WordPress Vulnerability Report

WordPress Vulnerability Report — July 9, 2025

Since last week, 149 new vulnerabilities emerged in the WordPress ecosystem, including 126 plugins and 23 themes. 84 of the vulnerable plugins and themes remain unpatched, but Solid Security Pro users are protected by virtual patching from Patchstack.

Avatar photo
Sarah Ulmer

In this report, 149 vulnerabilities have been publicly disclosed. Security patches for 65 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 84 plugin and theme vulnerabilities, and no patch has been available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of LowMediumHigh, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.8.1 was released on April 30, 2025. This maintenance release includes fixes for 15 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress, including the block editor, multisite, and REST API. For a full list, refer to the release candidate announcement.

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 51 Patched / 75 Unpatched

Soumettre.fr

Plugin Slug:
soumettre-fr
Installations
10,000+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Low
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 reCAPTCHA

Plugin Slug:
contact-form-7-recaptcha
Installations
6,000+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Chatra Live Chat + ChatBot + Cart Saver

Plugin Slug:
chatra-live-chat
Installations
4,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

(Simply) Guest Author Name

Plugin Slug:
guest-author-name
Installations
3,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Leyka

Plugin:
Leyka
Plugin Slug:
leyka
Installations
2,000+
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WC Pickup Store

Plugin Slug:
wc-pickup-store
Installations
2,000+
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Frontend File Manager Plugin

Plugin Slug:
nmedia-user-file-uploader
Installations
1,000+
Vulnerability:
Content Injection
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WP fancybox

Plugin Slug:
wp-fancybox
Installations
1,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
bulk-featured-image
Installations
900+
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener Plugin For WordPress

Plugin Slug:
exact-links
Installations
700+
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
gallery-widget
Installations
600+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

OwnerRez

Plugin:
OwnerRez
Plugin Slug:
ownerrez
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Easy Elements Hider

Plugin Slug:
easy-elements-hider
Installations
400+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Aviation Weather from NOAA

Plugin Slug:
aviation-weather-from-noaa
Installations
200+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Form 7 Editor Button

Plugin Slug:
cf7-editor-button
Installations
200+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

bSecure – Your Universal Checkout

Plugin Slug:
bsecure
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Dot html,php,xml etc pages

Plugin Slug:
dot-htmlphpxml-etc-pages
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

SMu Manual DoFollow

Plugin Slug:
manuall-dofollow
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Media Folder

Plugin Slug:
media-folder
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Pay with Contact Form 7

Plugin Slug:
pay-with-contact-form-7
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Tennis Court Bookings

Plugin Slug:
tennis-court-bookings
Installations
100+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Video List Manager

Plugin Slug:
video-list-manager
Installations
100+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Infility Global

Plugin Slug:
infility-global
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Paytiko for WooCommerce

Plugin Slug:
paytiko
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Smart Docs

Plugin:
Smart Docs
Plugin Slug:
smart-docs
Installations
80+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More

Plugin Slug:
ultimate-push-notifications
Installations
80+
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Posts Slider Shortcode

Plugin Slug:
posts-slider-shortcode
Installations
40+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Cool fade popup

Plugin Slug:
cool-fade-popup
Installations
30+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Card flip image slideshow

Plugin Slug:
card-flip-image-slideshow
Installations
10+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Custom Login And Signup Widget

Plugin Slug:
custom-login-and-signup-widget
Installations
10+
Vulnerability:
Arbitrary Code Execution
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
pixelating-image-slideshow-gallery
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
wp-iframe-images-gallery
Installations
10+
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

CF7 7 Mailchimp Add-on

Plugin:
CF7 7 Mailchimp Add-on
Plugin Slug:
CF7-mailchimp-addon
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Product Multi-Action

Plugin:
WooCommerce Product Multi-Action
Plugin Slug:
Woo-product-multiaction
Vulnerability:
Deserialization of untrusted data
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Allmart

Plugin:
Allmart
Plugin Slug:
allmart-core
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro Plugin

Plugin:
Ads Pro Plugin
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Ads Pro Plugin

Plugin:
Ads Pro Plugin
Plugin Slug:
ap-plugin-scripteo
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)

Plugin:
Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer)
Plugin Slug:
azon-addon-js-composer
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Booking X

Plugin:
Booking X
Plugin Slug:
booking-x
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Contact Us page – Contact people LITE

Plugin:
Contact Us page – Contact people LITE
Plugin Slug:
contact-us-page-contact-people
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

DocCheck Login

Plugin:
DocCheck Login
Plugin Slug:
doccheck-login
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Shop Page Builder

Plugin:
WooCommerce Shop Page Builder
Plugin Slug:
dzs-wootable
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

EventON

Plugin:
EventON
Plugin Slug:
eventon
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.
Plugin:
FW Gallery
Plugin Slug:
fw-gallery
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

GoZen Forms

Plugin:
GoZen Forms
Plugin Slug:
gozen-forms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

WP Human Resource Management

Plugin:
WP Human Resource Management
Plugin Slug:
hrm
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Human Resource Management

Plugin:
WP Human Resource Management
Plugin Slug:
hrm
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Amazon Products to WooCommerce

Plugin:
Amazon Products to WooCommerce
Plugin Slug:
import-products-to-wc
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

JKDEVKIT

Plugin:
JKDEVKIT
Plugin Slug:
jkdevkit
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

LoginWP – Pro

Plugin:
LoginWP – Pro
Plugin Slug:
loginwp-pro
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Magic Buttons for Elementor

Plugin:
Magic Buttons for Elementor
Plugin Slug:
magic-buttons-for-elementor
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

MF Plus WPML

Plugin:
MF Plus WPML
Plugin Slug:
mf-plus-wpml
Vulnerability:
Settings Change
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Opal Estate Pro

Plugin:
Opal Estate Pro
Plugin Slug:
opal-estate-pro
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

PrivateContent – Mail Actions

Plugin:
PrivateContent – Mail Actions
Plugin Slug:
private-content-mail-actions
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

ProcessingJS for WordPress

Plugin:
ProcessingJS for WordPress
Plugin Slug:
processingjs-for-wp
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Profiler – What Slowing Down Your WP

Plugin:
Profiler – What Slowing Down Your WP
Plugin Slug:
profiler-what-slowing-down
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

RD Contacto

Plugin:
RD Contacto
Plugin Slug:
rd-wapp
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

Multi-language Responsive Contact Form

Plugin:
Multi-language Responsive Contact Form
Plugin Slug:
responsive-contact-form
Vulnerability:
Broken Access Control
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Service Finder Booking

Plugin:
Service Finder Booking
Plugin Slug:
sf-booking
Vulnerability:
Privilege Escalation
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should deactivate the plugin.

Super Store Finder

Plugin:
Super Store Finder
Plugin Slug:
superstorefinder-wp
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Email Address Security by WebEmailProtector

Plugin:
Email Address Security by WebEmailProtector
Plugin Slug:
webemailprotector
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

PayMaster for WooCommerce

Plugin:
PayMaster for WooCommerce
Plugin Slug:
woocommerce-paymaster-gateway-019
Vulnerability:
Server Side Request Forgery (SSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auto Spinner

Plugin:
WordPress Auto Spinner
Plugin Slug:
wp-auto-spinner
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

WP Firebase Push Notification

Plugin:
WP Firebase Push Notification
Plugin Slug:
wp-push-notification-firebase
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
Medium
The vulnerability has not been patched. You should deactivate the plugin.

WPQuiz

Plugin:
WPQuiz
Plugin Slug:
wpquiz
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

yContributors

Plugin:
yContributors
Plugin Slug:
ycontributors
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should deactivate the plugin.

Premium Addons for Elementor

Plugin Slug:
premium-addons-for-elementor
Installations
700,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.10.70
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 4.10.70.

Migration, Backup, Staging – WPvivid Backup & Migration

Plugin Slug:
wpvivid-backuprestore
Installations
700,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
0.9.117
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 0.9.117.

Contact Form 7 Database Addon – CFDB7

Plugin Slug:
contact-form-cfdb7
Installations
600,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.3.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.2.

WP Shortcodes Plugin — Shortcodes Ultimate

Plugin Slug:
shortcodes-ultimate
Installations
500,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.4.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.4.1.

SureForms – Drag and Drop Form Builder for WordPress

Plugin Slug:
sureforms
Installations
200,000+
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.7.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.7.4.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.8.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.8.5.

AI Engine

Plugin:
AI Engine
Plugin Slug:
ai-engine
Installations
100,000+
Vulnerability:
Open Redirection
Patched in Version:
2.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.8.5.

Element Pack Elementor Addons and Templates

Plugin Slug:
bdthemes-element-pack-lite
Installations
100,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.1.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.1.0.

Contact Form by Everest Forms – Simple Contact Form to Advanced Contact Form, Quiz, Survey, & Custom Contact Form Builder for WordPress

Plugin Slug:
everest-forms
Installations
100,000+
Vulnerability:
PHP Object Injection
Patched in Version:
3.2.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.3.

Ultra Addons for Contact Form 7

Plugin Slug:
ultimate-addons-for-contact-form-7
Installations
60,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.5.22
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.5.22.
Plugin Slug:
beautiful-and-responsive-cookie-consent
Installations
40,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
4.6.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.6.2.

Download Plugin

Plugin Slug:
download-plugin
Installations
40,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
2.2.9
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.2.9.

WP Visitor Statistics (Real Time Traffic)

Plugin Slug:
wp-stats-manager
Installations
30,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
7.9
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 7.9.
Plugin Slug:
portfolio-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
3.2.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 3.2.1.

All-in-One Addons for Elementor – WidgetKit

Plugin Slug:
widgetkit-for-elementor
Installations
10,000+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.5.5
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.5.5.

WP Compress – Instant Performance & Speed Optimization

Plugin Slug:
wp-compress-image-optimizer
Installations
9,000+
Vulnerability:
Broken Authentication
Patched in Version:
6.30.31
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.30.31.

Melapress File Monitor

Plugin Slug:
website-file-changes-monitor
Installations
5,000+
Vulnerability:
Broken Access Control
Patched in Version:
2.2.0
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.2.0.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar
Installations
4,000+
Vulnerability:
SQL Injection
Patched in Version:
3.2.18
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.2.18.

VikRentCar Car Rental Management System

Plugin Slug:
vikrentcar
Installations
4,000+
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.4.4
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.4.4.

WP Travel Gutenberg Blocks

Plugin Slug:
wp-travel-blocks
Installations
1,000+
Vulnerability:
Local File Inclusion
Patched in Version:
3.9.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.9.1.

Booking Calendar Contact Form

Plugin Slug:
booking-calendar-contact-form
Installations
600+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.2.59
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.2.59.
Plugin Slug:
ngg-smart-image-search
Installations
500+
Vulnerability:
SQL Injection
Patched in Version:
3.4.3
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.4.3.

PW WooCommerce On Sale!

Plugin Slug:
pw-woocommerce-on-sale
Installations
400+
Vulnerability:
Broken Access Control
Patched in Version:
1.40
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.40.

Easy restaurant menu manager

Plugin Slug:
easy-pdf-restaurant-menu-upload
Installations
300+
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0.2
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.0.2.

Trust Payments Gateway for WooCommerce (JavaScript Library)

Plugin Slug:
trust-payments-gateway-3ds2
Installations
300+
Vulnerability:
Cross Site Request Forgery (CSRF)
Patched in Version:
1.3.7
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 1.3.7.

Click & Pledge Connect

Plugin Slug:
click-pledge-connect
Installations
200+
Vulnerability:
Privilege Escalation
Patched in Version:
25.07000000-WP6.8.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 25.07000000-WP6.8.1.

Easy Stripe – Tips, Payments, and Donations

Plugin Slug:
easy-stripe
Installations
40+
Vulnerability:
Remote Code Execution (RCE)
Patched in Version:
1.2
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.2.

Site Chat on Telegram

Plugin Slug:
site-chat-on-telegram
Installations
20+
Vulnerability:
PHP Object Injection
Patched in Version:
1.0.6
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.0.6.

All In One Slider Responsive

Plugin:
All In One Slider Responsive
Plugin Slug:
all_in_one_carousel
Vulnerability:
SQL Injection
Patched in Version:
3.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.8.

Case Theme User

Plugin:
Case Theme User
Plugin Slug:
case-theme-user
Vulnerability:
Local File Inclusion
Patched in Version:
1.0.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.0.4.

CMSMasters Content Composer

Plugin:
CMSMasters Content Composer
Plugin Slug:
cmsmasters-content-composer
Vulnerability:
Local File Inclusion
Patched in Version:
2.5.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.5.7.

CouponXxL Custom Post Types

Plugin:
CouponXxL Custom Post Types
Plugin Slug:
couponxxl-cpt
Vulnerability:
Privilege Escalation
Patched in Version:
3.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 3.1.

CSS3 Vertical Web Pricing Tables

Plugin:
CSS3 Vertical Web Pricing Tables
Plugin Slug:
css3_vertical_web_pricing_tables
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.0
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.

CSS3 Compare Pricing Tables for WordPress

Plugin:
CSS3 Compare Pricing Tables for WordPress
Plugin Slug:
css3_web_pricing_tables_grids
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
11.7
Severity Score:
High
The vulnerability has been patched, so you should update to version 11.7.

Drag and Drop Multiple File Upload (Pro) – WooCommerce

Plugin:
Drag and Drop Multiple File Upload (Pro) – WooCommerce
Plugin Slug:
drag-and-drop-file-uploads-wc-pro
Vulnerability:
Arbitrary File Upload
Patched in Version:
1.7.2,5.0.7
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.7.2,5.0.7.

eventlist

Plugin:
eventlist
Plugin Slug:
eventlist
Vulnerability:
Local File Inclusion
Patched in Version:
2.0.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 2.0.2.

Masteriyo LMS PRO

Plugin:
Masteriyo LMS PRO
Plugin Slug:
learning-management-system-pro
Vulnerability:
Privilege Escalation
Patched in Version:
2.20.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 2.20.1.

PeepSo Core: Groups

Plugin:
PeepSo Core: Groups
Plugin Slug:
peepso-groups
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
6.4.6.1
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 6.4.6.1.

Testimonials Showcase

Plugin:
Testimonials Showcase
Plugin Slug:
testimonials-showcase
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
1.9.18
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.18.

Uncode Core

Plugin:
Uncode Core
Plugin Slug:
uncode-core
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
2.9.4.3
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 2.9.4.3.

WordPress Themes — 14 Patched / 9 Unpatched

Electrician – Electrical Service WordPress

Theme:
Electrician – Electrical Service WordPress
Theme Slug:
electrician
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Easy Video Player WordPress & WooCommerce

Theme:
Easy Video Player WordPress & WooCommerce
Theme Slug:
fwdevp
Vulnerability:
Arbitrary File Download
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Home Villas

Theme:
Home Villas
Theme Slug:
homevillas-real-estate
Vulnerability:
Arbitrary File Deletion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Invico – WordPress Consulting Business Theme

Theme:
Invico – WordPress Consulting Business Theme
Theme Slug:
invico
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Kossy – Minimalist eCommerce WordPress Theme

Theme:
Kossy – Minimalist eCommerce WordPress Theme
Theme Slug:
kossy
Vulnerability:
Local File Inclusion
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

ListingEasy

Theme:
ListingEasy
Theme Slug:
listingeasy
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

LMS

Theme:
LMS
Theme Slug:
lms
Vulnerability:
SQL Injection
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

LogisticsHub

Theme:
LogisticsHub
Theme Slug:
logistics-hub
Vulnerability:
Arbitrary File Upload
Patched in Version:
No Fix
Severity Score:
Critical
The vulnerability has not been patched. You should switch themes.

Ofiz – WordPress Business Consulting Theme

Theme:
Ofiz – WordPress Business Consulting Theme
Theme Slug:
ofiz
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
No Fix
Severity Score:
High
The vulnerability has not been patched. You should switch themes.

Alone

Theme:
Alone
Theme Slug:
alone
Vulnerability:
Arbitrary Code Execution
Patched in Version:
7.8.5
Severity Score:
High
The vulnerability has been patched, so you should update to version 7.8.5.

Amwerk

Theme:
Amwerk
Theme Slug:
amwerk
Vulnerability:
PHP Object Injection
Patched in Version:
1.3.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 1.3.0.

Classiera

Theme:
Classiera
Theme Slug:
classiera
Vulnerability:
SQL Injection
Patched in Version:
4.0.35
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.0.35.

CouponXxL

Theme:
CouponXxL
Theme Slug:
couponxxl
Vulnerability:
PHP Object Injection
Patched in Version:
3.1.0
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.1.0.

Diza

Theme:
Diza
Theme Slug:
diza
Vulnerability:
Local File Inclusion
Patched in Version:
1.3.11
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.3.11.

Education Center

Theme:
Education Center
Theme Slug:
education
Vulnerability:
PHP Object Injection
Patched in Version:
3.6.11
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 3.6.11.

Elessi

Theme:
Elessi
Theme Slug:
elessi-theme
Vulnerability:
Local File Inclusion
Patched in Version:
6.4.1
Severity Score:
High
The vulnerability has been patched, so you should update to version 6.4.1.

Houzez

Theme:
Houzez
Theme Slug:
houzez
Vulnerability:
Local File Inclusion
Patched in Version:
4.0.8
Severity Score:
High
The vulnerability has been patched, so you should update to version 4.0.8.

Networker

Theme:
Networker
Theme Slug:
networker
Vulnerability:
Local File Inclusion
Patched in Version:
1.2.2
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.2.2.

RealHomes

Theme:
RealHomes
Theme Slug:
realhomes
Vulnerability:
Privilege Escalation
Patched in Version:
4.4.1
Severity Score:
Critical
The vulnerability has been patched, so you should update to version 4.4.1.

Vikinger

Theme:
Vikinger
Theme Slug:
vikinger
Vulnerability:
Arbitrary File Deletion
Patched in Version:
1.9.33
Severity Score:
High
The vulnerability has been patched, so you should update to version 1.9.33.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Content Injection
Patched in Version:
8.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.4.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Cross Site Scripting (XSS)
Patched in Version:
8.2.4
Severity Score:
Medium
The vulnerability has been patched, so you should update to version 8.2.4.

WoodMart

Theme:
WoodMart
Theme Slug:
woodmart
Vulnerability:
Local File Inclusion
Patched in Version:
8.2.4
Severity Score:
High
The vulnerability has been patched, so you should update to version 8.2.4.

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security