WordPress Vulnerability Report

WordPress Vulnerability Report — July 2, 2025

Since last week, 213 new vulnerabilities emerged in the WordPress ecosystem, including 175 plugins and 38 themes. 149 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 213 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 149 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 49 Patched / 126 Unpatched

Mollie Payments for WooCommerce

Plugin Slug:
mollie-payments-for-woocommerce
Installations
100,000+
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Edit

Plugin:
WP Edit
Plugin Slug:
wp-edit
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
cyrlitera
Installations
40,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
grand-media
Installations
9,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Hover Effects – easily create any hover effect

Plugin Slug:
hover-effects
Installations
8,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Additional Order Filters for WooCommerce

Plugin Slug:
additional-order-filters-for-woocommerce
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Cron Logger

Plugin Slug:
cron-logger
Installations
2,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons

Plugin Slug:
easy-sticky-sidebar
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Address Autocomplete via Google for Gravity Forms

Plugin Slug:
gf-google-address-autocomplete
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Hide Admin Bar From Front End

Plugin Slug:
hide-admin-bar-from-front-end
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Cleanup

Plugin Slug:
image-cleanup
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Import external attachments

Plugin Slug:
import-external-attachments
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations
2,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Wp Brand – Hide menu & Hide Plugin

Plugin Slug:
my-wp-brand
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

ONet Regenerate Thumbnails

Plugin Slug:
onet-regenerate-thumbnails
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Slickstream: Engagement and Conversions

Plugin Slug:
slick-engagement
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Virusdie – One-click website security

Plugin Slug:
virusdie
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-permalink-translator
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP YouTube Live

Plugin Slug:
wp-youtube-live
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Writesonic

Plugin:
Writesonic
Plugin Slug:
writesonic
Installations
2,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Omnipress

Plugin:
Omnipress
Plugin Slug:
omnipress
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

IS-theme-companion

Plugin Slug:
weblizar-companion
Installations
1,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Football Pool

Plugin Slug:
football-pool
Installations
900+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PlatiOnline Payments

Plugin Slug:
plationline
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Spreadconnect

Plugin Slug:
wc-spod
Installations
800+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
add-replace-affiliate-links-for-amazon
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Thumbnail Editor

Plugin Slug:
thumbnail-editor
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Trusty Whistleblowing Solution

Plugin Slug:
trusty-whistleblowing-solution
Installations
600+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP DataTable

Plugin Slug:
wp-datatable
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Dashboard Widget Sidebar

Plugin Slug:
dashboard-widget-sidebar
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

iCount Payment Gateway

Plugin Slug:
icount
Installations
500+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EC Stars Rating

Plugin Slug:
ec-stars-rating
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Theme Junkie Team Content

Plugin Slug:
theme-junkie-team-content
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Abandoned Contact Form 7

Plugin Slug:
abandoned-contact-form-7
Installations
200+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Accept Stripe Payments Using Contact Form 7

Plugin Slug:
accept-stripe-payments-using-contact-form-7
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aviation Weather from NOAA

Plugin Slug:
aviation-weather-from-noaa
Installations
200+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Osom Blocks

Plugin Slug:
osomblocks
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Accept Authorize.NET Payments Using Contact Form 7

Plugin Slug:
accept-authorize-net-payments-using-contact-form-7
Installations
100+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Content Manager Light

Plugin Slug:
content-manager-light
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Forum Server

Plugin Slug:
forum-server
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Forum Server

Plugin Slug:
forum-server
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

HidePost

Plugin:
HidePost
Plugin Slug:
hidepost
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

National Weather Service Alerts

Plugin Slug:
national-weather-service-alerts
Installations
100+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Navayan Subscribe

Plugin Slug:
navayan-subscribe
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OnionBuzz

Plugin:
OnionBuzz
Plugin Slug:
onionbuzz-viral-quiz
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pre-Publish Post Checklist

Plugin Slug:
pre-publish-post-checklist
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Raise The Money

Plugin Slug:
raise-the-money
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Relocate Upload

Plugin Slug:
relocate-upload
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Twitch TV Embed Suite

Plugin Slug:
twitch-tv-embed-suite
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP DB Booster

Plugin Slug:
wp-db-booster
Installations
100+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Optimizer

Plugin Slug:
wp-optimizer
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WPShapere Lite

Plugin Slug:
wpshapere-lite
Installations
100+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

xili-dictionary

Plugin Slug:
xili-dictionary
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
90+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

MDJM Event Management

Plugin Slug:
mobile-dj-manager
Installations
90+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Track Everything

Plugin Slug:
track-everything
Installations
90+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Photo Express for Google

Plugin Slug:
photo-express-for-google
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

My Resume Builder

Plugin Slug:
my-resume-builder
Installations
70+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

DirectIQ Email Marketing

Plugin Slug:
directiq-wp
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

A/B Testing for WordPress

Plugin:
A/B Testing for WordPress
Plugin Slug:
ab-testing-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aioseo Multibyte Descriptions

Plugin:
Aioseo Multibyte Descriptions
Plugin Slug:
aioseo-multibyte-descriptions
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Backwp

Plugin:
Backwp
Plugin Slug:
backwp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Beauty Contact Popup Form

Plugin:
Beauty Contact Popup Form
Plugin Slug:
beauty-contact-popup-form
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CMS Blocks

Plugin:
CMS Blocks
Plugin Slug:
cms-blocks
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form – 7 : Hide Success Message

Plugin:
Contact Form – 7 : Hide Success Message
Plugin Slug:
contact-form-7-hide-success-message
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

CTUsers

Plugin:
CTUsers
Plugin Slug:
ctuser
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Davenport – Versatile Blog and Magazine WordPress Theme

Plugin:
Davenport – Versatile Blog and Magazine WordPress Theme
Plugin Slug:
davenport
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Devnex Addons For Elementor

Plugin:
Devnex Addons For Elementor
Plugin Slug:
devnex-addons-for-elementor
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Drive Folder Embedder

Plugin:
Drive Folder Embedder
Plugin Slug:
drive-folder-embeder
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

enigma-buttons

Plugin:
enigma-buttons
Plugin Slug:
e.nigma buttons
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Evangelische Termine

Plugin:
Evangelische Termine
Plugin Slug:
evangtermine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

File Manager Plugin For WordPress

Plugin:
File Manager Plugin For WordPress
Plugin Slug:
file-manager-plugin-for-wordpress
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

FL3R Accessibility Suite

Plugin:
FL3R Accessibility Suite
Plugin Slug:
fl3r-accessibility-suite
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Flexo Counter

Plugin:
Flexo Counter
Plugin Slug:
flexo-countdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Free Downloads EDD

Plugin:
Free Downloads EDD
Plugin Slug:
free-downloads-edd
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

FW Food Menu

Plugin:
FW Food Menu
Plugin Slug:
fw-food-menu
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FW Gallery
Plugin Slug:
fw-gallery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FW Gallery
Plugin Slug:
fw-gallery
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Game Users Share Buttons

Plugin:
Game Users Share Buttons
Plugin Slug:
game-users-share-buttons
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

GC Social Wall

Plugin:
GC Social Wall
Plugin Slug:
gc-social-wall
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

GG Bought Together for WooCommerce

Plugin:
GG Bought Together for WooCommerce
Plugin Slug:
gg-bought-together
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Homerunner

Plugin:
Homerunner
Plugin Slug:
homerunner-smartcheckout
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Image Shadow

Plugin:
Image Shadow
Plugin Slug:
image-shadow
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Image Slider With Description

Plugin:
Image Slider With Description
Plugin Slug:
image-slider-with-description
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Products to WooCommerce

Plugin:
Amazon Products to WooCommerce
Plugin Slug:
import-products-to-wc
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Namasha By Mdesign

Plugin:
Namasha By Mdesign
Plugin Slug:
namasha-by-mdesign
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opal Estate Pro

Plugin:
Opal Estate Pro
Plugin Slug:
opal-estate-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Plugin Inspector

Plugin:
Plugin Inspector
Plugin Slug:
plugin-inspector
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Podcast Feed Player Widget and Shortcode

Plugin:
Podcast Feed Player Widget and Shortcode
Plugin Slug:
podcast-feed-player-widget
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Post Rating and Review

Plugin:
Post Rating and Review
Plugin Slug:
post-rating-and-review
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PT Project Notebooks

Plugin:
PT Project Notebooks
Plugin Slug:
project-notebooks
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Simple Link Directory
Plugin Slug:
qc-simple-link-directory
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Quick Favicon

Plugin:
Quick Favicon
Plugin Slug:
quick-favicon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

re.place

Plugin:
re.place
Plugin Slug:
replace
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Responsive Food and Drink Menu

Plugin:
Responsive Food and Drink Menu
Plugin Slug:
responsive-food-and-drink-menu
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Owl carousel responsive
Plugin Slug:
responsive-owl-carousel
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RSS Digest

Plugin:
RSS Digest
Plugin Slug:
rss-digest
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SB Breadcrumbs

Plugin:
SB Breadcrumbs
Plugin Slug:
sb-breadcrumbs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP SmartPay

Plugin:
WP SmartPay
Plugin Slug:
smartpay
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Spo?eczno?ciowa 6 PL 2013

Plugin:
Spo?eczno?ciowa 6 PL 2013
Plugin Slug:
spolecznosciowa-6-pl-2013
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The Countdown – Block Countdown Timer

Plugin:
The Countdown – Block Countdown Timer
Plugin Slug:
the-countdown
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

The Pack Elementor addons

Plugin:
The Pack Elementor addons
Plugin Slug:
the-pack-addon
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

TimeZoneCalculator

Plugin:
TimeZoneCalculator
Plugin Slug:
timezonecalculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tournament Bracket Generator

Plugin:
Tournament Bracket Generator
Plugin Slug:
tournament-bracket-generator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Rankie

Plugin:
Rankie
Plugin Slug:
valvepress-rankie
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

VG WORT METIS

Plugin:
VG WORT METIS
Plugin Slug:
vgw-metis
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VG WORT METIS

Plugin:
VG WORT METIS
Plugin Slug:
vgw-metis
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

VR Calendar

Plugin:
VR Calendar
Plugin Slug:
vr-calendar-sync
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

web-cam

Plugin:
web-cam
Plugin Slug:
web-cam
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Email Address Security by WebEmailProtector

Plugin:
Email Address Security by WebEmailProtector
Plugin Slug:
webemailprotector
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Event RSVP and Simple Event Management Plugin

Plugin:
Event RSVP and Simple Event Management Plugin
Plugin Slug:
wp-easy-events
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP GDPR Cookie Consent
Plugin Slug:
wp-gdpr-cookie-consen
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JobSearch

Plugin:
JobSearch
Plugin Slug:
wp-jobsearch
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Optimize By xTraffic

Plugin:
WP Optimize By xTraffic
Plugin Slug:
wp-optimize-by-xtraffic
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP-PhotoNav

Plugin:
WP-PhotoNav
Plugin Slug:
wp-photonav
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP-Recall

Plugin:
WP-Recall
Plugin Slug:
wp-recall
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP SoundSystem

Plugin:
WP SoundSystem
Plugin Slug:
wp-soundsystem
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Visual Sitemap

Plugin:
WP Visual Sitemap
Plugin Slug:
wp-visual-sitemap
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Wall

Plugin:
WP Wall
Plugin Slug:
wp-wall
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPCRM – CRM for Contact form CF7 & WooCommerce

Plugin:
WPCRM – CRM for Contact form CF7 & WooCommerce
Plugin Slug:
wpcrm
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WPKit For Elementor

Plugin:
WPKit For Elementor
Plugin Slug:
wpkit-elementor
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ninja Forms – The Contact Form Builder That Grows With You

Plugin Slug:
ninja-forms
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.10.2.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.10.2.2.

Royal Elementor Addons and Templates

Plugin Slug:
royal-elementor-addons
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.1025
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.1025.

SiteOrigin Widgets Bundle

Plugin Slug:
so-widgets-bundle
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.69.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.69.0.

Burst Statistics – Privacy-Friendly Analytics for WordPress

Plugin Slug:
burst-statistics
Installations
300,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.0.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.8.

Firelight Lightbox

Plugin Slug:
easy-fancybox
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.16
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.16.

Qi Addons For Elementor

Plugin Slug:
qi-addons-for-elementor
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.2.
Plugin Slug:
responsive-lightbox
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

Ninja Tables – Easy Data Table Builder

Plugin Slug:
ninja-tables
Installations
80,000+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
5.0.19
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.0.19.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.22.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.20
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.20.

HT Slider For Elementor

Plugin Slug:
ht-slider-for-elementor
Installations
20,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.6.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.6.6.

Frontend Admin by DynamiApps

Plugin Slug:
acf-frontend-form-element
Installations
10,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
3.28.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.28.8.

BuddyPress Docs

Plugin Slug:
buddypress-docs
Installations
8,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.5.

AI ChatBot for WordPress – WPBot

Plugin Slug:
chatbot
Installations
7,000+
Vulnerability:
Broken Access Control
Patched in Version:
6.7.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.7.5.

Hotel Booking

Plugin Slug:
nd-booking
Installations
5,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

Post Carousel Slider for Elementor

Plugin Slug:
post-carousel-slider-for-elementor
Installations
4,000+
Vulnerability:
Broken Access Control
Patched in Version:
1.7.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.7.0.

Responsive Blocks – WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.7.

HT Mega – Absolute Addons for WPBakery Page Builder

Plugin Slug:
ht-mega-for-wpbakery
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.0.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.0.9.

Off-Canvas Sidebars & Menus (Slidebars)

Plugin Slug:
off-canvas-sidebars
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.5.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.5.8.5.

Popup addon for Ninja Forms

Plugin Slug:
popup-addon-for-ninja-forms
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.

WP AdCenter – Ad Manager & Adsense Ads

Plugin Slug:
wpadcenter
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.1.

Image Editor by Pixo

Plugin Slug:
image-editor-by-pixo
Installations
800+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.7.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form
Installations
700+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.59.

SmartAgenda – Prise de rendez-vous en ligne

Plugin Slug:
smart-agenda-prise-de-rendez-vous-en-ligne
Installations
500+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.0.

Conference Scheduler

Plugin Slug:
conference-scheduler
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.2.

Audio Editor & Recorder

Plugin Slug:
audio-editor-recorder
Installations
200+
Vulnerability:
Sensitive Data Exposure
Patched in Version:
2.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.4.

Euro FxRef Currency Converter

Plugin Slug:
euro-fxref-currency-converter
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.3.

SERPed.net

Plugin:
SERPed.net
Plugin Slug:
serped-net
Installations
200+
Vulnerability:
Local File Inclusion
Patched in Version:
4.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.

WP Masonry & Infinite Scroll

Plugin Slug:
wp-masonry-infinite-scroll
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.3.

isMobile() Shortcode for WordPress

Plugin Slug:
ismobile
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.2.

Modern Design Library

Plugin Slug:
mdl-shortcodes
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.1.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.1.5.

Simple Payment

Plugin Slug:
simple-payment
Installations
40+
Vulnerability:
Bypass Vulnerability
Patched in Version:
2.3.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.3.9.

Aiomatic

Plugin:
Aiomatic
Plugin Slug:
aiomatic-automatic-ai-content-writer
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.5.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.1.

BeeTeam368 Extensions

Plugin:
BeeTeam368 Extensions
Plugin Slug:
beeteam368-extensions
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.5.

BeeTeam368 Extensions Pro

Plugin:
BeeTeam368 Extensions Pro
Plugin Slug:
beeteam368-extensions-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
2.3.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.3.5.

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin:
Drag and Drop Multiple File Upload (Pro) – WooCommerce
Plugin Slug:
drag-and-drop-file-upload-wc-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.0.7.

Everest Forms Pro

Plugin:
Everest Forms Pro
Plugin Slug:
everest-forms-pro
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.9.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.5.

JetEngine

Plugin:
JetEngine
Plugin Slug:
jet-engine
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.7.1.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.7.1.1.

BRW

Plugin:
BRW
Plugin Slug:
ova-brw
Vulnerability:
Local File Inclusion
Patched in Version:
1.8.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.8.8.

Team Showcase

Plugin:
Team Showcase
Plugin Slug:
team-showcase-cm
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
25.05.13
Severity Score:
High
The vulnerability has been patched, so you should update to version 25.05.13.

Zikzag Core

Plugin:
Zikzag Core
Plugin Slug:
zikzag-core
Vulnerability:
Local File Inclusion
Patched in Version:
1.4.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.4.6.

WordPress Themes — 15 Patched / 23 Unpatched

Constructor

Theme Slug:
constructor
Downloads
435,600
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

Zita

Theme:
Zita
Theme Slug:
zita
Downloads
405,845
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

PrintXtore

Theme:
PrintXtore
Theme Slug:
bw-printxtore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Zenny

Theme:
Zenny
Theme Slug:
bw-zenny
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

CityGov

Theme:
CityGov
Theme Slug:
citygov
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Domnoo

Theme:
Domnoo
Theme Slug:
domnoo
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Homey

Theme:
Homey
Theme Slug:
homey
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Katerio – Magazine

Theme:
Katerio – Magazine
Theme Slug:
katerio
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

LMS

Theme:
LMS
Theme Slug:
lms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

LMS

Theme:
LMS
Theme Slug:
lms
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

LogisticsHub

Theme:
LogisticsHub
Theme Slug:
logistics-hub
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

MagOne

Theme:
MagOne
Theme Slug:
magone
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

MBStore – Digital WooCommerce WordPress Theme

Theme:
MBStore – Digital WooCommerce WordPress Theme
Theme Slug:
mbstore
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Nuss

Theme:
Nuss
Theme Slug:
nuss
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Pressroom – News Magazine WordPress Theme

Theme:
Pressroom – News Magazine WordPress Theme
Theme Slug:
pressroom
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

RealtyElite

Theme:
RealtyElite
Theme Slug:
realtyelite
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Red Art

Theme:
Red Art
Theme Slug:
redart
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sala

Theme:
Sala
Theme Slug:
sala
Vulnerability:
PHP Object Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Samex – Clean, Minimal Shop WooCommerce WordPress Theme

Theme:
Samex – Clean, Minimal Shop WooCommerce WordPress Theme
Theme Slug:
samex
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Seven Stars

Theme:
Seven Stars
Theme Slug:
sevenstars
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

SNS Vicky

Theme:
SNS Vicky
Theme Slug:
snsvicky
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Sofass

Theme:
Sofass
Theme Slug:
sofass
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Blogbyte

Theme:
Blogbyte
Theme Slug:
blogbyte
Downloads
5,082
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.2.

Blogmine

Theme:
Blogmine
Theme Slug:
blogmine
Downloads
3,498
Vulnerability:
Local File Inclusion
Patched in Version:
1.1.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.8.

Blogprise

Theme Slug:
blogprise
Downloads
5,171
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.10.

Blogty

Theme:
Blogty
Theme Slug:
blogty
Downloads
3,128
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.12
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.12.

Blogvy

Theme:
Blogvy
Theme Slug:
blogvy
Downloads
4,752
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.8.

Magty

Theme:
Magty
Theme Slug:
magty
Downloads
2,670
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.7.

Magways

Theme:
Magways
Theme Slug:
magways
Downloads
1,899
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

Magze

Theme:
Magze
Theme Slug:
magze
Downloads
3,707
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.10
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.10.

Neom Blog

Theme Slug:
neom-blog
Downloads
22,211
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
0.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 0.1.0.

Amely

Theme:
Amely
Theme Slug:
amely
Vulnerability:
SQL Injection
Patched in Version:
3.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.0.

DWT – Directory & Listing

Theme:
DWT – Directory & Listing
Theme Slug:
dwt-listing
Vulnerability:
Privilege Escalation
Patched in Version:
3.3.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.3.7.

Elessi

Theme:
Elessi
Theme Slug:
elessi-theme
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

Greenmart

Theme:
Greenmart
Theme Slug:
greenmart
Vulnerability:
Local File Inclusion
Patched in Version:
4.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.2.4.

Litho

Theme:
Litho
Theme Slug:
litho
Vulnerability:
Arbitrary File Deletion
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

Puca

Theme:
Puca
Theme Slug:
puca
Vulnerability:
Local File Inclusion
Patched in Version:
2.6.34
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.6.34.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security