
Binary MLM Woocommerce
Plugin Slug:
woo-binary-mlm
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Woo Ukrposhta

Plugin:
Woo Ukrposhta
Plugin Slug:
woo-ukrposhta
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket

Plugin:
WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket
Plugin Slug:
woocommerce-digital-content-delivery-with-drm-flickrocket
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Live Sales Notification for Woocommerce – Woomotiv

Plugin:
Live Sales Notification for Woocommerce – Woomotiv
Plugin Slug:
woomotiv
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:
WordPress Auction Plugin
Plugin Slug:
wp-auctions
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Simple Sitemap

Plugin:
WP Simple Sitemap
Plugin Slug:
wp-simple-sitemap
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPAchievements Free

Plugin:
WPAchievements Free
Plugin Slug:
wpachievements-free
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

wpSOL

Plugin:
wpSOL
Plugin Slug:
wpsol
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Custom Product Tabs for WooCommerce

Plugin:
Custom Product Tabs for WooCommerce
Plugin Slug:
yikes-inc-easy-custom-woocommerce-product-tabs
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

UpdraftPlus: WP Backup & Migration Plugin

Plugin Slug:
updraftplus
Installations
3,000,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.24.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.24.12.

Envato Elements – Photos & Elementor Templates

Plugin Slug:
envato-elements
Installations
1,000,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
2.0.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.15.

Migration, Backup, Staging – WPvivid Backup & Migration

Plugin Slug:
wpvivid-backuprestore
Installations
600,000+
Vulnerability:
Broken Access Control
Patched in Version:
0.9.107
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 0.9.107.

PixelYourSite – Your smart PIXEL (TAG) & API Manager

Plugin Slug:
pixelyoursite
Installations
500,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
10.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 10.0.2.

Astra Widgets

Plugin Slug:
astra-widgets
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.16.

Pods – Custom Content Types and Fields

Plugin Slug:
pods
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.8.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.8.1.
Plugin Slug:
wordpress-popular-posts
Installations
100,000+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
7.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.2.0.

Backup Migration

Plugin Slug:
backup-backup
Installations
80,000+
Vulnerability:
PHP Object Injection
Patched in Version:
1.4.6.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.6.1.

Media Library Assistant

Plugin Slug:
media-library-assistant
Installations
70,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.24
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.24.

Piotnet Addons For Elementor

Plugin Slug:
piotnet-addons-for-elementor
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.32
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.32.

Compact WP Audio Player

Plugin Slug:
compact-wp-audio-player
Installations
30,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.9.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.15.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic
Installations
20,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.10.37
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.10.37.

Post Grid Elementor Addon

Plugin Slug:
post-grid-elementor-addon
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.19
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.19.

AFI – The Easiest Integration Plugin

Plugin Slug:
advanced-form-integration
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.97.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.97.0.

AyeCode Connect

Plugin Slug:
ayecode-connect
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.9.

Export Import Menus

Plugin Slug:
export-import-menus
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.

Mang Board WP

Plugin Slug:
mangboard
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.5.

WP Post Author – Boost Your Blog’s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder

Plugin Slug:
wp-post-author
Installations
10,000+
Vulnerability:
SQL Injection
Patched in Version:
3.8.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.3.

Export All Posts, Products, Orders, Refunds & Users

Plugin Slug:
wp-ultimate-exporter
Installations
10,000+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
2.9.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.9.2.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
7,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.30.04
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.30.04.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.15
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.15.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor
Installations
5,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.1.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.1.4.

Ashe Extra

Plugin:
Ashe Extra
Plugin Slug:
ashe-extra
Installations
3,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.

Move Addons for Elementor

Plugin Slug:
move-addons
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

Classic Addons – WPBakery Page Builder

Plugin Slug:
classic-addons-wpbakery-page-builder-addons
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

MyBookTable Bookstore by Stormhill Media

Plugin Slug:
mybooktable
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.5.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.

Premium Blocks – Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.43
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.43.

Pronamic Google Maps

Plugin Slug:
pronamic-google-maps
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.3.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.

WP Wand – AI Writer, AI Content Generator & AI Assistant by ChatGPT, OpenAI | Generate SEO Friendly AI Blog Post & Article with 20X Speed

Plugin Slug:
ai-content-generation
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.2.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.6.

Accessibility by AllAccessible

Plugin Slug:
allaccessible
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
1.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.5.
Plugin Slug:
contest-gallery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
24.0.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 24.0.4.

Enter Addons – Ultimate Template Builder for Elementor

Plugin Slug:
enteraddons
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.1.

Locatoraid Store Locator

Plugin Slug:
locatoraid
Installations
1,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.9.51
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.51.

????? ?? ???? – ???? ?? ????

Plugin Slug:
pgall-for-woocommerce
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
5.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.2.2.

Themify Audio Dock

Plugin Slug:
themify-audio-dock
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.5.

WP Docs

Plugin:
WP Docs
Plugin Slug:
wp-docs
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.2.
Plugin Slug:
wp-responsive-photo-gallery
Installations
1,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
1.0.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.16.

WP Smart Import : Import any XML File to WordPress

Plugin Slug:
wp-smart-import
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.3.

ConvertCalculator for WordPress

Plugin Slug:
convertcalculator
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Event Espresso – Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
5.0.31.decaf
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.31.decaf.

WP Social AutoConnect

Plugin Slug:
wp-fb-autoconnect
Installations
900+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
4.6.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.3.

Hestia Nginx Cache

Plugin Slug:
hestia-nginx-cache
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
2.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.1.

Dynamics 365 Integration

Plugin Slug:
integration-dynamics
Installations
800+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.3.24
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.24.

Just Writing Statistics

Plugin Slug:
just-writing-statistics
Installations
800+
Vulnerability:
SQL Injection
Patched in Version:
4.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.8.

WP jQuery DataTable

Plugin Slug:
wp-jquery-datatable
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.1.0.

One to one user Chat by WPGuppy

Plugin Slug:
wpguppy-lite
Installations
800+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

One to one user Chat by WPGuppy

Plugin Slug:
wpguppy-lite
Installations
800+
Vulnerability:
PHP Object Injection
Patched in Version:
1.1.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.1.1.

WPMasterToolKit (WPMTK) – All in one plugin

Plugin Slug:
wpmastertoolkit
Installations
800+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.14.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.14.0.

WPMasterToolKit (WPMTK) – All in one plugin

Plugin Slug:
wpmastertoolkit
Installations
800+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.14.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.14.0.

Service Box

Plugin Slug:
service-boxs
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.

WP Multi Store Locator

Plugin Slug:
wp-multi-store-locator
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.4.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.4.6.

WP Mailster

Plugin Slug:
wp-mailster
Installations
300+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
1.8.18.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.8.18.0.

ACF City Selector

Plugin Slug:
acf-city-selector
Installations
200+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.15.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.15.0.

CC Canadian Mortgage Calculator

Plugin Slug:
cc-canadian-mortgage-calculator
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.1.

Multiple Shipping And Billing Address For Woocommerce

Plugin Slug:
different-shipping-and-billing-address-for-woocommerce
Installations
200+
Vulnerability:
SQL Injection
Patched in Version:
1.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.

Email Reminders

Plugin Slug:
email-reminders
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

Turnkey bbPress by WeaverTheme

Plugin Slug:
weaver-for-bbpress
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.1.

Interactive UK Map

Plugin Slug:
interactive-uk-map
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
3.4.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.4.9.

JobBoard Job listing plugin

Plugin Slug:
job-board-light
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.2.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.7.

Pretty Simple Popup Builder

Plugin Slug:
pretty-simple-popup-builder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.10.

PlainInventory – Inventory Management Plugin

Plugin Slug:
z-inventory-manager
Installations
100+
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.7.

Notify Odoo

Plugin Slug:
notify-odoo
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.0.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.1.

Error Log Viewer By WP Guru

Plugin Slug:
error-log-viewer-wp
Installations
80+
Vulnerability:
Arbitrary File Download
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

GS Shots for Dribbble

Plugin Slug:
gs-dribbble-portfolio
Installations
30+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.1.

Highlight Sitewide Notice, Text, Button Menu

Plugin Slug:
highlight
Installations
20+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.6.

GS Coaches

Plugin:
GS Coaches
Plugin Slug:
gs-coach
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.1.

WPMozo Addons Lite for Elementor

Plugin Slug:
wpmozo-addons-lite-for-elementor
Installations
10+
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.1.

Coins MarketCap

Plugin:
Coins MarketCap
Plugin Slug:
coins-marketcap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.5.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.5.9.

Floating Action Buttons

Plugin Slug:
floating-action-buttons
Vulnerability:
Broken Access Control
Patched in Version:
1.0.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.1.

Goodlayers Core

Plugin:
Goodlayers Core
Plugin Slug:
goodlayers-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.10
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.10.

ShopElement

Plugin Slug:
shopelement
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.1.0.

Tourmaster

Plugin:
Tourmaster
Plugin Slug:
tourmaster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.3.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.3.4.

WordPress Themes — 2 Patched / 21 Unpatched

Store Commerce

Theme Slug:
store-commerce
Downloads
50,956
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Aports – Single Property WordPress Theme

Theme:
Aports – Single Property WordPress Theme
Theme Slug:
aports
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Boliin – Resort & Hotel Booking WordPress Theme

Theme:
Boliin – Resort & Hotel Booking WordPress Theme
Theme Slug:
boliin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Constix – Construction Factory & Industrial WordPress Theme

Theme:
Constix – Construction Factory & Industrial WordPress Theme
Theme Slug:
constix
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Conult – Consulting Business WordPress Themes

Theme:
Conult – Consulting Business WordPress Themes
Theme Slug:
conult
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Digi Store

Theme:
Digi Store
Theme Slug:
digi-store
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Education LMS

Theme:
Education LMS
Theme Slug:
education-lms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Fioxen

Theme:
Fioxen
Theme Slug:
fioxen
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

TheFude – Crowdfunding & Charity WordPress Theme

Theme:
TheFude – Crowdfunding & Charity WordPress Theme
Theme Slug:
fude
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Gowilds – Travel & Tour Booking WordPress Theme

Theme:
Gowilds – Travel & Tour Booking WordPress Theme
Theme Slug:
gowilds
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Halpes

Theme:
Halpes
Theme Slug:
halpes
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Lestin – Directory Listing WordPress Theme

Theme:
Lestin – Directory Listing WordPress Theme
Theme Slug:
lestin
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Modins – Insurance & Finance WordPress Theme

Theme:
Modins – Insurance & Finance WordPress Theme
Theme Slug:
modins
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Orgarium – Agriculture & Organic Farm WordPress Theme

Theme:
Orgarium – Agriculture & Organic Farm WordPress Theme
Theme Slug:
orgarium
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Paroti

Theme:
Paroti
Theme Slug:
paroti
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pisole – Digital Creative Agency WordPress Theme

Theme:
Pisole – Digital Creative Agency WordPress Theme
Theme Slug:
pisole
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Qempo

Theme:
Qempo
Theme Slug:
qempo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Qizon – Crowdfunding & Charity WordPress Theme

Theme:
Qizon – Crowdfunding & Charity WordPress Theme
Theme Slug:
qizon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sominx – Creative Business Agency WordPress Theme

Theme:
Sominx – Creative Business Agency WordPress Theme
Theme Slug:
sominx
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Tevily – Travel & Tour Booking WordPress Theme

Theme:
Tevily – Travel & Tour Booking WordPress Theme
Theme Slug:
tevily
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

welowe

Theme:
welowe
Theme Slug:
welowe
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SimpleCharm

Theme Slug:
simplecharm
Downloads
1,014
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.4.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.4.

Aurum

Theme:
Aurum
Theme Slug:
aurum-minimalist-shopping-theme
Vulnerability:
Broken Access Control
Patched in Version:
4.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.0.3.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security