WordPress Vulnerability Report

WordPress Vulnerability Report — July 30, 2025

Since last week, 113 new vulnerabilities have emerged in the WordPress ecosystem, including 100 plugins and 13 themes. 53 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 113 vulnerabilities have been publicly disclosed. Security patches for 60 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 53 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.2 was released on July 15, 2025. This maintenance release includes fixes for 20 Core tickets and 15 Block Editor issues. For a full list of bug fixes, please refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 50 Patched / 50 Unpatched

Structured Content (JSON-LD) #wpsc

Plugin Slug:
structured-content
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Graphina – Elementor Charts and Graphs

Plugin Slug:
graphina-elementor-charts-and-graphs
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-links-page
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video Blogster Lite

Plugin Slug:
video-blogster-lite
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
featured-image-plus
Installations
700+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Pipes

Plugin:
WP Pipes
Plugin Slug:
wp-pipes
Installations
500+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CaptionPix

Plugin:
CaptionPix
Plugin Slug:
captionpix
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ONLYOFFICE Docs

Plugin Slug:
onlyoffice
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Nginx Cache Purge Preload

Plugin Slug:
fastcgi-cache-purge-and-preload-nginx
Installations
70+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Supreme Addons for Beaver Builder –

Plugin Slug:
supreme-addons-for-beaver-builder-lite
Installations
60+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP Get The Table

Plugin Slug:
wp-get-the-table
Installations
50+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Point Of Sale (POS)

Plugin Slug:
woo-point-of-salepos
Installations
40+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Advanced Google Universal Analytics

Plugin:
Advanced Google Universal Analytics
Plugin Slug:
advanced-google-universal-analytics
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Affiliate Plus

Plugin:
Affiliate Plus
Plugin Slug:
affiliate-plus
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Post Grid Master

Plugin:
Post Grid Master
Plugin Slug:
ajax-filter-posts
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Birth Chart Compatibility

Plugin:
Birth Chart Compatibility
Plugin Slug:
birth-chart-compatibility
Vulnerability:
Full Path Disclosure (FPD)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

bSecure – Your Universal Checkout

Plugin:
bSecure – Your Universal Checkout
Plugin Slug:
bsecure
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Valuation Calculator

Plugin:
Valuation Calculator
Plugin Slug:
commercial-real-estate-valuation-calculator
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Droip

Plugin:
Droip
Plugin Slug:
droip
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Fan Page

Plugin:
Fan Page
Plugin Slug:
fan-page
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Fleetwire Fleet Management

Plugin:
Fleetwire Fleet Management
Plugin Slug:
fleetwire-fleet-management
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Get Youtube Subs

Plugin:
Get Youtube Subs
Plugin Slug:
get-youtube-subs
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

hiWeb Export Posts

Plugin:
hiWeb Export Posts
Plugin Slug:
hiweb-export-posts
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

iThoughts Advanced Code Editor

Plugin:
iThoughts Advanced Code Editor
Plugin Slug:
ithoughts-advanced-code-editor
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Latest Post Accordian Slider

Plugin:
Latest Post Accordian Slider
Plugin Slug:
latest-post-accordian-slider
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Like & Share My Site

Plugin:
Like & Share My Site
Plugin Slug:
like-share-my-site
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LoginWP – Pro

Plugin:
LoginWP – Pro
Plugin Slug:
loginwp-pro
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Mine CloudVod

Plugin:
Mine CloudVod
Plugin Slug:
mine-cloudvod
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

muse.ai video embedding

Plugin:
muse.ai video embedding
Plugin Slug:
muse-ai
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

My Reservation System

Plugin:
My Reservation System
Plugin Slug:
my-reservation-system
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Omnishop

Plugin:
Omnishop
Plugin Slug:
omnishop
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Omnishop

Plugin:
Omnishop
Plugin Slug:
omnishop
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Orion Login with SMS

Plugin:
Orion Login with SMS
Plugin Slug:
orion-login-with-sms
Vulnerability:
Broken Authentication
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

The E-Commerce ERP

Plugin:
The E-Commerce ERP
Plugin Slug:
profitori
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Qwizcards

Plugin:
Qwizcards
Plugin Slug:
qwiz-online-quizzes-and-flashcards
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Realty Portal – Agent

Plugin:
Realty Portal – Agent
Plugin Slug:
realty-portal-agent
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

RT-Theme 18 | Extensions

Plugin:
RT-Theme 18 | Extensions
Plugin Slug:
rt18-extensions
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Social Streams

Plugin:
Social Streams
Plugin Slug:
social-streams
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Station Pro

Plugin:
Station Pro
Plugin Slug:
station-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
Supermalink
Plugin Slug:
supermalink
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Tablesome Table Premium

Plugin:
Tablesome Table Premium
Plugin Slug:
tablesome-premium
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Taeggie Feed

Plugin:
Taeggie Feed
Plugin Slug:
taeggie-feed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Voltax Video Player

Plugin:
Voltax Video Player
Plugin Slug:
voltax-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
WP Applink
Plugin Slug:
wp-applink
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP JobHunt

Plugin:
WP JobHunt
Plugin Slug:
wp-jobhunt
Vulnerability:
Insecure Direct Object References (IDOR)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Wallcreeper

Plugin:
WP Wallcreeper
Plugin Slug:
wp-wallcreeper
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

YANewsflash

Plugin:
YANewsflash
Plugin Slug:
yanewsflash
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
YouTube Embed – YouTube Gallery, Vimeo Gallery – WordPress Plugin
Plugin Slug:
youram-youtube-embed
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Elementor Website Builder – More Than Just a Page Builder

Plugin Slug:
elementor
Installations
10,000,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.30.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.30.3.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.3.

Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES and more

Plugin Slug:
post-smtp
Installations
400,000+
Vulnerability:
Broken Authentication
Patched in Version:
3.3.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.3.0.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.7.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.2.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
2.9.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.5.

Brizy – Page Builder

Plugin Slug:
brizy
Installations
80,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.6.21
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.6.21.

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin

Plugin Slug:
user-registration
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.3.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.3.0.

WP-Members Membership Plugin

Plugin Slug:
wp-members
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.4.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.4.2.

Advanced iFrame

Plugin Slug:
advanced-iframe
Installations
50,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2025.6
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2025.6.

Timber

Plugin:
Timber
Plugin Slug:
timber-library
Installations
30,000+
Vulnerability:
Other Vulnerability Type
Patched in Version:
1.23.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.23.3.

CSS & JavaScript Toolbox

Plugin Slug:
css-javascript-toolbox
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
12.0.3
Severity Score:
High
The vulnerability has been patched, so you should update to version 12.0.3.

Wonder Slider Lite

Plugin Slug:
wonderplugin-slider-lite
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.5.

WP REST Cache

Plugin Slug:
wp-rest-cache
Installations
10,000+
Vulnerability:
Local File Inclusion
Patched in Version:
2025.1.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2025.1.1.

WPeMatico RSS Feed Fetcher

Plugin Slug:
wpematico
Installations
10,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
2.8.8
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.8.

Security Ninja – WordPress Security Plugin & Firewall

Plugin Slug:
security-ninja
Installations
9,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
5.243
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.243.

ProfileGrid – User Profiles, Groups and Communities

Plugin Slug:
profilegrid-user-profiles-groups-and-communities
Installations
7,000+
Vulnerability:
SQL Injection
Patched in Version:
5.9.5.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 5.9.5.4.

Simple File List

Plugin Slug:
simple-file-list
Installations
6,000+
Vulnerability:
Arbitrary File Download
Patched in Version:
6.1.15
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.1.15.

Geo Mashup

Plugin:
Geo Mashup
Plugin Slug:
geo-mashup
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.13.17
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.13.17.

Melapress Login Security

Plugin Slug:
melapress-login-security
Installations
2,000+
Vulnerability:
Privilege Escalation
Patched in Version:
2.2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.0.

Custom API for WP

Plugin Slug:
custom-api-for-wp
Installations
1,000+
Vulnerability:
Privilege Escalation
Patched in Version:
4.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.2.3.

Ebook Store

Plugin Slug:
ebook-store
Installations
1,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
5.8013
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 5.8013.

Ebook Store

Plugin Slug:
ebook-store
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
5.8013
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 5.8013.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Broken Access Control
Patched in Version:
22.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 22.0.

SEOPress for MainWP

Plugin Slug:
seopress-for-mainwp
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
1.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.5.

StreamWeasels Twitch Integration

Plugin Slug:
streamweasels-twitch-integration
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.9.4.

SureDash

Plugin:
SureDash
Plugin Slug:
suredash
Installations
500+
Vulnerability:
Privilege Escalation
Patched in Version:
1.1.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.1.0.

CRM and Lead Management by vcita

Plugin Slug:
crm-customer-relationship-management-by-vcita
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.0.

ReachShip WooCommerce Multi-Carrier & Conditional Shipping

Plugin Slug:
elex-reachship-multi-carrier-conditional-shipping
Installations
100+
Vulnerability:
Arbitrary File Upload
Patched in Version:
4.3.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.3.2.

Dataverse Integration

Plugin Slug:
integration-cds
Installations
100+
Vulnerability:
Privilege Escalation
Patched in Version:
2.81.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.81.1.

WPBookit

Plugin:
WPBookit
Plugin Slug:
wpbookit
Installations
30+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.7.

Elite Video Player

Plugin:
Elite Video Player
Plugin Slug:
elite-video-player
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
10.0.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 10.0.7.

Foxypress

Plugin:
Foxypress
Plugin Slug:
foxypress
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.4.2.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.4.2.2.

WPBakery Page Builder

Plugin:
WPBakery Page Builder
Plugin Slug:
js_composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.5.

Responsive HTML5 Audio Player PRO With Playlist

Plugin:
Responsive HTML5 Audio Player PRO With Playlist
Plugin Slug:
lbg-audio2-html5
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.5.9.

Universal Video Player – Addon for WPBakery Page Builder

Plugin:
Universal Video Player – Addon for WPBakery Page Builder
Plugin Slug:
lbg-universal-video-player-addon-visual-composer
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.2.2.0.

Simple Business Directory Pro

Plugin:
Simple Business Directory Pro
Plugin Slug:
simple-business-directory-pro
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
15.5.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 15.5.2.

Support Board

Plugin:
Support Board
Plugin Slug:
supportboard
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

Support Board

Plugin:
Support Board
Plugin Slug:
supportboard
Vulnerability:
Local File Inclusion
Patched in Version:
3.8.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.1.

Youtube Vimeo Video Player and Slider WP Plugin

Plugin:
Youtube Vimeo Video Player and Slider WP Plugin
Plugin Slug:
video-player-youtube-vimeo
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.

Wonder Slider

Plugin:
Wonder Slider
Plugin Slug:
wonderplugin-slider
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
14.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 14.5.

WordPress Themes — 10 Patched / 3 Unpatched

Educenter

Theme Slug:
educenter
Downloads
175,744
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should switch themes.

News Magazine X

Theme Slug:
news-magazine-x
Downloads
27,720
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

VidMov

Theme:
VidMov
Theme Slug:
vidmov
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Bricks Builder

Theme:
Bricks Builder
Theme Slug:
bricks
Vulnerability:
SQL Injection
Patched in Version:
2.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.0.

Caliris

Theme:
Caliris
Theme Slug:
caliris-wp
Vulnerability:
Local File Inclusion
Patched in Version:
1.6
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.6.

Cena Store

Theme:
Cena Store
Theme Slug:
cena
Vulnerability:
Local File Inclusion
Patched in Version:
2.11.27
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.11.27.

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme:
KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme
Theme Slug:
kallyas
Vulnerability:
Arbitrary File Deletion
Patched in Version:
4.22.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.22.0.

KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme

Theme:
KALLYAS – Creative eCommerce Multi-Purpose WordPress Theme
Theme Slug:
kallyas
Vulnerability:
Local File Inclusion
Patched in Version:
4.22.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.22.0.

MediCenter – Health Medical Clinic

Theme:
MediCenter – Health Medical Clinic
Theme Slug:
medicenter
Vulnerability:
PHP Object Injection
Patched in Version:
15.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 15.2.

MinimogWP

Theme:
MinimogWP
Theme Slug:
minimog
Vulnerability:
Content Injection
Patched in Version:
3.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.1.

Jobmonster

Theme:
Jobmonster
Theme Slug:
noo-jobmonster
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.7.9
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.7.9.

Platform

Theme:
Platform
Theme Slug:
platform
Vulnerability:
Broken Access Control
Patched in Version:
1.4.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.4.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Broken Access Control
Patched in Version:
8.2.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.7.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security